Advisory Details

September 29th, 2015

(0Day) Moxa OnCell Central Manager Server MessageBrokerServlet Authentication Bypass Vulnerability

ZDI-15-452
ZDI-CAN-2526

CVE ID CVE-2015-6480
CVSS SCORE 7.5, AV:N/AC:L/Au:N/C:P/I:P/A:P
AFFECTED VENDORS Moxa
AFFECTED PRODUCTS OnCell Central Manager
TREND MICRO CUSTOMER PROTECTION Trend Micro TippingPoint IPS customers are protected against this vulnerability by Digital Vaccine protection filter ID ['19418']. For further product information on the TippingPoint IPS: http://www.tippingpoint.com
VULNERABILITY DETAILS


This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Moxa OnCell Central Manager Server. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the MessageBrokerServlet servlet, which does not ensure a user is authenticated prior to accepting commands. An attacker can exploit this condition to perform various actions, including addUserAndGroup, to take full control of the product and achieve code execution on all managed hosts.

ADDITIONAL DETAILS


This vulnerability is being disclosed publicly without a patch in accordance with the ZDI vulnerability disclosure policy on lack of vendor response.

02/05/2015 - ZDI sent reports to ICS-CERT
02/09/2015 - ZDI receieved an ACK and ticket # from ICS-CERT
04/14/2015 - ZDI recieved an update from ICS-CERT that these cases were in work, but "months out"
04/15/2015 - ZDI reminded ISC-CERT of the prediacted disclosure date, but indicated some flexibility if the vendor could come close
05/14/2015 - ICS-CERT advised ZDI that the vendor could not patch until August
05/14/2015 - ZDI agreed to go out to August 5
09/14/2015 - After getting a response that other Moxa cases had patched, but seemingly not these, ZDI asked ICS-CERT if these did not patch with the August 27 patch
09/15/2015 - ICS-CERT indicated that they would reach out to the vendor for clarification and requested extension to do so. ZDI declined an extension, but indicated we "will wait a couple of days, for a status."
09/18/2015 - ZDI notified ICS-CERT of the intent to 0-day the reports

-- Mitigation:
Given the nature of the vulnerability, the only salient mitigation strategy is to restrict interaction with the service to trusted machines. Only the clients and servers that have a legitimate procedural relationship with the service should be permitted to communicate with it. This could be accomplished in a number of ways, most notably with firewall rules/whitelisting. These features are available in the native Windows Firewall, as described in http://technet.microsoft.com/en-us/library/cc725770%28WS.10%29.aspx and numerous other Microsoft Knowledge Base articles.

-- Vendor Patch:
See https://ics-cert.us-cert.gov/advisories/ICSA-15-328-01


DISCLOSURE TIMELINE
  • 2015-02-05 - Vulnerability reported to vendor
  • 2015-09-29 - Coordinated public release of advisory
CREDIT Andrea Micalizzi (rgod)
BACK TO ADVISORIES