While the number of IoT devices continue to exponentially increase, the level of security of these smart objects is often not adequate end exposes users at risk of cyber attacks.
According to the security advisory, the Miele Professional PG 8528 appliance is affected by a Web Server Directory Traversal vulnerability tracked as CVE-2017-7240. The Miele Professional PG 8528 is a medical equipment used to disinfect laboratory and surgical instruments. The flaw could be exploited by an unauthenticated attacker to access any directory on the web server.
“The corresponding embeded webserver “PST10 WebServer” typically listens to port 80 and is prone to a directory traversal attack, therefore an unauthenticated attacker may be able to exploit this issue to access sensitive information to aide in subsequent attacks.” reads the advisory.
The flaw could allow attackers to access sensitive data on the server, to drop and execute malicious code on the web server.
The flaw was discovered by the expert Jens Regel at the German consultancy Schneider & Wulf who reported the issue to Mele in December 2016. Unfortunately, he did not receive the reply from the company, so after four months he decided to publicly disclose it.
Regel also published a proof-of-concept (PoC) exploit code for this flaw, for this reason, it is important that the vendor will fix the issue as soon as possible.
Do you want to hack the Mele washer-disinfector?
It is simple, the PoC exploit code that is used by the expert to request the embedded system’s shadow file and any file on the filesystem.
Proof of Concept: ================= ~$ telnet 192.168.0.1 80 Trying 192.168.0.1... Connected to 192.168.0.1. Escape character ist '^]'.
GET /../../../../../../../../../../../../etc/shadow HTTP/1.1 to whatever IP the dishwasher has on the LAN.
Waiting for a patch disconnect the washer-disinfector from the Internet.
(Security Affairs – washer-disinfector, hacking)
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.