It's this easy to seize control of someone's Nexx 'smart' home plugs, garage doors
- Reference: 1680865214
- News link: https://www.theregister.co.uk/2023/04/07/cisa_nexx_iot_flaws/
- Source link:
After the Internet-of-Things biz reportedly ignored attempts over three months by [1]Sam Sabetan , who discovered the vulnerabilities, and the US government's Cybersecurity and Infrastructure Security Agency (CISA) to help fix the flaws, both Sabetan and Uncle Sam [2]have gone public with the details so users can minimize their risk.
Or better yet, as Sabetan suggests, " [3]immediately unplug all Nexx devices."
[4]
The Register tried to contact Nexx for this story, and the manufacturer didn't respond to our requests, either.
[5]
[6]
As of April 4, CISA said it wasn't aware of exploits that specifically target these vulnerabilities, though now that details are out there, that may change quickly.
The five vulnerabilities affect Nexx garage door controllers (NXG-100B, NXG-200) with firmware version nxg200v-p3-4-1 and prior; Nexx smart plugs (NXPG-100W) version nxpg100cv4-0-0 and prior; and Nexx smart alarms (NXAL-100) version nxal100v-p1-9-1 and prior.
[7]
[8]CVE-2023-1748 is the most serious flaw, and it received a 9.3 out of 10 CVSS severity score. Essentially, vulnerable Nexx smart home products use hard-coded credentials. Miscreants can easily obtain these magic creds from Nexx's mobile app or firmware, and use them to access any stranger's Nexx hardware remotely.
An unauthenticated attacker can use these credentials to access Nexx's Message Queuing Telemetry Transport (MQTT) server — MQTT is the messaging protocol Nexx garage door controllers, smart plugs, and other IoT devices use. From there, the miscreant can see all MQTT messages for Nexx's customers and devices, and send commands to control strangers' garage doors and power plugs.
This is the vulnerability Sabetan said can be exploited to remotely open garage doors, and he shared a [9]video about it on YouTube.
[10]
Because Nexx smart plugs are vulnerable to this flaw, miscreants could turn on and off household appliances connected to these plugs, "or even security cameras," Sabetan added.
The next two vulnerabilities, [11]CVE-2023-1749 and [12]CVE-2023-1750 are insecure direct object reference (IDOR) vulnerabilities. That's a fancy way of saying the devices don't perform sufficient checks when told to do something. In this case, an attacker just needs someone's NexxHome deviceId to send instructions to that person's smart home device, via the Nexx API, and the hardware will just obey it.
A third flaw, [13]CVE-2023-1751 , is due to improper input validation. The affected devices use a WebSocket server to manage messages between Nexx's cloud and the devices.
The server, however, doesn't properly validate if the bearer token in the authorization header belongs to the device trying to connect to the cloud. This could allow any Nexx user with a valid authorization token from a single device to control any smart home alarm.
[14]Hey Siri, use this ultrasound attack to disarm a smart-home system
[15]Smart ovens do really dumb stuff to check for Wi-Fi
[16]Nice smart device – how long does it get software updates?
[17]Swatting suspects charged with subverting Ring doorbell cams and calling cops
Finally, [18]CVE-2023-1752 allows someone to register an already-registered home alarm using the device's MAC address. "As a result, the device is removed from the original owner's account, allowing the attacker to gain full access and arm or disarm the alarm," Sabetan said.
After finding the flaws, Sabetan reached out to Nexx via the vendor's support website on January 4. "Efforts to reach Nexx include support tickets from various accounts, a public phone number found through OSINT, personal email addresses from FCC filings, social media posts on Twitter and Facebook, as well as government and media involvement," he noted.
CISA began trying to contact the IoT device maker later in January. After several more failed attempts over the next few months, on March 16 the agency issued an advisory due to the lack of support from the manufacturer. ®
Get our [19]Tech Resources
[1] https://twitter.com/samsabetan/status/1643276048577224705
[2] https://www.cisa.gov/news-events/ics-advisories/icsa-23-094-01
[3] https://medium.com/@samsabetan/the-uninvited-guest-idors-garage-doors-and-stolen-secrets-e4b49e02dadc
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZDA@JasTwufGViMkAHHoWQAAAIg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZDA@JasTwufGViMkAHHoWQAAAIg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZDA@JasTwufGViMkAHHoWQAAAIg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZDA@JasTwufGViMkAHHoWQAAAIg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-1748
[9] https://youtu.be/kD1cBfv9To8
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZDA@JasTwufGViMkAHHoWQAAAIg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[11] http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-1749
[12] http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-1750
[13] http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-1751
[14] https://www.theregister.com/2023/04/04/siri_alexa_cortana_google_nuit/
[15] https://www.theregister.com/2023/01/26/smart_ovens_do_dumb_stuff/
[16] https://www.theregister.com/2023/01/16/smart_device_software_support/
[17] https://www.theregister.com/2022/12/20/ring_swatting_suspects_charged/
[18] http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-1752
[19] https://whitepapers.theregister.com/
the manufacturer didn't respond to our requests
Perhaps someone remotely turned off their email server.
Elementary, Watson!
Why, why why?!!! Hard coded credentials?
Because security is still not taken seriously by some. Agree with b0llchit that there should be some financial consequences for the manufacturer.
Re: Elementary, Watson!
The problem is that financial consequences mostly aren't consequential. If the fines are small, the company shrugs them off. If they're large, it declares bankruptcy, parachutes out the officers, and the remnants are bought up by a competitor. Many of the employees suffer, including perhaps some of the responsible developers, but not the people calling the shots.
In cases of extreme negligence like this we need the courts to pierce the corporate veil and hold officers to account. I'm not worried about any "chilling effect" on business or innovation; corporatist culture has no shortage of adherents who will be happy to take their place.
If you live in the UK
You can get it repaired under the [1]The Consumer Rights Act 2015 . However since, I suspect, that a fix will never be forthcoming then ask for your money back from the retailer.
I wish that many people would do this because it will make the retailers only sell goods from reputable manufacturers who have a good history of: a) selling stuff that works; b) providing fixes for things like this. Currently many retailers sell whatever is cheap and try to fob off consumers when things are found to be faulty.
[1] https://www.citizensadvice.org.uk/about-us/our-work/citizens-advice-consumer-work/the-consumer-rights-act-2015/
Re: If you live in the UK
I suspect most consumers will never know their kit is vulnerable and will carry on using it regardless, unless things hit the fan or there is huge publicity about the failings of the kit.
"vulnerable Nexx smart home products use hard-coded credentials"
Also known as : hacker paradise.
And the company isn't responding to any questions, official or otherwise ? Well duh, the CEO is busy packing the suitcase with the contents of the cash register and bank account.
He has an urgent meeting in Madagascar, you see.
Where is the product liability
...issued an advisory due to the lack of support from the manufacturer.
Shouldn't this be called criminal negligence ? The C-suite should be personally liable for this crap.