Got an unpatched LG 'smart' television? It could be watching you back
- Reference: 1712685606
- News link: https://www.theregister.co.uk/2024/04/09/lg_tv_critical_bugs/
- Source link:
Once they have gained root, your TV essentially belongs to the intruder who can use that access to do all sorts of nefarious things including moving laterally through your home network, dropping malware, using the device as part of a botnet, spying on you — or at the very least severely screwing up your streaming service algorithms.
Bitdefender Labs researcher Alexandru Lazăr spotted the four vulnerabilities that affect WebOS versions 4 through 7. In an [1]analysis published today, the security firm noted that while the vulnerable service is only intended for LAN access, more than 91,000 devices are exposed to the internet, according to a Shodan scan.
[2]
Here's a look at the four flaws:
[3]CVE-2023-6317 : a PIN/prompt bypass that allows an attacker to set a variable and add a new user account to the TV without requiring a security PIN. It has a CVSS rating of 7.2.
[4]CVE-2023-6318 : a critical command injection flaw with a 9.1 CVSS rating that allows an attacker to elevate an initial access to root-level privileges and take over the TV.
[5]CVE-2023-6319 : another 9.1-rated command injection vulnerability that can be triggered by manipulating the music-lyrics library.
[6]CVE-2023-6320 : a critical command injection vulnerability that can be triggered by manipulating an API endpoint to allow execution of commands on the device as dbus, which has similar permissions as root. It also received a 9.1 CVSS score.
In order to abuse any of the command injection flaws, however, the attacker must first exploit CVE-2023-6317. This issue is down to WebOS running a service on ports 3000/3001 that allows users to control their TV on their smartphone using a PIN. But, there's a bug in the account handler function that sometimes allows skipping the PIN verification:
The function that handles account registration requests uses a variable called skipPrompt which is set to true when either the client-key or the companion-client-key parameters correspond to an existing profile. It also takes into consideration what permissions are requested when deciding whether to prompt the user for a PIN, as confirmation is not required in some cases.
After creating an account with no permissions, an attacker can then request a new account with elevated privileges "but we specify the companion-client-key variable to match the key we got when we created the first account," the team reports.
[7]Easy-to-use make-me-root exploit lands for recent Linux kernels. Get patching
[8]Chinese smart TV boxes infected with malware in PEACHPIT ad fraud campaign
[9]What can be done to protect open source devs from next xz backdoor drama?
[10]Hotel check-in terminal bug spews out access codes for guest rooms
The server confirms that the key exists, but doesn't verify which account it belongs to, we're told. "Thus, the skipPrompt variable will be true and the account will be created without requesting a PIN confirmation on the TV," the team reports
And then, after creating this account with elevated privileges, an attacker can use that access to exploit the other three flaws that lead to root access or command execution as the dbus user.
[11]
Lazăr responsibly reported the flaws to LG on November 1, 2023, and LG asked for a time extension to fix them. The electronics giant issued patches on March 22. It's a good idea to check your TV for software updates and apply the WebOS patch now. ®
Get our [12]Tech Resources
[1] https://www.bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZhW6hokOFE-d7TbaotkeoQAAAJM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.cve.org/CVERecord?id=CVE-2023-6317
[4] https://www.cve.org/CVERecord?id=CVE-2023-6318
[5] https://www.cve.org/CVERecord?id=CVE-2023-6319
[6] https://www.cve.org/CVERecord?id=CVE-2023-6320
[7] https://www.theregister.com/2024/03/29/linux_kernel_flaw/
[8] https://www.theregister.com/2023/10/09/in_brief_security/
[9] https://www.theregister.com/2024/04/06/register_kettle_xz/
[10] https://www.theregister.com/2024/04/05/hotel_checkin_terminal_bug/
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZhW6hokOFE-d7TbaotkeoQAAAJM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[12] https://whitepapers.theregister.com/
Re: Or your best solution is...
The problem affects people who don't frequent this website and/or aren't aware that a TV tlcould be exploited in this way. Is the inference that anybody who uses apps on TVs is stupid?
The snootiness exhibited by some techies is incredible.
...while the vulnerable service is only intended for LAN access, more than 91,000 devices are exposed to the internet, according to a Shodan scan.
Just how do folks manage that? I mean, just how do they not have NAT/firewall by default, or ended up port-forwarding them for exposure?
your TV essentially belongs to the intruder
Instead of LG, of course. Can't have all that lovely collectible data going to someone other than the mothership.
(Still waiting for 'smart' TVs that will try and hijack your wifi - or even, I suppose, come with a built in secret phone connection. And I note a recent patent from Roku (as reported by Louis Rossman) whereby adverts will be inserted into HDMI streams, irrespective of source.)
Re: your TV essentially belongs to the intruder
Yes.
I work for an advertising agency. LG aggressively markets its TV sets to ad agencies as an advertising vector.
Buy one, if you like, if it's cheap enough, but don't connect it to the network. Get your online content from some kind of separately-securable attached device.
-A.
Or your best solution is...
Whoops, I have one of these TVs. But I have, never, ever, let it have access to the internet. How stupid would you need to be to let your 'smart' TV, which will report everything you're watching back to home base along with photos of your living room at the time, have access to the internet? It's just a dumb screen for the media box.