|
|
|
View Notes By
|
|
|
|
Other Documents
|
|
|
|
 |
Vulnerability Note VU#362332
Wind River Systems VxWorks debug service enabled by default
OverviewSome products based on VxWorks have the WDB target agent debug service enabled by default. This service provides read/write access to the device's memory and allows functions to be called.
I. DescriptionThe VxWorks WDB target agent is a target-resident, run-time facility that is required for connecting host tools to a VxWorks target system during development. WDB is a selectable component in the VxWorks configuration and is enabled by default. The WDB debug agent access is not secured and does provide a security hole in a deployed system.
It is advisable for production systems to reconfigure VxWorks with only those components needed for deployed operation and to build it as the appropriate type of system image. It is recommended to remove host development components such as the WDB target agent and debugging components (INCLUDE_WDB and INCLUDE_DEBUG) as well as other operating system components that are not required to support customer applications.
Consult the VxWorks Kernel Programmer's guide for more information on WDB.
Additional information can be found in ICS-CERT advisory ICSA-10-214-01 and on the Metasploit Blog.
II. ImpactAn attacker can use the debug service to fully compromise the device.
III. SolutionDisable debug agent
Vendors should remove the WDB target debug agent in their VxWorks based products by removing the INCLUDE_WDB & INCLUDE_DEBUG components from their VxWorks Image.
Restrict access
Appropriate firewall rules should be implemented to restrict access to the debug service (17185/udp) to only trusted sources until vendors have released patches to disable it.
Vendor Information
| Vendor | Status | Date Notified | Date Updated |
| 3com Inc | Affected | 2010-06-14 | 2010-07-27 |
| Actelis Networks | Affected | 2010-06-29 | 2010-07-27 |
| Alcatel-Lucent | Affected | 2010-06-14 | 2010-07-27 |
| Allied Telesis | Affected | 2010-06-29 | 2010-07-27 |
| Alvarion | Affected | 2010-06-29 | 2010-07-27 |
| amx | Affected | 2010-06-29 | 2010-07-27 |
| Aperto Networks | Affected | 2010-06-29 | 2010-07-27 |
| Apple Inc. | Affected | 2010-06-14 | 2010-07-27 |
| ARRIS | Affected | 2010-06-18 | 2011-01-20 |
| Avaya, Inc. | Affected | 2010-06-14 | 2010-07-27 |
| Broadcom | Affected | 2010-06-14 | 2010-07-27 |
| Brocade | Unknown | 2010-08-03 | 2010-08-03 |
| Canon | Not Affected | 2010-06-18 | 2010-08-17 |
| Ceragon Networks Inc | Affected | 2010-06-29 | 2010-07-27 |
| Cisco Systems, Inc. | Affected | 2010-06-14 | 2010-06-23 |
| D-Link Systems, Inc. | Affected | 2010-06-14 | 2010-07-27 |
| Dell Computer Corporation, Inc. | Affected | 2010-06-14 | 2010-07-27 |
| Digicom | Affected | 2010-06-29 | 2010-07-27 |
| DrayTek Corporation | Affected | 2010-06-29 | 2010-07-27 |
| EMC Corporation | Affected | 2010-06-14 | 2010-07-27 |
| Enablence | Affected | 2010-06-29 | 2010-07-27 |
| Enterasys Networks | Affected | 2010-06-18 | 2010-07-27 |
| Epson America, Inc. | Affected | 2010-06-18 | 2010-07-27 |
| Ericsson | Affected | 2010-06-14 | 2010-07-27 |
| Fluke Networks | Affected | 2010-06-14 | 2010-07-27 |
| Foundry Networks, Inc. | Affected | 2010-06-14 | 2010-07-27 |
| Gilat Network Systems | Affected | 2010-06-29 | 2010-07-27 |
| Guangzhou Gaoke Communications | Affected | 2010-06-29 | 2010-07-27 |
| Hewlett-Packard Company | Affected | 2010-06-14 | 2010-07-27 |
| Huawei Technoligies | Affected | 2010-06-18 | 2010-07-27 |
| Intel Corporation | Unknown | 2010-07-02 | 2010-07-27 |
| IWATSU Voice Networks | Affected | 2010-06-29 | 2010-07-27 |
| Keda Communications | Affected | 2010-06-29 | 2010-07-27 |
| Knovative Inc | Affected | 2010-06-29 | 2010-07-27 |
| Lenovo | Affected | 2010-06-14 | 2010-07-27 |
| Lutron Electronics | Affected | 2010-06-29 | 2010-07-27 |
| Maipu Communication Technology | Affected | 2010-06-29 | 2010-07-27 |
| Mitel Networks, Inc. | Affected | 2010-06-14 | 2010-07-27 |
| Motorola, Inc. | Affected | 2010-06-14 | 2010-07-27 |
| Netgear, Inc. | Affected | 2010-06-18 | 2010-07-27 |
| Nokia | Affected | 2010-06-18 | 2010-07-27 |
| Nortel Networks, Inc. | Affected | 2010-06-14 | 2010-07-27 |
| Polycom | Affected | 2010-06-14 | 2010-12-07 |
| Proxim, Inc. | Affected | 2010-06-14 | 2010-07-27 |
| Rad Vision, Inc. | Affected | 2010-06-14 | 2010-07-27 |
| Ricoh Company Ltd. | Affected | 2010-06-14 | 2010-08-06 |
| Rockwell Automation | Affected | 2010-06-15 | 2010-07-30 |
| SFR | Affected | | 2010-09-01 |
| Shoretel Communications, Inc. | Affected | 2010-06-14 | 2010-07-27 |
| Siemens | Affected | 2010-06-14 | 2011-04-29 |
| SMC Networks, Inc. | Affected | 2010-06-18 | 2010-07-27 |
| TRENDnet | Affected | 2010-06-14 | 2010-07-27 |
| Tut Systems, Inc. | Affected | 2010-06-18 | 2010-07-27 |
| Wind River Systems, Inc. | Affected | 2010-06-14 | 2010-08-02 |
| Xerox | Affected | 2010-06-14 | 2010-07-27 |
References
http://www.cisco.com/warp/public/707/cisco-sa-20051116-7920.shtml
http://seclists.org/vuln-dev/2002/May/179
http://blog.metasploit.com/2010/08/vxworks-vulnerabilities.html
http://www.us-cert.gov/control_systems/pdf/ICSA-10-214-01_VxWorks_Vulnerabilities.pdf
http://blogs.windriver.com/chauhan/2010/08/vxworks-secure.html
https://support.windriver.com/olsPortal/faces/maintenance/downloadDetails.jspx?contentId=033708
http://thesauceofutterpwnage.blogspot.com/2010/08/metasploit-vxworks-wdb-agent-attack.html
Credit
Thanks to HD Moore for reporting a wider scope with additional research related to this vulnerability. Earlier public reports came from Bennett Todd and Shawn Merdinger.
This document was written by Jared Allar.
Other Information
| Date Public: | 2010-08-02 |
| Date First Published: | 2010-08-02 |
| Date Last Updated: | 2011-04-29 |
| CERT Advisory: | |
| CVE-ID(s): | |
| NVD-ID(s): | |
| US-CERT Technical Alerts: | |
| Severity Metric: | 14.04 |
| Document Revision: | 72 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
|