10:05 AM
Connect Directly

Security Holes Exposed In Smart Lighting System

Sylvania Osram Lightify vulnerabilities could allow an attacker to turn out the lights or ultimately infiltrate the corporate network.

Researchers at Rapid7 have uncovered flaws in the Home and Pro versions of Sylvania Osram Lightify products that could allow attackers to hack a corporate network via the lighting system in an office or retail store.  

Deral Heiland, research lead at Rapid7, says his tests were conducted with the full knowledge and cooperation of Sylvania, which already has issued patches for the vast majority of the discovered flaws. The most potentially harmful issues were found in the Pro Edition of the Osram Lightify, which is sold to businesses, mostly offices and retailers. 

The team found that Osram Lightify systems’ installed web management console, which runs on ports 80 and 443, is open to a persistent cross site scripting (XSS) vulnerability that could let a malicious actor inject JavaScript and HTML code into various fields within the Pro web management interface.

The injected code could be executed under the guise of an authenticated user, allowing an attacker to modify the system configuration, exfiltrate or alter stored data, or take controls of the product to launch browser-based attacks against the authenticated user’s workstation that manages the lighting system.

Heiland was also able to wage an XSS attack on the Wireless Client Mode configuration page via another XSS flaw the team found. He did this by using a rogue access point to broadcast via WiFi SSID containing the XSS payload. Using a script command, it’s possible to broadcast the XSS payload as an SSID name. This could allow an attacker to infiltrate the corporate network remotely.

“So essentially, it’s possible to put the exploit code in the SSID,” Heiland explains. “What’s dangerous is that it’s possible to reconfigure the device and then interact with the enterprise corporate network. In fact, the probability of using this to carry out further attacks and exploits against the device and the authenticated user to the device to exploit the network [remotely] is most likely.”

Black Hat USA returns to the fabulous Mandalay Bay in Las Vegas, Nevada July 30 through Aug. 4, 2016. Click for information on the conference schedule and to register.

Heiland also found weak default WPA2 pre-shared keys (PSKs) on the devices he examined: they used an eight-character PSK that used only the characters from the set “0123456789abcdef.” This small keyspace of limited characters and a fixed, short length makes it possible to crack a captured WPA2 authentication handshake, which gives the hacker remote access to the cleartext WPA2 PSK.

“I was able to crack one device in about five hours and another device in about two hours,” Heiland says of his research.

Illuminating the Issue

Heiland added that a vendor-supplied patch will provide longer default PSKs that will use a larger keyspace that includes both uppercase and lowercase alphanumeric characters and punctuation. These are more secure because they are not typically intended to be remembered by humans.

Although the flaws found in the Home version of the Sylvania products were not as serious as the Pro version, Heiland says that it does give both the enterprise and home IoT industry more insight into the potential risk.

The Home edition contained a flaw in the pre-authentication command execution. When Heiland examined the network services on the gateway, he found that port 4000/TCP is used for local control when Internet services are down and it didn’t require authentication to pass commands to this TCP port.

With this access, a hacker can execute commands to change lighting and also execute commands to reconfigure the devices.

“While it’s not as serious as the flaw we found in the Pro edition -- which could access a corporate network -- we thought it was important to point these type of flaws out so they don’t migrate to the Pro editions,” he says.

UPDATE 7/27:

Osram provided this statement to Dark Reading:

"OSRAM agreed to security testing on existing LIGHTIFY products by Security researchers from Rapid7. Since being notified about the vulnerabilities identified by Rapid7, OSRAM has taken actions to analyze, validate and implement a risk-based remediation strategy, and the majority of vulnerabilities will be patched in the next version update, currently planned for release in August. 

Rapid7 security researchers also highlighted certain vulnerabilities within the ZigBee® protocol, which are unfortunately not in OSRAM’s area of influence. OSRAM is in ongoing coordination with the ZigBee® Alliance in relation to known and newly discovered vulnerabilities."

Related Content:



Steve Zurier has more than 30 years of journalism and publishing experience, most of the last 24 of which were spent covering networking and security technology. Steve is based in Columbia, Md. View Full Bio

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
13 Russians Indicted for Massive Operation to Sway US Election
Kelly Sheridan, Associate Editor, Dark Reading,  2/16/2018
From DevOps to DevSecOps: Structuring Communication for Better Security
Robert Hawk, Privacy & Security Lead at xMatters,  2/15/2018
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Current Issue
How to Cope with the IT Security Skills Shortage
Most enterprises don't have all the in-house skills they need to meet the rising threat from online attackers. Here are some tips on ways to beat the shortage.
Flash Poll
[Strategic Security Report] Navigating the Threat Intelligence Maze
[Strategic Security Report] Navigating the Threat Intelligence Maze
Most enterprises are using threat intel services, but many are still figuring out how to use the data they're collecting. In this Dark Reading survey we give you a look at what they're doing today - and where they hope to go.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.