Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


10:05 AM
Connect Directly

Security Holes Exposed In Smart Lighting System

Sylvania Osram Lightify vulnerabilities could allow an attacker to turn out the lights or ultimately infiltrate the corporate network.

Researchers at Rapid7 have uncovered flaws in the Home and Pro versions of Sylvania Osram Lightify products that could allow attackers to hack a corporate network via the lighting system in an office or retail store.  

Deral Heiland, research lead at Rapid7, says his tests were conducted with the full knowledge and cooperation of Sylvania, which already has issued patches for the vast majority of the discovered flaws. The most potentially harmful issues were found in the Pro Edition of the Osram Lightify, which is sold to businesses, mostly offices and retailers. 

The team found that Osram Lightify systems’ installed web management console, which runs on ports 80 and 443, is open to a persistent cross site scripting (XSS) vulnerability that could let a malicious actor inject JavaScript and HTML code into various fields within the Pro web management interface.

The injected code could be executed under the guise of an authenticated user, allowing an attacker to modify the system configuration, exfiltrate or alter stored data, or take controls of the product to launch browser-based attacks against the authenticated user’s workstation that manages the lighting system.

Heiland was also able to wage an XSS attack on the Wireless Client Mode configuration page via another XSS flaw the team found. He did this by using a rogue access point to broadcast via WiFi SSID containing the XSS payload. Using a script command, it’s possible to broadcast the XSS payload as an SSID name. This could allow an attacker to infiltrate the corporate network remotely.

“So essentially, it’s possible to put the exploit code in the SSID,” Heiland explains. “What’s dangerous is that it’s possible to reconfigure the device and then interact with the enterprise corporate network. In fact, the probability of using this to carry out further attacks and exploits against the device and the authenticated user to the device to exploit the network [remotely] is most likely.”

Black Hat USA returns to the fabulous Mandalay Bay in Las Vegas, Nevada July 30 through Aug. 4, 2016. Click for information on the conference schedule and to register.

Heiland also found weak default WPA2 pre-shared keys (PSKs) on the devices he examined: they used an eight-character PSK that used only the characters from the set “0123456789abcdef.” This small keyspace of limited characters and a fixed, short length makes it possible to crack a captured WPA2 authentication handshake, which gives the hacker remote access to the cleartext WPA2 PSK.

“I was able to crack one device in about five hours and another device in about two hours,” Heiland says of his research.

Illuminating the Issue

Heiland added that a vendor-supplied patch will provide longer default PSKs that will use a larger keyspace that includes both uppercase and lowercase alphanumeric characters and punctuation. These are more secure because they are not typically intended to be remembered by humans.

Although the flaws found in the Home version of the Sylvania products were not as serious as the Pro version, Heiland says that it does give both the enterprise and home IoT industry more insight into the potential risk.

The Home edition contained a flaw in the pre-authentication command execution. When Heiland examined the network services on the gateway, he found that port 4000/TCP is used for local control when Internet services are down and it didn’t require authentication to pass commands to this TCP port.

With this access, a hacker can execute commands to change lighting and also execute commands to reconfigure the devices.

“While it’s not as serious as the flaw we found in the Pro edition -- which could access a corporate network -- we thought it was important to point these type of flaws out so they don’t migrate to the Pro editions,” he says.

UPDATE 7/27:

Osram provided this statement to Dark Reading:

"OSRAM agreed to security testing on existing LIGHTIFY products by Security researchers from Rapid7. Since being notified about the vulnerabilities identified by Rapid7, OSRAM has taken actions to analyze, validate and implement a risk-based remediation strategy, and the majority of vulnerabilities will be patched in the next version update, currently planned for release in August. 

Rapid7 security researchers also highlighted certain vulnerabilities within the ZigBee® protocol, which are unfortunately not in OSRAM’s area of influence. OSRAM is in ongoing coordination with the ZigBee® Alliance in relation to known and newly discovered vulnerabilities."

Related Content:



Steve Zurier has more than 30 years of journalism and publishing experience, most of the last 24 of which were spent covering networking and security technology. Steve is based in Columbia, Md. View Full Bio

Recommended Reading:

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/3/2020
'BootHole' Vulnerability Exposes Secure Boot Devices to Attack
Kelly Sheridan, Staff Editor, Dark Reading,  7/29/2020
Average Cost of a Data Breach: $3.86 Million
Jai Vijayan, Contributing Writer,  7/29/2020
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2020-08-05
Affected versions of Atlassian Fisheye allow remote attackers to view the HTTP password of a repository via an Information Disclosure vulnerability in the logging feature. The affected versions are before version 4.8.3.
PUBLISHED: 2020-08-04
In solidus before versions 2.8.6, 2.9.6, and 2.10.2, there is an bility to change order address without triggering address validations. This vulnerability allows a malicious customer to craft request data with parameters that allow changing the address of the current order without changing the shipm...
PUBLISHED: 2020-08-04
Extreme Analytics in Extreme Management Center before allows unauthenticated reflected XSS via a parameter in a GET request, aka CFD-4887.
PUBLISHED: 2020-08-04
save-server (npm package) before version 1.05 is affected by a CSRF vulnerability, as there is no CSRF mitigation (Tokens etc.). The fix introduced in version version 1.05 unintentionally breaks uploading so version v1.0.7 is the fixed version. This is patched by implementing Double submit. The CSRF...
PUBLISHED: 2020-08-04
An exploitable arbitrary file delete vulnerability exists in SoftPerfect RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request packet (IRP) can allow an unprivileged user to delete any file on the filesystem. An attacker can send a malicious IRP to trigger this vulnerability.