
ETS5 Password Recovery Tool is a PoC for CVE-2021-36799
Have you forgotten the password to one of your ETS5 projects and cannot access the configuration for the KNX installation anymore? The ETS5 Password Recovery Tool allows you to retrieve the project password and other secrets saved in the project store of the ETS5. This is possible because the ETS5 has a significant design flaw, it uses a hard-coded password and salt to encrypt the project information (CVE-2021-36799).
Storing cryptographic secrets in source code is ill-advised because they can be recovered by reverse engineering the software, thus offering little more protection than storing the information as cleartext. This can pose a threat to the security of the KNX installations. If an attacker is able to gain access to the files in the project store, they can decrypt them despite not knowing the project password. The information contained within allow to eaves-drop on, impersonate and reconfigure KNX devices. This is particularly problematic, because the ETS5 gives the users the impression that project password would be used to encrypt the project information, not just for exported projects. Hence, it is likely that many users and system integrators have not taken additional steps to ensure the confidentiality of the project store. If the ETS5 would properly implement the encryption and a strong project password is chosen, it would provide a harder challenge for an attacker, even if they managed to get remote access to the computer.
The following confidential information are improperly encrypted:
The ETS5 Password Recovery Tool is a proof of concept that demonstrates the issue by decrypting and displaying the sensitive information. It was developed as part of the coordinated vulnerability disclosure and is released with permission by the KNX Association. Publishing the tool serves the following purposes:
WARNING: Only use this tool if you are legally authorized to view the project information. Circumventing security measurements, even ineffective ones, to gain access to information you are not permitted to see, may be a felony in your jurisdiction.
The executable can be downloaded from the release section. It does not need to be installed and can be placed in any directory of choice.
Alternatively, if you do not want to run an untrusted binary on your system, you can decrypt individual attributes from the project's XML files on the CyberChef website.
The software depends on .NET Framework 4.6 or later. Windows 10 already includes a suitable .NET version by default. Users of earlier Windows versions will have to install a current .NET Framework version to run the software.
Contrary to what the user interface suggests, the ETS5 does not encrypt your locally stored project files in C:\ProgramData\KNX\ETS5\ProjectStore with the project password. Instead, it uses the hard-coded password ETS5Password and salt Ivan Medvedev to obfuscate specific attributes in the project's XML files. Hard-coded cryptographic secrets are against best practice, as explained in CWE-798 and CWE-321.
The process for the deobfuscation is:
Ivan Medvedev as ASCII or UTF-8 encoded string.ETS5Password as password and the byte representation of Ivan Medvedev as salt. The first 32 bytes of the key derivation output will be used as key and the following 16 bytes as IV.An implementation of the deobfuscation can be found in the Deobfuscator.cs file. Since the password and salt are constant, it would be possible to precompute the key and IV to skip the key derivation. This is not done in the implementation of this software, as it is meant to show all steps of the deobfuscation. However, if you need the key and IV, they are listed below.
| Hex | Base64 | |
|---|---|---|
| Key | 22BD16CDBB96B0E18E977BB3FEFADD8886E7E38A2F8A6FD9D2F2F5663AC20371 | Ir0WzbuWsOGOl3uz/vrdiIbn44ovim/Z0vL1ZjrCA3E= |
| IV | 8E977BB3FEFADD88E6AE6CBEAE3E7CAF | jpd7s/763Yjmrmy+rj58rw== |
Exported project files (.knxproj) are not affected by this design flaw, and thus this tool cannot be used to recover the project password for them. The .knxproj file is a ZIP file that contains another ZIP file with the sensitive information. The latter uses Deflate compression, ZipCrypto / PKWARE encryption and the project password for the derivation of the encryption key.