Batu69 Posted September 13, 2015 Share Posted September 13, 2015 HP PCs/Laptops and Notebooks LTE Module vulnerable to remote code execution flawThe HP PCs/Laptops and Notebooks which have HP lt4112 LTE/HSPA+ Gobi 4G Module onboard, have been found to have critical vulnerabilities which can be exploited by potential hackers to remotely execute arbitrary code.The vulnerabilities have been assigned following numbers :CVE-2015-5367CVE-2015-5368SSRT101965The vulnerability listed under CVE-2015-5367 allows a potential attacker to exploit this flaw to obtain the root permission, access the system by connecting the serial port, and view or modify configuration. The upgrade package of the HP lt4112 LTE/HSPA+ Gobi 4G wireless module contains the hash values of the root account and password. An attacker can obtain the password of the root account through reverse cracking.The module provides a debugging serial port at the rear for troubleshooting, opening a way for physical cracking by hackers. The hackers can connect to the serial port of the wireless module, and enter the root account and password to log in to the operating system of the module.While the CVE-2015-5368 allows an attacker to tamper with the upgrade package, leading to an upgrade failure or the upgrade of an incorrect package. As a result, services may become unavailable.This module implements upgrade check using CRC16, which is insecure. Much study is done for reversely cracking this algorithm. Hackers may change or add a code segment to the upgrade file, recalculate a CRC value, and tamper with the firmware of this module through CRC check during upgrade.The vulnerabilities exists in the HP lt4112 LTE/HSPA+ Gobi 4G Module which is used by HP PCs/Laptops and Notebooks to connect the users to 3G/4G/LTE radios.According the the listing, the following HP PCs/Laptops and Notebooks are vulnerable to this flaw :HP EliteBook 725 G2HP EliteBook 745 G1HP EliteBook 755 G2HP EliteBook 820 G1HP EliteBook 820 G2HP EliteBook 840 G1HP EliteBook 840 G2HP EliteBook 850 G1HP EliteBook 850 G2HP EliteBook 1040 G1HP EliteBook 1040 G2HP EliteBook Folio 9470mHP EliteBook Revolve 810 G2HP EliteBook Revolve 810 G3HP ElitePad 1000 G2HP Elite x2 1011 G2HP ProBook 430 G1HP ProBook 430 G2HP ProBook 440 G0HP ProBook 440 G1HP ProBook 440 G2HP ProBook 450 G0HP ProBook 450 G1HP ProBook 450 G2HP ProBook 640 G1HP ProBook 645 G1HP ProBook 650 G1HP ProBook 655 G1HP Pro x2 612 G1HP Spectre x2 13-SMB ProHP ZBook 14HP ZBook 14 G2HP ZBook 15HP ZBook 15 G2HP ZBook 15u HP ZBook 17HP Zbook 17 G2mt41 Thin ClientUsers of above HP products are advised to update their firmware following the below methodTo acquire the firmware updates, go to hp.comSelect “Support” and then “Download Drivers” Enter your product name or number in the “Find my product” field. Choose the product from the returned search Choose the operating system Under the Download Index, select “Firmware”, and download the 12.500.00.15.1803 firmware or later (HP Softpaq # SP72435 or later). Follow the installation instructions to install the firmware update.Resource : HP Software Security Response TeamArticle source Link to comment Share on other sites More sharing options...
straycat19 Posted September 13, 2015 Share Posted September 13, 2015 The hackers can connect to the serial port of the wireless module, and enter the root account and password to log in to the operating system of the module.This isn't remote, this requires access to the system. Link to comment Share on other sites More sharing options...
knowledge-Spammer Posted September 13, 2015 Share Posted September 13, 2015 The hackers can connect to the serial port of the wireless module, and enter the root account and password to log in to the operating system of the module.This isn't remote, this requires access to the system. still bad Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.