Headline
CVE-2023-31190: Insecure Firmware Update – Nozomi Networks
DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an Improper Authentication vulnerability during the firmware update procedure.
Specifically, the firmware update procedure ignores and does not check the validity of the TLS certificate of the HTTPS endpoint from which the firmware update package (.tar.bz2 file) is downloaded. An attacker with the ability to put himself in a Man-in-the-Middle situation (e.g., DNS poisoning, ARP poisoning, control of a node on the route to the endpoint, etc.) can trick the DroneScout ds230 to install a crafted malicious firmware update containing arbitrary files (e.g., executable and configuration) and gain administrative (root) privileges on the underlying Linux operating system. This issue affects DroneScout ds230 firmware from version 20211210-1627 through 20230329-1042.
CVE-2023-31190
Summary
DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an Improper Authentication vulnerability during the firmware update procedure.
Impact
The firmware update procedure ignores and does not check the validity of the TLS certificate of the HTTPS endpoint from which the firmware update package (.tar.bz2 file) is downloaded. An attacker with the ability to put himself in a Man-in-the-Middle situation can trick the DroneScout ds230 to install a crafted malicious firmware update.
Affects
The vulnerability affects: DroneScout ds230 from firmware version 20211210-1627 to firmware version 20230329-1042
CVSS Details
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Solution
Update to firmware version newer than 20230329-1042
Acknowledgments
Nicolò Facchi of Nozomi Networks
**Threat **Intelligence****
****Curated and maintained by Nozomi Networks Labs, the Threat Intelligence™ service provides threat and vulnerability updates to Guardian, making it easy for IT/OT professionals to stay on top of current OT and IoT risks.****
Threat actors love finding new ways to attack critical infrastructure. We love finding new ways to detect their malware before damage occurs.
Andrea Carcano & MorenoCarullo
Co-founders, Nozomi Networks
Let’s get started
Discover how easy it is to anticipate, diagnose and respond to cyber threats and process issues before they impact your operations.