Successful exploitation of these remotely exploitable vulnerabilities, discovered by Ithaca Labs of Odyssey Cyber Security, could lead to privilege escalation, unauthorized execution of actions, a denial-of-service condition, or retrieval of sensitive information.
SAUTER reports these vulnerabilities affect the following EY-modulo 5 Building Automation Stations: EY-AS525F001 with moduWeb.
CVE-2023-28650 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 8.8.
In addition, a malicious user could leverage a cross-site scripting vulnerability to escalate privileges or perform unauthorized actions in the context of the targeted privileged users.
CVE-2023-28655 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 8.0.
Also, an unauthenticated remote attacker could force all authenticated users, such as administrative users, to perform unauthorized actions by viewing the logs. This action would also grant the attacker privilege escalation.
CVE-2023-22300 is the case number assigned to this vulnerability, which has as CVSS v3 base score of 8.8.
Further, an authenticated malicious user could acquire the simple mail transfer protocol (SMTP) Password in cleartext format, despite it being protected and hidden behind asterisks. The attacker could then perform further attacks using the SMTP credentials.
CVE-2023-27927 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.5.
In another issue, an authenticated malicious user could successfully upload a malicious image could lead to a denial-of-service condition.
CVE-2023-28652 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 6.5.
The product sees is mainly in the critical manufacturing and energy sectors, and on a global basis.
No known public exploits specifically target these vulnerabilities. These vulnerabilities are exploitable remotely. These vulnerabilities have low attack complexity.
According to SAUTER, the EY-modulo 5 Building Automation Stations product line does not support encryption on its communication protocols. As such, it is not appropriate for open networks.
Switzerland-based SAUTER recommends deactivating moduWeb when not in use as doing so closes the vulnerabilities related to the web server and the mail client service; users can upgrade to the latest generation modulo 6 with moduWeb Unity as the web server, which supports encrypted communication with TLS.
SAUTER recommends users take all necessary measures to protect the integrity of building automation networks, restrict access to the devices, and leverage all appropriate means and policies to minimize risks. Users should evaluate and upgrade legacy systems to current solutions where necessary.

