Spacelabs recommends updating to the latest release to mitigate an improper input validation vulnerability in its Xhibit Telemetry Receiver, according to a report with CISA.

A remote code execution vulnerability called BlueKeep (CVE-2019-0708) exists within the Remote Desktop Protocol (RDP) used by the Microsoft Windows operating systems. An attacker can exploit this vulnerability to perform remote code execution on an unprotected system.

According to Microsoft, an attacker can send specially crafted packets to operating systems with RDP enabled. After successfully sending the packets the attacker could perform a number of actions, including adding accounts with full user rights; viewing, changing, or deleting data; or installing programs. This exploit, which requires no user interaction, must occur for successful authentication.

BlueKeep is considered “worm-able” because malware exploiting this vulnerability on a system could propagate to other vulnerable systems; thus a BlueKeep exploit would be capable of rapidly spreading like the WannaCry malware attacks of 2017.

Schneider Bold

Public exploits are available for the vulnerability, discovered by Microsoft, where an attacker with low skill level could leverage the issue. The following versions and operating systems of Spacelabs Xhibit Telemetry Receiver suffer from the remotely exploitable vulnerability:

  • Xhibit Telemetry Receiver (XTR), Model number 96280, v1.0.2
  • Arkon (99999), all versions – previously sold by Spacelabs, no longer a supported product
  • The following Microsoft Windows operating systems, including 32- and 64-bit versions, as well as all Service Pack versions, suffer from the issue:

  • Windows 2000
  • Windows Vista
  • Windows XP
  • Windows 7
  • Windows Server 2003
  • Windows Server 2003 R2
  • Windows Server 2008
  • Windows Server 2008 R2
  • The affected product is vulnerable to a remote code execution vulnerability that exists in Remote Desktop Services (formerly known as Terminal Services) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would need to send a specially crafted request to the target system’s Remote Desktop Service via RDP.

    CVE-2019-0708 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 9.8.

    The product sees use mainly in the healthcare and public health sectors. It also sees action on a global basis.

    Spacelabs has determined the recommended remediation is to update to the newest release v1.2.1 or later. All deployed XTR hardware appliances are capable of update and should be updated.

    Spacelabs products are appliances and users are not intended to perform updates on them. Products or systems that are obsolete or are not able to be patched may use this alternate mitigation step to help protect against BlueKeep:

  • Block Transmission Control Protocol (TCP) Port 3389 at the enterprise perimeter firewall. Because Port 3389 is used to initiate an RDP session, blocking it prevents an attacker from exploiting BlueKeep from outside the user’s network. However, this will block legitimate RDP sessions and may not prevent unauthenticated sessions from being initiated inside a network.
  • Spacelabs also encourages users and administrators to review the Microsoft Security Advisory and the Microsoft Customer Guidance for CVE-2019-0708 and apply the appropriate mitigation measures as soon as possible.

    If you own an XTR device or have any questions about this security advisory, please contact Spacelabs at 1-800-522-7025 and select 2 for technical support. XTR is an appliance that has no user interface, so your service representative can help you to determine the installed version of software on your XTR product and will work to coordinate updates as needed.

    For additional information about this vulnerability, click on the Spacelabs Security Advisory.

    ISSSource

    Pin It on Pinterest

    Share This