Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 16, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 16, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 16, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 16, 2025

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025

      Minecraft licensing robbed us of this controversial NFL schedule release video

      May 16, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      The power of generators

      May 16, 2025
      Recent

      The power of generators

      May 16, 2025

      Simplify Factory Associations with Laravel’s UseFactory Attribute

      May 16, 2025

      This Week in Laravel: React Native, PhpStorm Junie, and more

      May 16, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025
      Recent

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Hacking of Ewon Cosy+ Secure Industrial Remote Access Gateway is Possible

    Hacking of Ewon Cosy+ Secure Industrial Remote Access Gateway is Possible

    August 13, 2024

    While industrial VPN gateways such as Cosy+ play a crucial role in enabling secure remote access to critical operational technology (OT) systems, these devices have become lucrative targets for threat actors due to their importance and architectural vulnerabilities within industrial environments.

    Researchers uncovered several vulnerabilities in the Cosy+ that could allow attackers significant control over the device and connected industrial infrastructure. They also presented their findings at the recent DEF CON 32.

    Hacking Ewon Cosy+ Devices To Obtain Root Access

    The researchers from German cybersecurity firm SySS GmbH focused on finding vulnerabilities that allowed them to learn more about the Cosy+’s functionality, as the device’s encrypted firmware and hardware security measures posed a steep initial challenge. Their persistence paid off when they discovered a simple OS command injection vulnerability in the way Cosy+ handled user-provided OpenVPN configurations.

    By carefully crafting the OpenVPN configuration, the researchers were able to bypass the vendor’s filter mechanisms and execute arbitrary commands on the device, ultimately obtaining root-level access. This access allowed them to deploy their own persistent SSH service, providing them a reliable method of accessing the Cosy+ remotely.

    The Cosy+ is touted as a secure hardware security module (HSM) that protects sensitive data and cryptographic functions. However, the analysis exposed that the communication between the device’s main processor and HSM was not properly secured.

    The researchers were able to reverse-engineer the decryption process, allowing them to access the sensitive information stored within the HSM. They also investigated the encryption used to protect the Cosy+’s firmware updates and configuration files. Despite the security perimeters in place, the researchers were able to bypass the encryption and access the plaintext contents, including passwords and other sensitive information.

    By combining the vulnerabilities such as OS command injection and Cross-Site Scripting (XSS) they were able to devise an exploit chain that would allow an unauthenticated attacker to gain root access to the Cosy+ and potentially hijack remote access sessions, posing significant security risks to the device’s users and the connected industrial infrastructure.

    Responsible Disclosure and Vendor Response

    The researchers responsibly disclosed their findings to HMS Industrial Networks, the vendor who develops the Ewon Cosy+. The vendor acknowledged the issues and has since worked to address them in subsequent firmware updates.

    However, the widespread use of the Cosy+ in critical industrial environments poses an additional challenge and consideration for thorough security assessments and the need for vendors of similar scale to prioritize the security of their products.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleMiddle East’s Top 100 Cybersecurity Leaders to Follow
    Next Article BREAKING: International Effort Dismantles ‘Radar/Dispossessor’ Ransomware Group

    Related Posts

    Machine Learning

    Salesforce AI Releases BLIP3-o: A Fully Open-Source Unified Multimodal Model Built with CLIP Embeddings and Flow Matching for Image Understanding and Generation

    May 16, 2025
    Security

    Nmap 7.96 Launches with Lightning-Fast DNS and 612 Scripts

    May 16, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    What is a front end developer hiring in 2025

    Web Development

    Creating a Sound A/B Test Hypothesis

    Development

    CSS Animation Effects: Bringing Web Designs to Life

    Development

    PlayStation says Windows PC is not a “major risk,” probably because blanket ‘day and date’ PlayStation game launches on PC are coming sooner than you think

    Development

    Highlights

    News & Updates

    Google DeepMind CEO says “AGI is coming and I’m not sure society is ready” as the prospects keep him up at night

    May 6, 2025

    Google DeepMind CEO Demis Hassabis recently highlighted alarming concerns about the rapid progression and advances…

    Medusa ransomware: FBI and CISA urge organisations to act now to mitigate threat

    March 16, 2025

    Optimize Your Eloquent Queries with AI

    May 7, 2024

    Build a financial research assistant using Amazon Q Business and Amazon QuickSight for generative AI–powered insights

    May 14, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.