External risk intelligence

HMS Industrial Networks eCatcher Stack Buffer Overflow Remote Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2020-14498

eCatcher is a remote access client/management software used to establish connections to industrial systems. As a remote access and connectivity tool designed to facilitate external communication with remote sites, it is commonly deployed in a manner that facilitates internet-based access.

Out-of-bounds Write

Hms Networks Ecatcher

before 6.5.5

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the eCatcher software, a tool used for remote access to industrial systems. This flaw could potentially allow unauthorized individuals to execute malicious code remotely, posing a significant risk to operational technology environments. The primary concern is confirming the relevance and exposure of this vulnerability within our specific deployments.

  • Remote code execution vulnerability in connection software.
  • Affects remote access tools for industrial systems.
  • Confirm relevance and any potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could target HMS Industrial Networks AB eCatcher by sending specially crafted data over the network. This data could exploit a buffer overflow vulnerability in the software, potentially allowing the attacker to execute their own code on the affected system.

  • Requires network access to the vulnerable system.
  • Triggered by sending malicious data to the software.
  • Can lead to remote code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to remotely execute arbitrary code on systems running the affected software. This could occur when the software is accessible over a network and may lead to unauthorized control or manipulation of connected industrial systems.

  • System code execution.
  • Remote network access.
  • Compromise of industrial systems.

Operational Fix

Recommended remediation, mitigation, and detection steps

Responsibility for addressing this vulnerability likely falls to teams managing operational technology (OT) infrastructure and potentially application owners, depending on how eCatcher is deployed and managed within the organization. The immediate priority is to inventory all instances of eCatcher, assess their exposure to external networks, and identify their business criticality to inform a prioritized remediation plan.

  • Ownership: OT infrastructure and application owners.
  • Verify: System exposure and business criticality.
  • Action: Plan and execute risk-based remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is HMS Industrial Networks eCatcher?

eCatcher is a software client that provides remote access to industrial systems. It acts as a bridge, allowing engineers and administrators to connect securely to remote sites and manage operational technology (OT) equipment over a network.

What does CVE-2020-14498 mean?

This vulnerability is classified as a stack-based buffer overflow (CWE-121, CWE-787). In plain terms, the software fails to properly manage the amount of data it receives, which can cause it to overwrite its own memory. This flaw allows a remote attacker to bypass normal controls and execute unauthorized code on the system.

How is this buffer overflow triggered?

The vulnerability is triggered when an attacker sends specially crafted data over the network to a vulnerable eCatcher instance. It requires direct network communication with the software. Simply using the application for standard remote access or having it installed while disconnected from the network does not trigger this flaw.

Why should I care about this vulnerability?

Halo Surface Signal notes that eCatcher is designed specifically for remote connectivity to industrial sites, often leading to configurations that permit internet-based access. Because the software is inherently built to facilitate external communication, systems running older versions are at a heightened risk of being reachable by remote attackers.

How do I respond to this threat?

Start by auditing your environment to inventory all instances of eCatcher. Prioritize systems based on their role in your OT infrastructure and their visibility to external networks. Consult the vendor's official security guidance to identify the required update path and ensure you are running version 6.5.5 or later, which contains the necessary security improvements.

References