External risk intelligence

Attacker can take control of your BG-TEK firewall to access sensitive data.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2021-4105

BG-TEK firewalls have a serious flaw that lets attackers take control and access your data. Act now to secure your network.

5Halo Surface Signal

Bg Tek Coslat Bx5s1d3 Firmware

5.24.0.r.20180630 to before 5.24.0.r.20210727

External exposure likelihood

Halo Surface Signal score for CVE-2021-4105

The product is a firewall, which is an internet edge device. The vulnerability exists in the interface that handles network requests, and the guidance explicitly identifies the need to restrict remote access to the administrative interface, confirming it is designed to be internet-facing or is commonly deployed in such a manner.

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in BG-TEK COSLAT Firewall allows for remote code inclusion, enabling unauthorized execution of code. This is significant because firewalls are critical security devices, and a compromise could allow an attacker to bypass security controls and gain deeper access to the network.

  • Attackers can execute arbitrary code.
  • Affects internet-facing firewalls.
  • Grants broad access and control.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted requests to a vulnerable COSLAT Firewall. This could allow them to remotely include arbitrary code, leading to full system compromise.

  • No authentication required.
  • Network accessible interface targeted.
  • Default credentials could increase risk.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in BG-TEK COSLAT Firewall allows for remote code inclusion, which attackers generally find attractive due to its potential for system compromise. The ease of exploitation and direct impact on a critical network device make it a compelling target, though specific attack trends are not yet widely observed.

  • Internet-facing firewall device.
  • Remote code inclusion vulnerability.
  • Affects multiple firmware versions.

Priority actions

Operational Fix

Recommended remediation, mitigation, and detection steps

Prioritize immediate patching for all affected BG-TEK COSLAT Firewall devices. If patching is not immediately feasible, isolate these devices from the network or restrict external access to their administrative interfaces to prevent exploitation of the remote code inclusion vulnerability.

  • Apply update to version 5.24.0.R.20210727.
  • Block external administrative access.
  • Monitor network traffic for suspicious activity.

Frequently asked questions

What is the BG-TEK COSLAT Firewall and what is it used for?

The BG-TEK COSLAT Firewall is a network security device used to control incoming and outgoing network traffic. It acts as a barrier between a private network and the internet, enforcing security rules to protect sensitive data and systems.

How does CVE-2021-4105 affect the COSLAT Firewall?

CVE-2021-4105 is an Improper Handling of Parameters vulnerability. In simpler terms, the firewall doesn't correctly process certain inputs, which an attacker can use to include and run their own code remotely on the device.

What conditions allow an attacker to exploit CVE-2021-4105?

An attacker can exploit this vulnerability by sending specially crafted network requests to a vulnerable COSLAT Firewall. The vulnerability can be triggered without requiring any authentication from the attacker.

Who should be concerned about this firewall vulnerability?

Organizations using BG-TEK COSLAT Firewall versions between 5.24.0.R.20180630 and 5.24.0.R.20210727 should be concerned. Since firewalls are often internet-facing, this vulnerability is considered to have a high likelihood of exposure.

What is the first step for responding to this CVE?

The immediate first step is to update the affected BG-TEK COSLAT Firewall firmware to version 5.24.0.R.20210727 or later. If an update isn't possible right away, restricting external access to the firewall's administrative interface is a crucial mitigation.

References