Horizon Alert
Summary of the vulnerability and why it matters
This issue allows a network attacker to gain full administrative control of a Garmin WDU device. It occurs when a user on a specially configured computer visits a malicious website, which then hijacks a WebSocket connection used to manage the device's settings. Teams should pay attention because this could lead to unauthorized control of critical marine equipment.
- Affects administrative settings.
- Requires a user to visit a malicious site.
- Network attackers can gain control.
Attack Path
How an attacker could exploit the issue
A network attacker can hijack WebSocket connections to an affected Garmin WDU through a malicious website. This requires the victim to visit a malicious site while using a multihomed browser on a host connected to both the Garmin network and another network, enabling the attacker to gain administrative control.
- Victim must visit malicious site.
- Requires multihomed host.
- Attacker gains admin control.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability affects a locally served web interface on Garmin WDU devices, and exploitation requires specific user interaction. Attackers might find this less appealing due to the niche setup and user involvement needed to trigger the exploit.
- Requires victim browser on a multihomed host.
- Victim must visit a malicious third-party website.
Priority actions
Operational Fix
Recommended remediation, mitigation, and detection steps
Prioritize investigating and isolating Garmin WDU devices running versions 1.4.6 or 5.0, as a critical vulnerability allows network attackers to gain full control through a cross-site origin WebSocket hijacking attack if a user visits a malicious website while on a multihomed host.
- Block access to malicious websites.
- Isolate affected devices from other networks.
- Monitor for unusual WDU activity.