Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability has been identified in certain building automation systems. This issue allows an unauthenticated remote attacker to read or overwrite arbitrary files on the device, potentially leading to a full system compromise. The main concern is confirming relevance and exposure within your operational technology environments.
- Attackers can read/overwrite sensitive files.
- Unauthenticated remote access is possible.
- Confirm relevance and exposure in OT environments.
Attack Path
How an attacker could exploit the issue
An unauthenticated remote attacker can exploit this vulnerability by leveraging the improper interpretation of dynamically created BACnet File Object names. These names are treated as file paths without sufficient validation, allowing the attacker to navigate outside the intended directory. This enables them to read or overwrite arbitrary files on the device, potentially leading to complete system compromise.
- No authentication required for access.
- Attacker controls file path naming.
- Risk of arbitrary file read/write.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an unauthenticated remote attacker to read or overwrite arbitrary files on the device by manipulating the object name of a dynamically created BACnet File Object. This could lead to a full system compromise when the device's BACnet service is accessible over the network and file path validation is insufficient.
- Arbitrary files on the device.
- Path traversal, when supported by the advisory.
- Full system compromise.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability in dynamically created BACnet File Objects could allow an unauthenticated remote attacker to read or overwrite arbitrary files, potentially leading to full system compromise. Real-world remediation will likely involve application owners, infrastructure teams, and security teams. The first practical step is to identify all instances of the affected technology, confirm their network reachability and business criticality, and then assign ownership for risk-based remediation planning.
- Assign ownership to the affected technology.
- Verify network exposure and criticality.
- Plan remediation based on identified risk.