Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability allows unauthenticated remote attackers to read or modify sensitive data within Asset Administration Shell submodels, potentially impacting the integrity and confidentiality of asset information. It affects technologies that utilize Asset Administration Shell endpoints, which can be exposed externally.
- Unauthenticated attackers can access or alter asset data.
- Executive attention is needed to confirm relevance and exposure.
- Understand potential data integrity and confidentiality risks.
Attack Path
How an attacker could exploit the issue
An attacker can remotely access and modify data within the Asset Administration Shell submodel without needing authentication. This can be achieved by sending specially crafted PATCH requests to alter data, or GET requests to read any exposed information.
- No authentication is required.
- Attacker sends PATCH or GET requests.
- Risk of unauthorized data modification or exposure.
Live Threat
Current exploitation, exposure, and threat context
An unauthenticated remote attacker could modify critical Asset Administration Shell submodel data and read all exposed data. This could occur when the system is configured to allow unauthenticated PATCH or GET requests to these endpoints.
- Asset Administration Shell submodel data.
- Via unauthenticated network requests.
- Unauthorized data access and modification.
Operational Fix
Recommended remediation, mitigation, and detection steps
This critical vulnerability in Asset Administration Shell submodel data, allowing unauthenticated remote attackers to modify and read data via PATCH and GET requests, impacts systems that expose these endpoints. Technical leaders and security teams should first identify all instances of the affected technology, determine their exposure and business criticality, and then locate the accountable owner to prioritize remediation efforts.
- Asset Administration Shell owners are responsible.
- Verify external reachability and business impact first.
- Plan remediation based on confirmed risk assessment.