Unlocking the Gates Hacking a secure Industrial Remote Access Solution
Moritz Abrell
DEF CON 32 Main Stage · Day 1 · Main Stage
Overview
In a compelling presentation at DEF CON 32, Moritz Abrell, a senior IT security consultant and penetration tester at the German company Sys, unveiled critical vulnerabilities within the Ewon Cosy Plus Industrial Remote Access Gateway by HMS. Titled "Unlocking the Gates," Abrell's research meticulously details how a combination of seemingly minor flaws can escalate into a severe security breach, granting attackers root access to devices and, more alarmingly, enabling a scalable attack capable of disconnecting and redirecting users from over half a million critical infrastructure assets worldwide.

Key moments
- 0:00 Introduction to industrial remote access and Ewon Cosy Plus
- 3:45 Gaining root privileges via OpenVPN config bypass
- 4:30 Combining XSS and insecure cookies for full compromise
- 5:55 Live demonstration of the full attack chain
- 6:40 Reverse engineering and decrypting encrypted configuration passwords
- 9:00 Discovering firmware update key decryption and leakage
- 10:00 Significant impact on industrial facilities worldwide
Unlocking the Gates Hacking a secure Industrial Remote Access Solution
Speakers: Moritz Abrell, Senior IT Security Consultant & Penetration Tester, Sys
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=fc6c2hP86Wk
Overview
In a compelling presentation at DEF CON 32, Moritz Abrell, a senior IT security consultant and penetration tester at the German company Sys, unveiled critical vulnerabilities within the Ewon Cosy Plus Industrial Remote Access Gateway by HMS. Titled "Unlocking the Gates," Abrell's research meticulously details how a combination of seemingly minor flaws can escalate into a severe security breach, granting attackers root access to devices and, more alarmingly, enabling a scalable attack capable of disconnecting and redirecting users from over half a million critical infrastructure assets worldwide.
The Ewon Cosy Plus is a widely adopted solution designed to provide secure remote access to industrial networks, with the vendor claiming over 500,000 devices in operation globally. HMS further markets the device with a strong emphasis on security, boasting features like a hardware security module (HSM) with a root of trust, individual certificates, secure boot, and independent third-party security certification. Abrell's talk systematically dismantles these claims, demonstrating that despite advanced hardware security features, fundamental software and implementation vulnerabilities can render these protections ineffective.
This article delves into Abrell's methodology, the specific vulnerabilities discovered, the intricate exploit chain, and the profound implications for industrial control systems (ICS) and critical infrastructure. The findings underscore a crucial lesson: the presence of advanced security hardware does not inherently guarantee a secure product if software implementation and operational practices introduce exploitable weaknesses. The ability to disrupt and potentially compromise access to energy plants, industrial facilities, and oil platforms highlights the urgent need for robust security postures in the realm of industrial remote access.
Background
▶ Watch: Introduction to industrial remote access and Ewon Cosy Plus (0:00)
Industrial Remote Access solutions are pivotal in modern industrial operations, enabling service technicians and engineers to remotely manage and troubleshoot devices within industrial networks. The fundamental operational model typically involves a device within the industrial network establishing a VPN connection to a vendor-operated VPN server. When a technician requires access, they use vendor-provided software to initiate their own VPN connection, which is then routed by the central VPN server to the targeted industrial router and, consequently, the desired infrastructure. This setup is designed for convenience and efficiency, but its security is paramount given the sensitive nature of the connected systems.
Moritz Abrell specifically chose the Ewon Cosy Plus by HMS for his research for several compelling reasons. Firstly, its widespread deployment, with HMS claiming over half a million active devices, meant that any identified vulnerabilities could have a significant, far-reaching impact on critical infrastructure globally. Secondly, a similar Ewon device had previously been scrutinized, leading to the identification of security problems and a subsequent complete refactoring by the vendor, suggesting a potential historical context for security improvements that warranted re-evaluation.
Crucially, the vendor's explicit emphasis on security for the Cosy Plus was a key motivator. HMS highlighted features such as a Hardware Security Module (HSM) providing a root of trust, individual certificates for device identity, and secure boot mechanisms. Furthermore, the solution had undergone analysis by an independent company, which issued a certificate attesting to the security of the hardware, backend, and associated software, a claim prominently displayed on the vendor's website. These strong security assertions made the device an ideal candidate for black-box penetration testing, challenging the robustness of its defenses against a skilled attacker. Abrell's initial approach was entirely black box, driven by the device's encrypted firmware update files and a desire to avoid potentially damaging the hardware security module without prior software-level access.
Key Findings
▶ Watch: Combining XSS and insecure cookies for full compromise (4:30)
Moritz Abrell's research uncovered a series of interconnected vulnerabilities that, when chained together, completely undermined the Ewon Cosy Plus's security claims. The key findings can be broadly categorized into initial software-level access and deeper firmware analysis post-compromise.
Initially, Abrell achieved root access to the device through a straightforward command injection vulnerability in the OpenVPN configuration parsing. Despite a blacklist implemented to prevent the use of the up parameter, a simple bypass allowed arbitrary command execution with root privileges. This initial foothold, however, required administrative access to the device's web interface.
To address the need for administrative access, Abrell discovered a persistent Cross-Site Scripting (XSS) vulnerability stemming from FTP login attempts. Malicious JavaScript injected via an FTP login attempt would execute whenever an administrative user visited the device's logging page. This was coupled with an insecure cookie that conveniently stored the base64-encoded administrative password in plain text, making credential theft trivial. This sophisticated exploit chain allowed an attacker to gain administrative access, then leverage the OpenVPN vulnerability for root privileges.
With root access, Abrell could then delve into the device's firmware internals. He successfully reverse-engineered the encryption algorithm used for sensitive data, such as passwords and VPN certificates, stored in configuration files. This was possible due to the use of well-known OpenSSL functions and the discovery of a hardcoded key and Initialization Vector (IV) within the device's read-only data section.
Perhaps the most critical finding related to the firmware update encryption. Despite the presence of an NXP EdgeLock HSM and the use of the i.MX6 cryptographic acceleration module, Abrell was able to reconstruct the firmware update process. He discovered that while the HSM was involved in decrypting an encrypted key, this key was then stored in a file and used to decrypt a bash script. Crucially, each firmware version had its own encryption key, and a rooted device could be used to leak these firmware-specific encryption keys. This leakage opened the door to a highly scalable and devastating attack.
The ultimate impact of these findings is the ability for an attacker to use a rooted Ewon Cosy Plus to obtain a correctly signed certificate for a foreign device. This certificate can then be used to authenticate to the vendor's VPN server, effectively disconnecting the original legitimate device and redirecting any user attempting to connect to that serial number to the attacker's malicious client. Given the enumerable nature of serial numbers, this attack is highly scalable, capable of affecting more than 500,000 devices globally, including critical infrastructure such as energy plants, industrial facilities, and oil platforms.
Technical Deep Dive
▶ Watch: Live demonstration of the full attack chain (5:55)
The technical depth of Moritz Abrell's research lies in the meticulous chaining of multiple vulnerabilities to achieve complete compromise and, subsequently, the reverse engineering of cryptographic implementations.
The initial path to gaining a root shell on the Ewon Cosy Plus began with a command injection vulnerability related to the OpenVPN configuration file parsing. OpenVPN, a widely used VPN protocol, allows for custom command execution via the up parameter (and others like down, route-up, etc.). The Ewon device permitted the upload of custom OpenVPN configuration files, but the up parameter was explicitly blacklisted to prevent malicious command execution. Abrell discovered that this blacklist could be bypassed by simply adding two dashes (--) before the command, for example, up -- <command>. This technique, often seen in command-line argument parsing, allowed the command to execute with root privileges, as the filter failed to correctly parse arguments following the -- separator. By crafting an OpenVPN configuration file containing a reverse shell command, Abrell was able to obtain a persistent root shell on the device.
However, this initial root shell required administrative access to the Ewon Cosy Plus's web interface. To overcome this, Abrell uncovered an elegant exploit chain that did not require prior admin credentials. This chain leveraged a persistent Cross-Site Scripting (XSS) vulnerability and an insecure cookie handling mechanism. The XSS originated from FTP login attempts: if an attacker attempted to log into the device's FTP service with a specially crafted username containing JavaScript, this malicious script would be stored and later executed when an administrative user visited the device's logging page. The second component was an insecure cookie present in the administrator's browser, which contained the base64-encoded administrative password in plain text.
The full exploit chain for gaining administrative access and then root access was as follows:
- An attacker injects malicious JavaScript code into the device's logs via a crafted FTP login attempt.
- An administrative user of the Ewon Cosy Plus visits the device's logging page through their web browser.
- The injected JavaScript executes in the administrator's browser context.
- This malicious JavaScript accesses the insecure cookie, extracts the base64-encoded administrative password, decodes it to plain text, and then sends it to an attacker-controlled server.
- With the administrator's plain text password, the attacker logs into the Ewon Cosy Plus web interface.
- The attacker then uploads a specially crafted OpenVPN configuration file containing the
up -- <reverse_shell_command>payload. - The device processes the OpenVPN configuration, executing the reverse shell command with root privileges, granting the attacker full control.
Abrell also credited Khan Ganeshin for reporting a similar cookie-related issue on an earlier Ewon device in 2015, highlighting a potential recurring security pattern.
Once root access was established, Abrell proceeded to analyze the firmware internals. One immediate area of interest was the encryption of sensitive data within configuration files, such as VPN certificates and passwords. By searching for a specific prefix used for encrypted values, he located the responsible code within an ARM binary. Through reverse engineering, he identified that the encryption relied on well-known OpenSSL functions. Critically, he discovered a hardcoded AES key and Initialization Vector (IV) embedded directly within the read-only data section of the binary. With these, he could re-implement the encryption algorithm and decrypt any sensitive data encrypted on the device.
The most complex and impactful part of the technical deep dive concerned the firmware update encryption. The vendor claimed the use of an NXP EdgeLock Hardware Security Module (HSM), which Abrell confirmed was present. Initial attempts to eavesdrop on the I2C communication between the HSM and the System-on-Chip (SoC) revealed that while the APDU command structure was unencrypted, the payloads were encrypted, preventing passive interception of sensitive data. Furthermore, a proof-of-concept tool developed using NXP's Plug and Trust middleware to directly access keys from the HSM on the rooted device was unsuccessful, indicating that the HSM policies were correctly configured to prevent direct key extraction.
Despite these obstacles, Abrell successfully reconstructed the firmware update encryption process. He found that the process involved reading four bytes from an unencrypted flash memory section, which specified the length of subsequent data. This data was then decrypted using the i.MX6 cryptographic acceleration and assurance module. Following this, session keys were derived from the decrypted data and subsequently used to encrypt communication via AES in CBC mode. A critical observation was that Abrell, having only a single device, could not definitively determine if the data stored on the unencrypted flash was unique per device or a generic component.
The pivotal discovery regarding firmware updates was the leakage of firmware-specific encryption keys. The update process involved:
- Reading a key type from the update file.
- Reading an encrypted key and IV.
- The encrypted key being decrypted by the HSM and then stored in a file on the device.
- An encrypted bash script being extracted from the update file and then decrypted using the plain text key that was just stored.
This meant that while the HSM protected the key during decryption, the decrypted key was temporarily accessible on the file system of a rooted device. Consequently, an attacker with root access to one Ewon Cosy Plus could extract the firmware-specific encryption key for that particular firmware version. This allows an attacker to decrypt any firmware update for that version, analyze it, or potentially craft malicious updates. More critically, it enables the extraction of signed certificates that are part of the update process, which can then be used to impersonate legitimate devices on the vendor's VPN infrastructure.
Demo / Proof of Concept
▶ Watch: Discovering firmware update key decryption and leakage (9:00)
Moritz Abrell provided a clear demonstration of the exploit chain in action, visually illustrating the practical impact of the vulnerabilities. The demo showcased the administrative password theft and subsequent root shell acquisition.
The demonstration proceeded as follows:
- On the left side of the screen, a victim's web browser was displayed, simulating an administrator accessing the Ewon Cosy Plus web interface.
- On the right side, the attacker's terminal was shown, ready to execute the exploit.
- The victim administrator navigated to the logging page of the Ewon Cosy Plus web interface. At this point, the malicious JavaScript previously injected by the attacker (via a crafted FTP login attempt) executed within the victim's browser.
- The malicious JavaScript silently accessed the victim's browser cookies, extracted the base64-encoded administrative password, decoded it, and transmitted the plaintext password to the attacker's server (not explicitly shown in the demo but implied as the next step after JS execution).
- With the administrative credentials obtained, the attacker then uploaded a specially crafted OpenVPN configuration file to the device. This configuration file contained the command injection payload designed to establish a reverse shell.
- After a brief moment, the attacker's terminal successfully received a reverse shell connection from the Ewon Cosy Plus, confirming root access to the device.
Beyond this live demonstration of initial compromise, Abrell also described the broader proof of concept for the scalable attack. This involved using a rooted Ewon Cosy Plus to extract the firmware-specific encryption keys and subsequently obtain correctly signed certificates for other devices. The concept was then to use these certificates for VPN authentication to the vendor's central VPN server. By authenticating with a certificate associated with a legitimate device's serial number, the attacker could effectively cause a loss of connection for the original device. Furthermore, any user attempting to connect to that specific serial number would then be forwarded to the attacker's client, enabling further attacks, such as accessing the victim's client's remote desktop service. The enumerability of serial numbers meant this attack was not limited to a single device but could be scaled to target a vast number of the half-million deployed Ewon Cosy Plus gateways.
Abrell also mentioned developing a small proof of concept tool using NXP's Plug and Trust middleware to attempt direct access to keys stored on the HSM from the rooted device. However, this attempt was unsuccessful due to correctly configured policies within the HSM, demonstrating that the HSM itself was not directly compromised for key extraction, but rather the process of key handling and storage outside the HSM was flawed.
Defensive Implications
▶ Watch: Significant impact on industrial facilities worldwide (10:00)
The vulnerabilities identified by Moritz Abrell in the Ewon Cosy Plus Industrial Remote Access Gateway carry profound defensive implications for organizations relying on such solutions, particularly those operating critical infrastructure. Addressing these issues requires a multi-layered approach, ranging from immediate patching to fundamental architectural and operational changes.
- Immediate Patching and Firmware Updates: The most urgent defensive action is for all users of the Ewon Cosy Plus to immediately update their devices to the latest firmware version provided by HMS. Vendors typically release patches for disclosed vulnerabilities, and timely application of these updates is crucial to mitigate the specific exploit chain (command injection, XSS, insecure cookie handling). Organizations should have a robust patch management policy for all industrial control systems and associated remote access infrastructure.
- Secure Cookie Handling: The discovery of a plaintext administrative password in a base64-encoded cookie highlights a critical lapse in web application security. Developers should never store sensitive information, especially credentials, directly in cookies. If session tokens are necessary, they must be securely generated, ephemeral, and protected with
HttpOnly,Secure, andSameSiteattributes to prevent client-side script access, transmission over unencrypted channels, and cross-site request forgery.
- Robust Input Validation and Sanitization: The OpenVPN command injection and the persistent XSS via FTP login attempts underscore the need for stringent input validation and sanitization across all user-supplied data inputs. All input fields, whether in web forms, configuration file uploads, or network protocols (like FTP usernames), must be thoroughly validated against expected formats and sanitized to remove or neutralize any potentially malicious characters or code before processing. This prevents command injection, XSS, and other code injection vulnerabilities.
- Principle of Least Privilege: The fact that the OpenVPN commands executed with root privileges is a significant security flaw. Services and processes should always run with the minimum necessary privileges required for their function. If OpenVPN needs to execute custom scripts, those scripts should ideally run in a restricted environment or as a non-privileged user, limiting the impact of successful command injection.
- Strengthening Hardware Security Module (HSM) Integration: While the NXP EdgeLock HSM itself wasn't directly compromised for key extraction, its integration into the overall system allowed for key leakage. Defenders and vendors must ensure that HSMs are used effectively throughout the entire key lifecycle. Keys decrypted by an HSM should never be stored in plaintext on an accessible file system, even temporarily. Robust key management practices, including ephemeral in-memory handling and strict access controls, are paramount to prevent leakage even if the device gains root access. Firmware update keys should be unique per device and never derivable or exfiltratable from a compromised device.
- Secure Firmware Update Process: The ability to leak firmware-specific encryption keys from a rooted device is a severe issue. Firmware updates must be signed and verified cryptographically, and the keys used for decryption should be strictly managed by the HSM without ever being exposed in plaintext on the device's file system. This ensures that even if an attacker gains root access, they cannot compromise the integrity of future updates or impersonate legitimate devices on a large scale.
- Network Segmentation and Access Controls: Organizations should implement strong network segmentation to isolate industrial control networks (OT) from enterprise IT networks and the internet. Remote access solutions should be placed in a demilitarized zone (DMZ), and access to OT segments should be strictly controlled, monitored, and limited to only essential services and personnel.
- Comprehensive Logging and Monitoring: Implement detailed logging for all administrative actions, VPN connections, FTP login attempts, and device reconfigurations. Active monitoring of these logs can help detect anomalous behavior, such as repeated failed FTP logins, unusual VPN connection attempts, or unexpected device disconnections, which could indicate an ongoing attack.
- Vendor Due Diligence and Security Audits: Organizations deploying such critical remote access solutions must conduct thorough vendor due diligence and request independent security audit reports. Simply relying on vendor claims of "secure by design" or third-party certifications is insufficient without understanding the scope and depth of those assessments. Regular, independent penetration testing of deployed systems is also recommended.
- Supply Chain Security: The incident underscores the importance of security throughout the entire product lifecycle, from design and development to deployment and maintenance. Organizations must consider the security posture of their entire supply chain when integrating industrial IoT and remote access devices.
Key Takeaways
- Industrial Remote Access Gateways, like the Ewon Cosy Plus, are critical components in OT environments, and their widespread deployment makes them high-value targets for attackers seeking access to critical infrastructure.
- Despite strong security claims, including the presence of Hardware Security Modules (HSMs), root of trust, and secure boot, fundamental software and implementation vulnerabilities can render these hardware protections ineffective.
- A multi-stage exploit chain, combining persistent Cross-Site Scripting (XSS) via FTP login attempts, an insecure cookie storing plaintext administrative passwords, and a command injection vulnerability in OpenVPN, can lead to complete root compromise of the device.
- Achieving root access allows attackers to decrypt sensitive configuration data (passwords, VPN certificates) due to hardcoded encryption keys and IVs found in the firmware.
- Crucially, a rooted device can be used to leak firmware-specific encryption keys from the update process, enabling a highly scalable attack to disconnect and redirect users of over 500,000 devices globally, including critical infrastructure.
- True security requires not just advanced hardware features but also secure software development practices, robust input validation, secure cookie handling, strict adherence to the principle of least privilege, and comprehensive key management that prevents leakage even from a compromised system.
About the Speaker(s)
Moritz Abrell is a Senior IT Security Consultant and Penetration Tester at Sys, a German company. He is passionate about security research and is known for his expertise in identifying and exploiting vulnerabilities in various systems. Abrell regularly presents his findings at prominent security conferences, including Black Hat and DEF CON, contributing valuable insights to the cybersecurity community. His work often involves "breaking stuff" to uncover critical weaknesses that can impact widely used technologies.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
Abrell's research on the Ewon Cosy Plus is a masterclass in dismantling vendor security theater. He meticulously chains seemingly minor vulnerabilities – from basic command injection and persistent XSS to insecure cookie handling – to achieve full root compromise. The true punch comes with the reverse engineering of the firmware update process, demonstrating how an attacker can leverage a single rooted device to leak firmware-specific encryption keys, enabling a scalable attack capable of disconnecting and redirecting users from over half a million critical infrastructure assets. This isn't just a vulnerability; it's a blueprint for a global ICS nightmare, proving that hardware security…