The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack. Among other uses, the WDU utilizes WebSockets to control settings, including administrative settings. This allows a network attacker to take full control of a WDU. To initiate an exploit of this vulnerability, the victim must (1) be utilizing a web browser on a multihomed host that has local interfaces on the Garmin Marine Network as well as another network, and (2) access a malicious third party website created by the attacker.
The Garmin WDU device hosts a local website that uses the WebSocket protocol for settings management, including administrative settings. The vulnerability results from lack of proper verification of the origin of WebSocket requests (CWE-352 — Cross-Site Request Forgery). The attack requires the victim to use a browser on a host connected simultaneously to both the Garmin Marine Network and another network (multi-interface host), and then visit a malicious website prepared by the attacker. The malicious website initiates a WebSocket connection to the local interface of the WDU device, bypassing browser isolation mechanisms.
The attacker gains full control over the Garmin WDU device, including the ability to modify administrative settings, which may lead to violation of confidentiality and integrity of data transmitted or stored by the device.
Apply patches available from the manufacturer according to references. As a workaround, avoid using a web browser on hosts connected simultaneously to both the Garmin Marine Network and other external networks, especially when browsing untrusted websites.
Garmin WDU v1 firmware version 1.4.6 and Garmin WDU v2 firmware version 5.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NGarmin Empirbus Wireless Display Unit
HWGarminv1v2Garmin Empirbus Wireless Display Unit Firmware
OSGarmin1.4.65.00
Related vulnerabilities
The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack. If a malicious gr...
The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. ...
Lokalnie obsługiwana strona internetowa na urządzeniu Garmin WDU (wersje v1 1.4.6 i v2 5.0) jest podatna na re...
Integer overflow w Garmin Connect-IQ API — przejęcie firmware urządzenia
Buffer overflow w Garmin Connect-IQ API — przejęcie firmware urządzenia