An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code execution on the system by sending a crafted request to the libraries installation route and injecting malicious input into the request body.
The attacker sends a crafted network request to the endpoint responsible for library installation in the XWEB Pro system. In the request body, they inject malicious operating system commands, which are then executed by the vulnerable component without proper validation and sanitization of input data. The attack is possible remotely over the network without the need to possess an account in the system.
Successful exploitation of the vulnerability gives the attacker full control over the device through remote code execution (RCE) with operating system privilege level, which may lead to violations of confidentiality, integrity, and system availability.
Patches available from the manufacturer should be applied in accordance with the references — update available at https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate. It is also recommended to limit network access to XWEB Pro devices through a firewall and to isolate the OT network from corporate networks and the Internet.
Copeland XWEB Pro in version 1.12.1 and earlier — affects Copeland Xweb 500B Pro, Copeland Xweb 300D Pro, and Copeland Xweb 500D Pro devices (firmware and software).
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HCopeland Xweb 300d Pro
HWCopelandall versionsCopeland Xweb 300d Pro Firmware
OSCopeland≤ 1.12.1Copeland Xweb 500b Pro
HWCopelandall versionsCopeland Xweb 500b Pro Firmware
OSCopeland≤ 1.12.1Copeland Xweb 500d Pro
HWCopelandall versionsCopeland Xweb 500d Pro Firmware
OSCopeland≤ 1.12.1
Related vulnerabilities
Auth Bypass i RCE w Copeland XWEB Pro – firmware sterowników przemysłowych
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticate...
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authentica...
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated...
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated...