When The Front Door Becomes a Backdoor: The Security Paradox of OSDP

No ratings

Presented at BlackHat Europe 2023 by

Ever imagined that the modern Physical Access Control Systems (PACS) at the front door of your facility could actually serve as an entry point into your internal IP network? Surprisingly, this is not as far-fetched as it seems. In this talk, we will demonstrate how to go through doors, protected with the latest advancements in building access control security - both physically and digitally.We will delve into modern access control readers located at the front door, and explore their connectivity with access controllers, managed within the internal network of the building. Focusing on Open Supervised Device Protocol (OSDP), the newest standard for reader-controller communication, we'll discuss how this increasingly adopted protocol was expected to improve building access security, but ironically introduces some unprecedented risks - way beyond access control…Our endeavor begins with bypassing physical tamper protection of access control readers (in under 15 seconds!) and continues with 6 zero-day vulnerabilities in OSDP specifications and its different vendor implementations. We will leverage these vulnerabilities to gain unauthorized physical access to the building, deny entry to authorized personnel, and more importantly – move laterally over serial connection into the internal building digital infrastructure and gain a foothold in the local IP network, using an RCE vulnerability in the access controller. Even though the evolvement of PACS communication introduced much-needed security enhancements, it also brought a new attack surface along. While unauthorized access is not a novel attack scenario, lateral movement into the internal network from the front door has not been shown before. Given the diversity of PACS vendors, we are releasing an open-source OSDP fuzzing and assessment tool for assessors, red teamers, and researchers to enable further research and assessment of these systems. Based on beer-budget hardware and a standard PC, it already uncovered several vulnerabilities on its own and was used as the main framework during our research. We will demo how this framework can be leveraged to easily set up a Man-in-The-Middle on the serial connection, identify insecure OSDP messages, fuzz access controllers and readers, and ultimately assist with developing exploits for lateral movement over the serial channel.