Optergy Proton And Enterprise BMS 2.0.3a Command Injection
Posted by deepcore on March 29, 2023 – 12:15 pm
This Metasploit module exploits an undocumented backdoor vulnerability in the Optergy Proton and Enterprise Building Management System (BMS) applications. Versions 2.0.3a and below are vulnerable. Attackers can exploit this issue by directly navigating to an undocumented backdoor script called Console.jsp in the tools directory and gain full system access. Successful exploitation results in root command execution using sudo as user optergy.
Post a reply
You must be logged in to post a comment.