CVE-2022-30422: ViewState deserialization in Proietti Planet Time Enterprise
A default validationKey in Planet Time Enterprise's web.config lets an unauthenticated attacker forge a malicious ViewState and execute commands remotely on the server.
- CVE
- CVE-2022-30422
- Product
- Proietti Planet Time Enterprise (up to 4.2.0.1)
- CVSS
- 8.1
- Severity
- high
- Status
- patched
TL;DR
Planet Time Enterprise, Proietti Tech’s time-and-attendance software, ships with a
default validationKey in its web.config. Knowing that key — identical across
every installation — an unauthenticated attacker can forge a malicious
__VIEWSTATE and abuse ASP.NET deserialization to execute commands remotely on the
Windows server.
Research I carried out in my work at Tinexta Cyber, published under responsible disclosure.
Context
Planet Time Enterprise is a suite for time-and-attendance tracking and HR management, usable both on Windows and on the web. It is adopted by hundreds of clients, which amplifies the impact of a cryptographic key shared across installations.
Details
| Asset | Vulnerability | CVSS | Severity |
|---|---|---|---|
| Planet Time Enterprise (3.3.0.0 → 4.2.0.1) | ViewState deserialization | 8.1 | High |
Affected versions: 4.2.0.1, 4.2.0.0, 4.1.0.0, 4.0.0.0, 3.3.1.0, 3.3.0.0.
In ASP.NET Web Forms the __VIEWSTATE field is protected by a MAC computed with
the validationKey present in web.config. If that key is known, an attacker can
craft a ViewState with a valid MAC containing a malicious serialized payload: when
the server deserializes it, the payload is executed. Here the key was the
default one installed with the product, therefore the same and known on every
installation. Exploitation requires no authentication.
Proof of Concept
The payload was generated with
ysoserial.net, using the default
validationKey:
.\ysoserial.exe -p ViewState -g TextFormattingRunProperties `
-c "powershell -ep bypass -windowstyle hidden -encodedCommand <BASE64>" `
--validationalg="SHA1" --validationkey="<DEFAULT_KEY>" --generator=<GEN>
The ViewState thus generated was sent in a POST request as the __VIEWSTATE
parameter.

The result is an interactive shell on the server hosting the application.

Impact
The attacker gains command execution on the Windows server, with the ability to exfiltrate personal and sensitive data, move laterally across the infrastructure and encrypt data with ransomware for extortion. Since it is a default key, the attack is reproducible on every unremediated installation.
Fix and mitigations
- Keep the .NET framework updated to the latest supported version.
- Verify the IIS settings:
enableViewStateMacset totrue;aspnet:AllowInsecureDeserializationset tofalse.
- Regenerate or replace the
validationKeyinweb.config, or set it to be auto-generated. - Update the software to the latest available version.
Timeline
| Date | Event |
|---|---|
| 2022-03-29 | Vulnerability discovered |
| 2022-04-07 | First contact with the vendor (no reply) |
| 2022-04-21 | Second contact with the vendor (reply received) |
| 2022-04-22 | Report shared with the vendor |
| 2022-05-03 | CVE-ID requested from MITRE |
| 2022-05-19 | Vendor requests patch verification |
| 2022-05-27 | CVE-2022-30422 assigned |
| 2022-05-31 | Publication date agreed |
| 2022-06-16 | Security advisory published |