CVE-2022-30422: ViewState deserialization in Proietti Planet Time Enterprise

A default validationKey in Planet Time Enterprise's web.config lets an unauthenticated attacker forge a malicious ViewState and execute commands remotely on the server.

CVE
CVE-2022-30422
Product
Proietti Planet Time Enterprise (up to 4.2.0.1)
CVSS
8.1
Severity
high
Status
patched

TL;DR

Planet Time Enterprise, Proietti Tech’s time-and-attendance software, ships with a default validationKey in its web.config. Knowing that key — identical across every installation — an unauthenticated attacker can forge a malicious __VIEWSTATE and abuse ASP.NET deserialization to execute commands remotely on the Windows server.

Research I carried out in my work at Tinexta Cyber, published under responsible disclosure.

Context

Planet Time Enterprise is a suite for time-and-attendance tracking and HR management, usable both on Windows and on the web. It is adopted by hundreds of clients, which amplifies the impact of a cryptographic key shared across installations.

Details

Asset Vulnerability CVSS Severity
Planet Time Enterprise (3.3.0.0 → 4.2.0.1) ViewState deserialization 8.1 High

Affected versions: 4.2.0.1, 4.2.0.0, 4.1.0.0, 4.0.0.0, 3.3.1.0, 3.3.0.0.

In ASP.NET Web Forms the __VIEWSTATE field is protected by a MAC computed with the validationKey present in web.config. If that key is known, an attacker can craft a ViewState with a valid MAC containing a malicious serialized payload: when the server deserializes it, the payload is executed. Here the key was the default one installed with the product, therefore the same and known on every installation. Exploitation requires no authentication.

Proof of Concept

The payload was generated with ysoserial.net, using the default validationKey:

.\ysoserial.exe -p ViewState -g TextFormattingRunProperties `
  -c "powershell -ep bypass -windowstyle hidden -encodedCommand <BASE64>" `
  --validationalg="SHA1" --validationkey="<DEFAULT_KEY>" --generator=<GEN>

The ViewState thus generated was sent in a POST request as the __VIEWSTATE parameter.

POST request with the ViewState payload

The result is an interactive shell on the server hosting the application.

Reverse shell obtained on the server

Impact

The attacker gains command execution on the Windows server, with the ability to exfiltrate personal and sensitive data, move laterally across the infrastructure and encrypt data with ransomware for extortion. Since it is a default key, the attack is reproducible on every unremediated installation.

Fix and mitigations

  • Keep the .NET framework updated to the latest supported version.
  • Verify the IIS settings:
    • enableViewStateMac set to true;
    • aspnet:AllowInsecureDeserialization set to false.
  • Regenerate or replace the validationKey in web.config, or set it to be auto-generated.
  • Update the software to the latest available version.

Timeline

Date Event
2022-03-29 Vulnerability discovered
2022-04-07 First contact with the vendor (no reply)
2022-04-21 Second contact with the vendor (reply received)
2022-04-22 Report shared with the vendor
2022-05-03 CVE-ID requested from MITRE
2022-05-19 Vendor requests patch verification
2022-05-27 CVE-2022-30422 assigned
2022-05-31 Publication date agreed
2022-06-16 Security advisory published

References

← all posts