How Can BLEEDINGBIT Breach Enterprise Networks?

100 views
•
May 16, 2019
by
RSAC Cybersecurity
YouTube video player
How Can BLEEDINGBIT Breach Enterprise Networks?

TL;DR

BLEEDINGBIT can let a nearby attacker compromise a vulnerable wireless access point through Bluetooth Low Energy without authentication, then cross boundaries between guest and corporate networks. After installing a malicious agent on the access point, the attacker can use its guest-network internet connection to maintain remote command-and-control access for days or weeks without remaining nearby.

Transcript

Hi, everyone. Uh, thanks for joining our session, uh, where we're gonna talk about, uh, connectivity, all the risk that comes from it, and specifically, uh, how you can potentially hop right into enterprise networks, uh, using BLE. Um, I'm Nadir Israel, I'm the CTO and co-founder of Armis. I'm Misha Selter, uh, chief solutions architect at Armis. U... Read More

Key Insights

  • BLEEDINGBIT is a set of two critical vulnerabilities disclosed by Armis researchers to Texas Instruments, with the enterprise analysis focused on Bluetooth Low Energy components embedded in widely used Cisco, Aruba, and Meraki wireless access points.
  • Bluetooth Low Energy is used across phones, laptops, medical devices, manufacturing environments, retail systems, offices, smart locks, televisions, headsets, beacons, scanners, and badge readers because it requires relatively little hardware and enjoys broad device support.
  • Enterprise access points are endpoints on the network, even though administrators often treat them as abstract infrastructure. Newer access points can contain a standard Linux stack and standard BLE implementation while remaining unmanaged, unprotected, and unable to run conventional security agents.
  • BLE radios in access points support legitimate applications, including indoor navigation, customer movement tracking, medical asset location, patient-bed tracking, and telemetry from smart sensors in medical or manufacturing environments.
  • BLEEDINGBIT access is unauthenticated and difficult to detect because the attacker enters through a peripheral radio path rather than the network's expected authentication mechanisms. Certificate-based authentication and encryption do not address compromise occurring through this separate route.
  • Network segmentation is only as strong as the switches and access points enforcing it. If an attacker controls an access point that projects both guest and corporate networks, the attacker can potentially break the intended separation and move between those segments.
  • A BLE attack can begin from a parking lot or lobby because the attacker communicates wirelessly with the access point. Physical entry into a protected office or a direct wired connection is therefore unnecessary for the initial compromise described.
  • Persistent access can continue after the attacker leaves Bluetooth range. The attacker can install a malicious agent on the compromised access point within seconds, use the guest network's internet connectivity to reach a command-and-control server, and continue the attack remotely for days or weeks.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is BLEEDINGBIT and what systems does it affect?

BLEEDINGBIT is a set of two critical vulnerabilities that Armis researchers disclosed to Texas Instruments. The enterprise-focused research examined vulnerable Bluetooth Low Energy components inside wireless access points, including products associated with Cisco, Aruba, and Meraki. These access points are part of corporate infrastructure and may expose organizations to wireless compromise through low-level embedded chips.

Q: How can BLEEDINGBIT provide access to an enterprise network?

BLEEDINGBIT can provide entry by allowing an attacker to target the Bluetooth Low Energy component of a vulnerable wireless access point. The path is described as unauthenticated and invisible because it does not use the network's normal login mechanisms. After compromising the BLE chip, its software stack, and the access point, the attacker can reach networks projected by that device.

Q: Why do enterprise wireless access points include Bluetooth Low Energy?

Wireless access points include Bluetooth Low Energy for practical functions beyond providing Wi-Fi. Examples include locating a user indoors by identifying the closest access point, tracking customer movement through stores, finding medical devices and patient beds in hospitals, and receiving telemetry from smart sensors. Similar capabilities also support asset tracking and monitoring in manufacturing environments.

Q: Why can BLE compromise bypass authentication and encryption?

BLE compromise can bypass existing controls because the attacker enters through a peripheral radio path that the access point was not expected to expose as a route into the network. Normal certificate-based authentication and encryption protect their intended communications, but they do not prevent exploitation of a separate vulnerable BLE component. Consequently, the initial access requires no standard network authentication.

Q: How does access point compromise defeat network segmentation?

Network segmentation depends on physical devices, including access points and switches, to enforce separation. A single access point may project multiple networks that administrators view as distinct, such as guest and corporate networks. If an attacker controls that shared device, the attacker can break the enforced boundaries, enter through the guest side, and potentially gain access to the corporate side.

Q: Can a BLEEDINGBIT attacker operate from outside an office?

A BLEEDINGBIT attacker does not necessarily need to enter the protected workplace or connect directly to its wired network. Because the initial attack uses wireless communication, the attacker may target an access point from a nearby parking lot or a generic lobby. The attack still requires sufficient proximity for the initial Bluetooth interaction, but continued physical presence is not required afterward.

Q: How can an attacker maintain access after leaving Bluetooth range?

After taking control of a vulnerable access point, an attacker can install a malicious agent on it within seconds. That agent can contact a command-and-control server through the guest network, which already provides internet access. The attacker can then leave the area and continue operating remotely from home for days or weeks instead of remaining within Bluetooth range.

Q: What security risks follow a BLEEDINGBIT access point takeover?

A successful takeover can give an attacker full remote control of the wireless access point and undermine the boundaries between networks it projects. The described malicious potential includes traffic sniffing, malware distribution, and lateral movement across network segments. Because the entry occurs through BLE and can support a persistent command-and-control agent, existing network authentication may not reveal the compromise.

Summary & Key Takeaways

  • BLEEDINGBIT is a set of two critical vulnerabilities disclosed by Armis researchers to Texas Instruments. The research examined Bluetooth Low Energy as an enterprise risk surface, particularly in Cisco, Aruba, and Meraki wireless access points that form part of the corporate infrastructure in organizations around the world.

  • Bluetooth Low Energy appears in access points for legitimate functions such as indoor navigation, retail customer tracking, medical asset tracking, and sensor telemetry. However, enterprises may not realize that these radios exist, use standard BLE implementations, and operate with high privileges inside otherwise unmanaged and unprotected network infrastructure.

  • An attacker can approach a vulnerable access point wirelessly, exploit its BLE component, take control of the device, and undermine network segmentation. A malicious agent installed within seconds can contact a command-and-control server through the guest network, allowing continued remote access, traffic sniffing, malware distribution, and lateral movement between network segments.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚