Medical washer-disinfector appliance's web server open to attack
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-7240 | An issue was discovered on Miele Professional PST10 devices. An issue was discovered on Miele Professional PST10 devices. The corresponding embedded webserver "PST10 WebServer" typically listens to port 80 and is prone to a directory traversal attack; therefore, an unauthenticated attacker may be able to exploit this issue to access sensitive information to aide in subsequent attacks. A Proof of Concept is GET /../../../../../../../../../../../../etc/shadow HTTP/1.1. This affects PG8527 devices 2.02 before 2.12, PG8527 devices 2.51 before 2.61, PG8527 devices 2.52 before 2.62, PG8527 devices 2.54 before 2.64, PG8528 devices 2.02 before 2.12, PG8528 devices 2.51 before 2.61, PG8528 devices 2.52 before 2.62, PG8528 devices 2.54 before 2.64, PG8535 devices 1.00 before 1.10, PG8535 devices 1.04 before 1.14, PG8536 devices 1.10 before 1.20, and PG8536 devices 1.14 before 1.24. NVD description · AI analysis pending | 7.5 | 17% | PoC |
| — |
Full article222 words · extracted from helpnetsecurity.com · click to collapse
Here’s a string of words that you probably never thought you’ll hear: An Internet-connected washer-disinfector appliance by German manufacturer Miele sports a vulnerable embedded web server.

The vulnerable device
The appliance in question – Miele Professional PG 8528 – is used in medical establishments to clean and thoroughly disinfect medical and laboratory instruments and glassware.
It has an RS 232 serial interface that facilitates the exchange of data with other appliances (e.g. for process documentation), and an Ethernet interface that enables cable-supported communication in the local network.
The vulnerability
“The corresponding embedded webserver ‘PST10 WebServer’ typically listens to port 80 and is prone to a directory traversal attack, therefore an unauthenticated attacker may be able to exploit this issue to access sensitive information to aid in subsequent attacks,” Jens Regel, IT security consultant at German consultancy Schneider & Wulf, explained.
He also published proof-of-concept exploit code for the flaw.
What now?
The vulnerability (CVE-2017-7240) is not critical, but that doesn’t mean that it can’t be dangerous or that it should not be fixed.
According to Regel, Miele has been notified of it, but has still not said when a fix can be expected or if it exists and it’s already being implemented.
Therefore, for the time being, disconnecting the device from the Internet is the best option for keeping it secure.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2017/03/27/miele-web-server-open-attack/