{"id":3940,"date":"2024-06-07T11:55:39","date_gmt":"2024-06-07T16:55:39","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/hotel-check-in-kiosks-expose-guest-data-room-keys"},"modified":"2024-06-07T11:55:39","modified_gmt":"2024-06-07T16:55:39","slug":"hotel-check-in-kiosks-expose-guest-data-room-keys","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/06\/07\/hotel-check-in-kiosks-expose-guest-data-room-keys\/","title":{"rendered":"Hotel Check-in Kiosks Expose Guest Data, Room Keys"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt8efcb6c99f898c8b\/666335c6323a831c1f62c986\/hotel-Henk_Vrieselaar-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/hotel-check-in-kiosks-expose-guest-data-room-keys.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/hotel-check-in-kiosks-expose-guest-data-room-keys.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A software vulnerability in Ariane Systems&#8217; kiosk platform allows attackers to access the personal data of hotel guests through check-in terminals equipped with the software.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Through a kiosk mode bypass flaw (<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/github.com\/advisories\/GHSA-3w3g-gjcj-rg22\" rel=\"noopener\">CVE-2024-37364<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, CVSS 3.0 score 6.8) malicious actors could access locally stored reservations and invoices as well as personally identifiable information (PII), according to Pentagrid security researcher Martin Schobert, who discovered the vulnerability in March.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Vulnerable terminals running Ariane Allegro Scenario Player also potentially could be used to create room keys for other hotel rooms, as the ability to make RFID transponders used as keycards is also installed on the check-in terminals, he <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.pentagrid.ch\/en\/blog\/ariane-allegro-hotel-check-in-terminal-kios-escape\/\" rel=\"noopener\">warned in a blog post<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> this week.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The impact could be wide-ranging: On its website, Ariane claims to be &#8220;the world&#8217;s leading provider of self-check-in and -out solutions for the hotel industry with more than 3,000 installations.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"How the Ariane Hotel Check-In Exploit Works\">How the Ariane Hotel Check-In Exploit Works<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The software enables guests to check in and book rooms at the hotel. Hotel guests can use it to search for existing reservations by entering their surname or a booking number.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, if a single quote is entered when searching for a name, the application hangs.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;When touching the screen of the terminal again, the Windows operating system will ask the user if Windows should wait any longer or stop the task,&#8221; Schobert wrote.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Exiting also ends the software&#8217;s kiosk mode, giving the user access to the system&#8217;s Windows desktop, with code-execution ability \u2014 and to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/marina-bay-sands-hospitality-cyber-victim\" rel=\"noopener\">the data stored there<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and the network.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">\u201cWith the ability to inject and execute program code, it seems possible to get room keys created for other rooms because the functionality of provisioning RFID transponders is implemented in the terminal,&#8221; he continued.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">He noted an attacker needs physical access to a check-in terminal to carry out an attack, and depending on the threat actor&#8217;s preparation, it does require some time at the terminal. That means incidents can be prevented with proper physical monitoring.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">John Bambenek, president at Bambenek Consulting, recommends that these kiosks should always be in highly visible areas with antivirus surveillance, and says access to anything except the touchscreen should be inaccessible to the public.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;These devices probably cannot be completely isolated from the main hotel network as part of the point is to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/omni-hotel-it-outage-causes-operational-disruptions\" rel=\"noopener\">issue keys and handle room management<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">,&#8221; he notes. &#8220;However, the devices should be limited to sending only require machines and ports with everything else filtered.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Multiple Hospitality Risks, Access to Rooms&nbsp;\">Multiple Hospitality Risks, Access to Rooms&nbsp;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">John Gallagher, vice president of Viakoo Labs at Viakoo, says providing unauthorized access to data contained within a hotel check-in terminal gives rise to multiple risks.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;These include knowing details on someone&#8217;s stay, if a room is occupied or not, potential lateral movement to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/stalkerware-app-with-security-bug-discovered-on-hotel-systems\" rel=\"noopener\">systems on the same network<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, and data capturing applications being put onto the kiosk,&#8221; he explains.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">He adds that if access to the kiosk can also provide access to the broader hotel network, it would provide the attacker with much more data.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The situation I would be most concerned about is if I could see someone using the self-check-in terminal, then follow them in using it, crash the Ariane application, get access to the last guest&#8217;s check-in information, print a new RFID card, then have access to that person&#8217;s room,&#8221; Gallagher explains.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Update Kiosk Software, Limit Access\">Update Kiosk Software, Limit Access<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Ariane told Pentagrid that the vulnerability had been fixed in a new version of the Allegro Scenario Player, and that the terminal examined by Schobert was a &#8220;legacy system.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, according to the researcher, the manufacturer did not disclose the exact version in which the problem was patched.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">According to Schobert, the system he investigated was an Ariane Duo 6000 series terminal. But Adam Neel, senior threat detection engineer at Critical Start, says hotel operators must ensure all check-in terminals are running the latest version of the Ariane Allegro Scenario Player to fully address the software flaw.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Meanwhile, Neel notes that in general, organizations should make sure that all Internet of things (IoT) devices are patched with the latest security updates \u2014 and often-overlooked area for IT teams.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Beyond regular patching, &#8220;implementing network isolation by <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/plugging-the-kiosk-sized-security-hole\" rel=\"noopener\">placing terminals on a separate VLAN or network segment<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> from critical systems is also crucial,&#8221; he adds. &#8220;And finally, having an incident response plan in place is essential for quickly addressing any security breaches.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/hotel-check-in-kiosks-expose-guest-data-room-keys\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A software vulnerability in Ariane Systems&#8217; kiosk platform allows attackers<\/p>\n","protected":false},"author":12,"featured_media":3941,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3940","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/hotel-check-in-kiosks-expose-guest-data-room-keys-scaled.jpg?fit=2560%2C1308&ssl=1",2560,1308,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/hotel-check-in-kiosks-expose-guest-data-room-keys-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/hotel-check-in-kiosks-expose-guest-data-room-keys-scaled.jpg?fit=300%2C153&ssl=1",300,153,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/hotel-check-in-kiosks-expose-guest-data-room-keys-scaled.jpg?fit=640%2C327&ssl=1",640,327,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/hotel-check-in-kiosks-expose-guest-data-room-keys-scaled.jpg?fit=640%2C327&ssl=1",640,327,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/hotel-check-in-kiosks-expose-guest-data-room-keys-scaled.jpg?fit=1536%2C785&ssl=1",1536,785,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/hotel-check-in-kiosks-expose-guest-data-room-keys-scaled.jpg?fit=2048%2C1046&ssl=1",2048,1046,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/hotel-check-in-kiosks-expose-guest-data-room-keys-scaled.jpg?fit=1024%2C523&ssl=1",1024,523,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/hotel-check-in-kiosks-expose-guest-data-room-keys-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/hotel-check-in-kiosks-expose-guest-data-room-keys-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/hotel-check-in-kiosks-expose-guest-data-room-keys-scaled.jpg?fit=2560%2C1308&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3940","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3940"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3940\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3941"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3940"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3940"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3940"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}