Vulnerability record · CVE-2019-7276 · published 1 July 2019
CVE-2019-7276: Optergy Proton and Enterprise backdoor console allows remote root code execution
Optergy · Enterprise
Optergy Proton and Enterprise devices expose a backdoor console that permits remote code execution with root privileges. The flaw is network-reachable and requires no authentication or user interaction, so any host that can reach the device can attempt it. It matters because these are building management system products, and full root control of a BMS controller can disrupt or manipulate physical building operations.
Description
Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication and full root code execution on building control systems, combined with a 99.8th percentile EPSS score, makes this an urgent exposure despite the absence of KEV listing.
What it is
Optergy Proton and Enterprise devices expose a backdoor console that permits remote code execution with root privileges. The flaw is network-reachable and requires no authentication or user interaction, so any host that can reach the device can attempt it. It matters because these are building management system products, and full root control of a BMS controller can disrupt or manipulate physical building operations.
Impact
An attacker gains remote root-level code execution on the affected device, allowing full control of the system, its data and any connected building control functions.
Attack surface
Reached over the network via the exposed backdoor console, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is very high at 0.93384 (99.8th percentile), indicating strong predicted exploitation activity. Reference tags are only Third Party Advisory and VDB Entry, with no exploit tag, so public exploit code is not confirmed by the record.
What to do
- Apply the vendor fix for Optergy Proton/Enterprise; the record does not state a patched version, so confirm the current release with Optergy.
- Isolate BMS devices from untrusted networks and the internet; restrict management access to a dedicated, firewalled segment.
- Block or disable the backdoor console service and any unnecessary management interfaces on affected devices.
- Require VPN or jump-host access with authentication for all administrative reachability to these devices.
- Monitor vendor advisories and the Applied Risk AR-2019-008 advisory for updated remediation guidance.
Detection
- Alert on unexpected inbound connections to Optergy management or console ports from outside the authorized management segment.
- Monitor device logs and process activity for unexpected command execution or new processes running as root.
- Baseline normal BMS traffic and flag anomalous outbound connections or configuration changes from Proton/Enterprise hosts.
- Inventory all Optergy Proton and Enterprise devices on the network to confirm which are exposed and unpatched.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/171564/Optergy-Proton-And-Enterprise-BMS-2.0.3a-Command-Injection.html | |
| http://www.securityfocus.com/bid/108686 | Third Party AdvisoryVDB Entry |
| https://applied-risk.com/labs/advisories | Third Party Advisory |
| https://www.applied-risk.com/resources/ar-2019-008 | Third Party Advisory |
| http://packetstormsecurity.com/files/171564/Optergy-Proton-And-Enterprise-BMS-2.0.3a-Command-Injection.html | |
| http://www.securityfocus.com/bid/108686 | Third Party AdvisoryVDB Entry |
| https://applied-risk.com/labs/advisories | Third Party Advisory |
| https://www.applied-risk.com/resources/ar-2019-008 | Third Party Advisory |
Track CVE-2019-7276 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-7276), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.