Accessing a VPN though Raspberry Pi

Hi, I’m here for professional curiosity, but I’m not a professional hacker. I’m an embedded systems engineer. I’m working with a client who has built an IoT product off a raspberry pi. This raspberry pi is running openVPN to connect to their servers for mission control, monitoring and provisioning. As part of my work I’ve had to access the device by exploiting the serial connection connection on the pi and I’m now able to log in to the device with superuser permissions.

Here’s my question: now that I’m logged into their device over serial, can I now connect to their servers through the VPN client running on the Pi? Is this an actual security vulnerability? Assuming it is, what is the risk to them? ie, what could be realistically be done with this access?

submitted by /u/Only-Friend-8483
[link] [comments]

May 31, 2023
Read More >>