ICS Advisories https://www.cisa.gov/ en mySCADA myPRO Manager https://www.cisa.gov/news-events/ics-advisories/icsa-24-326-07 <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v4 10.0</strong></li> <li><strong>ATTENTION</strong>: Exploitable remotely/low attack complexity</li> <li><strong>Vendor:</strong> mySCADA</li> <li><strong>Equipment</strong>: myPRO</li> <li><strong>Vulnerabilities</strong>: OS Command Injection, Improper Authentication, Missing Authentication for Critical Function, Path Traversal.</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary commands or disclose sensitive information.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>The following mySCADA products are affected:</p> <ul> <li>myPRO Manager: Versions prior to 1.3</li> <li>myPRO Runtime: Versions prior to 9.2.1</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-cwe-78"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank"><strong>Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE-78</strong></a></h4> <p>A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-47407" target="_blank">CVE-2024-47407</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 10.0 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank">AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-47407" target="_blank">CVE-2024-47407</a>. A base score of 10.0 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H" target="_blank">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</a>).</p> <h4 id="322-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-cwe-78"><strong>3.2.2 </strong><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank"><strong>Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE-78</strong></a></h4> <p>An OS Command Injection vulnerability exists within myPRO Manager. A parameter within a command can be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-52034" target="_blank">CVE-2024-52034</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 10.0 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank">AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-52034" target="_blank">CVE-2024-52034</a>. A base score of 10.0 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H" target="_blank">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</a>).</p> <h4 id="323-improper-authentication-cwe-287"><strong>3.2.3 </strong><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank"><strong>Improper Authentication CWE-287</strong></a></h4> <p>The web application uses a weak authentication mechanism to verify that a request is coming from an authenticated and authorized resource.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-45369" target="_blank">CVE-2024-45369</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 8.1 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-45369" target="_blank">CVE-2024-45369</a>. A base score of 9.2 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>).</p> <h4 id="324-missing-authentication-for-critical-function-cwe-306"><strong>3.2.4 </strong><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank"><strong>Missing Authentication for Critical Function CWE-306</strong></a></h4> <p>The administrative interface listens by default on all interfaces on a TCP port and does not require authentication when being accessed</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-47138" target="_blank">CVE-2024-47138</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 9.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-47138" target="_blank">CVE-2024-47138</a>. A base score of 9.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>).</p> <h4 id="325-path-traversal--cwe-35"><strong>3.2.5 </strong><a href="https://cwe.mitre.org/data/definitions/35.html" target="_blank"><strong>Path Traversal: '.../...//' CWE-35</strong></a></h4> <p>The backend does not sufficiently verify the user-controlled filename parameter which makes it possible for an attacker to perform a path traversal attack and retrieve arbitrary files from the file system</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-50054" target="_blank">CVE-2024-50054</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-50054" target="_blank">CVE-2024-50054</a>. A base score of 8.7 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Czech Republic</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Michael Heinzl reported these vulnerabilities to CISA.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>mySCADA recommends updating to the latest versions.</p> <ul> <li>mySCADA PRO Manager <a href="https://www.myscada.org/resources/" target="_blank">1.3</a></li> <li>mySCADA PRO Runtime <a href="https://www.myscada.org/resources/" target="_blank">9.2.1</a></li> </ul> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:</p> <ul> <li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the internet</a>.</li> <li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li> <li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</li> </ul> <p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p> <ul> <li>Do not click web links or open attachments in unsolicited email messages.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf" target="_blank">Recognizing and Avoiding Email Scams</a> for more information on avoiding email scams.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/ncas/tips/ST04-014" target="_blank">Avoiding Social Engineering and Phishing Attacks</a> for more information on social engineering attacks.</li> </ul> <p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 21, 2024: Initial Publication</li> </ul> Thu, 21 Nov 24 12:00:00 +0000 CISA /node/22616 Schneider Electric PowerLogic PM5300 Series https://www.cisa.gov/news-events/ics-advisories/icsa-24-326-06 <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v4 8.7</strong></li> <li><strong>ATTENTION</strong>: Exploitable remotely/low attack complexity</li> <li><strong>Vendor</strong>: Schneider Electric</li> <li><strong>Equipment</strong>: PowerLogic PM5300 Series</li> <li><strong>Vulnerability</strong>: Uncontrolled Resource Consumption</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of this vulnerability could cause the device to become unresponsive resulting in communication loss.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>Schneider Electric reports that the following PowerLogic energy meters are affected:</p> <ul> <li>PowerLogic PM5320: Versions 2.3.8 and prior</li> <li>PowerLogic PM5340: Versions 2.3.8 and prior</li> <li>PowerLogic PM5341: Versions 2.6.6 and prior</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-uncontrolled-resource-consumption-cwe-400"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/400.html" target="_blank"><strong>UNCONTROLLED RESOURCE CONSUMPTION CWE-400</strong></a></h4> <p>An uncontrolled resource consumption vulnerability exists that could cause Schneider Electric PowerLogic PM5300 Series devices to become unresponsive resulting in communication loss when a large amount of IGMP packets is present in the network.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-9409" target="_blank">CVE-2024-9409</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-9409" target="_blank">CVE-2024-9409</a>. A base score of 8.7 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Commercial Facilities, Critical Manufacturing, Energy</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> France</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Schneider Electric reported this vulnerability to CISA.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Schneider Electric has identified the following remediations users can apply to reduce risk:</p> <ul> <li>PowerLogic PM5320: <a href="https://www.se.com/ww/en/product/METSEPM5320/power-meter-powerlogic-pm5320-ethernet-up-to-31st-harmonic-256kb-2di-2do-35-alarms/" target="_blank">Version 2.4.0 of PowerLogic PM5320</a> includes a fix for this vulnerability.</li> <li>PowerLogic PM5340: <a href="https://www.se.com/ww/en/product/METSEPM5340/power-meter-powerlogic-pm5340-ethernet-up-to-31st-harmonic-256kb-2di-2do-35-alarms/" target="_blank">Version 2.4.0 of PowerLogic PM5340</a> includes a fix for this vulnerability.</li> <li>PowerLogic PM5341: <a href="https://www.se.com/ww/en/product/METSEPM5341/pm5341-meter-ethernet-up-to-31st-h-256k-2di-2do-35-alarms-mid/" target="_blank">Version 2.7.0 of PowerLogic PM5341</a> includes a fix for this vulnerability.</li> </ul> <p>If users choose not to apply the remediation provided above, Schneider Electric recommends immediately applying the following steps to reduce the risk of exploitation:</p> <ol> <li>Enable IGMP Snooping: Ensure that IGMP Snooping is enabled on the switch. This feature allows the switch to intelligently forward multicast traffic only to the necessary ports where interested hosts reside. It prevents unnecessary flooding of multicast traffic across all ports, thereby enhancing network efficiency and minimizing unnecessary load on network resources.</li> <li>Configure VLAN Interface Settings: Set up VLAN interface settings on the switch. It's important to have distinct configurations for each VLAN to ensure proper IGMP operation.</li> <li>Multicast Filtering: Use IGMP filtering to control the propagation of IGMP traffic through the network. This involves configuring filters on a switch virtual interface (SVI), per-port, or per-port per-VLAN basis. Multicast filtering helps manage IGMP snooping and controls multicast traffic forwarding effectively.</li> </ol> <p>Schneider Electric strongly recommend the following industry cybersecurity best practices:</p> <ul> <li>Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.</li> <li>Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.</li> <li>Place all controllers in locked cabinets and never leave them in the "Program" mode.</li> <li>Never connect programming software to any network other than the network intended for that device.</li> <li>Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.</li> <li>Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.</li> <li>Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.</li> <li>When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version<br>available. Also, understand that VPNs are only as secure as the connected devices.</li> </ul> <p>For more information refer to the <a href="https://www.se.com/us/en/download/document/7EN52-0390/" target="_blank">Schneider Electric Recommended Cybersecurity Best Practices document</a> and the associated Schneider Electric Security Notification SEVD-2024-317-01 in <a href="https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-317-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2024-317-01.pdf" target="_blank">PDF</a> and <a href="https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-317-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=sevd-2024-317-01.json" target="_blank">CSAF.</a></p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 21, 2024: Initial Publication</li> </ul> Thu, 21 Nov 24 12:00:00 +0000 CISA /node/22615 Schneider Electric EcoStruxure IT Gateway https://www.cisa.gov/news-events/ics-advisories/icsa-24-326-05 <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v4 10.0</strong></li> <li><strong>ATTENTION</strong>: Exploitable remotely/low attack complexity</li> <li><strong>Vendor</strong>: Schneider Electric</li> <li><strong>Equipment</strong>: EcoStruxure IT Gateway</li> <li><strong>Vulnerability</strong>: Missing Authorization</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of this vulnerability could allow unauthorized access.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>Schneider Electric reports that the following versions of EcoStruxure IT Gateway are affected:</p> <ul> <li>EcoStruxure IT Gateway: 1.21.0.6</li> <li>EcoStruxure IT Gateway: 1.22.0.3</li> <li>EcoStruxure IT Gateway: 1.22.1.5</li> <li>EcoStruxure IT Gateway: 1.23.0.4</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-missing-authorization-cwe-862"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank"><strong>MISSING AUTHORIZATION CWE-862</strong></a></h4> <p>A missing authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connected devices.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-10575" target="_blank">CVE-2024-10575</a> has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for  <a href="https://www.cve.org/CVERecord?id=CVE-2024-10575" target="_blank">CVE-2024-10575</a>. A base score of 10 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:L/SA:H" target="_blank">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:L/SA:H</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Commercial Facilities, Information Technology, Healthcare and Public Health, Critical Manufacturing, Transportation Systems, Energy, Chemical</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> France</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Schneider Electric reported this vulnerability to CISA.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Schneider Electric recommends users download <a href="https://community.se.com/t5/What-s-new-in-EcoStruxure-IT/Download-the-EcoStruxure-IT-Gateway/ta-p/455022" target="_blank">EcoStruxure IT Gateway version 1.23.1.10 </a>to remediate this vulnerability. The link also provides instructions. Versions prior to 1.21.0.6 are not impacted by this vulnerability.</p> <p>Schneider Electric encourages users to <a href="https://community.se.com/t5/Gateway-FAQ/Gateway-auto-update-in-IT-Expert/ta-p/447059" target="_blank">enable automatic updates</a> to receive updates promptly. Users who have enabled automatic updates do not need to take any further action.</p> <p>Users should protect the Gateway from remote access by controlling access to the software over a network. The following actions could be taken:</p> <ul> <li>Place the Gateway software on protected access-controlled networks only</li> <li>Implement a local firewall to deny remote access to the web API.</li> <li>Remove the Gateway software and installing a clean build of 1.23.1.10</li> </ul> <p>Schneider Electric strongly recommend the following industry cybersecurity best practices:</p> <ul> <li>Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.</li> <li>Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.</li> <li>Place all controllers in locked cabinets and never leave them in the "Program" mode.</li> <li>Never connect programming software to any network other than the network intended for that device.</li> <li>Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.</li> <li>Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.</li> <li>Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.</li> <li>When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version<br>available. Also, understand that VPNs are only as secure as the connected devices.</li> </ul> <p>For more information refer to the <a href="https://www.se.com/us/en/download/document/7EN52-0390/" target="_blank">Schneider Electric Recommended Cybersecurity Best Practices document</a> and the associated Schneider Electric Security Notification SEVD-2024-317-04 in <a href="https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-317-04&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2024-317-04.pdf" target="_blank">PDF</a> and <a href="https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-317-04&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=sevd-2024-317-04.json" target="_blank">CSAF.</a></p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 21, 2024: Initial Publication</li> </ul> Thu, 21 Nov 24 12:00:00 +0000 CISA /node/22613 Schneider Electric Modicon M340, MC80, and Momentum Unity M1E https://www.cisa.gov/news-events/ics-advisories/icsa-24-326-04 <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v4 9.2</strong></li> <li><strong>ATTENTION</strong>: Exploitable remotely</li> <li><strong>Vendor</strong>: Schneider Electric</li> <li><strong>Equipment</strong>: Modicon M340, MC80, and Momentum Unity M1E</li> <li><strong>Vulnerabilities</strong>: Improper Input Validation, Improper Restriction of Operations within the Bounds of a Memory Buffer</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of these vulnerabilities could allow an attacker to tamper with memory on these devices.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>The following versions of Schneider Electric Modicon M340, MC80, and Momentum Unity M1E are affected:</p> <ul> <li>Modicon M340 CPU (part numbers BMXP34*): Versions prior to SV3.65</li> <li>Modicon MC80 (part numbers BMKC80)(CVE-2024-8937, CVE-2024-8938): All versions</li> <li>Modicon Momentum Unity M1E Processor (171CBU*)(CVE-2024-8937, CVE-2024-8938): All versions</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-improper-input-validation-cwe-20"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>Improper Input Validation CWE-20</strong></a></h4> <p>An Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory after a successful Man-In-The-Middle attack followed by sending a crafted Modbus function call used to tamper with memory.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-8936" target="_blank">CVE-2024-8936</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 6.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N" target="_blank">AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-8936" target="_blank">CVE-2024-8936</a>. A base score of 8.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N" target="_blank">CVSS4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N</a>).</p> <h4 id="322-improper-restriction-of-operations-within-the-bounds-of-a-memory-buffer-cwe-119"><strong>3.2.2 </strong><a href="https://cwe.mitre.org/data/definitions/119.html" target="_blank"><strong>Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-119</strong></a></h4> <p>Arbitrary code execution can potentially be achieved after a successful Man-In-The Middle attack followed by sending a crafted Modbus function call to tamper with memory area involved in the authentication process.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-8937" target="_blank">CVE-2024-8937</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 8.1 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-8937" target="_blank">CVE-2024-8937</a>. A base score of 9.2 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>).</p> <h4 id="323-improper-restriction-of-operations-within-the-bounds-of-a-memory-buffer-cwe-119"><strong>3.2.3 </strong><a href="https://cwe.mitre.org/data/definitions/119.html" target="_blank"><strong>Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-119</strong></a></h4> <p>Arbitrary code execution can potentially be achieved after a successful Man-In-The Middle attack followed by sending a crafted Modbus function call to tamper with memory area involved in memory size computation.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-8938" target="_blank">CVE-2024-8938</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 8.1 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-8938" target="_blank">CVE-2024-8938</a>. A base score of 9.2 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Commercial Facilities, Critical Manufacturing, Energy</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> France</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Schneider Electric reported these vulnerabilities to CISA.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Schneider Electric recommends the following:</p> <p>Version SV3.65 of Modicon M340 firmware includes a fix for these vulnerabilities and is available for download <a href="https://www.se.com/ww/en/product-range/1468-modicon-m340" target="_blank">here</a>.</p> <p>Users should use appropriate patching methodologies when applying these patches to their systems. Schneider Electric strongly recommends the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric's <a href="https://www.se.com/us/en/work/support/contacts.jsp" target="_blank">Customer Care Center</a> if you need assistance removing a patch.</p> <p>If users choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit:</p> <p>Modicon M340 CPU (part numbers BMXP34*) Versions prior to SV3.65</p> <ul> <li>Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP</li> <li>Configure the Access Control List following the recommendations of the user manuals: <a href="https://www.se.com/ww/en/download/document/31007131K01000/" target="_blank">"Modicon M340 for Ethernet Communications Modules and Processors User Manual"</a> chapter "Messaging Configuration Parameters"</li> <li>Consider use of external firewall devices such as EAGLE40-07 from Belden to establish VPN connections. For more details refer to <a href="https://www.se.com/ww/en/download/document/EIO0000001999/" target="_blank">"Modicon Controller Systems Cybersecurity, User Guide"</a></li> <li>Ensure the M340 CPU is running with the memory protection activated by configuring the input bit to a physical input, for more details refer to the following guideline <a href="https://www.se.com/ww/en/download/document/EIO0000001999/" target="_blank">"Modicon Controller Systems Cybersecurity, User Guide" chapter "Controler Memory Protection"</a></li> </ul> <p>Schneider Electric is establishing a remediation plan for all future versions of Modicon MC80 that will include fixes for CVE-2024-8937 and CVE-2024-8938. Schneider Electric will update this document when the remediations are available. Until then, users should immediately apply the following mitigations to reduce the risk of exploit:</p> <ul> <li>Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP</li> <li>Configure the Access Control List following the recommendations of the user manuals: <a href="https://www.se.com/ww/en/download/document/EIO0000002071/" target="_blank">"MC80 Programmable Logic Controller(PLC), User Manual"</a> in the section "Access Control List (ACL)".</li> <li>Consider use of external firewall devices such as EAGLE40-07 from Belden to establish VPN connections. For more details refer to <a href="https://www.se.com/ww/en/download/document/EIO0000001999/" target="_blank">"Modicon Controller Systems Cybersecurity, User Guide"</a></li> </ul> <p>Schneider Electric is also establishing a remediation plan for all future versions of Modicon Momentum that will include fixes for CVE-2024-8937 and CVE-2024-8938. Schneider Electric will update this document when the remediations are available. Until then, users should immediately apply the following mitigations to reduce the risk of exploit:</p> <ul> <li>Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP</li> <li>Configure the Access Control List following the recommendations of the user manuals: <a href="https://www.se.com/ww/en/download/document/HRB44124/" target="_blank">"Momentum for EcoStruxure™ Control Expert - 171CBU78090, 171CBU98090, 171CBU98091 Processors, User Guide"</a> in the section "Controlling Access"</li> <li>Consider use of external firewall devices such as EAGLE40-07 from Belden to establish VPN connections. For more details refer to <a href="https://www.se.com/ww/en/download/document/EIO0000001999/" target="_blank">"Modicon Controller Systems Cybersecurity, User Guide"</a></li> </ul> <p>To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric's <a href="https://www.se.com/en/work/support/cybersecurity/security-notifications.jsp" target="_blank">security notification service</a>.</p> <p>General Security Recommendations:<br>Schneider Electric strongly recommend the following industry cybersecurity best practices.</p> <ul> <li>Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.</li> <li>Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.</li> <li>Place all controllers in locked cabinets and never leave them in the "Program" mode.</li> <li>Never connect programming software to any network other than the network intended for that device.</li> <li>Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.</li> <li>Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.</li> <li>Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.</li> <li>When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.</li> </ul> <p>For more information refer to the Schneider Electric <a href="https://www.se.com/us/en/download/document/7EN52-0390/" target="_blank">Recommended Cybersecurity Best Practices</a> document.</p> <p>For more information see the associated Schneider Electric Security Notification SEVD-2024-317-03 in <a href="https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-317-03&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2024-317-03.pdf" target="_blank">PDF</a> and <a href="https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-317-03&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=sevd-2024-317-03.json" target="_blank">CSAF.</a></p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:</p> <ul> <li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the internet</a>.</li> <li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li> <li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</li> </ul> <p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities have a high attack complexity.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 21, 2024: Initial Publication</li> </ul> Thu, 21 Nov 24 12:00:00 +0000 CISA /node/22612 Schneider Electric Modicon M340, MC80, and Momentum Unity M1E https://www.cisa.gov/news-events/ics-advisories/icsa-24-326-03 <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v4 7.7</strong></li> <li><strong>ATTENTION</strong>: Exploitable remotely</li> <li><strong>Vendor</strong>: Schneider Electric</li> <li><strong>Equipment</strong>: Modicon M340, MC80, and Momentum Unity M1E</li> <li><strong>Vulnerabilities</strong>: Improper Enforcement of Message Integrity During Transmission in a Communication Channel, Authentication Bypass by Spoofing</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of these vulnerabilities could allow an attacker to retrieve password hashes or cause a denial-of-service condition.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>The following versions of Schneider Electric Modicon M340, MC80, and Momentum Unity M1E are affected:</p> <ul> <li>Modicon M340 CPU (part numbers BMXP34*): All versions (CVE-2024-8933)</li> <li>Modicon M340 CPU (part numbers BMXP34*): versions after SV3.60 (CVE-2024-8935)</li> <li>Modicon MC80 (part numbers BMKC80): All versions (CVE-2024-8933)</li> <li>Modicon Momentum Unity M1E Processor (171CBU*): All versions (CVE-2024-8933)</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-improper-enforcement-of-message-integrity-during-transmission-in-a-communication-channel-cwe-924"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/924.html" target="_blank"><strong>Improper Enforcement of Message Integrity During Transmission in a Communication Channel CWE-924</strong></a></h4> <p>A vulnerability exists that could cause retrieval of password hash that could lead to denial of service and loss of confidentiality and integrity of controllers. To be successful, the attacker needs to inject themselves inside the logical network while a valid user uploads or downloads a project file into the controller.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-8933" target="_blank">CVE-2024-8933</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank">AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-8933" target="_blank">CVE-2024-8933</a>. A base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>).</p> <h4 id="322-authentication-bypass-by-spoofing-cwe-290"><strong>3.2.2 </strong><a href="https://cwe.mitre.org/data/definitions/290.html" target="_blank"><strong>Authentication Bypass by Spoofing CWE-290</strong></a></h4> <p>A vulnerability exists that could cause a denial of service and loss of confidentiality and integrity of controllers when conducting a Man-In-The-Middle attack between the controller and the engineering workstation while a valid user is establishing a communication session. This vulnerability is inherent to the Diffie Hellman algorithm which does not protect against Man-In-The-Middle attacks.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-8935" target="_blank">CVE-2024-8935</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank">AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-8935" target="_blank">CVE-2024-8935</a>. A base score of 7.7 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Commercial Facilities, Critical Manufacturing, Energy</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> France</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Schneider Electric reported these vulnerabilities to CISA.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Schneider Electric is establishing a remediation plan for all future versions of Modicon M340 that will include a fix for CVE-2024-8933 vulnerability and a mitigation for CVE-2024-8935.</p> <p>Additionally, Schneider Electric will update this document when the remediation is available. Until then, users should immediately apply the following mitigations to reduce the risk of exploit:</p> <ul> <li>Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP</li> <li>Configure the Access Control List following the recommendations of the user manuals: <a href="https://www.se.com/ww/en/download/document/31007131K01000/" target="_blank">"Modicon M340 for Ethernet Communications Modules and Processors User Manual"</a> in chapter "Messaging Configuration Parameters"</li> <li>Consider use of external firewall devices such as EAGLE40-07 from Belden to establish VPN connections. For more details refer to <a href="https://www.se.com/ww/en/download/document/EIO0000001999/" target="_blank">"Modicon Controller Systems Cybersecurity, User Guide"</a></li> <li>Ensure the M340 CPU is running with the memory protection activated by configuring the input bit to a physical input, for more details refer to the following guideline <a href="https://www.se.com/ww/en/download/document/EIO0000001999/" target="_blank">"Modicon Controller Systems Cybersecurity, User Guide"</a> chapter "Controler Memory Protection"</li> </ul> <p>Schneider Electric is also establishing a remediation plan for all future versions of Modicon MC80 that will include a fix for CVE-2024-8933. Schneider Electric will update this document when the remediation is available. Until then, users should immediately apply the following mitigations to reduce the risk of exploit:</p> <ul> <li>Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP</li> <li>Configure the Access Control List following the recommendations of the user manuals: <a href="https://www.se.com/ww/en/download/document/EIO0000002071/" target="_blank">"MC80 Programmable Logic Controller(PLC), User Manual"</a> in the section "Access Control List (ACL)"</li> <li>Consider use of external firewall devices such as EAGLE40-07 from Belden to establish VPN connections. For more details refer to <a href="https://www.se.com/ww/en/download/document/EIO0000001999/" target="_blank">"Modicon Controller Systems Cybersecurity, User Guide"</a></li> </ul> <p>Schneider Electric is also establishing a remediation plan for all future versions of Modicon Momentum that will include a fix for CVE-2024-8933. Schneider Electric will update this document when the remediation is available. Until then, users should immediately apply the following mitigations to reduce the risk of exploit:</p> <ul> <li>Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP</li> <li>Configure the Access Control List following the recommendations of the user manuals: <a href="https://www.se.com/ww/en/download/document/HRB44124/" target="_blank">"Momentum for EcoStruxure™ Control Expert -171CBU78090, 171CBU98090, 171CBU98091 Processors, User Guide"</a> in the section "Controlling Access"</li> <li>Consider use of external firewall devices such as EAGLE40-07 from Belden to establish VPN connections. For more details refer to <a href="https://www.se.com/ww/en/download/document/EIO0000001999/" target="_blank">"Modicon Controller Systems Cybersecurity, User Guide"</a></li> </ul> <p>To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric's security notification service <a href="https://www.se.com/en/work/support/cybersecurity/security-notifications.jsp" target="_blank">here</a>.</p> <p>General Security Recommendations<br>Schneider Electric strongly recommend the following industry cybersecurity best practices.</p> <ul> <li>Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.</li> <li>Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.</li> <li>Place all controllers in locked cabinets and never leave them in the "Program" mode.</li> <li>Never connect programming software to any network other than the network intended for that device.</li> <li>Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.</li> <li>Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.</li> <li>Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.</li> <li>When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.</li> </ul> <p>For more information refer to the Schneider Electric <a href="https://www.se.com/us/en/download/document/7EN52-0390/" target="_blank">Recommended Cybersecurity Best Practices</a> document.</p> <p>For more information see the associated Schneider Electric Security Notification SEVD-2024-317-02 in <a href="https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-317-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2024-317-02.pdf" target="_blank">PDF</a> and <a href="https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-317-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=sevd-2024-317-02.json" target="_blank">CSAF.</a></p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:</p> <ul> <li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the internet</a>.</li> <li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li> <li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</li> </ul> <p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p> <ul> <li>Do not click web links or open attachments in unsolicited email messages.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf" target="_blank">Recognizing and Avoiding Email Scams</a> for more information on avoiding email scams.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/ncas/tips/ST04-014" target="_blank">Avoiding Social Engineering and Phishing Attacks</a> for more information on social engineering attacks.</li> </ul> <p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities have a high attack complexity.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 21, 2024: Initial Publication</li> </ul> Thu, 21 Nov 24 12:00:00 +0000 CISA /node/22611 OSCAT Basic Library https://www.cisa.gov/news-events/ics-advisories/icsa-24-326-02 <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v4 5.1</strong></li> <li><strong>ATTENTION</strong>: Low attack complexity</li> <li><strong>Vendor</strong>: CODESYS GmbH</li> <li><strong>Equipment</strong>: OSCAT Basic Library</li> <li><strong>Vulnerability</strong>: Out-of-bounds Read</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of this vulnerability allows an local, unprivileged attacker to access limited internal data of the PLC, which may lead to a crash of the affected service.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>The following versions CODESYS OSCAT, are affected:</p> <ul> <li>CODESYS OSCAT Basic Library: Version 3.3.5.0</li> <li>oscat.de OSCAT Basic Library: Versions 3.3.5 and prior</li> <li>oscat.de OSCAT Basic Library: Versions 335 and prior</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-out-of-bounds-read-cwe-125"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/125.html" target="_blank"><strong>OUT-OF-BOUNDS READ CWE-125</strong></a></h4> <p>The affected product is vulnerable to an out-of-bounds read in the OSCAT Basic Library, which allows a local, unprivileged attacker to access limited internal data of the PLC which may lead to a crash of the affected service.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-6876" target="_blank">CVE-2024-6876</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 5.1 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" target="_blank">AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-6876" target="_blank">CVE-2024-6876</a>. A base score of 5.1 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing, Energy, Water and Wastewater Systems</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Germany</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Corban Villa, Hithem Lamri, Constantine Doumanidis, Michail Maniatakos of Modern Microprocessors Architecture (MoMA) Lab at NYU Abu Dhabi reported this vulnerability to CERT@VDE and CODESYS.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>CODESYS GmbH recommends users update OSCAT Basic Library to address the security vulnerability:</p> <ul> <li>Update the OSCAT Basic Library to Version 3.3.5.</li> </ul> <p>To make the fix effective for existing CODESYS projects, the user also must adjust the version of the OSCAT Basic library to be used in the Library Manager of the CODESYS project to Version 3.3.5.0. Then the user must update the CODESYS application on the PLC by download or online change and rebuild/download the boot application.</p> <p>Without an update, the vulnerability can be prevented by validating all values in the PLC program before they are passed to the affected function. In particular, negative values must be blocked as function parameters of MONTH_TO_STRING.</p> <p>Regardless of whether the OSCAT Basic library in the programming system was updated or the security vulnerability in the PLC program was mitigated, a download or online change must be performed to update the application on the PLC. CODESYS reminds users to rebuild/download the boot project.</p> <p>For more information see the associated CERT@VDE <a href="https://certvde.com/de/advisories/VDE-2024-046/" target="_blank">security advisory</a>.</p> <p>For a list of system environments the library has been validated against see <a href="http://www.oscat.de/de/component/jdownloads/send/2-oscat-basic/9-oscat-basic333-en.html?Itemid=0" target="_blank">OSCAT's library documentation</a>.</p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 21, 2024: Initial Publication</li> </ul> Thu, 21 Nov 24 12:00:00 +0000 CISA /node/22610 Automated Logic WebCTRL Premium Server https://www.cisa.gov/news-events/ics-advisories/icsa-24-326-01 <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v4 10.0</strong></li> <li><strong>ATTENTION</strong>: Exploitable remotely/low attack complexity</li> <li><strong>Vendor</strong>: Automated Logic</li> <li><strong>Equipment</strong>: WebCTRL Premium Server</li> <li><strong>Vulnerabilities</strong>: Unrestricted Upload of File with Dangerous Type, URL Redirection to Untrusted Site ('Open Redirect')</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of these vulnerabilities could allow an unauthenticated remote attacker to execute arbitrary commands on the server hosting WebCTRL or redirect legitimate users to malicious sites.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>The following Automated Logic products are affected:</p> <ul> <li>Automated Logic WebCTRL® Server : Version 7.0</li> <li>Carrier i-Vu: Version 7.0</li> <li>Automated Logic SiteScan Web: Version 7.0</li> <li>Automated Logic WebCTRL for OEMs: Version 7.0</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-unrestricted-upload-of-file-with-dangerous-type-cwe-434"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/434.html" target="_blank"><strong>UNRESTRICTED UPLOAD OF FILE WITH DANGEROUS TYPE CWE-434</strong></a></h4> <p>A vulnerability in Automated Logic WebCTRL 7.0 allows an unauthenticated user to upload files of dangerous types without restrictions, which could lead to remote command execution.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-8525" target="_blank">CVE-2024-8525</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 10.0 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank">AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-8525" target="_blank">CVE-2024-8525</a>. A base score of 10.0 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H" target="_blank">CVSS4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</a>).</p> <h4 id="322-url-redirection-to-untrusted-site-open-redirect-cwe-601"><strong>3.2.2 </strong><a href="https://cwe.mitre.org/data/definitions/601.html" target="_blank"><strong>URL REDIRECTION TO UNTRUSTED SITE ('OPEN REDIRECT') CWE-601</strong></a></h4> <p>A vulnerability in Automated Logic WebCTRL 7.0 could allow an attacker to send a maliciously crafted URL, which when visited by an authenticated WebCTRL user, could result in the redirection of the user to a malicious webpage via "index.jsp"</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-8526" target="_blank">CVE-2024-8526</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 6.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank">AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-8526" target="_blank">CVE-2024-8526</a>. A base score of 5.9 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" target="_blank">CVSS4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> United States of America</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Jaryl Low, Thuy D. Nguyen, and Cynthia E. Irvine reported these vulnerabilities to CISA.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Automated Logic has recommended the following:</p> <ul> <li>For CVE-2024-8525, a software update is available on the authorized dealer support site. Although a software update is available for this issue, the last support date for v7.0 was 1/27/2023 and it is recommended that customers upgrade their software to the latest supported version.</li> <li>For CVE-2024-8526, the vulnerability was fixed at version 8.0 for all impacted products.</li> <li>Additionally, Customers are encouraged to follow Automated Logic's [Security Best Practices Checklists for Building Automation Systems (BAS)](<a href="https://www.automatedlogic.com/en/media/Security" target="_blank">https://www.automatedlogic.com/en/media/Security</a> Best Practices for a WebCTRL v8.0 system-522_tcm702-168128.pdf) to ensure alignment with best practices installation guidelines.</li> </ul> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:</p> <ul> <li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the internet</a>.</li> <li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li> <li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</li> </ul> <p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p> <ul> <li>Do not click web links or open attachments in unsolicited email messages.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf" target="_blank">Recognizing and Avoiding Email Scams</a> for more information on avoiding email scams.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/ncas/tips/ST04-014" target="_blank">Avoiding Social Engineering and Phishing Attacks</a> for more information on social engineering attacks.</li> </ul> <p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 21, 2024: Initial Publication</li> </ul> Thu, 21 Nov 24 12:00:00 +0000 CISA /node/22609 Mitsubishi Electric MELSEC iQ-F Series https://www.cisa.gov/news-events/ics-advisories/icsa-24-324-01 <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v3 7.5</strong></li> <li><strong>ATTENTION</strong>: Exploitable remotely/low attack complexity</li> <li><strong>Vendor</strong>: Mitsubishi Electric Corporation</li> <li><strong>Equipment</strong>: MELSEC iQ-F Series</li> <li><strong>Vulnerability</strong>: Improper Validation of Specified Type of Input</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service condition in Ethernet communication on the module. A system reset of the module is required for recovery.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>Mitsubishi Electric reports that the following versions of MELSEC iQ-F Series Ethernet module and EtherNet/IP module are affected:</p> <ul> <li>MELSEC iQ-F Series FX5-ENET: version 1.100 and later</li> <li>MELSEC iQ-F Series FX5-ENET/IP: version 1.100 to 1.104</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-improper-validation-of-specified-type-of-input-cwe-1287"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/1287.html" target="_blank"><strong>Improper Validation of Specified Type of Input CWE-1287</strong></a></h4> <p>A denial-of-service vulnerability due to improper validation of a specified type of input exists in MELSEC iQ-F Ethernet Module and EtherNet/IP Module.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-8403" target="_blank">CVE-2024-8403</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Japan</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Mitsubishi Electric reported this vulnerability to CISA.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Mitsubishi Electric has fixed this issue in MELSEC iQ-F Series FX5-ENET/IP version 1.106 or later. The firmware update file can be found on <a href="https://www.mitsubishielectric.com/fa/download/index.html" target="_blank">Mitsubishi Electric's download page.</a> Refer to "9 FIRMWARE UPDATE FUNCTION" in the "MELSEC iQ-F FX5 User's Manual (Application)" for information on how to update the firmware.</p> <p>Mitsubishi Electric recommends that users take the following mitigations/workarounds to minimize the risk of exploiting this vulnerability:</p> <ul> <li>Use within a LAN and block access from untrusted networks and hosts through firewalls.</li> <li>Restrict physical access to the product, as well as to computers and network devices located within the same network as the product.</li> <li>Use a firewall or virtual private network (VPN), etc. to prevent unauthorized access when internet access is required.</li> <li>Use IP filter function to block access from untrusted hosts. For details on the IP filter function, please refer to the following manual: MELSEC iQ-F FX5 User's Manual (Communication) "13.1 IP Filter Function"</li> </ul> <p>For specific update instructions and additional details see the <a href="https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2024-009_en.pdf" target="_blank">Mitsubishi Electric advisory.</a></p> <p>Please contact your <a href="https://www.mitsubishielectric.com/fa/support/index.html" target="_blank">local Mitsubishi Electric representative.</a></p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as:</p> <ul> <li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the internet</a>.</li> <li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li> <li>When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</li> </ul> <p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 19, 2024: Initial Publication</li> </ul> Tue, 19 Nov 24 12:00:00 +0000 CISA /node/22590 2N Access Commander https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-17 <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v3.1 7.2</strong></li> <li><strong>ATTENTION</strong>: Exploitable remotely/low attack complexity</li> <li><strong>Vendor</strong>: 2N</li> <li><strong>Equipment</strong>: Access Commander</li> <li><strong>Vulnerabilities</strong>: Path Traversal, Insufficient Verification of Data Authenticity</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of these vulnerabilities could allow an attacker to escalate their privileges, execute arbitrary code, or gain root access to the system.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>The following versions of 2N Access Commander, an IP access control system, are affected:</p> <p>Access Commander: versions 3.1.1.2 and prior</p> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-cwe-22"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank"><strong>IMPROPER LIMITATION OF A PATHNAME TO A RESTRICTED DIRECTORY ('PATH TRAVERSAL') CWE-22</strong></a></h4> <p>In 2N Access Commander versions 3.1.1.2 and prior, a Path Traversal vulnerability could allow an attacker to write files on the filesystem to achieve arbitrary remote code execution.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-47253" target="_blank">CVE-2024-47253</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 7.2 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank">AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a>).</p> <h4 id="322-insufficient-verification-of-data-authenticity-cwe-345"><strong>3.2.2 </strong><a href="https://cwe.mitre.org/data/definitions/345.html" target="_blank"><strong>INSUFFICIENT VERIFICATION OF DATA AUTHENTICITY CWE-345</strong></a></h4> <p>In 2N Access Commander versions 3.1.1.2 and prior, an Insufficient Verification of Data Authenticity vulnerability could allow an attacker to escalate their privileges and gain root access to the system.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-47254" target="_blank">CVE-2024-47254</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 6.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H" target="_blank">AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</a>).</p> <h4 id="323-insufficient-verification-of-data-authenticity-cwe-345"><strong>3.2.3 </strong><a href="https://cwe.mitre.org/data/definitions/345.html" target="_blank"><strong>INSUFFICIENT VERIFICATION OF DATA AUTHENTICITY CWE-345</strong></a></h4> <p>In 2N Access Commander versions 3.1.1.2 and prior, a local attacker can escalate their privileges in the system which could allow for arbitrary code execution with root permissions.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-47255" target="_blank">CVE-2024-47255</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 4.7 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N" target="_blank">AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Government Services and Facilities, Commercial Facilities, Communications, Information Technology</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> United States</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Noam Moshe of Claroty Research - Team82 reported these vulnerabilities to CISA.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>2N has released the following to fix these vulnerabilities:</p> <ul> <li>Access Commander: Update to Access Commander version 3.2 from the 2N <a href="https://www.2n.com/en-GB/download-center/?product=2n-access-commander&amp;category=softwarefirmware&amp;sort=category-desc" target="_blank">download center</a></li> </ul> <p>Please see 2N's <a href="https://www.2n.com/pl-PL/download/Access-Commander-Security-Advisory-2024-11" target="_blank">security advisory</a> for additional details.</p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:</p> <ul> <li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the internet</a>.</li> <li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li> <li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</li> </ul> <p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 19, 2024: Initial Publication</li> </ul> Thu, 14 Nov 24 12:00:00 +0000 CISA /node/22574 Hitachi Energy MSM https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-16 <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v3 8.6</strong></li> <li><strong>ATTENTION</strong>: Exploitable remotely/low attack complexity</li> <li><strong>Vendor</strong>: Hitachi Energy</li> <li><strong>Equipment</strong>: MSM</li> <li><strong>Vulnerabilities</strong>: Missing Release of Resource after Effective Lifetime, Loop with Unreachable Exit Condition ('Infinite Loop')</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of these vulnerabilities could allow an attacker to impact the confidentiality, integrity or availability of the MSM.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>The following versions of Hitachi Energy MSM, a condition monitoring system, are affected:</p> <ul> <li>MSM: Versions 2.2.8 and earlier</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-missing-release-of-resource-after-effective-lifetime-cwe-772"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/772.html" target="_blank"><strong>Missing Release of Resource after Effective Lifetime CWE-772</strong></a></h4> <p>When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory. Further, this error condition fails silently and is therefore not easily detected by an application.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-2398" target="_blank">CVE-2024-2398</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 8.6 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" target="_blank">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L</a>).</p> <h4 id="322-loop-with-unreachable-exit-condition-infinite-loop-cwe-835"><strong>3.2.2 </strong><a href="https://cwe.mitre.org/data/definitions/835.html" target="_blank"><strong>Loop with Unreachable Exit Condition ('Infinite Loop') CWE-835</strong></a></h4> <p>A denial-of-service vulnerability exists in the processing of multipart/form-data requests in the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. A specially crafted HTTP request can lead to an infinite loop in the process. The request can be unauthenticated in the form of GET or POST requests and does not require the requested resource to exist on the server.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2019-5097" target="_blank">CVE-2019-5097</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Energy</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Switzerland</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Hitachi Energy reported these vulnerabilities to CISA.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Hitachi Energy recommends that users apply the update as soon as it is available. in the meantime, Hitachi Energy recommends the general mitigation factors/workarounds given below are followed.</p> <p>MSM is not intrinsically designed and intended to be directly connected to the internet. Please disconnect the device from any internet facing network, if any installation has performed the same. Hitachi Energy suggests adopting user access management and any state-of-the-art antivirus protection engines equipped with the latest signature rules on the computers that have installed and operating the MSM Client application. As an example, please use the operating system (OS) inbuilt user access management functionality, if supported, to limit the probability of unauthorized access followed by rogue commands via MSM Client application.</p> <p>Also, Hitachi Energy recommends following the hardening guidelines published by <a href="https://www.cisecurity.org/about-us/" target="_blank">"The Center for Internet Security (CIS)"</a> to protect the host operating system of computers that connects with MSM. This measure would then prevent the lateral movement of the attack vector into MSM via these connected devices. Some examples for Windows based computers are listed below:</p> <p>1) <a href="https://www.cisecurity.org/">CIS Microsoft Windows Desktop Benchmarks</a><br>2) <a href="https://www.cisecurity.org/">CIS Microsoft Windows Server Benchmarks</a></p> <p>Hitachi Energy has provided the additional following security practices and firewall configurations can help protect a process control network from attacks that originate from outside the network:</p> <ul> <li>Physically protect process control systems from direct access by unauthorized personnel.</li> <li>Do not connect directly to the Internet.</li> <li>Separate from other networks by means of a firewall system that has a minimal number of ports exposed.</li> <li>Process control systems should not be used for Internet surfing, instant messaging, or receiving e-mails.</li> <li>Portable computers and removable storage media should be carefully scanned for viruses before they are connected to a control system.</li> </ul> <p>For more information, see Hitachi Energy's security advisory <a href="https://publisher.hitachienergy.com/preview?DocumentID=8DBD000205&amp;LanguageCode=en" target="_blank">8DBD000205</a></p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 14, 2024: Initial Publication</li> </ul> Thu, 14 Nov 24 12:00:00 +0000 CISA /node/22573 Rockwell Automation Arena Input Analyzer https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-15 <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v4 7.0</strong></li> <li><strong>ATTENTION</strong>: Low attack complexity</li> <li><strong>Vendor</strong>: Rockwell Automation</li> <li><strong>Equipment</strong>: Arena Input Analyzer</li> <li><strong>Vulnerability</strong>: Improper Validation of Specified Quantity in Input</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of this vulnerability could allow an attacker to disclose information and execute arbitrary code on the program.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>The following versions of Rockwell Automation Input Analyzer (Arena), an event simulation and automation software, are affected:</p> <ul> <li>Arena Input Analyzer: v16.20.03 and prior</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-improper-validation-of-specified-quantity-in-input-cwe-1284"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/1284.html" target="_blank"><strong>IMPROPER VALIDATION OF SPECIFIED QUANTITY IN INPUT CWE-1284</strong></a></h4> <p>Rockwell Automation Input Analyzer version v16.20.00 (as included in Arena v16.20.03) is vulnerable to memory corruption when parsing DFT files. Local threat actors can exploit this issue to disclose information and to execute arbitrary code. To exploit this vulnerability a legitimate user must open a malicious DFT file.</p> <p> <a href="https://www.cve.org/CVERecord?id=CVE-2024-6068" target="_blank">CVE-2024-6068</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 7.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank">AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-6068" target="_blank">CVE-2024-6068</a>. A base score of 7.0 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> United States</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Michael Heinzl reported this vulnerability to Rockwell Automation.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Rockwell Automation encourages users to update Arena Input Analyzer to version 16.20.04 or later.</p> <p>For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement suggested <a href="https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight" target="_blank">security best practices</a> to minimize the risk of the vulnerability.</p> <p>Please see <a href="https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html" target="_blank">Rockwell Automation's security advisory</a> for more information on this issue.</p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as:</p> <ul> <li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the internet</a>.</li> <li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li> <li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</li> </ul> <p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p> <ul> <li>Do not click web links or open attachments in unsolicited email messages.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf" target="_blank">Recognizing and Avoiding Email Scams</a> for more information on avoiding email scams.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/ncas/tips/ST04-014" target="_blank">Avoiding Social Engineering and Phishing Attacks</a> for more information on social engineering attacks.</li> </ul> <p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 14, 2024: Initial Publication</li> </ul> Thu, 14 Nov 24 12:00:00 +0000 CISA /node/22572 Rockwell Automation FactoryTalk Updater (Update A) https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-14 <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v4 9.1</strong></li> <li><strong>ATTENTION</strong>: Exploitable remotely/low attack complexity</li> <li><strong>Vendor</strong>: Rockwell Automation</li> <li><strong>Equipment</strong>: FactoryTalk Updater</li> <li><strong>Vulnerabilities</strong>: Insecure Storage of Sensitive Information, Improper Input Validation, Improperly Implemented Security Check for Standard</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of these vulnerabilities could result in an authentication bypass, remote code execution, and/or a local privilege escalation</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>The following versions of FactoryTalk Updater are affected:</p> <ul> <li>FactoryTalk Updater - Web Client: Version 4.00.00 to 4.20.00</li> <li>FactoryTalk Updater - Client: Versions prior to 4.20.00</li> <li>FactoryTalk Updater - Agent: Versions prior to 4.20.00</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-insecure-storage-of-sensitive-information-cwe-922"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/922.html" target="_blank"><strong>INSECURE STORAGE OF SENSITIVE INFORMATION CWE-922</strong></a></h4> <p>An authentication bypass vulnerability exists due to shared secrets across accounts, which could allow a threat actor to impersonate a user if the threat actor is able to enumerate additional information required during authentication.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-10943" target="_blank">CVE-2024-10943</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 9.1 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" target="_blank">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-10943" target="_blank">CVE-2024-10943</a>. A base score of 9.1 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N</a>).</p> <h4 id="322-improper-input-validation-cwe-20"><strong>3.2.2 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4> <p>A Remote Code Execution vulnerability exists in the affected product. The vulnerability requires a high level of permissions and exists due to improper input validation resulting in the possibility of a malicious Updated Agent being deployed.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-10944" target="_blank">CVE-2024-10944</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 8.4 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" target="_blank">AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-10944" target="_blank">CVE-2024-10944</a>. A base score of 7.1 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L" target="_blank">CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L</a>).</p> <h4 id="323-improperly-implemented-security-check-for-standard-cwe-358"><strong>3.2.3 </strong><a href="https://cwe.mitre.org/data/definitions/358.html" target="_blank"><strong>IMPROPERLY IMPLEMENTED SECURITY CHECK FOR STANDARD CWE-358</strong></a></h4> <p>A Local Privilege Escalation vulnerability exists in the affected product. The vulnerability requires a local, low privileged threat actor to replace certain files during update and exists due to a failure to perform proper security checks before installation.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-10945" target="_blank">CVE-2024-10945</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 7.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank">AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-10945" target="_blank">CVE-2024-10945</a>. A base score of 7.0 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> United States</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Rockwell Automation reported these vulnerabilities to CISA.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Rockwell Automation recommends users follow the following mitigations:</p> <ul> <li>FactoryTalk Updater - Web Client: Update to V4.20.00</li> <li>FactoryTalk Updater - Client: Update to V4.20.00</li> <li>FactoryTalk Updater - Agent: Update to V4.20.00</li> </ul> <p>Users using the affected software, FactoryTalk Updater - Client, are encouraged to apply the risk mitigations, if possible.</p> <ul> <li>Control access to the server where FactoryTalk Updater is running.</li> <li>Click the ‘Scan' button, which will update the database</li> </ul> <p>For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourage users to implement their suggested <a href="https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US" target="_blank">security best practices</a> to minimize the risk of the vulnerabilities.</p> <p>Users can use <a href="https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc" target="_blank">Stakeholder-Specific Vulnerability Categorization</a> to generate more environment-specific prioritization.</p> <p>For more information about these issues, please see the <a href="https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD%201710.html" target="_blank">Rockwell Automation security advisory.</a></p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:</p> <ul> <li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the Internet</a>.</li> <li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li> <li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</li> </ul> <p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p> <ul> <li>Do not click web links or open attachments in unsolicited email messages.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf" target="_blank">Recognizing and Avoiding Email Scams</a> for more information on avoiding email scams.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/ncas/tips/ST04-014" target="_blank">Avoiding Social Engineering and Phishing Attacks</a> for more information on social engineering attacks.</li> </ul> <p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 14, 2024: Initial Publication</li> <li>November 18, 2024: Update A - Clarified version information, corrected critical infrastructure sector</li> </ul> Thu, 14 Nov 24 12:00:00 +0000 CISA /node/22571 Rockwell Automation Verve Reporting (Update A) https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-13 <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v4 8.6</strong></li> <li><strong>ATTENTION</strong>: Exploitable remotely/low attack complexity</li> <li><strong>Vendor</strong>: Rockwell Automation</li> <li><strong>Equipment</strong>: Verve Reporting</li> <li><strong>Vulnerability</strong>: Dependency on Vulnerable Third-Party Component</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of this vulnerability could lead to arbitrary code execution.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>The following versions of Verve Reporting are affected:</p> <ul> <li>Verve Reporting: Versions prior to 1.39</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-dependency-on-vulnerable-third-party-component-cwe-1395"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/1395.html" target="_blank"><strong>DEPENDENCY ON VULNERABLE THIRD-PARTY COMPONENT CWE-1395</strong></a></h4> <p>Verve Reporting utilizes Kibana, which contains a remote code execution vulnerability that allows an attacker with access to ML and alerting connecting features as well as write access to internal ML to trigger a prototype pollution vulnerability, which can ultimately lead to arbitrary code execution. The code execution is limited to the container.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-37287" target="_blank">CVE-2024-37287</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 7.2 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank">AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-37287" target="_blank">CVE-2024-37287</a>. A base score of 8.6 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> United States</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Rockwell Automation reported this vulnerability to CISA.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Rockwell recommends users to apply the following mitigation and follow their security best practices:</p> <ul> <li>Restrict Access to Built-in Verve Account <ul> <li>Access to the built-in "verve" account should be limited to only administrators who need to perform administrative functions and should only be used for administrative purposes. Separate accounts should be used for day-to-day functions.</li> <li>Change the password for the built-in "verve" account if it has been shared.</li> </ul> </li> <li>Restrict Privileges for Other Accounts <ul> <li>Verve Reporting comes with built-in roles to simplify the delegation of user permissions. Assigning a user the following two roles will allow them access to most Verve Reporting features (excluding user administration), but will not give them permission to execute this vulnerability. <ul> <li>all-all</li> <li>feature-all-all</li> </ul> </li> </ul> </li> <li>Disable Machine Learning <ul> <li>Machine learning can be disabled in the Elasticsearch configuration override. Contact Verve support for assistance if needed. <ol> <li>Connect to the Reporting server via SSH or terminal.</li> <li>Copy the Elasticsearch configuration override to the working directory. <ul> <li>docker exec $(docker ps --filter "name=Reporting_elasticsearch" --format "{{ .ID }}") cat /usr/share/elasticsearch/config-templates/elasticsearch.override.yml &gt; elasticsearch.override.yml</li> </ul> </li> <li>Add the following line and save. <ul> <li>xpack.ml.enabled: false</li> </ul> </li> <li>Disable Verve Reporting from the Verve Software Manager.</li> <li>Update the Elasticsearch configuration override. <ul> <li>docker config rm elasticsearchymloverride</li> <li>docker config create elasticsearchymloverride ./elasticsearch.override.yml</li> </ul> </li> <li>Enable Verve Reporting from the Verve Software Manager and confirm that the application starts and "Machine Learning" is no longer listed in the main navigation bar under Analytics.</li> <li>Delete the copy of the Elasticsearch configuration override. <ul> <li>rm elasticsearch.override.yml</li> </ul> </li> </ol> </li> </ul> </li> <li><a href="https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US" target="_blank">Security Best Practices</a></li> </ul> <p>For more information, please see the <a href="https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1712.html" target="_blank">Rockwell Automation security advisory.</a></p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as:</p> <ul> <li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the Internet</a>.</li> <li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li> <li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</li> </ul> <p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p> <ul> <li>Do not click web links or open attachments in unsolicited email messages.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf" target="_blank">Recognizing and Avoiding Email Scams</a> for more information on avoiding email scams.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/ncas/tips/ST04-014" target="_blank">Avoiding Social Engineering and Phishing Attacks</a> for more information on social engineering attacks.</li> </ul> <p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 14, 2024: Initial Publication</li> <li>November 18, 2024: Update A - Corrected affected product name and version range</li> </ul> Thu, 14 Nov 24 12:00:00 +0000 CISA /node/22570 Siemens Mendix Runtime https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-12 <p>As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory.&nbsp;For the most up-to-date information on vulnerabilities in this advisory, please see&nbsp;<a class="ext" href="https://new.siemens.com/global/en/products/services/cert.html#SecurityPublications" title="(opens in a new window)">Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).</a></p> <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v4 6.9</strong></li> <li><strong>ATTENTION</strong>: Exploitable remotely/low attack complexity</li> <li><strong>Vendor</strong>: Siemens</li> <li><strong>Equipment</strong>: Mendix Runtime</li> <li><strong>Vulnerability</strong>: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of this vulnerability could allow unauthenticated remote attackers to circumvent default account lockout measures.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>The following versions of Mendix Runtime are affected:</p> <ul> <li>Mendix Runtime: V8</li> <li>Mendix Runtime: V9</li> <li>Mendix Runtime: V10</li> <li>Mendix Runtime: V10.6</li> <li>Mendix Runtime: V10.12</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-concurrent-execution-using-shared-resource-with-improper-synchronization-race-condition-cwe-362"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/362.html" target="_blank"><strong>CONCURRENT EXECUTION USING SHARED RESOURCE WITH IMPROPER SYNCHRONIZATION ('RACE CONDITION') CWE-362</strong></a></h4> <p>The basic authentication implementation of affected applications contains a race condition vulnerability, which could allow unauthenticated remote attackers to circumvent default account lockout measures</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-50313" target="_blank">CVE-2024-50313</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank">AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-50313" target="_blank">CVE-2024-50313</a>. A base score of 6.9 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Germany</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Siemens reported this vulnerability to CISA.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Siemens has identified the following specific workarounds and mitigations that users can apply to reduce risk:</p> <ul> <li>Mendix Runtime V8: Currently no fix is planned</li> <li>Mendix Runtime V9: Update to Mendix Runtime V9.24.29 or later versions</li> <li>Mendix Runtime V10: Update to Mendix Runtime V10.16.0 or later versions</li> <li>Mendix Runtime V10.6: Update to Mendix Runtime V10.6.15 or later versions</li> <li>Mendix Runtime V10.12: Update to Mendix Runtime V10.12.7 or later versions</li> <li>Do not use basic authentication, but setup an alternative authentication module (e.g. SAML, MendixSSO), or your own Identity Provider (IDP)</li> </ul> <p>As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to <a href="https://www.siemens.com/cert/operational-guidelines-industrial-security" target="_blank">Siemens' operational guidelines for industrial security</a>, and following the recommendations in the product manuals.</p> <p>Additional information on industrial security by Siemens can be found on the <a href="https://www.siemens.com/industrialsecurity" target="_blank">Siemens industrial security webpage</a></p> <p>For more information see the associated Siemens security advisory SSA-914892 in <a href="https://cert-portal.siemens.com/productcert/html/ssa-914892.html" target="_blank">HTML</a> and <a href="https://cert-portal.siemens.com/productcert/csaf/ssa-914892.json" target="_blank">CSAF</a>.</p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as:</p> <ul> <li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the Internet</a>.</li> <li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li> <li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</li> </ul> <p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p> <ul> <li>Do not click web links or open attachments in unsolicited email messages.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf" target="_blank">Recognizing and Avoiding Email Scams</a> for more information on avoiding email scams.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/ncas/tips/ST04-014" target="_blank">Avoiding Social Engineering and Phishing Attacks</a> for more information on social engineering attacks.</li> </ul> <p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 14, 2024: Initial Publication</li> </ul> Thu, 14 Nov 24 12:00:00 +0000 CISA /node/22569 Siemens SIMATIC CP https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-11 <p>As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory.&nbsp;For the most up-to-date information on vulnerabilities in this advisory, please see&nbsp;<a class="ext" href="https://new.siemens.com/global/en/products/services/cert.html#SecurityPublications" title="(opens in a new window)">Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).</a></p> <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v4 8.7</strong></li> <li><strong>ATTENTION</strong>: Exploitable remotely/low attack complexity</li> <li><strong>Vendor</strong>: Siemens</li> <li><strong>Equipment</strong>: SIMATIC CP</li> <li><strong>Vulnerability</strong>: Incorrect Authorization</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of this vulnerability could allow an unauthenticated attacker to gain access to the filesystem.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>The following version of SIMATIC CP is affected:</p> <ul> <li>SIMATIC CP1543-1: V4.0 (6GK7543-1AX10-0XE0)</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-incorrect-authorization-cwe-863"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/863.html" target="_blank"><strong>INCORRECT AUTHORIZATION CWE-863</strong></a></h4> <p>Affected devices do not properly handle authorization. This could allow an unauthenticated remote attacker to gain access to the filesystem.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-50310" target="_blank">CVE-2024-50310</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C" target="_blank">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-50310" target="_blank">CVE-2024-50310</a>. A base score of 8.7 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Germany</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Siemens reported this vulnerability to CISA.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Siemens has identified the following specific workarounds and mitigations that users can apply to reduce risk:</p> <ul> <li>SIMATIC CP1543-1 V4.0 (6GK7543-1AX10-0XE0): Update to SIMATIC CP1543-1 V4.0.50 or later versions</li> <li>Restrict access to Port 8448/tcp to trusted systems only</li> </ul> <p>As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to <a href="https://www.siemens.com/cert/operational-guidelines-industrial-security" target="_blank">Siemens' operational guidelines for industrial security</a>, and following the recommendations in the product manuals.</p> <p>Additional information on industrial security by Siemens can be found on the <a href="https://www.siemens.com/industrialsecurity" target="_blank">Siemens industrial security webpage</a></p> <p>For more information see the associated Siemens security advisory SSA-654798 in <a href="https://cert-portal.siemens.com/productcert/html/ssa-654798.html" target="_blank">HTML</a> and <a href="https://cert-portal.siemens.com/productcert/csaf/ssa-654798.json" target="_blank">CSAF</a>.</p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as:</p> <ul> <li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the Internet</a>.</li> <li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li> <li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</li> </ul> <p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p> <ul> <li>Do not click web links or open attachments in unsolicited email messages.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf" target="_blank">Recognizing and Avoiding Email Scams</a> for more information on avoiding email scams.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/ncas/tips/ST04-014" target="_blank">Avoiding Social Engineering and Phishing Attacks</a> for more information on social engineering attacks.</li> </ul> <p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 14, 2024: Initial Publication</li> </ul> Thu, 14 Nov 24 12:00:00 +0000 CISA /node/22568 Siemens TeleControl Server https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-10 <p>As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory.&nbsp;For the most up-to-date information on vulnerabilities in this advisory, please see&nbsp;<a class="ext" href="https://new.siemens.com/global/en/products/services/cert.html#SecurityPublications" title="(opens in a new window)">Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).</a></p> <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v4 10.0</strong></li> <li><strong>ATTENTION</strong>: Exploitable remotely/low attack complexity</li> <li><strong>Vendor</strong>: Siemens</li> <li><strong>Equipment</strong>: TeleControl Server</li> <li><strong>Vulnerability</strong>: Deserialization of Untrusted Data</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of this vulnerability could allow an unauthenticated attacker to execute arbitrary code on the device.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>The following versions of TeleControl Server are affected:</p> <ul> <li>PP TeleControl Server Basic 8 to 32 V3.1 (6NH9910-0AA31-0AB1): versions prior to V3.1.2.1</li> <li>PP TeleControl Server Basic 32 to 64 V3.1 (6NH9910-0AA31-0AF1): versions prior to V3.1.2.1</li> <li>PP TeleControl Server Basic 64 to 256 V3.1 (6NH9910-0AA31-0AC1): versions prior to V3.1.2.1</li> <li>PP TeleControl Server Basic 256 to 1000 V3.1 (6NH9910-0AA31-0AD1): versions prior to V3.1.2.1</li> <li>PP TeleControl Server Basic 1000 to 5000 V3.1 (6NH9910-0AA31-0AE1): versions prior to V3.1.2.1</li> <li>TeleControl Server Basic 8 V3.1 (6NH9910-0AA31-0AA0): versions prior to V3.1.2.1</li> <li>TeleControl Server Basic 32 V3.1 (6NH9910-0AA31-0AF0): versions prior to V3.1.2.1</li> <li>TeleControl Server Basic 64 V3.1 (6NH9910-0AA31-0AB0): versions prior to V3.1.2.1</li> <li>TeleControl Server Basic 256 V3.1 (6NH9910-0AA31-0AC0): versions prior to V3.1.2.1</li> <li>TeleControl Server Basic 1000 V3.1 (6NH9910-0AA31-0AD0): versions prior to V3.1.2.1</li> <li>TeleControl Server Basic 5000 V3.1 (6NH9910-0AA31-0AE0): versions prior to V3.1.2.1</li> <li>TeleControl Server Basic Serv Upgr (6NH9910-0AA31-0GA1): versions prior to V3.1.2.1</li> <li>TeleControl Server Basic Upgr V3.1 (6NH9910-0AA31-0GA0): versions prior to V3.1.2.1</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-deserialization-of-untrusted-data-cwe-502"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank"><strong>DESERIALIZATION OF UNTRUSTED DATA CWE-502</strong></a></h4> <p>The affected system allows remote users to send maliciously crafted objects. Due to insecure deserialization of user-supplied content by the affected software, an unauthenticated attacker could exploit this vulnerability by sending a maliciously crafted serialized object. This could allow the attacker to execute arbitrary code on the device with SYSTEM privileges.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-44102" target="_blank">CVE-2024-44102</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 10.0 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C" target="_blank">AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-44102" target="_blank">CVE-2024-44102</a>. A base score of 10.0 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H" target="_blank">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Germany</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Tenable reported these vulnerabilities to Siemens.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Siemens recommends users of the affected products <a href="https://support.industry.siemens.com/cs/ww/en/view/109975921/" target="_blank">update to V3.1.2.1 or later versions.</a></p> <p>Siemens has identified the following specific workarounds and mitigations that customers can apply to reduce the risk:</p> <ul> <li>Disable redundancy, if not used</li> <li>Restrict access to the affected systems to trusted IP addresses only</li> </ul> <p>As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to <a href="https://www.siemens.com/cert/operational-guidelines-industrial-security" target="_blank">Siemens' operational guidelines for industrial security</a>, and following the recommendations in the product manuals.</p> <p>Additional information on industrial security by Siemens can be found on the <a href="https://www.siemens.com/industrialsecurity" target="_blank">Siemens industrial security webpage</a></p> <p>For more information see the associated Siemens security advisory SSA-454789 in <a href="https://cert-portal.siemens.com/productcert/html/ssa-454789.html" target="_blank">HTML</a> and <a href="https://cert-portal.siemens.com/productcert/csaf/ssa-454789.json" target="_blank">CSAF</a>.</p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p> <ul> <li>Do not click web links or open attachments in unsolicited email messages.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf" target="_blank">Recognizing and Avoiding Email Scams</a> for more information on avoiding email scams.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/ncas/tips/ST04-014" target="_blank">Avoiding Social Engineering and Phishing Attacks</a> for more information on social engineering attacks.</li> </ul> <p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 14, 2024: Initial Publication</li> </ul> Thu, 14 Nov 24 12:00:00 +0000 CISA /node/22567 Siemens Spectrum Power 7 https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-09 <p>As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory.&nbsp;For the most up-to-date information on vulnerabilities in this advisory, please see&nbsp;<a class="ext" href="https://new.siemens.com/global/en/products/services/cert.html#SecurityPublications" title="(opens in a new window)">Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).</a></p> <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v4 8.5</strong></li> <li><strong>ATTENTION</strong>: Low attack complexity</li> <li><strong>Vendor</strong>: Siemens</li> <li><strong>Equipment</strong>: Spectrum Power 7</li> <li><strong>Vulnerability</strong>: Incorrect Privilege Assignment</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of this vulnerability could allow an authenticated local attacker to escalate privileges.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>The following versions of Spectrum Power 7 are affected:</p> <ul> <li>Spectrum Power 7: All versions prior to V24Q3</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-incorrect-privilege-assignment-cwe-266"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/266.html" target="_blank"><strong>INCORRECT PRIVILEGE ASSIGNMENT CWE-266</strong></a></h4> <p>The affected product contains several root-owned SUID binaries that could allow an authenticated local attacker to escalate privileges.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-29119" target="_blank">CVE-2024-29119</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-29119" target="_blank">CVE-2024-29119</a>. A base score of 8.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Germany</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Dimitri Lesy and Florens Schneider reported this vulnerability to Siemens.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Siemens has identified the following specific workarounds and mitigations that users can apply to reduce the risk:</p> <ul> <li>Spectrum Power 7: Update to V24Q3 or later version</li> </ul> <p>Operators of critical power systems (e.g. TSOs or DSOs) worldwide are usually required by regulations to build resilience into the power grids by applying multi-level redundant secondary protection schemes. Siemens recommends that the operators check whether appropriate resilient protection measures are in place. The risk of cyber incidents impacting the grid's reliability can thus be minimized by virtue of the grid design. Siemens strongly recommends applying the provided security updates using the corresponding tooling and documented procedures made available with the product. If supported by the product, an automated means to apply the security updates across multiple product instances may be used. Siemens strongly recommends prior validation of any security update before being applied, and supervision by trained staff of the update process in the target environment. As a general security measure, Siemens strongly recommends to protect network access with appropriate mechanisms (e.g. firewalls, segmentation, VPN). It is advised to configure the environment according to <a href="https://www.siemens.com/cert/operational-guidelines-industrial-security" target="_blank">Siemens' operational guidelines</a> in order to run the devices in a protected IT environment.</p> <p>Additional information on industrial security by Siemens can be found on the <a href="https://www.siemens.com/industrialsecurity" target="_blank">Siemens industrial security webpage</a></p> <p>For more information see the associated Siemens security advisory SSA-616032 in <a href="https://cert-portal.siemens.com/productcert/html/ssa-616032.html" target="_blank">HTML</a> and <a href="https://cert-portal.siemens.com/productcert/csaf/ssa-616032.json" target="_blank">CSAF</a>.</p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as:</p> <ul> <li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the Internet</a>.</li> <li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li> <li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</li> </ul> <p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p> <ul> <li>Do not click web links or open attachments in unsolicited email messages.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf" target="_blank">Recognizing and Avoiding Email Scams</a> for more information on avoiding email scams.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/ncas/tips/ST04-014" target="_blank">Avoiding Social Engineering and Phishing Attacks</a> for more information on social engineering attacks.</li> </ul> <p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 14, 2024: Initial Publication</li> </ul> Thu, 14 Nov 24 12:00:00 +0000 CISA /node/22566 Siemens SINEC INS https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-08 <p>As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory.&nbsp;For the most up-to-date information on vulnerabilities in this advisory, please see&nbsp;<a class="ext" href="https://new.siemens.com/global/en/products/services/cert.html#SecurityPublications" title="(opens in a new window)">Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).</a></p> <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v3 9.9</strong></li> <li><strong>ATTENTION</strong>: Exploitable remotely/low attack complexity/public exploits are available/known public exploitation</li> <li><strong>Vendor</strong>: Siemens</li> <li><strong>Equipment</strong>: SINEC INS</li> <li><strong>Vulnerabilities</strong>: Improper Authentication, Out-of-bounds Write, Inefficient Regular Expression Complexity, Excessive Iteration, Reachable Assertion, Uncontrolled Resource Consumption, Improper Input Validation, Improper Check for Unusual or Exceptional Conditions, Memory Allocation with Excessive Size Value, Heap-based Buffer Overflow, Missing Encryption of Sensitive Data, Path Traversal, Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive Information to an Unauthorized Actor, Covert Timing Channel, Truncation of Security-relevant Information, Integer Overflow or Wraparound, Use After Free, Code Injection, Path Traversal: 'dir/../../filename', Execution with Unnecessary Privileges, Server-Side Request Forgery (SSRF), OS Command Injection, HTTP Request/Response Smuggling, Use of Hard-coded Cryptographic Key, Insufficient Session Expiration</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of this vulnerability could allow an unauthenticated attacker cause a denial-of-service condition, bypass permissions, access data they shouldn't have access to, or run arbitrary code.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>The following Siemens products are affected:</p> <ul> <li>SINEC INS: versions prior to V1.0 SP2 Update 3</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-improper-authentication-cwe-287"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank"><strong>IMPROPER AUTHENTICATION CWE-287</strong></a></h4> <p>The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequence. Applications that use the AES-SIV algorithm and want to authenticate empty data entries as associated data can be mislead by removing adding or reordering such empty entries as these are ignored by the OpenSSL implementation. The AES-SIV algorithm allows for authentication of multiple associated data entries along with the encryption. To authenticate empty data the application has to call EVP_EncryptUpdate() (or EVP_CipherUpdate()) with NULL pointer as the output buffer and 0 as the input buffer length. The AES-SIV implementation in OpenSSL just returns success for such a call instead of performing the associated data authentication operation. The empty data thus will not be authenticated.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-2975" target="_blank">CVE-2023-2975</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</a>).</p> <h4 id="322-out-of-bounds-write-cwe-787"><strong>3.2.2 </strong><a href="https://cwe.mitre.org/data/definitions/787.html" target="_blank"><strong>OUT-OF-BOUNDS WRITE CWE-787</strong></a></h4> <p>The code that processes control channel messages sent to <code>named</code> calls certain functions recursively during packet parsing. Recursion depth is only limited by the maximum accepted packet size; depending on the environment, this may cause the packet-parsing code to run out of available stack memory, causing <code>named</code> to terminate unexpectedly. Since each incoming control channel message is fully parsed before its contents are authenticated, exploiting this flaw does not require the attacker to hold a valid RNDC key; only network access to the control channel's configured TCP port is necessary. This issue affects BIND 9 versions 9.2.0 through 9.16.43, 9.18.0 through 9.18.18, 9.19.0 through 9.19.16, 9.9.3-S1 through 9.16.43-S1, and 9.18.0-S1 through 9.18.18-S1.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-3341" target="_blank">CVE-2023-3341</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p> <h4 id="323-inefficient-regular-expression-complexity-cwe-1333"><strong>3.2.3 </strong><a href="https://cwe.mitre.org/data/definitions/1333.html" target="_blank"><strong>INEFFICIENT REGULAR EXPRESSION COMPLEXITY CWE-1333</strong></a></h4> <p>Applications that use the functions DH_check(), DH_check_ex() or EVP_PKEY_param_check() to check a DH key or DH parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a denial of service. The function DH_check() performs various checks on DH parameters. One of those checks confirms that the modulus ('p' parameter) is not too large. Trying to use a very large modulus is slow and OpenSSL will not normally use a modulus which is over 10,000 bits in length. However the DH_check() function checks numerous aspects of the key or parameters that have been supplied. Some of those checks use the supplied modulus value even if it has already been found to be too large. An application that calls DH_check() and supplies a key or parameters obtained from an untrusted source could be vulnerable to a denial-of-service attack. The function DH_check() is itself called by a number of other OpenSSL functions. An application calling any of those other functions may similarly be affected. The other functions affected by this are DH_check_ex() and EVP_PKEY_param_check(). Also vulnerable are the OpenSSL dhparam and pkeyparam command line applications when using the '-check' option. The OpenSSL SSL/TLS implementation is not affected by this issue. The OpenSSL 3.0 and 3.1 FIPS providers are not affected by this issue.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-3446" target="_blank">CVE-2023-3446</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</a>).</p> <h4 id="324-excessive-iteration-cwe-834"><strong>3.2.4 </strong><a href="https://cwe.mitre.org/data/definitions/834.html" target="_blank"><strong>EXCESSIVE ITERATION CWE-834</strong></a></h4> <p>Applications that use the functions DH_check(), DH_check_ex() or EVP_PKEY_param_check() to check a DH key or DH parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a denial of service. The function DH_check() performs various checks on DH parameters. After fixing CVE-2023-3446 it was discovered that a large q parameter value can also trigger an overly long computation during some of these checks. A correct q value, if present, cannot be larger than the modulus p parameter, thus it is unnecessary to perform these checks if q is larger than p. An application that calls DH_check() and supplies a key or parameters obtained from an untrusted source could be vulnerable to a denial-of-service attack. The function DH_check() is itself called by a number of other OpenSSL functions. An application calling any of those other functions may similarly be affected. The other functions affected by this are DH_check_ex() and EVP_PKEY_param_check(). Also vulnerable are the OpenSSL dhparam and pkeyparam command line applications when using the "-check" option. The OpenSSL SSL/TLS implementation is not affected by this issue. The OpenSSL 3.0 and 3.1 FIPS providers are not affected by this issue.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-3817" target="_blank">CVE-2023-3817</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</a>).</p> <h4 id="325-reachable-assertion-cwe-617"><strong>3.2.5 </strong><a href="https://cwe.mitre.org/data/definitions/617.html" target="_blank"><strong>REACHABLE ASSERTION CWE-617</strong></a></h4> <p>A flaw in the networking code handling DNS-over-TLS queries may cause <code>named</code> to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly reused under significant DNS-over-TLS query load. This issue affects BIND 9 versions 9.18.0 through 9.18.18 and 9.18.11-S1 through 9.18.18-S1.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-4236" target="_blank">CVE-2023-4236</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p> <h4 id="326-uncontrolled-resource-consumption-cwe-400"><strong>3.2.6 </strong><a href="https://cwe.mitre.org/data/definitions/400.html" target="_blank"><strong>UNCONTROLLED RESOURCE CONSUMPTION CWE-400</strong></a></h4> <p>The DNS message parsing code in <code>named</code> includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected <code>named</code> instance by exploiting this flaw. This issue affects both authoritative servers and recursive resolvers. This issue affects BIND 9 versions 9.0.0 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.9.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-4408" target="_blank">CVE-2023-4408</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p> <h4 id="327-improper-input-validation-cwe-20"><strong>3.2.7 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4> <p>The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications on the Windows 64 platform when running on newer X86_64 processors supporting the AVX512-IFMA instructions. If in an application that uses the OpenSSL library an attacker can influence whether the POLY1305 MAC algorithm is used, the application state might be corrupted with various application dependent consequences. The POLY1305 MAC (message authentication code) implementation in OpenSSL does not save the contents of non-volatile XMM registers on Windows 64 platform when calculating the MAC of data larger than 64 bytes. Before returning to the caller all the XMM registers are set to zero rather than restoring their previous content. The vulnerable code is used only on newer x86_64 processors supporting the AVX512-IFMA instructions. The consequences of this kind of internal application state corruption can be various - from no consequences, if the calling application does not depend on the contents of non-volatile XMM registers at all, to the worst consequences, where the attacker could get complete control of the application process. However given the contents of the registers are just zeroized so the attacker cannot put arbitrary values inside, the most likely consequence, if any, would be an incorrect result of some application dependent calculations or a crash leading to a denial of service. The POLY1305 MAC algorithm is most frequently used as part of the CHACHA20-POLY1305 AEAD (authenticated encryption with associated data) algorithm. The most common usage of this AEAD cipher is with TLS protocol versions 1.2 and 1.3 and a malicious client can influence whether this AEAD cipher is used by the server. This implies that server applications using OpenSSL can be potentially impacted. However we are currently not aware of any concrete application that would be affected by this issue therefore we consider this a Low severity security issue. As a workaround the AVX512-IFMA instructions support can be disabled at runtime by setting the environment variable OPENSSL_ia32cap: OPENSSL_ia32cap=:~0x200000 The FIPS provider is not affected by this issue.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-4807" target="_blank">CVE-2023-4807</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p> <h4 id="328-reachable-assertion-cwe-617"><strong>3.2.8 </strong><a href="https://cwe.mitre.org/data/definitions/617.html" target="_blank"><strong>REACHABLE ASSERTION CWE-617</strong></a></h4> <p>A flaw in query-handling code can cause <code>named</code> to exit prematurely with an assertion failure when: - <code>nxdomain-redirect &lt;domain&gt;;</code> is configured, and - the resolver receives a PTR query for an RFC 1918 address that would normally result in an authoritative NXDOMAIN response. This issue affects BIND 9 versions 9.12.0 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-5517" target="_blank">CVE-2023-5517</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p> <h4 id="329-improper-check-for-unusual-or-exceptional-conditions-cwe-754"><strong>3.2.9 </strong><a href="https://cwe.mitre.org/data/definitions/754.html" target="_blank"><strong>IMPROPER CHECK FOR UNUSUAL OR EXCEPTIONAL CONDITIONS CWE-754</strong></a></h4> <p>Applications that use the functions DH_generate_key() to generate an X9.42 DH key may experience long delays. Likewise, applications that use DH_check_pub_key(), DH_check_pub_key_ex() or EVP_PKEY_public_check() to check an X9.42 DH key or X9.42 DH parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a denial of service. While DH_check() performs all the necessary checks (as of CVE-2023-3817), DH_check_pub_key() doesn't make any of these checks, and is therefore vulnerable for excessively large P and Q parameters. Likewise, while DH_generate_key() performs a check for an excessively large P, it doesn't check for an excessively large Q. An application that calls DH_generate_key() or DH_check_pub_key() and supplies a key or parameters obtained from an untrusted source could be vulnerable to a denial-of-service attack. DH_generate_key() and DH_check_pub_key() are also called by a number of other OpenSSL functions. An application calling any of those other functions may similarly be affected. The other functions affected by this are DH_check_pub_key_ex(), EVP_PKEY_public_check(), and EVP_PKEY_generate(). Also vulnerable are the OpenSSL pkey command line application when using the "-pubcheck" option, as well as the OpenSSL genpkey command line application. The OpenSSL SSL/TLS implementation is not affected by this issue. The OpenSSL 3.0 and 3.1 FIPS providers are not affected by this issue.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-5678" target="_blank">CVE-2023-5678</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</a>).</p> <h4 id="3210-reachable-assertion-cwe-617"><strong>3.2.10 </strong><a href="https://cwe.mitre.org/data/definitions/617.html" target="_blank"><strong>REACHABLE ASSERTION CWE-617</strong></a></h4> <p>A bad interaction between DNS64 and serve-stale may cause <code>named</code> to crash with an assertion failure during recursive resolution, when both of these features are enabled. This issue affects BIND 9 versions 9.16.12 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.16.12-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-5679" target="_blank">CVE-2023-5679</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p> <h4 id="3211-uncontrolled-resource-consumption-cwe-400"><strong>3.2.11 </strong><a href="https://cwe.mitre.org/data/definitions/400.html" target="_blank"><strong>UNCONTROLLED RESOURCE CONSUMPTION CWE-400</strong></a></h4> <p>A bad interaction between DNS64 and serve-stale may cause <code>named</code> to crash with an assertion failure during recursive resolution, when both of these features are enabled. This issue affects BIND 9 versions 9.16.12 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.16.12-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-5680" target="_blank">CVE-2023-5680</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p> <h4 id="3212-out-of-bounds-write-cwe-787"><strong>3.2.12 </strong><a href="https://cwe.mitre.org/data/definitions/787.html" target="_blank"><strong>OUT-OF-BOUNDS WRITE CWE-787</strong></a></h4> <p>The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications running on PowerPC CPU based platforms if the CPU provides vector instructions. If an attacker can influence whether the POLY1305 MAC algorithm is used, the application state might be corrupted with various application dependent consequences. The POLY1305 MAC (message authentication code) implementation in OpenSSL for PowerPC CPUs restores the contents of vector registers in a different order than they are saved. Thus the contents of some of these vector registers are corrupted when returning to the caller. The vulnerable code is used only on newer PowerPC processors supporting the PowerISA 2.07 instructions. The consequences of this kind of internal application state corruption can be various - from no consequences, if the calling application does not depend on the contents of non-volatile XMM registers at all, to the worst consequences, where the attacker could get complete control of the application process. However unless the compiler uses the vector registers for storing pointers, the most likely consequence, if any, would be an incorrect result of some application dependent calculations or a crash leading to a denial of service. The POLY1305 MAC algorithm is most frequently used as part of the CHACHA20-POLY1305 AEAD (authenticated encryption with associated data) algorithm. The most common usage of this AEAD cipher is with TLS protocol versions 1.2 and 1.3. If this cipher is enabled on the server a malicious client can influence whether this AEAD cipher is used. This implies that TLS server applications using OpenSSL can be potentially impacted.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-6129" target="_blank">CVE-2023-6129</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H</a>).</p> <h4 id="3213-uncontrolled-resource-consumption-cwe-400"><strong>3.2.13 </strong><a href="https://cwe.mitre.org/data/definitions/400.html" target="_blank"><strong>UNCONTROLLED RESOURCE CONSUMPTION CWE-400</strong></a></h4> <p>Checking excessively long invalid RSA public keys may take a long time. Applications that use the function EVP_PKEY_public_check() to check RSA public keys may experience long delays. Where the key that is being checked has been obtained from an untrusted source this may lead to a denial of service. When function EVP_PKEY_public_check() is called on RSA public keys, a computation is done to confirm that the RSA modulus, n, is composite. For valid RSA keys, n is a product of two or more large primes and this computation completes quickly. However, if n is an overly large prime, then this computation would take a long time. An application that calls EVP_PKEY_public_check() and supplies an RSA key obtained from an untrusted source could be vulnerable to a denial-of-service attack. The function EVP_PKEY_public_check() is not called from other OpenSSL functions however it is called from the OpenSSL pkey command line application. For that reason that application is also vulnerable if used with the '-pubin' and '-check' options on untrusted data. The OpenSSL SSL/TLS implementation is not affected by this issue. The OpenSSL 3.0 and 3.1 FIPS providers are affected by this issue.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-6237" target="_blank">CVE-2023-6237</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.9 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p> <h4 id="3214-memory-allocation-with-excessive-size-value-cwe-789"><strong>3.2.14 </strong><a href="https://cwe.mitre.org/data/definitions/789.html" target="_blank"><strong>MEMORY ALLOCATION WITH EXCESSIVE SIZE VALUE CWE-789</strong></a></h4> <p>To keep its cache database efficient, <code>named</code> running as a recursive resolver occasionally attempts to clean up the database. It uses several methods, including some that are asynchronous: a small chunk of memory pointing to the cache element that can be cleaned up is first allocated and then queued for later processing. It was discovered that if the resolver is continuously processing query patterns triggering this type of cache-database maintenance, <code>named</code> may not be able to handle the cleanup events in a timely manner. This in turn enables the list of queued cleanup events to grow infinitely large over time, allowing the configured <code>max-cache-size</code> limit to be significantly exceeded. This issue affects BIND 9 versions 9.16.0 through 9.16.45 and 9.16.8-S1 through 9.16.45-S1.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-6516" target="_blank">CVE-2023-6516</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p> <h4 id="3215-heap-based-buffer-overflow-cwe-122"><strong>3.2.15 </strong><a href="https://cwe.mitre.org/data/definitions/122.html" target="_blank"><strong>HEAP-BASED BUFFER OVERFLOW CWE-122</strong></a></h4> <p>A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make all test Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248999.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-7104" target="_blank">CVE-2023-7104</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank">CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L</a>).</p> <h4 id="3216-missing-encryption-of-sensitive-data-cwe-311"><strong>3.2.16 </strong><a href="https://cwe.mitre.org/data/definitions/311.html" target="_blank"><strong>MISSING ENCRYPTION OF SENSITIVE DATA CWE-311</strong></a></h4> <p>The use of <code>Module._load()</code> can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. Note that at the time this CVE was issued, the policy was an experimental feature of Node.js.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-32002" target="_blank">CVE-2023-32002</a> has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p> <h4 id="3217-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-cwe-22"><strong>3.2.17 </strong><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank"><strong>IMPROPER LIMITATION OF A PATHNAME TO A RESTRICTED DIRECTORY ('PATH TRAVERSAL') CWE-22</strong></a></h4> <p><code>fs.mkdtemp()</code> and <code>fs.mkdtempSync()</code> can be used to bypass the permission model check using a path traversal attack. This flaw arises from a missing check in the fs.mkdtemp() API and the impact is a malicious actor could create an arbitrary directory. This vulnerability affects all users using the experimental permission model in Node.js 20. Note that at the time this CVE was issued, the permission model was an experimental feature of Node.js.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-32003" target="_blank">CVE-2023-32003</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</a>).</p> <h4 id="3218-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-cwe-22"><strong>3.2.18 </strong><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank"><strong>IMPROPER LIMITATION OF A PATHNAME TO A RESTRICTED DIRECTORY ('PATH TRAVERSAL') CWE-22</strong></a></h4> <p>A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improper handling of buffers in file system APIs causing a traversal path to bypass when verifying file permissions. This vulnerability affects all users using the experimental permission model in Node.js 20. Note that at the time this CVE was issued, the permission model was an experimental feature of Node.js.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-32004" target="_blank">CVE-2023-32004</a> has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p> <h4 id="3219-incorrect-permission-assignment-for-critical-resource-cwe-732"><strong>3.2.19 </strong><a href="https://cwe.mitre.org/data/definitions/732.html" target="_blank"><strong>INCORRECT PERMISSION ASSIGNMENT FOR CRITICAL RESOURCE CWE-732</strong></a></h4> <p>A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flag is used with a non-* argument. This flaw arises from an inadequate permission model that fails to restrict file stats through the <code>fs.statfs</code> API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to. This vulnerability affects all users using the experimental permission model in Node.js 20. Note that at the time this CVE was issued, the permission model was an experimental feature of Node.js.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-32005" target="_blank">CVE-2023-32005</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a>).</p> <h4 id="3220-missing-encryption-of-sensitive-data-cwe-311"><strong>3.2.20 </strong><a href="https://cwe.mitre.org/data/definitions/311.html" target="_blank"><strong>MISSING ENCRYPTION OF SENSITIVE DATA CWE-311</strong></a></h4> <p>The use of <code>module.constructor.createRequire()</code> can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x, and, 20.x. Note that at the time this CVE was issued, the policy was an experimental feature of Node.js.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-32006" target="_blank">CVE-2023-32006</a> has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p> <h4 id="3221-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-cwe-22"><strong>3.2.21 </strong><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank"><strong>IMPROPER LIMITATION OF A PATHNAME TO A RESTRICTED DIRECTORY ('PATH TRAVERSAL') CWE-22</strong></a></h4> <p>The use of the deprecated API <code>process.binding()</code> can bypass the permission model through path traversal. This vulnerability affects all users using the experimental permission model in Node.js 20.x. Note that at the time this CVE was issued, the permission model was an experimental feature of Node.js.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-32558" target="_blank">CVE-2023-32558</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a>).</p> <h4 id="3222-missing-encryption-of-sensitive-data-cwe-311"><strong>3.2.22 </strong><a href="https://cwe.mitre.org/data/definitions/311.html" target="_blank"><strong>MISSING ENCRYPTION OF SENSITIVE DATA CWE-311</strong></a></h4> <p>A privilege escalation vulnerability exists in the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. The use of the deprecated API <code>process.binding()</code> can bypass the policy mechanism by requiring internal modules and eventually take advantage of <code>process.binding('spawn_sync')</code> run arbitrary code, outside of the limits defined in a <code>policy.json</code> file. Note that at the time this CVE was issued, the policy was an experimental feature of Node.js.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-32559" target="_blank">CVE-2023-32559</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p> <h4 id="3223-improper-input-validation-cwe-20"><strong>3.2.23 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4> <p>When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementation, thus effectively disabling the integrity check. This vulnerability affects all users using the experimental policy mechanism in all active release lines: 18.x and, 20.x. At the time this CVE was issued, the policy mechanism was an experimental feature of Node.js.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-38552" target="_blank">CVE-2023-38552</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a>).</p> <h4 id="3224-improper-input-validation-cwe-20"><strong>3.2.24 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4> <p>A previously disclosed vulnerability (CVE-2023-30584) was patched insufficiently in commit 205f1e6. The new path traversal vulnerability arises because the implementation does not protect itself against the application overwriting built-in utility functions with user-defined implementations. Note that at the time this CVE was issued, the permission model was an experimental feature of Node.js.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-39331" target="_blank">CVE-2023-39331</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a>).</p> <h4 id="3225-improper-input-validation-cwe-20"><strong>3.2.25 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4> <p>Various <code>node:fs</code> functions allow specifying paths as either strings or <code>Uint8Array</code> objects. In Node.js environments, the <code>Buffer</code> class extends the <code>Uint8Array</code> class. Node.js prevents path traversal through strings (see CVE-2023-30584) and <code>Buffer</code> objects (see CVE-2023-32004), but not through non-<code>Buffer</code> <code>Uint8Array</code> objects. This is distinct from CVE-2023-32004 which only referred to <code>Buffer</code> objects. However, the vulnerability follows the same pattern using <code>Uint8Array</code> instead of <code>Buffer</code>. At the time this CVE was issued, the permission model was an experimental feature of Node.js.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-39332" target="_blank">CVE-2023-39332</a> has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p> <h4 id="3226-improper-input-validation-cwe-20"><strong>3.2.26 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4> <p>Maliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be able to access data and functions that the WebAssembly module itself does not have access to, similar to as if the WebAssembly module was a JavaScript module.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-39333" target="_blank">CVE-2023-39333</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.1 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</a>).</p> <h4 id="3227-uncontrolled-resource-consumption-cwe-400"><strong>3.2.27 </strong><a href="https://cwe.mitre.org/data/definitions/400.html" target="_blank"><strong>UNCONTROLLED RESOURCE CONSUMPTION CWE-400</strong></a></h4> <p>The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-44487" target="_blank">CVE-2023-44487</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p> <h4 id="3228-exposure-of-sensitive-information-to-an-unauthorized-actor-cwe-200"><strong>3.2.28 </strong><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank"><strong>EXPOSURE OF SENSITIVE INFORMATION TO AN UNAUTHORIZED ACTOR CWE-200</strong></a></h4> <p>Undici is an HTTP/1.1 client written from scratch for Node.js. Prior to version 5.26.2, Undici already cleared authorization headers on cross-origin redirects, but did not clear <code>cookie</code> headers. By design, <code>cookie</code> headers are forbidden request headers, disallowing them to be set in RequestInit.headers in browser environments. Since undici handles headers more liberally than the spec, there was a disconnect from the assumptions the spec made, and undici's implementation of fetch. As such this may lead to accidental leakage of cookie to a third-party site or a malicious attacker who can control the redirection target (ie. an open redirector) to leak the cookie to the third party site. This was patched in version 5.26.2. There are no known workarounds.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-45143" target="_blank">CVE-2023-45143</a> has been assigned to this vulnerability. A CVSS v3 base score of 3.9 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L" target="_blank">CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L</a>).</p> <h4 id="3229-covert-timing-channel-cwe-385"><strong>3.2.29 </strong><a href="https://cwe.mitre.org/data/definitions/385.html" target="_blank"><strong>COVERT TIMING CHANNEL CWE-385</strong></a></h4> <p>Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the Marvin Attack - <a href="https://people.redhat.com/~hkario/marvin/" target="_blank">https://people.redhat.com/~hkario/marvin/</a>, if PCKS #1 v1.5 padding is allowed when performing RSA descryption using a private key.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-46809" target="_blank">CVE-2023-46809</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.4 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N</a>).</p> <h4 id="3230-out-of-bounds-write-cwe-787"><strong>3.2.30 </strong><a href="https://cwe.mitre.org/data/definitions/787.html" target="_blank"><strong>OUT-OF-BOUNDS WRITE CWE-787</strong></a></h4> <p>A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled by perl, which can allow an attacker controlled byte buffer overflow in a heap allocated buffer.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-47038" target="_blank">CVE-2023-47038</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.0 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p> <h4 id="3231-heap-based-buffer-overflow-cwe-122"><strong>3.2.31 </strong><a href="https://cwe.mitre.org/data/definitions/122.html" target="_blank"><strong>HEAP-BASED BUFFER OVERFLOW CWE-122</strong></a></h4> <p>This security issue occurs while Perl for Windows relies on the system path environment variable to find the shell (<code>cmd.exe</code>). When running an executable that uses the Windows Perl interpreter, Perl attempts to find and execute <code>cmd.exe</code> within the operating system. However, due to path search order issues, Perl initially looks for cmd.exe in the current working directory. This flaw allows an attacker with limited privileges to place<code>cmd.exe</code> in locations with weak permissions, such as <code>C:\ProgramData</code>. By doing so, arbitrary code can be executed when an administrator attempts to use this executable from these compromised locations.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-47039" target="_blank">CVE-2023-47039</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p> <h4 id="3232-improper-input-validation-cwe-20"><strong>3.2.32 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4> <p>In Perl before 5.38.2, S_parse_uniprop_string in regcomp.c can write to unallocated space because a property name associated with a \p{...} regular expression construct is mishandled. The earliest affected version is 5.30.0.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-47100" target="_blank">CVE-2023-47100</a> has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p> <h4 id="3233-truncation-of-security-relevant-information-cwe-222"><strong>3.2.33 </strong><a href="https://cwe.mitre.org/data/definitions/222.html" target="_blank"><strong>TRUNCATION OF SECURITY-RELEVANT INFORMATION CWE-222</strong></a></h4> <p>The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in <a href="mailto:chacha20-poly1305@openssh.com">chacha20-poly1305@openssh.com</a> and (if CBC is used) the <a href="mailto:-etm@openssh.com">-etm@openssh.com</a> MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230101, trilead-ssh2 6401, the net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for Node.js, the thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust; and there could be effects on Bitvise SSH through 9.31.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-48795" target="_blank">CVE-2023-48795</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.9 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N</a>).</p> <h4 id="3234-improper-input-validation-cwe-20"><strong>3.2.34 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4> <p>Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-50387" target="_blank">CVE-2023-50387</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p> <h4 id="3235-uncontrolled-resource-consumption-cwe-400"><strong>3.2.35 </strong><a href="https://cwe.mitre.org/data/definitions/400.html" target="_blank"><strong>UNCONTROLLED RESOURCE CONSUMPTION CWE-400</strong></a></h4> <p>The Closest Enclosure Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-50868" target="_blank">CVE-2023-50868</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p> <h4 id="3236-integer-overflow-or-wraparound-cwe-190"><strong>3.2.36 </strong><a href="https://cwe.mitre.org/data/definitions/190.html" target="_blank"><strong>INTEGER OVERFLOW OR WRAPAROUND CWE-190</strong></a></h4> <p>UTF32Encoding.cpp in POCO has a Poco::UTF32Encoding integer overflow and resultant stack buffer overflow because Poco::UTF32Encoding::convert() and Poco::UTF32::queryConvert() may return a negative integer if a UTF-32 byte sequence evaluates to a value of 0x80000000 or higher. This is fixed in 1.11.8p2, 1.12.5p2, and 1.13.0.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-52389" target="_blank">CVE-2023-52389</a> has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p> <h4 id="3237-use-after-free-cwe-416"><strong>3.2.37 </strong><a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank"><strong>USE AFTER FREE CWE-416</strong></a></h4> <p>A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-0232" target="_blank">CVE-2024-0232</a> has been assigned to this vulnerability. A CVSS v3 base score of 4.7 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H</a>).</p> <h4 id="3238-improper-input-validation-cwe-20"><strong>3.2.38 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4> <p>Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential denial-of-service attack. Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-0727" target="_blank">CVE-2024-0727</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</a>).</p> <h4 id="3239-uncontrolled-resource-consumption-cwe-400"><strong>3.2.39 </strong><a href="https://cwe.mitre.org/data/definitions/400.html" target="_blank"><strong>UNCONTROLLED RESOURCE CONSUMPTION CWE-400</strong></a></h4> <p>Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions. An attacker may exploit certain server configurations to trigger unbounded memory growth that would lead to a denial of service. This problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is being used (but not if early_data support is also configured and the default anti-replay protection is in use). In this case, under certain conditions, the session cache can get into an incorrect state and it will fail to flush properly as it fills. The session cache will continue to grow in an unbounded manner. A malicious client could deliberately create the scenario for this failure to force a denial of service. It may also happen by accident in normal operation. This issue only affects TLS servers supporting TLSv1.3. It does not affect TLS clients. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. OpenSSL 1.0.2 is also not affected by this issue.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-2511" target="_blank">CVE-2024-2511</a> has been assigned to this vulnerability. A CVSS v3 base score of 3.7 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L</a>).</p> <h4 id="3240-use-after-free-cwe-416"><strong>3.2.40 </strong><a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank"><strong>USE AFTER FREE CWE-416</strong></a></h4> <p>Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously freed in some situations</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-4741" target="_blank">CVE-2024-4741</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p> <h4 id="3241-exposure-of-sensitive-information-to-an-unauthorized-actor-cwe-200"><strong>3.2.41 </strong><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank"><strong>EXPOSURE OF SENSITIVE INFORMATION TO AN UNAUTHORIZED ACTOR CWE-200</strong></a></h4> <p>Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer may cause a crash or memory contents to be sent to the peer. A buffer overread can have a range of potential consequences such as unexpected application behavior or a crash. In particular this issue could result in up to 255 bytes of arbitrary private data from memory being sent to the peer leading to a loss of confidentiality. However, only applications that directly call the SSL_select_next_proto function with a 0 length list of supported client protocols are affected by this issue. This would normally never be a valid scenario and is typically not under attacker control but may occur by accident in the case of a configuration or programming error in the calling application. The OpenSSL API function SSL_select_next_proto is typically used by TLS applications that support ALPN (Application Layer Protocol Negotiation) or NPN (Next Protocol Negotiation). NPN is older, was never standardized and is deprecated in favor of ALPN. We believe that ALPN is significantly more widely deployed than NPN. The SSL_select_next_proto function accepts a list of protocols from the server and a list of protocols from the client and returns the first protocol that appears in the server list that also appears in the client list. In the case of no overlap between the two lists it returns the first item in the client list. In either case it will signal whether an overlap between the two lists was found. In the case where SSL_select_next_proto is called with a zero length client list it fails to notice this condition and returns the memory immediately following the client list pointer (and reports that there was no overlap in the lists). This function is typically called from a server side application callback for ALPN or a client side application callback for NPN. In the case of ALPN the list of protocols supplied by the client is guaranteed by libssl to never be zero in length. The list of server protocols comes from the application and should never normally be expected to be of zero length. In this case if the SSL_select_next_proto function has been called as expected (with the list supplied by the client passed in the client/client_len parameters), then the application will not be vulnerable to this issue. If the application has accidentally been configured with a zero length server list, and has accidentally passed that zero length server list in the client/client_len parameters, and has additionally failed to correctly handle a "no overlap" response (which would normally result in a handshake failure in ALPN) then it will be vulnerable to this problem. In the case of NPN, the protocol permits the client to opportunistically select a protocol when there is no overlap. OpenSSL returns the first client protocol in the no overlap case in support of this. The list of client protocols comes from the application and should never normally be expected to be of zero length. However if the SSL_select_next_proto function is accidentally called with a client_len of 0 then an invalid memory pointer will be returned instead. If the application uses this output as the opportunistic protocol then the loss of confidentiality will occur. This issue has been assessed as Low severity because applications are most likely to be vulnerable if they are using NPN instead of ALPN - but NPN is not widely used. It also requires an application configuration or programming error. Finally, this issue would not typically be under attacker control making active exploitation unlikely. The FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue. Due to the low severity of this issue we are not issuing new releases of OpenSSL at this time. The fix will be included in the next releases when they become available.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-5535" target="_blank">CVE-2024-5535</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.9 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</a>).</p> <h4 id="3242-improper-authentication-cwe-287"><strong>3.2.42 </strong><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank"><strong>IMPROPER AUTHENTICATION CWE-287</strong></a></h4> <p>The Node.js Permission Model does not clarify in the documentation that wildcards should be only used as the last character of a file path. For example: <code>--allow-fs-read=/home/node/.ssh/*.pub</code> will ignore <code>pub</code> and give access to everything after <code>.ssh/</code>. This misleading documentation affects all users using the experimental permission model in Node.js 20 and Node.js 21. At the time this CVE was issued, the permission model was an experimental feature of Node.js.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-21890" target="_blank">CVE-2024-21890</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</a>).</p> <h4 id="3243-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-cwe-22"><strong>3.2.43 </strong><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank"><strong>IMPROPER LIMITATION OF A PATHNAME TO A RESTRICTED DIRECTORY ('PATH TRAVERSAL') CWE-22</strong></a></h4> <p>Node.js could allow a remote attacker to bypass security restrictions, caused by improper path traversal sequence sanitization. By using a path traversal attack, an attacker could exploit this vulnerability leading to filesystem permission model bypass.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-21891" target="_blank">CVE-2024-21891</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</a>).</p> <h4 id="3244-improper-control-of-generation-of-code-code-injection-cwe-94"><strong>3.2.44 </strong><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank"><strong>IMPROPER CONTROL OF GENERATION OF CODE ('CODE INJECTION') CWE-94</strong></a></h4> <p>Node.js could allow a local authenticated attacker to gain elevated privileges on the system, caused by a bug in the implementation of the exception of CAP_NET_BIND_SERVICE. An attacker could exploit this vulnerability to inject code that inherits the process's elevated privileges.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-21892" target="_blank">CVE-2024-21892</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p> <h4 id="3245-path-traversal-dirfilename-cwe-27"><strong>3.2.45 </strong><a href="https://cwe.mitre.org/data/definitions/27.html" target="_blank"><strong>PATH TRAVERSAL: 'DIR/../../FILENAME' CWE-27</strong></a></h4> <p>Node.js could allow a remote attacker to traverse directories on the system. By monkey-patching buffer internals, namely, Buffer.prototype.utf8Write, an attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to read arbitrary files on the system.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-21896" target="_blank">CVE-2024-21896</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.9 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N</a>).</p> <h4 id="3246-execution-with-unnecessary-privileges-cwe-250"><strong>3.2.46 </strong><a href="https://cwe.mitre.org/data/definitions/250.html" target="_blank"><strong>EXECUTION WITH UNNECESSARY PRIVILEGES CWE-250</strong></a></h4> <p>setuid() does not affect libuv's internal io_uring operations if initialized before the call to setuid(). This allows the process to perform privileged operations despite presumably having dropped such privileges through a call to setuid(). This vulnerability affects all users using version greater or equal than Node.js 18.18.0, Node.js 20.4.0 and Node.js 21.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-22017" target="_blank">CVE-2024-22017</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:L" target="_blank">CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:L</a>).</p> <h4 id="3247-uncontrolled-resource-consumption-cwe-400"><strong>3.2.47 </strong><a href="https://cwe.mitre.org/data/definitions/400.html" target="_blank"><strong>UNCONTROLLED RESOURCE CONSUMPTION CWE-400</strong></a></h4> <p>A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service. The server reads an unbounded number of bytes from a single connection, exploiting the lack of limitations on chunk extension bytes. The issue can cause CPU and network bandwidth exhaustion, bypassing standard safeguards like timeouts and body size limits.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-22019" target="_blank">CVE-2024-22019</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p> <h4 id="3248-uncontrolled-resource-consumption-cwe-400"><strong>3.2.48 </strong><a href="https://cwe.mitre.org/data/definitions/400.html" target="_blank"><strong>UNCONTROLLED RESOURCE CONSUMPTION CWE-400</strong></a></h4> <p>Node.js is vulnerable to a denial of service, caused by a resource exhaustion vulnerability in fetch() brotli decoding . By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a denial-of-service condition.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-22025" target="_blank">CVE-2024-22025</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</a>).</p> <h4 id="3249-exposure-of-sensitive-information-to-an-unauthorized-actor-cwe-200"><strong>3.2.49 </strong><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank"><strong>EXPOSURE OF SENSITIVE INFORMATION TO AN UNAUTHORIZED ACTOR CWE-200</strong></a></h4> <p>Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici already cleared authorization headers on cross-origin redirects, but did not clear <code>Proxy-Authentication</code> headers. This issue has been patched in versions 5.28.3 and 6.6.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-24758" target="_blank">CVE-2024-24758</a> has been assigned to this vulnerability. A CVSS v3 base score of 3.9 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L" target="_blank">CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L</a>).</p> <h4 id="3250-server-side-request-forgery-ssrf-cwe-918"><strong>3.2.50 </strong><a href="https://cwe.mitre.org/data/definitions/918.html" target="_blank"><strong>SERVER-SIDE REQUEST FORGERY (SSRF) CWE-918</strong></a></h4> <p>libuv is a multi-platform support library with a focus on asynchronous I/O. The <code>uv_getaddrinfo</code> function in <code>src/unix/getaddrinfo.c</code> (and its windows counterpart <code>src/win/getaddrinfo.c</code>), truncates hostnames to 256 characters before calling <code>getaddrinfo</code>. This behavior can be exploited to create addresses like <code>0x00007f000001</code>, which are considered valid by <code>getaddrinfo</code> and could allow an attacker to craft payloads that resolve to unintended IP addresses, bypassing developer checks. The vulnerability arises due to how the <code>hostname_ascii</code> variable (with a length of 256 bytes) is handled in <code>uv_getaddrinfo</code> and subsequently in <code>uv__idna_toascii</code>. When the hostname exceeds 256 characters, it gets truncated without a terminating null byte. As a result attackers may be able to access internal APIs or for websites (similar to MySpace) that allows users to have <code>username.example.com</code> pages. Internal services that crawl or cache these user pages can be exposed to SSRF attacks if a malicious user chooses a long vulnerable username. This issue has been addressed in release version 1.48.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-24806" target="_blank">CVE-2024-24806</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</a>).</p> <h4 id="3251-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-cwe-78"><strong>3.2.51 </strong><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank"><strong>IMPROPER NEUTRALIZATION OF SPECIAL ELEMENTS USED IN AN OS COMMAND ('OS COMMAND INJECTION') CWE-78</strong></a></h4> <p>Node.js could allow a remote attacker to execute arbitrary commands on the system, caused by the improper handling of batch files in child_process.spawn / child_process.spawnSync. By sending a specially crafted command line argument using args parameter, an attacker could exploit this vulnerability to inject and execute arbitrary commands on the system.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-27980" target="_blank">CVE-2024-27980</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</a>).</p> <h4 id="3252-inconsistent-interpretation-of-http-requests-http-requestresponse-smuggling-cwe-444"><strong>3.2.52 </strong><a href="https://cwe.mitre.org/data/definitions/444.html" target="_blank"><strong>INCONSISTENT INTERPRETATION OF HTTP REQUESTS ('HTTP REQUEST/RESPONSE SMUGGLING') CWE-444</strong></a></h4> <p>A vulnerability in the http server, where malformed headers can lead to HTTP request smuggling. Specifically, if a space is placed before a content-length header, it is not interpreted correctly, enabling attackers to smuggle in a second request within the body of the first.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-27982" target="_blank">CVE-2024-27982</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.1 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</a>).</p> <h4 id="3253-uncontrolled-resource-consumption-cwe-400"><strong>3.2.53 </strong><a href="https://cwe.mitre.org/data/definitions/400.html" target="_blank"><strong>UNCONTROLLED RESOURCE CONSUMPTION CWE-400</strong></a></h4> <p>Node.js is vulnerable to a denial of service, caused by an assertion failure in node::http2::Http2Session::~Http2Session(). By sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside, an attacker could exploit this vulnerability to cause the HTTP/2 server to crash.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-27983" target="_blank">CVE-2024-27983</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p> <h4 id="3254-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-cwe-22"><strong>3.2.54 </strong><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank"><strong>IMPROPER LIMITATION OF A PATHNAME TO A RESTRICTED DIRECTORY ('PATH TRAVERSAL') CWE-22</strong></a></h4> <p>The affected application does not properly sanitize user provided paths for SFTP-based file up- and downloads. This could allow an authenticated remote attacker to manipulate arbitrary files on the filesystem and achieve arbitrary code execution on the device.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-46888" target="_blank">CVE-2024-46888</a> has been assigned to this vulnerability. A CVSS v3 base score of 9.9 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a>).</p> <h4 id="3255-use-of-hard-coded-cryptographic-key-cwe-321"><strong>3.2.55 </strong><a href="https://cwe.mitre.org/data/definitions/321.html" target="_blank"><strong>USE OF HARD-CODED CRYPTOGRAPHIC KEY CWE-321</strong></a></h4> <p>The affected application uses hard-coded cryptographic key material to obfuscate configuration files. This could allow an attacker to learn that cryptographic key material through reverse engineering of the application binary and decrypt arbitrary backup files.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-46889" target="_blank">CVE-2024-46889</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a>).</p> <h4 id="3256-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-cwe-78"><strong>3.2.56 </strong><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank"><strong>IMPROPER NEUTRALIZATION OF SPECIAL ELEMENTS USED IN AN OS COMMAND ('OS COMMAND INJECTION') CWE-78</strong></a></h4> <p>The affected application does not properly validate input sent to specific endpoints of its web API. This could allow an authenticated remote attacker with high privileges on the application to execute arbitrary code on the underlying OS.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-46890" target="_blank">CVE-2024-46890</a> has been assigned to this vulnerability. A CVSS v3 base score of 9.1 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</a>).</p> <h4 id="3257-uncontrolled-resource-consumption-cwe-400"><strong>3.2.57 </strong><a href="https://cwe.mitre.org/data/definitions/400.html" target="_blank"><strong>UNCONTROLLED RESOURCE CONSUMPTION CWE-400</strong></a></h4> <p>The affected application does not properly restrict the size of generated log files. This could allow an unauthenticated remote attacker to trigger a large amount of logged events to exhaust the system's resources and create a denial-of-service condition.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-46891" target="_blank">CVE-2024-46891</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</a>).</p> <h4 id="3258-insufficient-session-expiration-cwe-613"><strong>3.2.58 </strong><a href="https://cwe.mitre.org/data/definitions/613.html" target="_blank"><strong>INSUFFICIENT SESSION EXPIRATION CWE-613</strong></a></h4> <p>The affected application does not properly invalidate sessions when the associated user is deleted or disabled or their permissions are modified. This could allow an authenticated attacker to continue performing malicious actions even after their user account has been disabled.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-46892" target="_blank">CVE-2024-46892</a> has been assigned to this vulnerability. A CVSS v3 base score of 4.9 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N</a>).</p> <h4 id="3259-exposure-of-sensitive-information-to-an-unauthorized-actor-cwe-200"><strong>3.2.59 </strong><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank"><strong>EXPOSURE OF SENSITIVE INFORMATION TO AN UNAUTHORIZED ACTOR CWE-200</strong></a></h4> <p>The affected application does not properly validate authorization of a user to query the "/api/sftp/users" endpoint. This could allow an authenticated remote attacker to gain knowledge about the list of configured users of the SFTP service and also modify that configuration.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-46894" target="_blank">CVE-2024-46894</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Germany</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Siemens reported these vulnerabilities to CISA.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Siemens has released <a href="https://support.industry.siemens.com/cs/ww/en/view/109975745/" target="_blank">SINEC INS V1.0 SP2 Update 3</a> and recommends updating to the latest version.</p> <p>Siemens has identified the following specific workarounds and mitigations users can apply to reduce risk:</p> <p>As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends configuring the environment according to <a href="https://www.siemens.com/cert/operational-guidelines-industrial-security" target="_blank">Siemens' operational guidelines for industrial security</a> and following recommendations in the product manuals.</p> <p>Additional information on industrial security by Siemens can be found on the <a href="https://www.siemens.com/industrialsecurity" target="_blank">Siemens industrial security webpage</a></p> <p>For more information see the associated Siemens security advisory SSA-915275 in <a href="https://cert-portal.siemens.com/productcert/html/ssa-915275.html" target="_blank">HTML</a> and <a href="https://cert-portal.siemens.com/productcert/csaf/ssa-915275.json" target="_blank">CSAF</a>.</p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p> <ul> <li>Do not click web links or open attachments in unsolicited email messages.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf" target="_blank">Recognizing and Avoiding Email Scams</a> for more information on avoiding email scams.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/ncas/tips/ST04-014" target="_blank">Avoiding Social Engineering and Phishing Attacks</a> for more information on social engineering attacks.</li> </ul> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 14, 2024: Initial Publication</li> </ul> Thu, 14 Nov 24 12:00:00 +0000 CISA /node/22565 Siemens Engineering Platforms https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-07 <p>As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory.&nbsp;For the most up-to-date information on vulnerabilities in this advisory, please see&nbsp;<a class="ext" href="https://new.siemens.com/global/en/products/services/cert.html#SecurityPublications" title="(opens in a new window)">Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).</a></p> <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v4 7.0</strong></li> <li><strong>ATTENTION</strong>: Low Attack Complexity</li> <li><strong>Vendor</strong>: Siemens</li> <li><strong>Equipment</strong>: Siemens Engineering Platforms</li> <li><strong>Vulnerability</strong>: Deserialization of Untrusted Data</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of this vulnerability could allow an attacker to cause a type confusion and execute arbitrary code within the affected application.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>Siemens reports that the following products are affected:</p> <ul> <li>SIMATIC S7-PLCSIM V16: all versions</li> <li>SIMATIC S7-PLCSIM V17: all versions</li> <li>SIMATIC STEP 7 Safety V16: all versions</li> <li>SIMATIC STEP 7 Safety V17: versions prior to V17 Update 8</li> <li>SIMATIC STEP 7 Safety V18: versions prior to V18 Update 5</li> <li>SIMATIC STEP 7 V16: all versions</li> <li>SIMATIC STEP 7 V17: versions prior to V17 Update 8</li> <li>SIMATIC STEP 7 V18: versions prior to V18 Update 5</li> <li>SIMATIC WinCC Unified V16: all versions</li> <li>SIMATIC WinCC Unified V17: versions prior to V17 Update 8</li> <li>SIMATIC WinCC Unified V18: versions prior to V18 Update 5</li> <li>SIMATIC WinCC V16: all versions</li> <li>SIMATIC WinCC V17: versions prior to V17 Update 8</li> <li>SIMATIC WinCC V18: versions prior to V18 Update 5</li> <li>SIMOCODE ES V16: all versions</li> <li>SIMOCODE ES V17: versions prior to V17 Update 8</li> <li>SIMOCODE ES V18: all versions</li> <li>SIMOTION SCOUT TIA V5.4 SP1: all versions</li> <li>SIMOTION SCOUT TIA V5.4 SP3: all versions</li> <li>SIMOTION SCOUT TIA V5.5 SP1: all versions</li> <li>SINAMICS Startdrive V16: all versions</li> <li>SINAMICS Startdrive V17: all versions</li> <li>SINAMICS Startdrive V18: all versions</li> <li>SIRIUS Safety ES V17: versions prior to V17 Update 8</li> <li>SIRIUS Safety ES V18: all versions</li> <li>SIRIUS Soft Starter ES V17: versions prior to V17 Update 8</li> <li>SIRIUS Soft Starter ES V18: all versions</li> <li>TIA Portal Cloud V16: all versions</li> <li>TIA Portal Cloud V17: versions prior to V4.6.0.1</li> <li>TIA Portal Cloud V18: versions prior to V4.6.1.0</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-deserialization-of-untrusted-data-cwe-502"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank"><strong>DESERIALIZATION OF UNTRUSTED DATA CWE-502</strong></a></h4> <p>Affected products do not properly sanitize user-controllable input when parsing user settings. This could allow an attacker to cause a type confusion and execute arbitrary code within the affected application.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-32736" target="_blank">CVE-2023-32736</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2023-32736" target="_blank">CVE-2023-32736</a>. A base score of 7.0 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Germany</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Siemens reported this vulnerability to CISA.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Siemens has released new versions for several affected products and recommends updating to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.</p> <ul> <li>SIMATIC WinCC V17: <a href="https://support.industry.siemens.com/cs/ww/en/view/109784441/" target="_blank">Update to V17 Update 8 or later version</a></li> <li>SIMATIC STEP 7 Safety V17, SIMATIC STEP 7 V17, SIMATIC WinCC Unified V17: <a href="https://support.industry.siemens.com/cs/ww/en/view/109784441/" target="_blank">Update to V17 Update 8 or later version</a></li> <li>SIMOCODE ES V17, SIRIUS Safety ES V17, SIRIUS Soft Starter ES V17: <a href="https://support.industry.siemens.com/cs/ww/en/view/109803780/" target="_blank">Update to V17 Update 8 or later version</a></li> <li>SIMATIC STEP 7 Safety V18, SIMATIC STEP 7 V18, SIMATIC WinCC Unified V18, SIMATIC WinCC V18: <a href="https://support.industry.siemens.com/cs/ww/en/view/109817218/" target="_blank">Update to V18 Update 5 or later version</a></li> <li>TIA Portal Cloud V18: <a href="https://support.industry.siemens.com/cs/ww/en/view/109817218/" target="_blank">TIA Portal Cloud V4.6.1.0 or later version updated TIA Portal to V18 Update 5 or later version</a></li> <li>SIMOCODE ES V18, SIMOTION SCOUT TIA V5.5 SP1, SINAMICS Startdrive V18, SIRIUS Safety ES V18, SIRIUS Soft Starter ES V18: <a href="https://support.industry.siemens.com/cs/ww/en/view/109817218/" target="_blank">Update SIMATIC STEP 7 V18 to V18 Update 5 or later version</a></li> <li>SIMOTION SCOUT TIA V5.4 SP3, SINAMICS Startdrive V17: <a href="https://support.industry.siemens.com/cs/ww/en/view/109784441/" target="_blank">Update SIMATIC STEP 7 V17 to V17 Update 8 or later version</a></li> <li>TIA Portal Cloud V17: <a href="https://support.industry.siemens.com/cs/ww/en/view/109784441/" target="_blank">TIA Portal Cloud V4.6.0.1 or later version updated TIA Portal to V17 Update 8 or later version</a></li> </ul> <p>Siemens has identified the following specific workarounds and mitigations users can apply to reduce risk:</p> <ul> <li>Avoid opening untrusted files from unknown sources in affected products</li> </ul> <p>As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends configuring the environment according to <a href="https://www.siemens.com/cert/operational-guidelines-industrial-security" target="_blank">Siemens' operational guidelines for industrial security</a> and following recommendations in the product manuals.</p> <p>Additional information on industrial security by Siemens can be found on the <a href="https://www.siemens.com/industrialsecurity" target="_blank">Siemens industrial security webpage</a></p> <p>For more information see the associated Siemens security advisory SSA-871035 in <a href="https://cert-portal.siemens.com/productcert/html/ssa-871035.html" target="_blank">HTML</a> and <a href="https://cert-portal.siemens.com/productcert/csaf/ssa-871035.json" target="_blank">CSAF</a>.</p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p> <ul> <li>Do not click web links or open attachments in unsolicited email messages.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf" target="_blank">Recognizing and Avoiding Email Scams</a> for more information on avoiding email scams.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/ncas/tips/ST04-014" target="_blank">Avoiding Social Engineering and Phishing Attacks</a> for more information on social engineering attacks.</li> </ul> <p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 14, 2024: Initial Publication</li> </ul> Thu, 14 Nov 24 12:00:00 +0000 CISA /node/22564 Siemens SCALANCE M-800 Family https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-06 <p>As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory.&nbsp;For the most up-to-date information on vulnerabilities in this advisory, please see&nbsp;<a class="ext" href="https://new.siemens.com/global/en/products/services/cert.html#SecurityPublications" title="(opens in a new window)">Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).</a></p> <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v4 8.6</strong></li> <li><strong>ATTENTION</strong>: Exploitable remotely/low attack complexity</li> <li><strong>Vendor</strong>: Siemens</li> <li><strong>Equipment</strong>: SCALANCE M-800 Family</li> <li><strong>Vulnerabilities</strong>: Out-of-bounds Read, Missing Encryption of Sensitive Data, Integer Overflow or Wraparound, Uncontrolled Resource Consumption, Excessive Iteration, Use After Free, Improper Output Neutralization for Logs, Observable Discrepancy, Improper Locking, Missing Release of Resource after Effective Lifetime, Improper Input Validation, Improper Access Control, Path Traversal, Cross-site Scripting, Injection</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of these vulnerabilities could impact the confidentiality, integrity or availability.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>The following Siemens products are affected:</p> <ul> <li>RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2): versions prior to V8.2</li> <li>RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2): versions prior to V8.2</li> <li>SCALANCE M804PB (6GK5804-0AP00-2AA2): versions prior to V8.2</li> <li>SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2): versions prior to V8.2</li> <li>SCALANCE M812-1 ADSL-Router (6GK5812-1BA00-2AA2): versions prior to V8.2</li> <li>SCALANCE M816-1 ADSL-Router (6GK5816-1AA00-2AA2): versions prior to V8.2</li> <li>SCALANCE M816-1 ADSL-Router (6GK5816-1BA00-2AA2): versions prior to V8.2</li> <li>SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2): versions prior to V8.2</li> <li>SCALANCE M874-2 (6GK5874-2AA00-2AA2): versions prior to V8.2</li> <li>SCALANCE M874-3 3G-Router (CN) (6GK5874-3AA00-2FA2): versions prior to V8.2</li> <li>SCALANCE M874-3 (6GK5874-3AA00-2AA2): versions prior to V8.2</li> <li>SCALANCE M876-3 (6GK5876-3AA02-2BA2): versions prior to V8.2</li> <li>SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2): versions prior to V8.2</li> <li>SCALANCE M876-4 (6GK5876-4AA10-2BA2): versions prior to V8.2</li> <li>SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2): versions prior to V8.2</li> <li>SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2): versions prior to V8.2</li> <li>SCALANCE MUM853-1 (A1) (6GK5853-2EA10-2AA1): versions prior to V8.2</li> <li>SCALANCE MUM853-1 (B1) (6GK5853-2EA10-2BA1): versions prior to V8.2</li> <li>SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1): versions prior to V8.2</li> <li>SCALANCE MUM856-1 (A1) (6GK5856-2EA10-3AA1): versions prior to V8.2</li> <li>SCALANCE MUM856-1 (B1) (6GK5856-2EA10-3BA1): versions prior to V8.2</li> <li>SCALANCE MUM856-1 (CN) (6GK5856-2EA00-3FA1): versions prior to V8.2</li> <li>SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1): versions prior to V8.2</li> <li>SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1): versions prior to V8.2</li> <li>SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2): versions prior to V8.2</li> <li>SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2): versions prior to V8.2</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-out-of-bounds-read-cwe-125"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/125.html" target="_blank"><strong>OUT-OF-BOUNDS READ CWE-125</strong></a></h4> <p>An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2021-3506" target="_blank">CVE-2021-3506</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H</a>).</p> <h4 id="322-missing-encryption-of-sensitive-data-cwe-311"><strong>3.2.2 </strong><a href="https://cwe.mitre.org/data/definitions/311.html" target="_blank"><strong>MISSING ENCRYPTION OF SENSITIVE DATA CWE-311</strong></a></h4> <p>An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0 UDP packet size was set to 4096 but should be 1232 because of DNS Flag Day 2020.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-28450" target="_blank">CVE-2023-28450</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p> <h4 id="323-integer-overflow-or-wraparound-cwe-190"><strong>3.2.3 </strong><a href="https://cwe.mitre.org/data/definitions/190.html" target="_blank"><strong>INTEGER OVERFLOW OR WRAPAROUND CWE-190</strong></a></h4> <p>dnsmasq 2.9 is vulnerable to Integer Overflow via forward_query.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-49441" target="_blank">CVE-2023-49441</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p> <h4 id="324-uncontrolled-resource-consumption-cwe-400"><strong>3.2.4 </strong><a href="https://cwe.mitre.org/data/definitions/400.html" target="_blank"><strong>UNCONTROLLED RESOURCE CONSUMPTION CWE-400</strong></a></h4> <p>Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions Impact summary: An attacker may exploit certain server configurations to trigger unbounded memory growth that would lead to a Denial of Service This problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is being used (but not if early_data support is also configured and the default anti-replay protection is in use). In this case, under certain conditions, the session cache can get into an incorrect state, and it will fail to flush properly as it fills. The session cache will continue to grow in an unbounded manner. A malicious client could deliberately create the scenario for this failure to force a Denial of Service. It may also happen by accident in normal operation. This issue only affects TLS servers supporting TLSv1.3. It does not affect TLS clients. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. OpenSSL 1.0.2 is also not affected by this issue.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-2511" target="_blank">CVE-2024-2511</a> has been assigned to this vulnerability. A CVSS v3 base score of 3.7 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L</a>).</p> <h4 id="325-excessive-iteration-cwe-834"><strong>3.2.5 </strong><a href="https://cwe.mitre.org/data/definitions/834.html" target="_blank"><strong>EXCESSIVE ITERATION CWE-834</strong></a></h4> <p>Issue summary: Checking excessively long DSA keys or parameters may be very slow. Impact summary: Applications that use the functions EVP_PKEY_param_check() or EVP_PKEY_public_check() to check a DSA public key or DSA parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a Denial of Service. The functions EVP_PKEY_param_check() or EVP_PKEY_public_check() perform various checks on DSA parameters. Some of those computations take a long time if the modulus (<code>p</code> parameter) is too large. Trying to use a very large modulus is slow and OpenSSL will not allow using public keys with a modulus which is over 10,000 bits in length for signature verification. However, the key and parameter check functions do not limit the modulus size when performing the checks. An application that calls EVP_PKEY_param_check() or EVP_PKEY_public_check() and supplies a key or parameters obtained from an untrusted source could be vulnerable to a Denial of Service attack. These functions are not called by OpenSSL itself on untrusted DSA keys so only applications that directly call these functions may be vulnerable. Also vulnerable are the OpenSSL pkey and pkeyparam command line applications when using the <code>-check</code> option. The OpenSSL SSL/TLS implementation is not affected by this issue. The OpenSSL 3.0 and 3.1 FIPS providers are affected by this issue.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-4603" target="_blank">CVE-2024-4603</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</a>).</p> <h4 id="326-use-after-free-cwe-416"><strong>3.2.6 </strong><a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank"><strong>USE AFTER FREE CWE-416</strong></a></h4> <p>Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously freed in some situations</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-4741" target="_blank">CVE-2024-4741</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p> <h4 id="327-improper-output-neutralization-for-logs-cwe-117"><strong>3.2.7 </strong><a href="https://cwe.mitre.org/data/definitions/117.html" target="_blank"><strong>IMPROPER OUTPUT NEUTRALIZATION FOR LOGS CWE-117</strong></a></h4> <p>control channel: refuse control channel messages with nonprintable characters in them. Security scope: a malicious openvpn peer can send garbage to openvpn log, or cause high CPU load</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-5594" target="_blank">CVE-2024-5594</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.4 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L</a>).</p> <h4 id="328-observable-discrepancy-cwe-203"><strong>3.2.8 </strong><a href="https://cwe.mitre.org/data/definitions/203.html" target="_blank"><strong>OBSERVABLE DISCREPANCY CWE-203</strong></a></h4> <p>iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-26306" target="_blank">CVE-2024-26306</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.9 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</a>).</p> <h4 id="329-improper-locking-cwe-667"><strong>3.2.9 </strong><a href="https://cwe.mitre.org/data/definitions/667.html" target="_blank"><strong>IMPROPER LOCKING CWE-667</strong></a></h4> <p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: release mutex after nft_gc_seq_end from abort path The commit mutex should not be released during the critical section between nft_gc_seq_begin() and nft_gc_seq_end(), otherwise, async GC worker could collect expired objects and get the released commit lock within the same GC sequence. nf_tables_module_autoload() temporarily releases the mutex to load module dependencies, then it goes back to replay the transaction again. Move it at the end of the abort phase after nft_gc_seq_end() is called.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-26925" target="_blank">CVE-2024-26925</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a>).</p> <h4 id="3210-missing-release-of-resource-after-effective-lifetime-cwe-772"><strong>3.2.10 </strong><a href="https://cwe.mitre.org/data/definitions/772.html" target="_blank"><strong>MISSING RELEASE OF RESOURCE AFTER EFFECTIVE LIFETIME CWE-772</strong></a></h4> <p>OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-28882" target="_blank">CVE-2024-28882</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N</a>).</p> <h4 id="3211-improper-input-validation-cwe-20"><strong>3.2.11 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4> <p>Affected devices do not properly validate input in configuration fields of the iperf functionality. This could allow an unauthenticated remote attacker to execute arbitrary code on the device.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-50557" target="_blank">CVE-2024-50557</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.2 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-50557" target="_blank">CVE-2024-50557</a>. A base score of 8.6 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>).</p> <h4 id="3212-improper-access-control-cwe-284"><strong>3.2.12 </strong><a href="https://cwe.mitre.org/data/definitions/284.html" target="_blank"><strong>IMPROPER ACCESS CONTROL CWE-284</strong></a></h4> <p>Affected devices improperly manage access control for read-only users. This could allow an attacker to cause a temporary denial of service condition.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-50558" target="_blank">CVE-2024-50558</a> has been assigned to this vulnerability. A CVSS v3 base score of 4.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-50558" target="_blank">CVE-2024-50558</a>. A base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N" target="_blank">CVSS4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N</a>).</p> <h4 id="3213-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-cwe-22"><strong>3.2.13 </strong><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank"><strong>IMPROPER LIMITATION OF A PATHNAME TO A RESTRICTED DIRECTORY ('PATH TRAVERSAL') CWE-22</strong></a></h4> <p>Affected devices do not properly validate the filenames of the certificate. This could allow an authenticated remote attacker to append arbitrary values which will lead to compromise of integrity of the system.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-50559" target="_blank">CVE-2024-50559</a> has been assigned to this vulnerability. A CVSS v3 base score of 4.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-50559" target="_blank">CVE-2024-50559</a>. A base score of 5.1 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N</a>).</p> <h4 id="3214-improper-input-validation-cwe-20"><strong>3.2.14 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4> <p>Affected devices truncates usernames longer than 15 characters when accessed via SSH or Telnet. This could allow an attacker to compromise system integrity.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-50560" target="_blank">CVE-2024-50560</a> has been assigned to this vulnerability. A CVSS v3 base score of 3.1 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-50560" target="_blank">CVE-2024-50560</a>. A base score of 2.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N</a>).</p> <h4 id="3215-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-cwe-79"><strong>3.2.15 </strong><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank"><strong>IMPROPER NEUTRALIZATION OF INPUT DURING WEB PAGE GENERATION ('CROSS-SITE SCRIPTING') CWE-79</strong></a></h4> <p>Affected devices do not properly sanitize the filenames before uploading. This could allow an authenticated remote attacker to compromise of integrity of the system.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-50561" target="_blank">CVE-2024-50561</a> has been assigned to this vulnerability. A CVSS v3 base score of 4.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-50561" target="_blank">CVE-2024-50561</a>. A base score of 5.1 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N</a>).</p> <h4 id="3216-improper-neutralization-of-special-elements-in-output-used-by-a-downstream-component-injection-cwe-74"><strong>3.2.16 </strong><a href="https://cwe.mitre.org/data/definitions/74.html" target="_blank"><strong>IMPROPER NEUTRALIZATION OF SPECIAL ELEMENTS IN OUTPUT USED BY A DOWNSTREAM COMPONENT ('INJECTION') CWE-74</strong></a></h4> <p>Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-50572" target="_blank">CVE-2024-50572</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.2 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-50572" target="_blank">CVE-2024-50572</a>. A base score of 8.6 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing, Communications</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Germany</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Siemens reported these vulnerabilities to CISA.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Siemens has identified the following specific workarounds and mitigations users can apply to reduce risk:</p> <ul> <li>All affected products: Update to V8.2 or <a href="https://support.industry.siemens.com/cs/ww/en/view/109976047/" target="_blank">later version</a></li> </ul> <p>As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends configuring the environment according to <a href="https://www.siemens.com/cert/operational-guidelines-industrial-security" target="_blank">Siemens' operational guidelines for industrial security</a> and following recommendations in the product manuals.</p> <p>Additional information on industrial security by Siemens can be found on the <a href="https://www.siemens.com/industrialsecurity" target="_blank">Siemens industrial security webpage</a></p> <p>For more information see the associated Siemens security advisory SSA-354112 in <a href="https://cert-portal.siemens.com/productcert/html/ssa-354112.html" target="_blank">HTML</a> and <a href="https://cert-portal.siemens.com/productcert/csaf/ssa-354112.json" target="_blank">CSAF</a>.</p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:</p> <ul> <li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the internet</a>.</li> <li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li> <li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices.</li> </ul> <p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p> <ul> <li>Do not click web links or open attachments in unsolicited email messages.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf" target="_blank">Recognizing and Avoiding Email Scams</a> for more information on avoiding email scams.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/ncas/tips/ST04-014" target="_blank">Avoiding Social Engineering and Phishing Attacks</a> for more information on social engineering attacks.</li> </ul> <p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 14, 2024: Initial Publication</li> </ul> Thu, 14 Nov 24 12:00:00 +0000 CISA /node/22563 Siemens Solid Edge https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-05 <p>As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory.&nbsp;For the most up-to-date information on vulnerabilities in this advisory, please see&nbsp;<a class="ext" href="https://new.siemens.com/global/en/products/services/cert.html#SecurityPublications" title="(opens in a new window)">Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).</a></p> <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v4 7.3</strong></li> <li><strong>ATTENTION</strong>: Low Attack Complexity</li> <li><strong>Vendor</strong>: Siemens</li> <li><strong>Equipment</strong>: Solid Edge</li> <li><strong>Vulnerabilities</strong>: Out-of-bounds Read, Uncontrolled Search Path Element</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of these vulnerabilities could allow an attacker to crash the application or execute arbitrary code.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>The following Siemens products are affected:</p> <ul> <li>Solid Edge SE2024: versions prior to V224.0 Update 9</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-out-of-bounds-read-cwe-125"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/125.html" target="_blank"><strong>OUT-OF-BOUNDS READ CWE-125</strong></a></h4> <p>The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PSM files. This could allow an attacker to execute code in the context of the current process.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-47940" target="_blank">CVE-2024-47940</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-47940" target="_blank">CVE-2024-47940</a>. A base score of 7.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>).</p> <h4 id="322-out-of-bounds-read-cwe-125"><strong>3.2.2 </strong><a href="https://cwe.mitre.org/data/definitions/125.html" target="_blank"><strong>OUT-OF-BOUNDS READ CWE-125</strong></a></h4> <p>The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-47941" target="_blank">CVE-2024-47941</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-47941" target="_blank">CVE-2024-47941</a>. A base score of 7.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>).</p> <h4 id="323-uncontrolled-search-path-element-cwe-427"><strong>3.2.3 </strong><a href="https://cwe.mitre.org/data/definitions/427.html" target="_blank"><strong>UNCONTROLLED SEARCH PATH ELEMENT CWE-427</strong></a></h4> <p>The affected applications suffer from a DLL hijacking vulnerability. This could allow an attacker to execute arbitrary code via placing a crafted DLL file on the system.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-47942" target="_blank">CVE-2024-47942</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.3 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-47942" target="_blank">CVE-2024-47942</a>. A base score of 7.0 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Germany</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Nafiez from Logix Advisor and Yu Zhou reported these vulnerabilities to Siemens.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Siemens has identified the following specific workarounds and mitigations users can apply to reduce risk:</p> <ul> <li>Update to V224.0 Update 9 or later version</li> <li>(CVE-2024-47940): Do not open untrusted PSM files in affected applications</li> <li>(CVE-2024-47941): Do not open untrusted PAR files in affected applications</li> </ul> <p>As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends configuring the environment according to <a href="https://www.siemens.com/cert/operational-guidelines-industrial-security" target="_blank">Siemens' operational guidelines for industrial security</a> and following recommendations in the product manuals.</p> <p>Additional information on industrial security by Siemens can be found on the <a href="https://www.siemens.com/industrialsecurity" target="_blank">Siemens industrial security webpage</a></p> <p>For more information see the associated Siemens security advisory SSA-351178 in <a href="https://cert-portal.siemens.com/productcert/html/ssa-351178.html" target="_blank">HTML</a> and <a href="https://cert-portal.siemens.com/productcert/csaf/ssa-351178.json" target="_blank">CSAF</a>.</p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:</p> <ul> <li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the internet</a>.</li> <li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li> <li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices.</li> </ul> <p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p> <ul> <li>Do not click web links or open attachments in unsolicited email messages.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf" target="_blank">Recognizing and Avoiding Email Scams</a> for more information on avoiding email scams.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/ncas/tips/ST04-014" target="_blank">Avoiding Social Engineering and Phishing Attacks</a> for more information on social engineering attacks.</li> </ul> <p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 14, 2024: Initial Publication</li> </ul> Thu, 14 Nov 24 12:00:00 +0000 CISA /node/22562 Siemens SINEC NMS https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-04 <p>As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory.&nbsp;For the most up-to-date information on vulnerabilities in this advisory, please see&nbsp;<a class="ext" href="https://new.siemens.com/global/en/products/services/cert.html#SecurityPublications" title="(opens in a new window)">Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).</a></p> <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v4 8.3</strong></li> <li><strong>ATTENTION</strong>: Exploitable remotely/low attack complexity</li> <li><strong>Vendor</strong>: Siemens</li> <li><strong>Equipment</strong>: SINEC NMS</li> <li><strong>Vulnerabilities</strong>: Improper Input Validation, Improper Check for Unusual or Exceptional Conditions, Out-of-bounds Write, Uncontrolled Resource Consumption, HTTP Request/Response Splitting, Missing Encryption of Sensitive Data, Out-of-bounds Read, Improper Certificate Validation, Missing Release of Resource after Effective Lifetime, Improper Validation of Certificate with Host Mismatch, Allocation of Resources Without Limits or Throttling, Incorrect Permission Assignment for Critical Resource</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of this could allow an authenticated medium-privileged attacker to write arbitrary content to any location in the filesystem of the host system.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>The following Siemens products are affected:</p> <ul> <li>Siemens SINEC NMS: versions prior to V3.0 SP1</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-improper-input-validation-cwe-20"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4> <p>Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications on the Windows 64 platform when running on newer X86_64 processors supporting the AVX512-IFMA instructions. Impact summary: If in an application that uses the OpenSSL library an attacker can influence whether the POLY1305 MAC algorithm is used, the application state might be corrupted with various application dependent consequences. The POLY1305 MAC (message authentication code) implementation in OpenSSL does not save the contents of non-volatile XMM registers on Windows 64 platform when calculating the MAC of data larger than 64 bytes. Before returning to the caller all the XMM registers are set to zero rather than restoring their previous content. The vulnerable code is used only on newer x86_64 processors supporting the AVX512-IFMA instructions. The consequences of this kind of internal application state corruption can be various - from no consequences, if the calling application does not depend on the contents of non-volatile XMM registers at all, to the worst consequences, where the attacker could get complete control of the application process. However given the contents of the registers are just zeroized so the attacker cannot put arbitrary values inside, the most likely consequence, if any, would be an incorrect result of some application dependent calculations or a crash leading to a denial of service. The POLY1305 MAC algorithm is most frequently used as part of the CHACHA20-POLY1305 AEAD (authenticated encryption with associated data) algorithm. The most common usage of this AEAD cipher is with TLS protocol versions 1.2 and 1.3 and a malicious client can influence whether this AEAD cipher is used by the server. This implies that server applications using OpenSSL can be potentially impacted. However, we are currently not aware of any concrete application that would be affected by this issue therefore we consider this a Low severity security issue. As a workaround the AVX512-IFMA instructions support can be disabled at runtime by setting the environment variable OPENSSL_ia32cap: OPENSSL_ia32cap=:~0x200000 The FIPS provider is not affected by this issue.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-4807" target="_blank">CVE-2023-4807</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p> <h4 id="322-improper-input-validation-cwe-20"><strong>3.2.2 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4> <p>Issue summary: A bug has been identified in the processing of key and initialization vector (IV) lengths. This can lead to potential truncation or overruns during the initialization of some symmetric ciphers. Impact summary: A truncation in the IV can result in non-uniqueness, which could result in loss of confidentiality for some cipher modes. When calling EVP_EncryptInit_ex2(), EVP_DecryptInit_ex2() or EVP_CipherInit_ex2() the provided OSSL_PARAM array is processed after the key and IV have been established. Any alterations to the key length, via the "keylen" parameter or the IV length, via the "ivlen" parameter, within the OSSL_PARAM array will not take effect as intended, potentially causing truncation or overreading of these values. The following ciphers and cipher modes are impacted: RC2, RC4, RC5, CCM, GCM and OCB. For the CCM, GCM and OCB cipher modes, truncation of the IV can result in loss of confidentiality. For example, when following NIST's SP 800-38D section 8.2.1 guidance for constructing a deterministic IV for AES in GCM mode, truncation of the counter portion could lead to IV reuse. Both truncations and overruns of the key and overruns of the IV will produce incorrect results and could, in some cases, trigger a memory exception. However, these issues are not currently assessed as security critical. Changing the key and/or IV lengths is not considered to be a common operation, and the vulnerable API was recently introduced. Furthermore, it is likely that application developers will have spotted this problem during testing since decryption would fail unless both peers in the communication were similarly vulnerable. For these reasons we expect the probability of an application being vulnerable to this to be quite low. However, if an application is vulnerable then this issue is considered very serious. For these reasons we have assessed this issue as Moderate severity overall. The OpenSSL SSL/TLS implementation is not affected by this issue. The OpenSSL 3.0 and 3.1 FIPS providers are not affected by this because the issue lies outside of the FIPS provider boundary. OpenSSL 3.1 and 3.0 are vulnerable to this issue.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-5363" target="_blank">CVE-2023-5363</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a>).</p> <h4 id="323-improper-check-for-unusual-or-exceptional-conditions-cwe-754"><strong>3.2.3 </strong><a href="https://cwe.mitre.org/data/definitions/754.html" target="_blank"><strong>IMPROPER CHECK FOR UNUSUAL OR EXCEPTIONAL CONDITIONS CWE-754</strong></a></h4> <p>Issue summary: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be very slow. Impact summary: Applications that use the functions DH_generate_key() to generate an X9.42 DH key may experience long delays. Likewise, applications that use DH_check_pub_key(), DH_check_pub_key_ex() or EVP_PKEY_public_check() to check an X9.42 DH key or X9.42 DH parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a Denial of Service. While DH_check() performs all the necessary checks (as of CVE-2023-3817), DH_check_pub_key() doesn't make any of these checks and is therefore vulnerable for excessively large P and Q parameters. Likewise, while DH_generate_key() performs a check for an excessively large P, it doesn't check for an excessively large Q. An application that calls DH_generate_key() or DH_check_pub_key() and supplies a key or parameters obtained from an untrusted source could be vulnerable to a Denial of Service attack. DH_generate_key() and DH_check_pub_key() are also called by a number of other OpenSSL functions. An application calling any of those other functions may similarly be affected. The other functions affected by this are DH_check_pub_key_ex(), EVP_PKEY_public_check(), and EVP_PKEY_generate(). Also vulnerable are the OpenSSL pkey command line application when using the "-pubcheck" option, as well as the OpenSSL genpkey command line application. The OpenSSL SSL/TLS implementation is not affected by this issue. The OpenSSL 3.0 and 3.1 FIPS providers are not affected by this issue.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-5678" target="_blank">CVE-2023-5678</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</a>).</p> <h4 id="324-out-of-bounds-write-cwe-787"><strong>3.2.4 </strong><a href="https://cwe.mitre.org/data/definitions/787.html" target="_blank"><strong>OUT-OF-BOUNDS WRITE CWE-787</strong></a></h4> <p>Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications running on PowerPC CPU based platforms if the CPU provides vector instructions. Impact summary: If an attacker can influence whether the POLY1305 MAC algorithm is used, the application state might be corrupted with various application dependent consequences. The POLY1305 MAC (message authentication code) implementation in OpenSSL for PowerPC CPUs restores the contents of vector registers in a different order than they are saved. Thus, the contents of some of these vector registers are corrupted when returning to the caller. The vulnerable code is used only on newer PowerPC processors supporting the PowerISA 2.07 instructions. The consequences of this kind of internal application state corruption can be various - from no consequences, if the calling application does not depend on the contents of non-volatile XMM registers at all, to the worst consequences, where the attacker could get complete control of the application process. However, unless the compiler uses the vector registers for storing pointers, the most likely consequence, if any, would be an incorrect result of some application dependent calculations or a crash leading to a denial of service. The POLY1305 MAC algorithm is most frequently used as part of the CHACHA20-POLY1305 AEAD (authenticated encryption with associated data) algorithm. The most common usage of this AEAD cipher is with TLS protocol versions 1.2 and 1.3. If this cipher is enabled on the server a malicious client can influence whether this AEAD cipher is used. This implies that TLS server applications using OpenSSL can be potentially impacted. As we are currently unaware of any concrete application that would be affected by this issue we consider this a Low severity security issue.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-6129" target="_blank">CVE-2023-6129</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H</a>).</p> <h4 id="325-uncontrolled-resource-consumption-cwe-400"><strong>3.2.5 </strong><a href="https://cwe.mitre.org/data/definitions/400.html" target="_blank"><strong>UNCONTROLLED RESOURCE CONSUMPTION CWE-400</strong></a></h4> <p>Issue summary: Checking excessively long invalid RSA public keys may take a long time. Impact summary: Applications that use the function EVP_PKEY_public_check() to check RSA public keys may experience long delays. Where the key that is being checked has been obtained from an untrusted source this may lead to a Denial of Service. When function EVP_PKEY_public_check() is called on RSA public keys, a computation is done to confirm that the RSA modulus, n, is composite. For valid RSA keys, n is a product of two or more large primes and this computation completes quickly. However, if n is an overly large prime, then this computation would take a long time. An application that calls EVP_PKEY_public_check() and supplies an RSA key obtained from an untrusted source could be vulnerable to a Denial of Service attack. The function EVP_PKEY_public_check() is not called from other OpenSSL functions however it is called from the OpenSSL pkey command line application. For that reason, that application is also vulnerable if used with the '-pubin' and '-check' options on untrusted data. The OpenSSL SSL/TLS implementation is not affected by this issue. The OpenSSL 3.0 and 3.1 FIPS providers are affected by this issue.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-6237" target="_blank">CVE-2023-6237</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.9 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p> <h4 id="326-improper-neutralization-of-crlf-sequences-in-http-headers-http-requestresponse-splitting-cwe-113"><strong>3.2.6 </strong><a href="https://cwe.mitre.org/data/definitions/113.html" target="_blank"><strong>IMPROPER NEUTRALIZATION OF CRLF SEQUENCES IN HTTP HEADERS ('HTTP REQUEST/RESPONSE SPLITTING') CWE-113</strong></a></h4> <p>Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-38709" target="_blank">CVE-2023-38709</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.1 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</a>).</p> <h4 id="327-improper-input-validation-cwe-20"><strong>3.2.7 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4> <p>This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with <code>domain=co.UK</code> when the URL used a lower-case hostname <code>curl.co.uk</code>, even though <code>co.uk</code> is listed as a PSL domain.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-46218" target="_blank">CVE-2023-46218</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</a>).</p> <h4 id="328-missing-encryption-of-sensitive-data-cwe-311"><strong>3.2.8 </strong><a href="https://cwe.mitre.org/data/definitions/311.html" target="_blank"><strong>MISSING ENCRYPTION OF SENSITIVE DATA CWE-311</strong></a></h4> <p>When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-46219" target="_blank">CVE-2023-46219</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</a>).</p> <h4 id="329-out-of-bounds-read-cwe-125"><strong>3.2.9 </strong><a href="https://cwe.mitre.org/data/definitions/125.html" target="_blank"><strong>OUT-OF-BOUNDS READ CWE-125</strong></a></h4> <p>The affected applications contain an out of bounds read vulnerability. This could allow an attacker to cause a Blue Screen of Death (BSOD) crash of the underlying Windows kernel.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-46280" target="_blank">CVE-2023-46280</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2023-46280" target="_blank">CVE-2023-46280</a>. A base score of 8.2 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H" target="_blank">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H</a>).</p> <h4 id="3210-improper-input-validation-cwe-20"><strong>3.2.10 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4> <p>Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). Because this function is related to writing data, it is not considered security significant. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-0727" target="_blank">CVE-2024-0727</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</a>).</p> <h4 id="3211-improper-input-validation-cwe-20"><strong>3.2.11 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4> <p>When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to curl.se with a plaintext protocol which has been explicitly disabled. curl --proto -all,-http <a href="http://curl.se/" target="_blank">http://curl.se</a> The flaw is only present if the set of selected protocols disables the entire set of available protocols, in itself a command with no practical use and therefore unlikely to be encountered in real situations. The curl security team has thus assessed this to be low severity bug.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-2004" target="_blank">CVE-2024-2004</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L</a>).</p> <h4 id="3212-improper-certificate-validation-cwe-295"><strong>3.2.12 </strong><a href="https://cwe.mitre.org/data/definitions/295.html" target="_blank"><strong>IMPROPER CERTIFICATE VALIDATION CWE-295</strong></a></h4> <p>libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-2379" target="_blank">CVE-2024-2379</a> has been assigned to this vulnerability. A CVSS v3 base score of 4.3 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N</a>).</p> <h4 id="3213-missing-release-of-resource-after-effective-lifetime-cwe-772"><strong>3.2.13 </strong><a href="https://cwe.mitre.org/data/definitions/772.html" target="_blank"><strong>MISSING RELEASE OF RESOURCE AFTER EFFECTIVE LIFETIME CWE-772</strong></a></h4> <p>When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory. Further, this error condition fails silently and is therefore not easily detected by an application.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-2398" target="_blank">CVE-2024-2398</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p> <h4 id="3214-improper-validation-of-certificate-with-host-mismatch-cwe-297"><strong>3.2.14 </strong><a href="https://cwe.mitre.org/data/definitions/297.html" target="_blank"><strong>IMPROPER VALIDATION OF CERTIFICATE WITH HOST MISMATCH CWE-297</strong></a></h4> <p>libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all uses of TLS protocols (HTTPS, FTPS, IMAPS, POPS3, SMTPS, etc).</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-2466" target="_blank">CVE-2024-2466</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N</a>).</p> <h4 id="3215-improper-neutralization-of-crlf-sequences-in-http-headers-http-requestresponse-splitting-cwe-113"><strong>3.2.15 </strong><a href="https://cwe.mitre.org/data/definitions/113.html" target="_blank"><strong>IMPROPER NEUTRALIZATION OF CRLF SEQUENCES IN HTTP HEADERS ('HTTP REQUEST/RESPONSE SPLITTING') CWE-113</strong></a></h4> <p>HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-24795" target="_blank">CVE-2024-24795</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.1 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</a>).</p> <h4 id="3216-allocation-of-resources-without-limits-or-throttling-cwe-770"><strong>3.2.16 </strong><a href="https://cwe.mitre.org/data/definitions/770.html" target="_blank"><strong>ALLOCATION OF RESOURCES WITHOUT LIMITS OR THROTTLING CWE-770</strong></a></h4> <p>HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-27316" target="_blank">CVE-2024-27316</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p> <h4 id="3217-incorrect-permission-assignment-for-critical-resource-cwe-732"><strong>3.2.17 </strong><a href="https://cwe.mitre.org/data/definitions/732.html" target="_blank"><strong>INCORRECT PERMISSION ASSIGNMENT FOR CRITICAL RESOURCE CWE-732</strong></a></h4> <p>The affected application contains a database function, that does not properly restrict the permissions of users to write to the filesystem of the host system. This could allow an authenticated medium-privileged attacker to write arbitrary content to any location in the filesystem of the host system.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-47808" target="_blank">CVE-2024-47808</a> has been assigned to this vulnerability. A CVSS v3 base score of 8.4 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-47808" target="_blank">CVE-2024-47808</a>. A base score of 8.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H" target="_blank">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Germany</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Siemens reported these vulnerabilities to CISA.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Siemens has identified the following specific workarounds and mitigations users can apply to reduce risk:</p> <ul> <li>SINEC NMS: Update to V3.0 SP1 or <a href="https://support.industry.siemens.com/cs/ww/en/view/109974917/" target="_blank">later version</a></li> </ul> <p>As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends configuring the environment according to <a href="https://www.siemens.com/cert/operational-guidelines-industrial-security" target="_blank">Siemens' operational guidelines for industrial security</a> and following recommendations in the product manuals.</p> <p>Additional information on industrial security by Siemens can be found on the <a href="https://www.siemens.com/industrialsecurity" target="_blank">Siemens industrial security webpage</a></p> <p>For more information see the associated Siemens security advisory SSA-331112 in <a href="https://cert-portal.siemens.com/productcert/html/ssa-331112.html" target="_blank">HTML</a> and <a href="https://cert-portal.siemens.com/productcert/csaf/ssa-331112.json" target="_blank">CSAF</a>.</p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:</p> <ul> <li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the internet</a>.</li> <li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li> <li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices.</li> </ul> <p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p> <ul> <li>Do not click web links or open attachments in unsolicited email messages.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf" target="_blank">Recognizing and Avoiding Email Scams</a> for more information on avoiding email scams.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/ncas/tips/ST04-014" target="_blank">Avoiding Social Engineering and Phishing Attacks</a> for more information on social engineering attacks.</li> </ul> <p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 14, 2024: Initial Publication</li> </ul> Thu, 14 Nov 24 12:00:00 +0000 CISA /node/22561 Siemens OZW672 and OZW772 Web Server https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-03 <p>As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory.&nbsp;For the most up-to-date information on vulnerabilities in this advisory, please see&nbsp;<a class="ext" href="https://new.siemens.com/global/en/products/services/cert.html#SecurityPublications" title="(opens in a new window)">Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).</a></p> <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v4 8.2</strong></li> <li><strong>ATTENTION</strong>: Exploitable remotely/low attack complexity</li> <li><strong>Vendor</strong>: Siemens</li> <li><strong>Equipment</strong>: OZW672 and OZW772 Web Server</li> <li><strong>Vulnerability</strong>: Cross-site Scripting</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of this vulnerability could allow an authenticated remote attacker to inject arbitrary JavaScript code that is later executed by another authenticated victim user with potential higher privileges than the attacker.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>The following Siemens products are affected:</p> <ul> <li>OZW672: versions prior to V5.2</li> <li>OZW772: versions prior to V5.2</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-cwe-79"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank"><strong>IMPROPER NEUTRALIZATION OF INPUT DURING WEB PAGE GENERATION ('CROSS-SITE SCRIPTING') CWE-79</strong></a></h4> <p>The user accounts tab of affected devices is vulnerable to stored cross-site scripting (XSS) attacks. This could allow an authenticated remote attacker to inject arbitrary JavaScript code that is later executed by another authenticated victim user with potential higher privileges than the attacker.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-36140" target="_blank">CVE-2024-36140</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N</a>).</p> <p>A CVSS v4 score has also been calculated for<a href="https://www.cve.org/CVERecord?id=CVE-2024-36140" target="_blank">CVE-2024-36140</a>. A base score of 8.2 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N" target="_blank">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical manufacturing</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Germany</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Paulo Mota reported this vulnerability to Siemens.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Siemens has identified the following specific workarounds and mitigations users can apply to reduce risk:</p> <ul> <li>All affected products: Update to V5.2 or later version</li> </ul> <p>As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends configuring the environment according to <a href="https://www.siemens.com/cert/operational-guidelines-industrial-security" target="_blank">Siemens' operational guidelines for industrial security</a> and following recommendations in the product manuals.</p> <p>Additional information on industrial security by Siemens can be found on the <a href="https://www.siemens.com/industrialsecurity" target="_blank">Siemens industrial security webpage</a></p> <p>For more information see the associated Siemens security advisory SSA-230445 in <a href="https://cert-portal.siemens.com/productcert/html/ssa-230445.html" target="_blank">HTML</a> and <a href="https://cert-portal.siemens.com/productcert/csaf/ssa-230445.json" target="_blank">CSAF</a>.</p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as:</p> <ul> <li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the internet</a>.</li> <li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li> <li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices.</li> </ul> <p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p> <ul> <li>Do not click web links or open attachments in unsolicited email messages.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf" target="_blank">Recognizing and Avoiding Email Scams</a> for more information on avoiding email scams.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/ncas/tips/ST04-014" target="_blank">Avoiding Social Engineering and Phishing Attacks</a> for more information on social engineering attacks.</li> </ul> <p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 14, 2024: Initial Publication</li> </ul> Thu, 14 Nov 24 12:00:00 +0000 CISA /node/22560 Siemens SIPORT https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-02 <p>As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory.&nbsp;For the most up-to-date information on vulnerabilities in this advisory, please see&nbsp;<a class="ext" href="https://new.siemens.com/global/en/products/services/cert.html#SecurityPublications" title="(opens in a new window)">Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).</a></p> <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v4 8.5</strong></li> <li><strong>ATTENTION</strong>: Low Attack Complexity</li> <li><strong>Vendor</strong>: Siemens</li> <li><strong>Equipment</strong>: SIPORT</li> <li><strong>Vulnerability</strong>: Incorrect Permission Assignment for Critical Resource</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of this vulnerability could allow a local attacker with an unprivileged account to override or modify the service executable and subsequently gain elevated privileges.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>The following Siemens products are affected:</p> <ul> <li>Siemens SIPORT: Versions prior to V3.4.0</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-incorrect-permission-assignment-for-critical-resource-cwe-732"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/732.html" target="_blank"><strong>INCORRECT PERMISSION ASSIGNMENT FOR CRITICAL RESOURCE CWE-732</strong></a></h4> <p>The affected application improperly assigns file permissions to installation folders. This could allow a local attacker with an unprivileged account to override or modify the service executables and subsequently gain elevated privileges.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-47783" target="_blank">CVE-2024-47783</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-47783" target="_blank">CVE-2024-47783</a>. A base score of 8.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Commercial Facilities</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Germany</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Siemens reported this vulnerability to CISA.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Siemens has identified the following specific workarounds and mitigations users can apply to reduce risk:</p> <ul> <li>Remove write permissions for non-administrative users on files and folders located under the installation path</li> <li>Update to V3.4.0 or <a href="https://support.industry.siemens.com/cs/ww/en/view/109826608/" target="_blank">later version</a></li> </ul> <p>As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends configuring the environment according to <a href="https://www.siemens.com/cert/operational-guidelines-industrial-security" target="_blank">Siemens' operational guidelines for industrial security</a> and following recommendations in the product manuals.</p> <p>Additional information on industrial security by Siemens can be found on the <a href="https://www.siemens.com/industrialsecurity" target="_blank">Siemens industrial security webpage</a></p> <p>For more information see the associated Siemens security advisory SSA-064257 in <a href="https://cert-portal.siemens.com/productcert/html/ssa-064257.html" target="_blank">HTML</a> and <a href="https://cert-portal.siemens.com/productcert/csaf/ssa-064257.json" target="_blank">CSAF</a>.</p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as:</p> <ul> <li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the internet</a>.</li> <li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li> <li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices.</li> </ul> <p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 14, 2024: Initial Publication</li> </ul> Thu, 14 Nov 24 12:00:00 +0000 CISA /node/22559 Siemens RUGGEDCOM CROSSBOW https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-01 <p>As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory.&nbsp;For the most up-to-date information on vulnerabilities in this advisory, please see&nbsp;<a class="ext" href="https://new.siemens.com/global/en/products/services/cert.html#SecurityPublications" title="(opens in a new window)">Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).</a></p> <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v3 5.5</strong></li> <li><strong>ATTENTION</strong>: Exploitable from adjacent network/low attack complexity</li> <li><strong>Vendor</strong>: Siemens</li> <li><strong>Equipment</strong>: RUGGEDCOM CROSSBOW</li> <li><strong>Vulnerabilities</strong>: Heap-based Buffer Overflow, Use After Free</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code or to cause a denial-of-service condition.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>The following Siemens products are affected:</p> <ul> <li>RUGGEDCOM CROSSBOW Station Access Controller (SAC): Versions prior to 5.6</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-heap-based-buffer-overflow-cwe-122"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/122.html" target="_blank"><strong>HEAP-BASED BUFFER OVERFLOW CWE-122</strong></a></h4> <p>A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248999.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2023-7104" target="_blank">CVE-2023-7104</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank">CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L</a>).</p> <h4 id="322-use-after-free-cwe-416"><strong>3.2.2 </strong><a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank"><strong>USE AFTER FREE CWE-416</strong></a></h4> <p>A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-0232" target="_blank">CVE-2024-0232</a> has been assigned to this vulnerability. A CVSS v3 base score of 4.7 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing, Energy</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Germany</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Siemens reported these vulnerabilities to CISA.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Siemens has released a new version for RUGGEDCOM CROSSBOW Station Access Controller (SAC) and recommends updating to the latest version:</p> <ul> <li>RUGGEDCOM CROSSBOW Station Access Controller (SAC): Update to <a href="https://support.industry.siemens.com/cs/ww/en/view/109976555/" target="_blank">V5.6 or later version</a></li> </ul> <p>Siemens has identified the following specific workarounds and mitigations users can apply to reduce risk:</p> <p>As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends configuring the environment according to <a href="https://www.siemens.com/cert/operational-guidelines-industrial-security" target="_blank">Siemens' operational guidelines for industrial security</a> and following recommendations in the product manuals.</p> <p>Additional information on industrial security by Siemens can be found on the <a href="https://www.siemens.com/industrialsecurity" target="_blank">Siemens industrial security webpage</a></p> <p>For more information see the associated Siemens security advisory SSA-000297 in <a href="https://cert-portal.siemens.com/productcert/html/ssa-000297.html" target="_blank">HTML</a> and <a href="https://cert-portal.siemens.com/productcert/csaf/ssa-000297.json" target="_blank">CSAF</a>.</p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:</p> <ul> <li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the internet</a>.</li> <li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li> <li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices.</li> </ul> <p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p> <ul> <li>Do not click web links or open attachments in unsolicited email messages.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf" target="_blank">Recognizing and Avoiding Email Scams</a> for more information on avoiding email scams.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/ncas/tips/ST04-014" target="_blank">Avoiding Social Engineering and Phishing Attacks</a> for more information on social engineering attacks.</li> </ul> <p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 14, 2024: Initial Publication</li> </ul> Thu, 14 Nov 24 12:00:00 +0000 CISA /node/22558 Subnet Solutions PowerSYSTEM Center https://www.cisa.gov/news-events/ics-advisories/icsa-24-317-01 <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v3 9.8</strong></li> <li><strong>ATTENTION</strong>: Exploitable remotely/low attack complexity</li> <li><strong>Vendor</strong>: Subnet Solutions</li> <li><strong>Equipment</strong>: PowerSYSTEM Center</li> <li><strong>Vulnerabilities</strong>: Improper Restriction of XML External Entity Reference, Integer Overflow or Wraparound</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of these vulnerabilities could allow an attacker to cause an integer overflow on the affected device.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>The following versions of SUBNET PowerSYSTEM Center, an OT device management platform, are affected:</p> <ul> <li>PowerSYSTEM Center PSC 2020: v5.22.x and prior</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-improper-restriction-of-xml-external-entity-reference-cwe-611"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/611.html" target="_blank"><strong>Improper Restriction of XML External Entity Reference CWE-611</strong></a></h4> <p>An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-45490" target="_blank">CVE-2024-45490</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 9.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p> <h4 id="322-integer-overflow-or-wraparound-cwe-190"><strong>3.2.2 </strong><a href="https://cwe.mitre.org/data/definitions/190.html" target="_blank"><strong>Integer Overflow or Wraparound CWE-190</strong></a></h4> <p>An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-45491" target="_blank">CVE-2024-45491</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 9.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p> <h4 id="323-integer-overflow-or-wraparound-cwe-190"><strong>3.2.3 </strong><a href="https://cwe.mitre.org/data/definitions/190.html" target="_blank"><strong>Integer Overflow or Wraparound CWE-190</strong></a></h4> <p>An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-45492" target="_blank">CVE-2024-45492</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 9.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing, Energy</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Canada</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Subnet Solutions Inc. reported these vulnerabilities to CISA</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Subnet Solutions inc. reports that dependencies have been updated and vulnerabilities are to be addressed in PowerSYSTEM Center 2020 Update 23 release.</p> <p>Subnet Solutions Inc. strongly recommends users update to the latest version. If this is not possible, the following mitigations have been identified:</p> <ul> <li>Apply application allow-listing to prevent unauthorized executables from running.</li> <li>Ensure Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR) are enabled within the operating system. Memory protection controls can be enabled via Windows Security. Please refer to <a href="https://support.microsoft.com/en-us/topic/what-is-data-execution-prevention-dep-60dabc2b-90db-45fc-9b18-512419135817" target="_blank">this article</a> for reference.</li> </ul> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:</p> <ul> <li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the internet</a>.</li> <li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li> <li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</li> </ul> <p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 12, 2024: Initial Publication</li> </ul> Tue, 12 Nov 24 12:00:00 +0000 CISA /node/22535 Hitachi Energy TRO600 https://www.cisa.gov/news-events/ics-advisories/icsa-24-317-02 <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v3 7.2</strong></li> <li><strong>ATTENTION</strong>: Exploitable remotely/low attack complexity</li> <li><strong>Vendor</strong>: Hitachi Energy</li> <li><strong>Equipment</strong>: TRO600 Series</li> <li><strong>Vulnerabilities</strong>: Command Injection, Improper Removal of Sensitive Information Before Storage or Transfer</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary system commands.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>The following products of Hitachi Energy are affected:</p> <ul> <li>Hitachi Energy TRO600 series firmware versions: 9.0.1.0 - 9.2.0.0 (CVE-2024-41156)</li> <li>Hitachi Energy TRO600 series firmware versions: 9.1.0.0 - 9.2.0.0 (CVE-2024-41153)</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-improper-neutralization-of-special-elements-used-in-a-command-command-injection-cwe-77"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/77.html" target="_blank"><strong>IMPROPER NEUTRALIZATION OF SPECIAL ELEMENTS USED IN A COMMAND ('COMMAND INJECTION') CWE-77</strong></a></h4> <p>Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of arbitrary system commands. If exploited, an attacker with write access to the web UI can execute commands on the device with root privileges, far more extensive than what the write privilege intends.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-41153" target="_blank">CVE-2024-41153</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.2 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a>).</p> <h4 id="322-improper-removal-of-sensitive-information-before-storage-or-transfer-cwe-212"><strong>3.2.2 </strong><a href="https://cwe.mitre.org/data/definitions/212.html" target="_blank"><strong>IMPROPER REMOVAL OF SENSITIVE INFORMATION BEFORE STORAGE OR TRANSFER CWE-212</strong></a></h4> <p>Profile files from TRO600 series radios are extracted in plain-text and encrypted file formats. Profile files provide potential attackers valuable configuration information about the Tropos network. Profiles can only be exported by authenticated users with write access.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-41156" target="_blank">CVE-2024-41156</a> has been assigned to this vulnerability. A CVSS v3 base score of 2.7 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Energy</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Switzerland</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Riley Barello-Myers, Idaho National Lab - CyTRICS reported these vulnerabilities to Hitachi Energy.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Hitachi Energy has identified the following specific workarounds and mitigations users can apply to reduce risk:</p> <ul> <li>(CVE-2024-41153) Hitachi Energy TRO600 series firmware versions from 9.1.0.0 to 9.2.0.0 (Edge computing functionality): Update to version 9.2.0.5</li> <li>(CVE-2024-41156) Hitachi Energy TRO600 series firmware versions from 9.0.1.0 to 9.2.0.0 (Configuration utility): Update to version 9.2.0.5</li> </ul> <p>Hitachi Energy has provided the additional following security practices and firewall configurations can help protect a process control network from attacks that originate from outside the network:</p> <ul> <li>Physically protect process control systems from direct access by unauthorized personnel.</li> <li>Do not connect directly to the Internet.</li> <li>Separate from other networks by means of a firewall system that has a minimal number of ports exposed.</li> <li>Process control systems should not be used for Internet surfing, instant messaging, or receiving e-mails.</li> <li>Portable computers and removable storage media should be carefully scanned for viruses before they are connected to a control system.</li> </ul> <p>For more details, refer to the "Configuration Guide" document for the respective TRO600 series router version.</p> <p>For more information, see Hitachi Energy's security advisory <a href="https://publisher.hitachienergy.com/preview?DocumentID=8DBD000147&amp;LanguageCode=en" target="_blank">8DBD000147</a></p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:</p> <ul> <li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the internet</a>.</li> <li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li> <li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices.</li> </ul> <p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 12, 2024: Initial Publication</li> </ul> Tue, 12 Nov 24 12:00:00 +0000 CISA /node/22536 Rockwell Automation FactoryTalk View ME https://www.cisa.gov/news-events/ics-advisories/icsa-24-317-03 <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v4 7.0</strong></li> <li><strong>ATTENTION</strong>: Low attack complexity</li> <li><strong>Vendor</strong>: Rockwell Automation</li> <li><strong>Equipment</strong>: FactoryTalk View ME</li> <li><strong>Vulnerability</strong>: Improper Input Validation</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of this vulnerability could allow a local low-privileged user to escalate their privileges by changing the macro to execute arbitrary code.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>Rockwell Automation reports that the following versions of FactoryTalk Software are affected:</p> <ul> <li>FactoryTalk View ME, when using default folder privileges: v14.0 and prior</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-improper-input-validation-cwe-20"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>Improper Input Validation CWE-20</strong></a></h4> <p>A remote code execution vulnerability exists in FactoryTalk View ME. The vulnerability allows users to save projects within the public directory allowing anyone with local access to modify and/or delete files. Additionally, a malicious user could potentially leverage this vulnerability to escalate their privileges by changing the macro to execute arbitrary code.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-37365" target="_blank">CVE-2024-37365</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 7.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for<a href="https://www.cve.org/CVERecord?id=CVE-2024-37365" target="_blank">CVE-2024-37365</a>. A base score of 7.0 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> United States</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Rockwell Automation reported this vulnerability to CISA.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Rockwell Automation has corrected this problem in V15.0.</p> <p>Rockwell Automation encourages users of the affected software who are not able to upgrade to one of the corrected versions to apply the following risk mitigations where possible.</p> <ul> <li>To enhance security and help prevent unauthorized modifications to HMI project files, harden the Windows OS by removing the INTERACTIVE group from the folder's security properties.</li> <li>Add specific users or user groups and assign their permissions to this folder using the least privileges principle. Users with read-only permission can still test run and run the FactoryTalk View ME Station.</li> <li>Guidance can be found in FactoryTalk View ME v14 Help topic: "HMI projects folder settings". It can be opened through the FactoryTalk View ME Studio menu "help\Contents\FactoryTalk View ME Help\Create a Machine Edition application-&gt;Open applications-&gt;HMI project folder settings".</li> <li><a href="https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight" target="_blank">Security Best Practices</a></li> </ul> <p>For more information, see <a href="https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html" target="_blank">Rockwell Automation's security advisory</a></p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as:</p> <ul> <li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the internet</a>.</li> <li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li> <li>When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</li> </ul> <p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 12, 2024: Initial Publication</li> </ul> Tue, 12 Nov 24 12:00:00 +0000 CISA /node/22537 Delta Electronics DIAScreen https://www.cisa.gov/news-events/ics-advisories/icsa-24-312-02 <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v4 8.4</strong></li> <li><strong>ATTENTION</strong>: Low attack complexity</li> <li><strong>Vendor</strong>: Delta Electronics</li> <li><strong>Equipment</strong>: DIAScreen</li> <li><strong>Vulnerabilities</strong>: Stack-based Buffer Overflow</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation of this these vulnerabilities could crash the device being accessed; a buffer overflow condition may allow remote code execution.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>The following versions of DIAScreen, which is a component of Delta's DIAStudio Smart Machine Suite integrated engineering software package, are affected:</p> <ul> <li>DIAScreen: versions prior to v1.5.0</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-stack-based-buffer-overflow-cwe-121"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/121.html" target="_blank"><strong>Stack-based Buffer Overflow CWE-121</strong></a></h4> <p>If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a stack-based buffer overflow in BACnetObjectInfo can be exploited, allowing the attacker to remotely execute arbitrary code.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-47131" target="_blank">CVE-2024-47131</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-47131" target="_blank">CVE-2024-47131</a>. A base score of 8.4 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>).</p> <h4 id="322-stack-based-buffer-overflow-cwe-121"><strong>3.2.2 </strong><a href="https://cwe.mitre.org/data/definitions/121.html" target="_blank"><strong>Stack-based Buffer Overflow CWE-121</strong></a></h4> <p>If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a stack-based buffer overflow in BACnetParameter can be exploited, allowing the attacker to remotely execute arbitrary code.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-39605" target="_blank">CVE-2024-39605</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-39605" target="_blank">CVE-2024-39605</a>. A base score of 8.4 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>).</p> <h4 id="323-stack-based-buffer-overflow-cwe-121"><strong>3.2.3 </strong><a href="https://cwe.mitre.org/data/definitions/121.html" target="_blank"><strong>Stack-based Buffer Overflow CWE-121</strong></a></h4> <p>If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a stack-based buffer overflow in CEtherIPTagItem can be exploited, allowing the attacker to remotely execute arbitrary code.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-39354" target="_blank">CVE-2024-39354</a> has been assigned to this vulnerability. A CVSS v3.1 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-39354" target="_blank">CVE-2024-39354</a>. A base score of 8.4 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>).</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Energy</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Taiwan</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>Natnael Samson working with Trend Micro Zero Day Initiative reported these vulnerabilities to CISA.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Delta Electronics has released <a href="https://diastudio.deltaww.com/home/downloads?sec=download" target="_blank">v1.5.0 of DIAScreen (login required)</a> and recommends users install this update on all affected systems.</p> <p>For more information, please see the <a href="https://www.deltaww.com/en-US/Cybersecurity_Advisory" target="_blank">Delta product cybersecurity advisory for these issues.</a></p> <p>CISA recommends users take the following measures to protect themselves from social engineering attacks:</p> <ul> <li>Do not click web links or open attachments in unsolicited email messages.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf" target="_blank">Recognizing and Avoiding Email Scams</a> for more information on avoiding email scams.</li> <li>Refer to <a href="https://www.cisa.gov/uscert/ncas/tips/ST04-014" target="_blank">Avoiding Social Engineering and Phishing Attacks</a> for more information on social engineering attacks.</li> </ul> <p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov/ics</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 7, 2024: Initial Publication</li> </ul> Thu, 07 Nov 24 12:00:00 +0000 CISA /node/22526 Beckhoff Automation TwinCAT Package Manager https://www.cisa.gov/news-events/ics-advisories/icsa-24-312-01 <p><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p> <h2 id="1-executive-summary">1. EXECUTIVE SUMMARY</h2> <ul> <li><strong>CVSS v4 7.0</strong></li> <li><strong>ATTENTION</strong>: Low Attack Complexity</li> <li><strong>Vendor</strong>: Beckhoff Automation</li> <li><strong>Equipment</strong>: TwinCAT Package Manager</li> <li><strong>Vulnerability</strong>: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</li> </ul> <h2 id="2-risk-evaluation">2. RISK EVALUATION</h2> <p>Successful exploitation this vulnerability could allow a local attacker with administrative access rights to execute arbitrary OS commands on the affected system.</p> <h2 id="3-technical-details">3. TECHNICAL DETAILS</h2> <h3 id="31-affected-products">3.1 AFFECTED PRODUCTS</h3> <p>The following Beckhoff Automation products are affected:</p> <ul> <li>TwinCAT Package Manager: Versions prior to 1.0.603.0</li> </ul> <h3 id="32-vulnerability-overview">3.2 Vulnerability Overview</h3> <h4 id="321-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-cwe-78"><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank"><strong>IMPROPER NEUTRALIZATION OF SPECIAL ELEMENTS USED IN AN OS COMMAND ('OS COMMAND INJECTION') CWE-78</strong></a></h4> <p>A local user with administrative access rights can enter specially crafted values for settings at the user interface (UI) of the TwinCAT Package Manager which then causes arbitrary OS commands to be executed.</p> <p><a href="https://www.cve.org/CVERecord?id=CVE-2024-8934" target="_blank">CVE-2024-8934</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H</a>).</p> <p>A CVSS v4 score has also been calculated for <a href="https://www.cve.org/CVERecord?id=CVE-2024-8934" target="_blank">CVE-2024-8934</a>. A base score of 7.0 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>)</p> <h3 id="33-background">3.3 BACKGROUND</h3> <ul> <li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing</li> <li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li> <li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Germany</li> </ul> <h3 id="34-researcher">3.4 RESEARCHER</h3> <p>elcazator of ELEX FEIGONG RESEARCH INSTITUTE of Elex CyberSecurity, Inc. reported this vulnerability to CISA.</p> <h2 id="4-mitigations">4. MITIGATIONS</h2> <p>Beckhoff Automation recommends users update to at least <a href="https://www.beckhoff.com/en-us/support/download-finder/" target="_blank">version 1.0.613.0</a>.</p> <p>Additionally, Beckhoff Automation has identified the following specific workarounds and mitigations users can apply to reduce risk:</p> <ul> <li>Administrative users should always act thoroughly and inspect the values which they enter.</li> <li>Please update to a recent version of the affected product.</li> </ul> <p>For more information CERT@VDE has released <a href="https://cert.vde.com/en/advisories/VDE-2024-064" target="_blank">security advisory VDE-2024-064</a></p> <p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as:</p> <ul> <li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the internet</a>.</li> <li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li> <li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices.</li> </ul> <p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p> <p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p> <p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p> <p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p> <p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p> <p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p> <h2 id="5-update-history">5. UPDATE HISTORY</h2> <ul> <li>November 7, 2024: Initial Publication</li> </ul> Thu, 07 Nov 24 12:00:00 +0000 CISA /node/22525