Full Report
McAfee has issued Security Bulletin SB10250 to address a vulnerabilty in McAfee Application and Change Control (MACC). SINAMICS PERFECT HARMONY GH180 Drives with HMIs produced between November 4th, 2015 and October 9th, 2018, use MACC as part of their software package, if option A30 was part of the order. Siemens has analyzed the vulnerability and has determined that this vulnerability applies to these HMIs. HMIs with this vulnerability can be compromised via local attack using removable USB storage devices to transfer malicious files. These file can be executed to compromise the HMI and by extension the drive system. For compatibility reasons, Siemens advises the installation of MACC 8.2.0 instead of version 8.0.0, hotfix 5 as mentioned in SB10250.
Analysis Summary
# Vulnerability: Improper Access Control in McAfee Application and Change Control (MACC) Affecting Siemens GH180 HMIs
## CVE Details
- **CVE ID:** CVE-2018-6682 (Associated with McAfee SB10250)
- **CVSS Score:** 7.2 (High) *Note: Based on standard CVSS for this McAfee flaw; Siemens context confirms high impact.*
- **CWE:** CWE-284 (Improper Access Control) / CWE-269 (Improper Privilege Management)
## Affected Systems
- **Products:** SINAMICS PERFECT HARMONY GH180 Drives (Human Machine Interfaces - HMIs)
- **Versions:** Units produced between November 4th, 2015, and October 9th, 2018.
- **Configurations:** Systems where **Option A30** was included in the order (this option includes the MACC software package).
## Vulnerability Description
A vulnerability exists in the McAfee Application and Change Control (MACC) software utilized by the GH180 HMI. The flaw allows for the bypass of security restrictions intended to prevent unauthorized file execution. In the context of the Siemens HMI, the software fails to adequately restrict file transfers and execution from external sources, allowing an attacker to bypass the "Allow-Listing" protection mechanism.
## Exploitation
- **Status:** Vulnerability confirmed by vendor; exploitation in the wild not explicitly reported in the provided text, but potential for high-impact local exploitation exists.
- **Complexity:** Low (Requires physical/local access)
- **Attack Vector:** Local (specifically via removable USB storage devices).
## Impact
- **Confidentiality:** High (Potential access to drive configuration and system data)
- **Integrity:** High (Malicious files can be executed to modify HMI and drive system behavior)
- **Availability:** High (Compromise of the HMI can lead to loss of control or shutdown of the drive system)
## Remediation
### Patches
- **Siemens Recommended Version:** Upgrade to **MACC 8.2.0**.
- *Note:* While McAfee SB10250 mentions MACC 8.0.0 Hotfix 5, Siemens specifically advises version 8.2.0 for GH180 systems to ensure hardware/software compatibility.
### Workarounds
- **Physical Security:** Restrict physical access to the HMI and the drive system cabinets.
- **USB Port Control:** Disable or physically block unused USB ports on the HMI to prevent the introduction of malicious storage devices.
- **Strict Media Policy:** Enforce rigorous scanning of any authorized removable media before use.
## Detection
- **Indicators of Compromise:** Presence of unauthorized executable files in system directories; unexpected system reboots or configuration changes; unauthorized processes running in the MACC dashboard.
- **Detection Methods:** Audit MACC logs for "Execution Denied" or "Bypass" events; perform integrity checks on the HMI file system.
## References
- **McAfee Security Bulletin:** SB10250
- **Siemens Security Advisory:** hxxps[://]www[.]siemens[.]com/cert/advisories
- **Product Information:** hxxps[://]support[.]industry[.]siemens[.]com/cs/products?pnid=13214