IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Security notifications archives

CRITICAL
CVSS 9.8
Date 2026-07-28T15:23:39+00:00
Source schneider-electric
Published by Schneider Electric

// Description

€260.40-1.96% * [test](https://www.se.com/ww/en/work/support/cybersecurity/security-notifications-archive#) Welcome to our corporate site. Looking for products? Select your location. [ENGLISH](https://www.se.com/ww/en/) | [FRENCH](https://www.se.com/ww/fr/) ![Image 1](https://cdn.builder.io/api/v1/pixel?apiKey=87a13b564d504489a60e78515594f31e) [](https://www.se.com/ww/en/work) / [](https://www.se.com/ww/en/work) Choose a video ![Image 2](https://www.se.com/ww/en/assets/v2/564/media/

// Vulnerabilities (246)

CVE ID CVSS Score Severity Description
CVE-2018-7812 0.0 unknown
No description available.
CVE-2019-1181 0.0 unknown
No description available.
CVE-2018-7821 0.0 unknown
No description available.
CVE-2019-6843 0.0 unknown
No description available.
CVE-2019-6811 0.0 unknown
No description available.
CVE-2018-7809 0.0 unknown
No description available.
CVE-2018-7822 0.0 unknown
No description available.
CVE-2017-9627 0.0 unknown
No description available.
CVE-2019-8258 0.0 unknown
CVE-2019-8258. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
CVE-2018-7773 0.0 unknown
No description available.
CVE-2018-7843 0.0 unknown
CVE-2018-7843. An uncaught exception vulnerability exists which could cause denial of service when reading memory blocks with an invalid data size or with an invalid data offset in the controller over Modbus.
CVE-2018-7245 0.0 unknown
No description available.
CVE-2019-12260 0.0 unknown
This vulnerability could lead to a buffer overflow of up to a full TCP receive window (by default, 10k-64k depending on version). The buffer overflow happens in the task calling recv()/recvfrom()/recvmsg(). Applications that pass a buffer equal to or larger than a full TCP window are not susceptible to this attack. Applications passing a stack-allocated variable as a buffer are the easiest to exploit. The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution.. CVE-2019-12260 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution.
CVE-2017-9957 0.0 unknown
No description available.
CVE-2019-12261 0.0 unknown
The impact of this vulnerability is a buffer overflow of up to a full TCP receive window (by default, 10k-64k depending on version). The buffer overflow happens in the task calling recv()/recvfrom()/recvmsg(). Applications that pass a buffer equal to or larger than a full TCP window are not susceptible to this attack. Applications passing a stack-allocated variable as a buffer are the easiest to exploit. The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution.. CVE-2019-12261 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution.
CVE-2014-7169 0.0 unknown
No description available.
CVE-2016-2177 0.0 unknown
CVE-2016-2177. OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveraging unexpected malloc behavior, related to s3_srvr.c, ssl_sess.c, and t1_lib.c.
CVE-2018-7856 0.0 unknown
CVE-2018-7856. An uncaught exception vulnerability exists which could cause a possible denial of service when writing invalid memory blocks to the controller over Modbus.
CVE-2018-7838 0.0 unknown
No description available.
CVE-2017-9967 0.0 unknown
No description available.
CVE-2019-11091 0.0 unknown
No description available.
CVE-2019-8272 0.0 unknown
CVE-2019-8272. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
CVE-2019-6825 0.0 unknown
No description available.
CVE-2019-1182 0.0 unknown
No description available.
CVE-2019-6816 0.0 unknown
No description available.
CVE-2015-8277 0.0 unknown
No description available.
CVE-2019-8268 0.0 unknown
CVE-2019-8268. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
CVE-2019-12257 0.0 unknown
DHCP packets may go past the local area network (LAN) via DHCP-relays, but are otherwise confined to the LAN. The DHCP-client may be used by VxWorks and in the bootrom. Bootrom, using DHCP/BOOTP, is only vulnerable during the boot-process. This vulnerability may be used to overwrite the heap, which could result in a later crash when a task requests memory from the heap. This vulnerability can result in remote code execution.CVE-2019-12257 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2014-8514 0.0 unknown
Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8513 and CVE-2014-9188. NOTE: this may be clarified later based on details provided by researchers.
CVE-2019-6857 0.0 unknown
This vulnerability could cause a denial-of-service condition in the controller when reading specific memory blocks using Modbus TCP.CVE-2019-6857 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-7846 0.0 unknown
CVE-2018-7846. A trust boundary violation vulnerability on connection to the controller exists which could cause unauthorized access by conducting a brute force attack on Modbus protocol to the controller.
CVE-2017-7494 0.0 unknown
No description available.
CVE-2017-7974 0.0 unknown
No description available.
CVE-2015-2291 0.0 unknown
No description available.
CVE-2019-20032 0.0 unknown
No description available.
CVE-2017-9969 0.0 unknown
No description available.
CVE-2018-7243 0.0 unknown
No description available.
CVE-2018-7789 0.0 unknown
No description available.
CVE-2018-7792 0.0 unknown
No description available.
CVE-2018-7759 0.0 unknown
No description available.
CVE-2018-7800 0.0 unknown
No description available.
CVE-2018-7849 0.0 unknown
CVE-2018-7849. An uncaught exception vulnerability exists which could cause a possible denial of service due to improper data integrity check when sending files to the controller over Modbus.
CVE-2018-7802 0.0 unknown
No description available.
CVE-2017-6017 0.0 unknown
No description available.
CVE-2019-6838 0.0 unknown
No description available.
CVE-2018-7494 0.0 unknown
No description available.
CVE-2019-12259 0.0 unknown
An attacker residing on the LAN may choose to hijack a DHCP-client session that requests an IPv4 address. The attacker can send a multicast IP address in the DHCP offer/ack message, which the victim system then incorrectly assigns. This vulnerability can be combined with CVE-2019-12259 to create a denial-of-service condition.. CVE-2019-12264 has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).This vulnerability can be combined with CVE-2019-12259 to create a denial-of-service condition.
CVE-2019-6830 0.0 unknown
CVE-2019-6830. An uncaught exception vulnerability exists, which could cause a possible denial of service when sending an appropriately timed HTTP request to the controller.
CVE-2017-9629 0.0 unknown
No description available.
CVE-2019-8261 0.0 unknown
CVE-2019-8261. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
CVE-2017-0143 8.1 high
Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 does not validate or incorrectly validates input via the SMBv1 port that can affect the control flow or data flow of a system. The SMBv1 input validation vulnerabilities could allow a remote attacker to gain unauthorized access to sensitive information, create denial of service conditions, or execute arbitrary code.For details, refer to Microsoft Security Bulletin MS17-010 and NCCIC WannaCry fact sheet.CVE-2017-0143 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2012-4681 0.0 unknown
No description available.
CVE-2017-7973 0.0 unknown
No description available.
CVE-2014-3566 0.0 unknown
No description available.
CVE-2018-7765 0.0 unknown
No description available.
CVE-2018-7770 0.0 unknown
No description available.
CVE-2019-8273 0.0 unknown
CVE-2019-8273. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
CVE-2019-6808 0.0 unknown
CVE-2019-6808. An improper access control vulnerability exists, which could cause a remote code execution by overwriting configuration settings of the controller over Modbus.
CVE-2017-0147 0.0 unknown
No description available.
CVE-2018-7797 0.0 unknown
No description available.
CVE-2018-7761 0.0 unknown
No description available.
CVE-2017-9959 0.0 unknown
No description available.
CVE-2019-8275 0.0 unknown
CVE-2019-8275. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
CVE-2019-8267 0.0 unknown
CVE-2019-8267. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
CVE-2018-7794 0.0 unknown
This vulnerability could cause a denial-of-service condition when reading data with invalid index using Modbus TCP. CVE-2018-7794 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is(AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).. --------- End Update A Part 1 of 1 ---------CVE-2018-7794 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is(AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2019-20034 0.0 unknown
No description available.
CVE-2019-6856 0.0 unknown
This vulnerability could cause a denial-of-service condition when writing specific physical memory blocks using Modbus TCP.CVE-2019-6856 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-7791 0.0 unknown
No description available.
CVE-2019-12262 0.0 unknown
An attacker residing on the LAN can send reverse-ARP responses to the victim system to assign unicast IPv4 addresses to the target.CVE-2019-12262 has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).
CVE-2018-7832 0.0 unknown
No description available.
CVE-2018-7240 0.0 unknown
No description available.
CVE-2019-6820 0.0 unknown
No description available.
CVE-2017-9631 0.0 unknown
No description available.
CVE-2019-1224 0.0 unknown
No description available.
CVE-2018-7811 0.0 unknown
No description available.
CVE-2019-6807 0.0 unknown
CVE-2019-6807. An uncaught exception vulnerability exists which could cause a possible denial of service when writing sensitive application variables to the controller over Modbus.
CVE-2018-7763 0.0 unknown
No description available.
CVE-2018-7834 0.0 unknown
No description available.
CVE-2018-7852 0.0 unknown
CVE-2018-7852. An uncaught exception vulnerability exists which could cause denial of service when an invalid private command parameter is sent to the controller over Modbus.
CVE-2018-7772 0.0 unknown
No description available.
CVE-2019-8280 0.0 unknown
CVE-2019-8280. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
CVE-2016-5195 0.0 unknown
No description available.
CVE-2017-3635 0.0 unknown
No description available.
CVE-2019-12256 0.0 unknown
This vulnerability resides in the IPv4 option parsing and may be triggered by IPv4 packets containing invalid options. The most likely outcome of triggering this defect is that the tNet0 task crashes. This vulnerability can result in remote code execution.CVE-2019-12256 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2018-7241 0.0 unknown
No description available.
CVE-2017-9961 0.0 unknown
No description available.
CVE-2017-7575 0.0 unknown
No description available.
CVE-2018-7844 0.0 unknown
CVE-2018-7844. An information exposure vulnerability exists, which could cause the disclosure of SNMP information when reading memory blocks from the controller over Modbus.
CVE-2018-7803 0.0 unknown
No description available.
CVE-2018-7242 0.0 unknown
No description available.
CVE-2019-8269 0.0 unknown
CVE-2019-8269. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
CVE-2019-1222 0.0 unknown
No description available.
CVE-2017-7972 0.0 unknown
No description available.
CVE-2019-8265 0.0 unknown
CVE-2019-8265. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
CVE-2019-6846 0.0 unknown
No description available.
CVE-2017-11357 9.8 critical
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.CVE-2017-11357 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2016-10395 0.0 unknown
No description available.
CVE-2018-7787 0.0 unknown
No description available.
CVE-2017-6028 0.0 unknown
No description available.
CVE-2018-7835 0.0 unknown
No description available.
CVE-2019-6809 0.0 unknown
CVE-2019-6809. An uncaught exception vulnerability exists, which could cause a possible denial of service when reading invalid data from the controller.
CVE-2017-7574 0.0 unknown
No description available.
CVE-2017-9962 0.0 unknown
No description available.
CVE-2019-20033 0.0 unknown
No description available.
CVE-2014-6277 0.0 unknown
No description available.
CVE-2019-6812 0.0 unknown
No description available.
CVE-2019-1223 0.0 unknown
No description available.
CVE-2017-3652 0.0 unknown
No description available.
CVE-2018-7839 0.0 unknown
No description available.
CVE-2019-8263 0.0 unknown
CVE-2019-8263. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
CVE-2017-3636 0.0 unknown
No description available.
CVE-2018-7854 0.0 unknown
CVE-2018-7854. An uncaught exception vulnerability exists which could cause a denial of service when sending invalid debug parameters to the controller over Modbus.
CVE-2019-20031 0.0 unknown
No description available.
CVE-2019-6837 0.0 unknown
No description available.
CVE-2018-7760 0.0 unknown
No description available.
CVE-2017-5571 0.0 unknown
No description available.
CVE-2018-7767 0.0 unknown
No description available.
CVE-2018-7246 0.0 unknown
No description available.
CVE-2017-5753 0.0 unknown
No description available.
CVE-2017-0145 0.0 unknown
No description available.
CVE-2017-0148 0.0 unknown
No description available.
CVE-2018-15361 0.0 unknown
CVE-2018-15361. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
CVE-2019-6810 0.0 unknown
An improper access control vulnerability exists that could allow the execution of commands by unauthorized users when using the IEC 60870-5-104 protocol.CVE-2019-6810 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H).
CVE-2018-7814 0.0 unknown
No description available.
CVE-2018-7804 0.0 unknown
No description available.
CVE-2018-7774 0.0 unknown
No description available.
CVE-2019-6834 0.0 unknown
No description available.
CVE-2018-7796 0.0 unknown
No description available.
CVE-2019-6819 0.0 unknown
No description available.
CVE-2017-7967 0.0 unknown
No description available.
CVE-2019-13537 0.0 unknown
No description available.
CVE-2018-7842 0.0 unknown
CVE-2018-7842. An authentication bypass by spoofing vulnerability exists which could cause an elevation of privilege by conducting a brute force attack on Modbus parameters sent to the controller.
CVE-2019-0708 0.0 unknown
The affected product is vulnerable to a remote code execution vulnerability that exists in Remote Desktop Services (formerly known as Terminal Services) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would need to send a specially crafted request to the target system 's Remote Desktop Service via RDP.CVE-2019-0708 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2018-7239 0.0 unknown
No description available.
CVE-2019-6806 0.0 unknown
CVE-2019-6806. An information exposure vulnerability exists which could cause the disclosure of SNMP information when reading variables in the controller using Modbus.
CVE-2015-2290 0.0 unknown
No description available.
CVE-2014-7187 0.0 unknown
No description available.
CVE-2018-7769 0.0 unknown
No description available.
CVE-2019-6853 0.0 unknown
No description available.
CVE-2018-7830 0.0 unknown
No description available.
CVE-2017-0144 0.0 unknown
No description available.
CVE-2018-7783 8.6 high
Schneider Electric SoMachine Basic prior to v1.6 SP1 suffers from an XML External Entity (XXE) vulnerability using the DTD parameter entities technique resulting in disclosure and retrieval of arbitrary data on the affected node via out-of-band (OOB) attack. This vulnerability is triggered when input passed to the xml parser is not sanitized while parsing the xml project/template file.CVE-2018-7783 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
CVE-2019-12264 0.0 unknown
This vulnerability requires that at least one IPv4 multicast address has been assigned to the target in an incorrect way (e.g., using the API intended for assigning unicast addresses). An attacker may use CVE-2019-12264 to incorrectly assign a multicast IP-address.. An attacker on the same LAN as the target system may use this vulnerability to cause a NULL pointer dereference, which most likely will crash the tNet0 task. An attacker on the same LAN as the target system may use this vulnerability to cause a NULL pointer dereference, which most likely will crash the tNet0 task.. CVE-2019-12259 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H).An attacker may use CVE-2019-12264 to incorrectly assign a multicast IP-address.
CVE-2019-6847 0.0 unknown
No description available.
CVE-2018-7762 0.0 unknown
No description available.
CVE-2019-8264 0.0 unknown
CVE-2019-8264. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
CVE-2017-9958 0.0 unknown
No description available.
CVE-2018-7833 0.0 unknown
No description available.
CVE-2017-9968 0.0 unknown
No description available.
CVE-2019-8274 0.0 unknown
CVE-2019-8274. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
CVE-2019-6835 0.0 unknown
No description available.
CVE-2019-6831 0.0 unknown
An improper check for unusual or exceptional conditions vulnerability exists that could cause disconnection of active connections when an unusually high number of IEC 60870-5-104 packets are received by the module on Port 2404/TCP.CVE-2019-6831 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-0146 0.0 unknown
No description available.
CVE-2019-6839 0.0 unknown
No description available.
CVE-2017-6034 0.0 unknown
No description available.
CVE-2018-7766 0.0 unknown
No description available.
CVE-2019-6815 0.0 unknown
No description available.
CVE-2018-12130 0.0 unknown
CVE-2018-12130. Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. Additional information about the vulnerabilities can be found in the INTEL website: [INTEL-SA-00233](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00233.html)
CVE-2018-7855 0.0 unknown
CVE-2018-7855. An uncaught exception vulnerability exists, which could cause a denial of service when sending invalid breakpoint parameters to the controller over Modbus.
CVE-2018-12126 0.0 unknown
No description available.
CVE-2015-7921 0.0 unknown
The FTP server in Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 has hardcoded credentials, which makes it easier for remote attackers to bypass authentication by leveraging knowledge of these credentials.
CVE-2017-9956 0.0 unknown
No description available.
CVE-2018-7784 0.0 unknown
No description available.
CVE-2018-7853 0.0 unknown
CVE-2018-7853. An uncaught exception vulnerability exists, which could cause denial of service when reading invalid physical memory blocks in the controller over Modbus.
CVE-2017-7969 0.0 unknown
No description available.
CVE-2014-9188 0.0 unknown
Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8513 and CVE-2014-8514. NOTE: this may be clarified later based on details provided by researchers.
CVE-2019-6842 0.0 unknown
No description available.
CVE-2019-8270 0.0 unknown
CVE-2019-8270. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
CVE-2018-7848 0.0 unknown
CVE-2018-7848. An information exposure vulnerability exists, which could cause the disclosure of SNMP information when reading files from the controller over Modbus.
CVE-2017-7971 0.0 unknown
No description available.
CVE-2017-9960 0.0 unknown
No description available.
CVE-2019-8259 0.0 unknown
CVE-2019-8259. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
CVE-2019-6845 0.0 unknown
No description available.
CVE-2019-8277 0.0 unknown
CVE-2019-8277. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
CVE-2018-7815 0.0 unknown
No description available.
CVE-2018-7790 0.0 unknown
No description available.
CVE-2018-7847 0.0 unknown
CVE-2018-7847. An improper access control vulnerability exists which could cause denial of service or potential code execution by overwriting configuration settings of the controller over Modbus.
CVE-2019-6827 0.0 unknown
No description available.
CVE-2019-8260 0.0 unknown
CVE-2019-8260. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
CVE-2019-6821 0.0 unknown
No description available.
CVE-2018-7764 0.0 unknown
No description available.
CVE-2019-8271 0.0 unknown
CVE-2019-8271. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
CVE-2019-6813 0.0 unknown
An improper check for unusual or exceptional conditions vulnerability exists that could cause a denial-of-service condition when truncated SNMP packets on Port 161/UDP are received by the device.CVE-2019-6813 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-7823 0.0 unknown
No description available.
CVE-2019-6844 0.0 unknown
No description available.
CVE-2018-7831 0.0 unknown
No description available.
CVE-2014-8512 0.0 unknown
Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8511. NOTE: this may be clarified later based on details provided by researchers.
CVE-2016-2292 0.0 unknown
Stack-based buffer overflow in Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 allows remote attackers to execute arbitrary code via unspecified vectors.
CVE-2019-6851 0.0 unknown
No description available.
CVE-2017-3651 0.0 unknown
No description available.
CVE-2018-7779 0.0 unknown
No description available.
CVE-2019-1225 0.0 unknown
No description available.
CVE-2019-12265 0.0 unknown
The IGMPv3 reception handler does not expect packets to be spread across multiple IP-fragments.CVE-2019-12265 has been assigned to this vulnerability. A CVSS v3 base score of 5.4 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).
CVE-2014-7186 0.0 unknown
No description available.
CVE-2018-7810 0.0 unknown
No description available.
CVE-2018-7845 0.0 unknown
CVE-2018-7845. An out-of-bounds read vulnerability exists, which could cause the disclosure of unexpected data from the controller when reading specific memory blocks in the controller over Modbus.
CVE-2018-7776 0.0 unknown
No description available.
CVE-2017-9970 0.0 unknown
No description available.
CVE-2018-7786 0.0 unknown
No description available.
CVE-2017-5754 0.0 unknown
No description available.
CVE-2018-7758 0.0 unknown
No description available.
CVE-2019-6841 0.0 unknown
No description available.
CVE-2019-8262 0.0 unknown
CVE-2019-8262. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
CVE-2018-7801 0.0 unknown
No description available.
CVE-2019-10981 0.0 unknown
No description available.
CVE-2019-6823 0.0 unknown
No description available.
CVE-2019-6822 0.0 unknown
No description available.
CVE-2019-8266 0.0 unknown
CVE-2019-8266. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
CVE-2017-7970 0.0 unknown
No description available.
CVE-2018-7795 0.0 unknown
No description available.
CVE-2019-6824 0.0 unknown
No description available.
CVE-2018-7813 0.0 unknown
No description available.
CVE-2018-7777 0.0 unknown
No description available.
CVE-2018-7798 0.0 unknown
No description available.
CVE-2019-1226 0.0 unknown
No description available.
CVE-2019-6832 0.0 unknown
No description available.
CVE-2018-7244 0.0 unknown
No description available.
CVE-2016-6273 0.0 unknown
No description available.
CVE-2019-6836 0.0 unknown
No description available.
CVE-2019-8276 0.0 unknown
CVE-2019-8276. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
CVE-2018-7850 0.0 unknown
CVE-2018-7850. A reliance on untrusted inputs in a security decision vulnerability exists which could cause invalid information displayed in Unity Pro software.
CVE-2014-6271 0.0 unknown
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
CVE-2018-7837 0.0 unknown
No description available.
CVE-2017-5715 0.0 unknown
CVE-2017-5715. An attacker with local access to the system could potentially disclose information from protected memory areas via a side-channel attack on the processor cache.
CVE-2018-12127 0.0 unknown
No description available.
CVE-2018-7841 0.0 unknown
No description available.
CVE-2015-3962 0.0 unknown
Schneider Electric StruxureWare Building Expert MPM before 2.15 does not use encryption for the client-server data stream, which allows remote attackers to discover credentials by sniffing the network.
CVE-2014-6278 0.0 unknown
No description available.
CVE-2018-7771 0.0 unknown
No description available.
CVE-2019-6828 0.0 unknown
CVE-2019-6828. An uncaught exception vulnerability exists, which could cause a possible denial of service when reading specific coils and registers in the controller over Modbus.
CVE-2019-12258 0.0 unknown
An attacker with the source and destination TCP-port and IP-addresses of a session can inject invalid TCP segments into the flow, causing the TCP-session to be reset. An application will see this as an ECONNRESET error message when using the socket after such an attack. The most likely outcome is a crash of the application reading from the affected socket.. CVE-2019-12258 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).The most likely outcome is a crash of the application reading from the affected socket.
CVE-2019-12255 0.0 unknown
An attacker can either hijack an existing TCP session and inject bad TCP segments or establish a new TCP session on any TCP port listened to by the target. This vulnerability could lead to a buffer overflow of up to a full TCP receive-window (by default, 10k-64k depending on version). The buffer overflow occurs in the task calling recv()/recvfrom()/recvmsg(). Applications that pass a buffer equal to or larger than a full TCP window are not susceptible to this attack. Applications passing a stack-allocated variable as a buffer are the easiest to exploit. The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution.. CVE-2019-12255 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).Applications that pass a buffer equal to or larger than a full TCP window are not susceptible to this attack. Applications passing a stack-allocated variable as a buffer are the easiest to exploit. The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution.
CVE-2018-7788 0.0 unknown
No description available.
CVE-2018-7778 0.0 unknown
No description available.
CVE-2018-7836 0.0 unknown
No description available.
CVE-2019-6829 0.0 unknown
CVE-2019-6829. An uncaught exception vulnerability exists which could cause a possible denial of service when writing to specific memory addresses in the controller over Modbus.
CVE-2019-6840 0.0 unknown
No description available.
CVE-2018-7785 0.0 unknown
No description available.
CVE-2018-7851 0.0 unknown
No description available.
CVE-2019-6854 0.0 unknown
No description available.
CVE-2019-12263 0.0 unknown
This vulnerability relies on a race-condition between the network task (tNet0) and the receiving application. It is very difficult to trigger the race on a system with a single CPU-thread enabled, and there is no way to reliably trigger a race on SMP targets.CVE-2019-12263 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2018-7817 0.0 unknown
No description available.
CVE-2018-7768 0.0 unknown
No description available.
CVE-2018-7857 0.0 unknown
CVE-2018-7857. An uncaught exception vulnerability exists, which could cause a possible denial of service when writing out of bounds variables to the controller over Modbus.
CVE-2019-6826 0.0 unknown
No description available.
CVE-2017-3641 0.0 unknown
No description available.

// Affected Products (28)

Vendor Product Asset Type Purdue Level Firmware
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Schneider Electric Software, LLC Unknown plc
L1
--
Schneider Electric Software, LLC Unknown plc
L1
--
Schneider Electric Software, LLC Unknown plc
L1
--
Schneider Electric Software, LLC Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Siemens Unknown hmi
L2
--
Siemens Unknown hmi
L2
--
Siemens Unknown hmi
L2
--
Siemens Unknown hmi
L2
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Software, LLC Unknown rtu
L1
vers:all/*
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
ABB ; Cisco ; Digi ; eWON ; Meinberg ; Moxa ; Red Lion; Siemens Unknown network_device -- --
ABB ; Cisco ; Digi ; eWON ; Meinberg ; Moxa ; Red Lion; Siemens Unknown scada_server
L2
--
ABB ; Cisco ; Digi ; eWON ; Meinberg ; Moxa ; Red Lion; Siemens Unknown network_device -- --
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--

// Remediations (222)

Patch: Update to V12.01 HF4
Update to V12.01 HF4
Patch: Update to V14.00
Update to V14.00
Patch: Update to V4.8
Update to V4.8
Mitigation: Restrict access to the device to the internal or VPN network and to trusted IP addresses only.
Restrict access to the device to the internal or VPN network and to trusted IP addresses only.
Mitigation: Schneider Electric’s Modicon Premium controllers have reached their end of life and are no longer co
Schneider Electric’s Modicon Premium controllers have reached their end of life and are no longer commercially available. They have been replaced by the Modicon M580 ePAC controller, our most current product offer. Customers should strongly consider migrating to the Modicon M580 ePAC. Please contact your local Schneider Electric technical support for more information. To mitigate the risks associated with Modbus/ weaknesses, users should immediately: • Set up network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List following the recommendations of the user manual “Premium and Atrium using EcoStruxure Control Expert - Ethernet Network Modules, User Manual” in chapters “Connection configuration parameters / TCP/IP Services Configuration Parameters / Connection Configuration Parameters”: https://www.se.com/ww/en/download/document/35006192K01000/
Patch: Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download
Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download here: 140CPU65860 [C] - https://www.schneider-electric.com/en/download/document/Quantum_140CPU65860_SV3.60
Patch: Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download
Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download here: 140CPU67861 [C] - https://www.schneider-electric.com/en/download/document/Quantum_140CPU67861_SV3.60
Mitigation: To mitigate the risks associated with Modbus/ weaknesses, users should immediately: • Set up network
To mitigate the risks associated with Modbus/ weaknesses, users should immediately: • Set up network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List feature as mentioned in “Quantum using EcoStruxure Control Expert - TCP/IP Configuration, User Manual” in chapter “Software Settings for Ethernet Communication / Messaging / Quantum NOE Ethernet Messaging Configuration”: https://www.se.com/ww/en/download/document/33002467K01000/
Patch: Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download
Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download here: 140CPU67261 [C] - https://www.schneider-electric.com/en/download/document/Quantum_140CPU67261_SV3.60
Patch: Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download
Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download here: 140CPU67160 [C] - https://www.schneider-electric.com/en/download/document/Quantum_140CPU67160_SV3.60
Mitigation: Schneider Electric’s Modicon Quantum and Quantum Safety controllers have reached their end of life a
Schneider Electric’s Modicon Quantum and Quantum Safety controllers have reached their end of life and are no longer commercially available. They have been replaced by the Modicon M580 or M580 Safety ePAC controller, our most current product offer. Customers should strongly consider migrating to the Modicon M580 ePAC. Please contact your local Schneider Electric technical support for more information. To mitigate the risks associated with Modbus/ weaknesses, users should immediately: • Set up network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List feature as mentioned in “Quantum using EcoStruxure Control Expert - TCP/IP Configuration, User Manual” in chapter “Software Settings for Ethernet Communication / Messaging / Quantum NOE Ethernet Messaging Configuration”: https://www.se.com/ww/en/download/document/33002467K01000/
Mitigation: To mitigate the risks associated with Modbus/ weaknesses, users should immediately: • Set up netwo
To mitigate the risks associated with Modbus/ weaknesses, users should immediately: • Set up network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List following the recommendations of the user manual “Premium and Atrium using EcoStruxure Control Expert - Ethernet Network Modules, User Manual” in chapters “Connection configuration parameters / TCP/IP Services Configuration Parameters / Connection Configuration Parameters”: https://www.se.com/ww/en/download/document/35006192K01000/
Patch: Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download
Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download here: 140CPU65150 [C] & 140CPU65160 [C] - https://www.schneider-electric.com/en/download/document/Quantum_140CPU651X0_SV3.60
Patch: Please contact your Schneider Electric customer support to get Premium V3.20 firmware. TSXP57104M
Please contact your Schneider Electric customer support to get Premium V3.20 firmware. TSXP57104M [C] TSXP57154M [C] TSXP571634M [C] TSXP57204M [C] TSXP572634M [C] TSXP57254M [C] TSXP57304M [C] TSXP573634M [C] TSXP57354M [C] TSXP574634M [C] TSXP57454M [C] TSXP575634M [C] TSXP57554M [C] TSXP576634M [C] TSXH5724M [C] TSXH5744M [C]
Patch: Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download
Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download here: 140CPU67260 [C] - https://www.schneider-electric.com/en/download/document/Quantum_140CPU67260_SV3.60
Patch: Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download
Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download here: 140CPU67261 [C] - https://www.schneider-electric.com/en/download/document/Quantum_140CPU67261_SV3.60
Mitigation: It is recommended to apply the following mitigations to reduce the risk of exploitation: • Set up
It is recommended to apply the following mitigations to reduce the risk of exploitation: • Set up an application password in the project properties • Set up network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List following the recommendations of the user manuals: o “Modicon M340 for Ethernet Communications Modules and Processors User Manual” in chapter “Messaging Configuration Parameters”: https://www.se.com/ww/en/download/document/31007131K01000/ • Set up a secure communication according to the following guideline “Modicon Controllers Platform Cyber Security Reference Manual,” in chapter “Setup secured communications”: https://www.se.com/ww/en/download/document/EIO0000001999/ • Consider use of external firewall devices such as EAGLE40-07 from Belden to establish VPN connections for M340 & M580 architectures. For more details refer to the chapter “How to protect M580 and M340 architectures with EAGLE40 using VPN”: https://www.se.com/ww/en/download/document/EIO0000001999/
Mitigation: It is recommended to apply the following mitigations to reduce the risk of exploitation: • Set up an
It is recommended to apply the following mitigations to reduce the risk of exploitation: • Set up an application password in the project properties • Set up network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List following the recommendations of the user manuals: https://www.se.com/ww/en/download/document/EIO0000001578/ • Set up a secure communication according to the following guideline “Modicon Controllers Platform Cyber Security Reference Manual,” in chapter “Setup secured communications”: https://www.se.com/ww/en/download/document/EIO0000001999/ NOTE: Use a BMENOC module and follow the instructions to configure IPSEC feature as described in the guideline “Modicon M580 - BMENOC03.1 Ethernet Communications Schneider Electric Security Notification Module, Installation and Configuration Guide” in the chapter “Configuring IPSEC communications”: https://www.se.com/ww/en/download/document/HRB62665/ OR • Use a BMENUA0100 module and follow the instructions to configure IPSEC feature as described in the chapter “Configuring the BMENUA0100 Cybersecurity Settings”: https://www.se.com/ww/en/download/document/PHA83350 OR • Consider using external firewall devices such as EAGLE40-07 from Belden to establish VPN connections for M340 and M580 architectures. For more details refer to the chapter “How to protect M580 and M340 architectures with EAGLE40 using VPN”: https://www.se.com/ww/en/download/document/EIO0000001999/ • Ensure the M580 CPU is running with the memory protection activated by configuring the input bit to a physical input, for more details refer to the following guideline “Modicon Controllers Platform Cyber Security Reference Manual”, “CPU Memory Protection section”: https://www.schneider-electric.com/en/download/document/EIO0000001999/ NOTE: The CPU memory protection cannot be configured with M580 Hot Standby CPUs. In such cases, use IPsec encrypted communication.
Patch: Version sv3.60 of Modicon M340 includes a fix for this vulnerability and is available for download h
Version sv3.60 of Modicon M340 includes a fix for this vulnerability and is available for download here: STEP 1: Update software and firmware • On the engineering workstation, update to EcoStruxure Control Expert v16.0 or later: https://www.se.com/ww/en/product-range/548-ecostruxure-control-expert-unity-pro/#software-and-firmware • On the Modicon M340 controller, update to firmware v3.60 or above: https://www.se.com/ww/en/product-range/1468- modicon-m340/#software-and-firmware STEP 2: Update projects in EcoStruxure Control Expert by: • Setting up an application password in the project properties • Changing the version of the controller firmware to match the new firmware version of the target controller STEP 3: Rebuild and transfer projects in EcoStruxure Control Expert: • Rebuild all current projects • Transfer them to Modicon controllers
Patch: Version sv4.20 of Modicon M580 includes a fix for this vulnerability and is available for download h
Version sv4.20 of Modicon M580 includes a fix for this vulnerability and is available for download here: STEP 1: Update software and firmware. • On the engineering workstation, update to EcoStruxure Control Expert v16.0: https://www.se.com/ww/en/product-range/548-ecostruxure-control-expert-unity-pro/#software-and-firmware • On the Modicon M580 controller, update to firmware SV4.20 or above: https://www.se.com/ww/en/product-range/62098-modicon-m580-epac/#software-and-firmware STEP 2: Update projects in EcoStruxure Control Expert by: • Setting up an application password in the project properties • Changing the version of the controller firmware to match the new firmware version of the target controller STEP 3: Rebuild and transfer projects in EcoStruxure Control Expert: • Rebuild all current projects
Mitigation: Belden Industrial Devices
Belden Industrial Devices
Mitigation: Woodward
Woodward
Mitigation: Rockwell Automation
Rockwell Automation
Mitigation: Xylem
Xylem
Mitigation: Xerox Printers
Xerox Printers
Mitigation: Avaya
Avaya
Mitigation: Schneider Electric
Schneider Electric
Mitigation: Sonicwall Firewalls
Sonicwall Firewalls
Mitigation: Mitsubishi Electric
Mitsubishi Electric
Mitigation: Siemens (SIPROTEC 5)
Siemens (SIPROTEC 5)
Mitigation: Siemens (RUGGEDCOM)
Siemens (RUGGEDCOM)
Mitigation: IDEC Corporation
IDEC Corporation
Mitigation: ABB
ABB
Mitigation: NetApp
NetApp
Mitigation: Siemens (Power Meters)
Siemens (Power Meters)
Mitigation: ExtremeNetworks
ExtremeNetworks
Mitigation: TrendMicro IPS
TrendMicro IPS
Mitigation: Microsoft states they have no history of support or integration work to include IPnet and have not r
Microsoft states they have no history of support or integration work to include IPnet and have not released a version of ThreadX bundled with IPnet. Microsoft does caution that some hardware makers could have used ThreadX and a custom set IPnet in the hardware.
Mitigation: Wind River has identified the following specific workarounds and mitigations users can apply to redu
Wind River has identified the following specific workarounds and mitigations users can apply to reduce risk:
Mitigation: All affected products: To obtain patches, email [email protected] and indicate the VxWorks major v
All affected products: To obtain patches, email [email protected] and indicate the VxWorks major version for which you need source patches.
Mitigation: All affected products: For more detailed information on the vulnerabilities and the mitigating contr
All affected products: For more detailed information on the vulnerabilities and the mitigating controls, please see the Wind River advisory at: https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/
Mitigation: Additional vendors affected by the reported vulnerabilities have also released security advisories r
Additional vendors affected by the reported vulnerabilities have also released security advisories related to their affected products. Those advisories are as follows:
Mitigation: All affected products: To obtain patches, email [email protected] and indicate the VxWorks major v
All affected products: To obtain patches, email [email protected] and indicate the VxWorks major version for which you need source patches.
Mitigation: Enea has no IPNet customers on support contract in the United States.
Enea has no IPNet customers on support contract in the United States.
Mitigation: ZebOS by IP Infusion has not yet responded to CISA inquiries.
ZebOS by IP Infusion has not yet responded to CISA inquiries.
Mitigation: TRON Forum reports they only publish the specification for ITRON RTOS. Various implementations are u
TRON Forum reports they only publish the specification for ITRON RTOS. Various implementations are used by many users world-wide and are created by various implementors (some commercial, and some academic and some government) according the specification document. TRON Forum, the caretaker of the ITRON specification, has not endorsed the use of any particular TCP/IP stack including one from Interpeak. The choice of TCP/IP stack is up to the RTOS vendor and application developers, and thus each application user needs to check whether TCP/IP stack developed by Interpeak is used inside their application. TRON Forum will send out a preliminary warning to members by mailing list to notify implementors of the reported vulnerabilities.
Mitigation: Green Hills Software has proactively informed affected users and offers consulting services to imple
Green Hills Software has proactively informed affected users and offers consulting services to implement mitigations.
Patch: Wind River has produced controls and patches to mitigate the reported vulnerabilities. To obtain pat
Wind River has produced controls and patches to mitigate the reported vulnerabilities. To obtain patches, email [email protected] and indicate the VxWorks major version for which you need source patches.
Patch: Microsoft states they have no history of support or integration work to include IPnet and have not r
Microsoft states they have no history of support or integration work to include IPnet and have not released a version of ThreadX bundled with IPnet. Microsoft does caution that some hardware makers could have used ThreadX and a custom set IPnet in the hardware.
Patch: For more detailed information on the vulnerabilities and the mitigating controls, please see the Win
For more detailed information on the vulnerabilities and the mitigating controls, please see the Wind River advisory.
Patch: Green Hills Software has proactively informed affected users and offers consulting services to imple
Green Hills Software has proactively informed affected users and offers consulting services to implement mitigations.
Patch: Additional vendors affected by the reported vulnerabilities have also released security advisories r
Additional vendors affected by the reported vulnerabilities have also released security advisories related to their affected products. Those advisories are as follows:
Patch: Enea has no IPNet customers on support contract in the United States.
Enea has no IPNet customers on support contract in the United States.
Patch: TRON Forum reports they only publish the specification for ITRON RTOS. Various implementations are u
TRON Forum reports they only publish the specification for ITRON RTOS. Various implementations are used by many users world-wide and are created by various implementors (some commercial, and some academic and some government) according the specification document. TRON Forum, the caretaker of the ITRON specification, has not endorsed the use of any particular TCP/IP stack including one from Interpeak. The choice of TCP/IP stack is up to the RTOS vendor and application developers, and thus each application user needs to check whether TCP/IP stack developed by Interpeak is used inside their application. TRON Forum will send out a preliminary warning to members by mailing list to notify implementors of the reported vulnerabilities.
Patch: Update to V4.41 or later version
Update to V4.41 or later version
Mitigation: Restrict access to the affected systems, especially to ports 22/tcp and 443/tcp to trusted IP addres
Restrict access to the affected systems, especially to ports 22/tcp and 443/tcp to trusted IP addresses only
Patch: Update to V3.2.7 or later version
Update to V3.2.7 or later version
Mitigation: Deactivate the webserver if not required, and if deactivation is supported by the product
Deactivate the webserver if not required, and if deactivation is supported by the product
Patch: Update to V3.2.7 or later version
Update to V3.2.7 or later version
Mitigation: Deactivate the webserver if not required, and if deactivation is supported by the product
Deactivate the webserver if not required, and if deactivation is supported by the product
Mitigation: Restrict access to the affected systems, especially to ports 22/tcp and 443/tcp to trusted IP addres
Restrict access to the affected systems, especially to ports 22/tcp and 443/tcp to trusted IP addresses only
Mitigation: For further information on these vulnerabilities, please see Schneider Electric’s security notificat
For further information on these vulnerabilities, please see Schneider Electric’s security notification (SEVD 2014-344-01) at Schneider Electric’s cybersecurity web page: (http://www2.schneider-electric.com/sites/corporate/en/support/cybersecurity/cyber-security-vulnerabilities-sorted.page)
Mitigation: Schneider Electric has released an updated version of the ProClima software, Version 6.1.7, which mi
Schneider Electric has released an updated version of the ProClima software, Version 6.1.7, which mitigates these vulnerabilities. Customers are encouraged to download the new version and update their installations. It is important that customers first uninstall the current version. The new version can be downloaded from Schneider Electric’s web site at the following location: (http://www.schneider-electric.com/ww/en/download/document/ProClima_software)
Patch: BMXP342000: Modicon M340 firmware v3.20
BMXP342000: Modicon M340 firmware v3.20
Mitigation: 140CPU65150 [C] and 140CPU65160 [C]: Modicon Quantum firmware v3.60
140CPU65150 [C] and 140CPU65160 [C]: Modicon Quantum firmware v3.60
Mitigation: For more information on this vulnerability and the associated upgrade, please see Schneider Electric
For more information on this vulnerability and the associated upgrade, please see Schneider Electric's SEVD-2019-344-01
Mitigation: BMEP582020 and H: Specific Modicon M580 firmware v3.10
BMEP582020 and H: Specific Modicon M580 firmware v3.10
Patch: BMXP3420302 and CL and H: Modicon M340 firmware v3.20
BMXP3420302 and CL and H: Modicon M340 firmware v3.20
Mitigation: Laptops that have connected to any other network besides the intended network should never be allowe
Laptops that have connected to any other network besides the intended network should never be allowed to connect to the safety or control networks without proper sanitation.
Mitigation: BMEP584040S: Specific Modicon M580 firmware v3.10
BMEP584040S: Specific Modicon M580 firmware v3.10
Mitigation: BMEP584020: Specific Modicon M580 firmware v3.10
BMEP584020: Specific Modicon M580 firmware v3.10
Mitigation: 140CPU67160 [C]: Modicon Quantum firmware v3.60
140CPU67160 [C]: Modicon Quantum firmware v3.60
Mitigation: BMEP582040 and H: Specific Modicon M580 firmware v3.10
BMEP582040 and H: Specific Modicon M580 firmware v3.10
Mitigation: For more details and assistance on how to protect during installation, please contact a Schneider El
For more details and assistance on how to protect during installation, please contact a Schneider Electric representative and/or Schneider Electric Industrial Cybersecurity Services. These organizations are aware of this situation and can support you through the process.
Mitigation: 140CPU65860 [C]: Modicon Quantum firmware v3.60
140CPU65860 [C]: Modicon Quantum firmware v3.60
Mitigation: Minimize network exposure for all control system devices and/or systems, and ensure that they are no
Minimize network exposure for all control system devices and/or systems, and ensure that they are not accessible from the Internet.
Mitigation: BMEP581020 and H: Specific Modicon M580 firmware v3.10
BMEP581020 and H: Specific Modicon M580 firmware v3.10
Mitigation: 140CPU67160S: Please contact Schneider Electric customer support to get the Quantum v3.60 firmware
140CPU67160S: Please contact Schneider Electric customer support to get the Quantum v3.60 firmware
Mitigation: BMEP583020: Specific Modicon M580 firmware v3.10
BMEP583020: Specific Modicon M580 firmware v3.10
Mitigation: BMEP582040S: Specific Modicon M580 firmware v3.10
BMEP582040S: Specific Modicon M580 firmware v3.10
Mitigation: All programming software should be kept in locked cabinets and should never be connected to any netw
All programming software should be kept in locked cabinets and should never be connected to any network other than the network for which the devices are intended.
Mitigation: 140CPU67861 [C]: Modicon Quantum firmware v3.60
140CPU67861 [C]: Modicon Quantum firmware v3.60
Patch: BMXP3420302: Modicon M340 firmware v3.20
BMXP3420302: Modicon M340 firmware v3.20
Mitigation: Physical controls should be in place so that no unauthorized person would have access to the ICS and
Physical controls should be in place so that no unauthorized person would have access to the ICS and safety controllers, peripheral equipment, or the ICS and safety networks.
Mitigation: BMEP586040 and C: Specific Modicon M580 firmware v3.10
BMEP586040 and C: Specific Modicon M580 firmware v3.10
Patch: BMXP341000 and H: Modicon M340 firmware v3.20
BMXP341000 and H: Modicon M340 firmware v3.20
Mitigation: BMEH586040 and C: Specific Modicon M580 firmware v3.10
BMEH586040 and C: Specific Modicon M580 firmware v3.10
Patch: BMXP3420102 and CL: Modicon M340 firmware v3.20
BMXP3420102 and CL: Modicon M340 firmware v3.20
Mitigation: BMEH582040 and C: Specific Modicon M580 firmware v3.10
BMEH582040 and C: Specific Modicon M580 firmware v3.10
Mitigation: 140CPU65160S: Please contact Schneider Electric customer support to get the Quantum v3.60 firmware
140CPU65160S: Please contact Schneider Electric customer support to get the Quantum v3.60 firmware
Mitigation: All methods of mobile data exchange with the isolated network, such as CDs, USB drives, etc., should
All methods of mobile data exchange with the isolated network, such as CDs, USB drives, etc., should be scanned before use in the terminals or any node connected to these networks.
Mitigation: BMEP583040: Specific Modicon M580 firmware v3.10
BMEP583040: Specific Modicon M580 firmware v3.10
Mitigation: BMEH586040S: Specific Modicon M580 firmware v3.10
BMEH586040S: Specific Modicon M580 firmware v3.10
Mitigation: When remote access is required, use secure methods, such as Virtual Private Networks (VPNs), recogni
When remote access is required, use secure methods, such as Virtual Private Networks (VPNs), recognizing that VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize that VPN is only as secure as the connected devices.
Mitigation: All controllers should reside in locked cabinets and never be left in the “Program” mode.
All controllers should reside in locked cabinets and never be left in the “Program” mode.
Mitigation: BMEP585040 and C: Specific Modicon M580 firmware v3.10
BMEP585040 and C: Specific Modicon M580 firmware v3.10
Mitigation: BMEH584040S: Specific Modicon M580 firmware v3.10
BMEH584040S: Specific Modicon M580 firmware v3.10
Mitigation: 140CPU65260 [C]: Modicon Quantum firmware v3.60
140CPU65260 [C]: Modicon Quantum firmware v3.60
Mitigation: 140CPU67260 [C]: Modicon Quantum firmware v3.60
140CPU67260 [C]: Modicon Quantum firmware v3.60
Mitigation: BMEP584040: Specific Modicon M580 firmware v3.10
BMEP584040: Specific Modicon M580 firmware v3.10
Mitigation: 140CPU67060 [C]: Modicon Quantum firmware v3.60
140CPU67060 [C]: Modicon Quantum firmware v3.60
Mitigation: BMEH584040 and C: Specific Modicon M580 firmware v3.10
BMEH584040 and C: Specific Modicon M580 firmware v3.10
Mitigation: 140CPU67261 [C]: Modicon Quantum firmware v3.60
140CPU67261 [C]: Modicon Quantum firmware v3.60
Mitigation: Modicon Premium v3.20 firmware is available by contacting Schneider Electric customer support.
Modicon Premium v3.20 firmware is available by contacting Schneider Electric customer support.
Patch: BMXP342020 and H: Modicon M340 firmware v3.20
BMXP342020 and H: Modicon M340 firmware v3.20
Mitigation: As only SIMATIC HMI image versions < V16 Update 4 are affected, please update the HMI Panel image as
As only SIMATIC HMI image versions < V16 Update 4 are affected, please update the HMI Panel image as included in your installation of SINAMICS GH150 to V16 Update 4 or later version
Mitigation: As only SIMATIC HMI image versions < V16 Update 4 are affected, please update the HMI Panel image as
As only SIMATIC HMI image versions < V16 Update 4 are affected, please update the HMI Panel image as included in your installation of SINAMICS GM150 (with option X30) to V16 Update 4 or later version
Mitigation: As only SIMATIC HMI image versions < V15 SP1 Update 6 are affected, please update the HMI Panel imag
As only SIMATIC HMI image versions < V15 SP1 Update 6 are affected, please update the HMI Panel image as included in your installation of SINAMICS SM150i to V15 SP1 Update 6 or later version
Mitigation: Restrict access to port 5900/tcp to trusted IP addresses only
Restrict access to port 5900/tcp to trusted IP addresses only
Mitigation: https://support.industry.siemens.com/cs/ww/en/view/109746530/
https://support.industry.siemens.com/cs/ww/en/view/109746530/
Mitigation: Follow SINAMICS MV Industrial Security guidelines
Follow SINAMICS MV Industrial Security guidelines
Mitigation: For any questions regarding update, please contact Siemens customer service or your system integrato
For any questions regarding update, please contact Siemens customer service or your system integrator.
Mitigation: As only SIMATIC HMI image versions < V16 Update 4 are affected, please update the HMI Panel image as
As only SIMATIC HMI image versions < V16 Update 4 are affected, please update the HMI Panel image as included in your installation of SINAMICS SM120 to V16 Update 4 or later version
Mitigation: As only SIMATIC HMI image versions < V16 Update 4 are affected, please update the HMI Panel image as
As only SIMATIC HMI image versions < V16 Update 4 are affected, please update the HMI Panel image as included in your installation of SINAMICS SH150 to V16 Update 4 or later version
Mitigation: As only SIMATIC HMI image versions < V16 Update 4 are affected, please update the HMI Panel image as
As only SIMATIC HMI image versions < V16 Update 4 are affected, please update the HMI Panel image as included in your installation of SINAMICS GL150 (with option X30) to V16 Update 4 or later version
Mitigation: https://support.industry.siemens.com/cs/ww/en/view/109763890/
https://support.industry.siemens.com/cs/ww/en/view/109763890/
Mitigation: Disable Sm@rtServer in the SIMATIC HMI Comfort Panels system component of SINAMICS. If this is not p
Disable Sm@rtServer in the SIMATIC HMI Comfort Panels system component of SINAMICS. If this is not possible, Defense-in-Depth should be used. Note: By default Sm@rtServer is disabled, but it can be enabled on request by the system integrator
Mitigation: As only SIMATIC HMI image versions < V15 SP1 Update 6 are affected, please update the HMI Panel imag
As only SIMATIC HMI image versions < V15 SP1 Update 6 are affected, please update the HMI Panel image as included in your installation of SINAMICS SM150 to V15 SP1 Update 6 or later version
Mitigation: As only SIMATIC HMI image versions < V15 SP1 Update 6 are affected, please update the HMI Panel imag
As only SIMATIC HMI image versions < V15 SP1 Update 6 are affected, please update the HMI Panel image as included in your installation of SINAMICS SL150 to V15 SP1 Update 6 or later version
Patch: Update SIMATIC WinCC (TIA Portal) to V16 Update 4 or later version, and then update panel to V16 Upd
Update SIMATIC WinCC (TIA Portal) to V16 Update 4 or later version, and then update panel to V16 Update 4 or later version
Mitigation: Restrict access to port 5900/tcp to trusted IP addresses only
Restrict access to port 5900/tcp to trusted IP addresses only
Patch: Update to V16 Update 4 or later version
Update to V16 Update 4 or later version
Mitigation: https://support.industry.siemens.com/cs/ww/en/view/109763890/
https://support.industry.siemens.com/cs/ww/en/view/109763890/
Mitigation: As only SIMATIC HMI image versions < V15 SP1 Update 6 are affected, please update the HMI Panel imag
As only SIMATIC HMI image versions < V15 SP1 Update 6 are affected, please update the HMI Panel image as included in your installation of SINAMICS SM150i to V15 SP1 Update 6 or later version
Mitigation: As only SIMATIC HMI image versions < V16 Update 4 are affected, please update the HMI Panel image as
As only SIMATIC HMI image versions < V16 Update 4 are affected, please update the HMI Panel image as included in your installation of SINAMICS GL150 (with option X30) to V16 Update 4 or later version
Mitigation: As only SIMATIC HMI image versions < V16 Update 4 are affected, please update the HMI Panel image as
As only SIMATIC HMI image versions < V16 Update 4 are affected, please update the HMI Panel image as included in your installation of SINAMICS GH150 to V16 Update 4 or later version
Mitigation: Follow SINAMICS MV Industrial Security guidelines
Follow SINAMICS MV Industrial Security guidelines
Mitigation: As only SIMATIC HMI image versions < V15 SP1 Update 6 are affected, please update the HMI Panel imag
As only SIMATIC HMI image versions < V15 SP1 Update 6 are affected, please update the HMI Panel image as included in your installation of SINAMICS SL150 to V15 SP1 Update 6 or later version
Mitigation: As only SIMATIC HMI image versions < V16 Update 4 are affected, please update the HMI Panel image as
As only SIMATIC HMI image versions < V16 Update 4 are affected, please update the HMI Panel image as included in your installation of SINAMICS SH150 to V16 Update 4 or later version
Mitigation: As only SIMATIC HMI image versions < V15 SP1 Update 6 are affected, please update the HMI Panel imag
As only SIMATIC HMI image versions < V15 SP1 Update 6 are affected, please update the HMI Panel image as included in your installation of SINAMICS SM150 to V15 SP1 Update 6 or later version
Mitigation: For any questions regarding update, please contact Siemens customer service or your system integrato
For any questions regarding update, please contact Siemens customer service or your system integrator.
Mitigation: As only SIMATIC HMI image versions < V16 Update 4 are affected, please update the HMI Panel image as
As only SIMATIC HMI image versions < V16 Update 4 are affected, please update the HMI Panel image as included in your installation of SINAMICS SM120 to V16 Update 4 or later version
Mitigation: As only SIMATIC HMI image versions < V16 Update 4 are affected, please update the HMI Panel image as
As only SIMATIC HMI image versions < V16 Update 4 are affected, please update the HMI Panel image as included in your installation of SINAMICS GM150 (with option X30) to V16 Update 4 or later version
Mitigation: Disable Sm@rtServer in the SIMATIC HMI Comfort Panels system component of SINAMICS. If this is not p
Disable Sm@rtServer in the SIMATIC HMI Comfort Panels system component of SINAMICS. If this is not possible, Defense-in-Depth should be used. Note: By default Sm@rtServer is disabled, but it can be enabled on request by the system integrator
Mitigation: Restrict access to port 5900/tcp to trusted IP addresses only
Restrict access to port 5900/tcp to trusted IP addresses only
Mitigation: https://support.industry.siemens.com/cs/ww/en/view/109746530/
https://support.industry.siemens.com/cs/ww/en/view/109746530/
Patch: Update SIMATIC WinCC (TIA Portal) to V16 Update 4 or later version, and then update panel to V16 Upd
Update SIMATIC WinCC (TIA Portal) to V16 Update 4 or later version, and then update panel to V16 Update 4 or later version
Mitigation: Restrict access to port 5900/tcp to trusted IP addresses only
Restrict access to port 5900/tcp to trusted IP addresses only
Patch: Update to V16 Update 4 or later version
Update to V16 Update 4 or later version
Patch: For additional information please see the Baxter Product Security Bulletin.
For additional information please see the Baxter Product Security Bulletin.
Patch: Baxter separately provided an ExactaMix Cybersecurity Guide, instructing users on good cybersecurity
Baxter separately provided an ExactaMix Cybersecurity Guide, instructing users on good cybersecurity practices relevant to the use of the ExactaMix product. The guide can be requested from [email protected]
Patch: Baxter recommends that users of the ExactaMix EM 2400 Versions 1.10 and 1.11, and ExactaMix EM1200 V
Baxter recommends that users of the ExactaMix EM 2400 Versions 1.10 and 1.11, and ExactaMix EM1200 Versions 1.1 and 1.2, should contact the service support team or regional product service support to upgrade to the ExactaMix Version 1.4 (EM1200) and ExactaMix Version 1.13 (EM2400) compounders. For all users, Baxter recommends the following compensating controls including, but not limited to:
Patch: Please contact your Schneider Electric customer support to get Premium V3.20 firmware. TSXP57104M
Please contact your Schneider Electric customer support to get Premium V3.20 firmware. TSXP57104M [C] TSXP57154M [C] TSXP571634M [C] TSXP57204M [C] TSXP572634M [C] TSXP57254M [C] TSXP57304M [C] TSXP573634M [C] TSXP57354M [C] TSXP574634M [C] TSXP57454M [C] TSXP575634M [C] TSXP57554M [C] TSXP576634M [C] TSXH5724M [C] TSXH5744M [C]
Mitigation: Schneider Electric’s Modicon Premium controllers have reached their end of life and are no longer co
Schneider Electric’s Modicon Premium controllers have reached their end of life and are no longer commercially available. They have been replaced by the Modicon M580 ePAC controller, our most current product offer. Customers should strongly consider migrating to the Modicon M580 ePAC. Please contact your local Schneider Electric technical support for more information. To mitigate the risks associated with Modbus/ weaknesses, users should immediately: • Set up network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List following the recommendations of the user manual “Premium and Atrium using EcoStruxure Control Expert - Ethernet Network Modules, User Manual” in chapters “Connection configuration parameters / TCP/IP Services Configuration Parameters / Connection Configuration Parameters”: https://www.se.com/ww/en/download/document/35006192K01000/
Mitigation: Schneider Electric’s Modicon Quantum and Quantum Safety controllers have reached their end of life a
Schneider Electric’s Modicon Quantum and Quantum Safety controllers have reached their end of life and are no longer commercially available. They have been replaced by the Modicon M580 or M580 Safety ePAC controller, our most current product offer. Customers should strongly consider migrating to the Modicon M580 ePAC. Please contact your local Schneider Electric technical support for more information. To mitigate the risks associated with Modbus/ weaknesses, users should immediately: • Set up network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List feature as mentioned in “Quantum using EcoStruxure Control Expert - TCP/IP Configuration, User Manual” in chapter “Software Settings for Ethernet Communication / Messaging / Quantum NOE Ethernet Messaging Configuration”: https://www.se.com/ww/en/download/document/33002467K01000/
Patch: Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download
Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download here: 140CPU67861 [C] - https://www.schneider-electric.com/en/download/document/Quantum_140CPU67861_SV3.60
Mitigation: Customers should immediately apply the following mitigations to reduce the risk of exploit: • Ensu
Customers should immediately apply the following mitigations to reduce the risk of exploit: • Ensure to use simulator default panel option to make PLC simulator accessible only locally. • Modbus network connections are disabled by default on the PLC Simulator present in EcoStruxure Control Expert, mitigating the risk associated to this vulnerability. Note: The PLC Simulator feature is part of the EcoStruxure Control Expert software, and it helps users to review and test their configurations files in a simulation environment. It is not intended to be used as a controller CPU in a production environment.
Patch: Version v15.1 of EcoStruxure Control Expert includes a fix for this vulnerability and is available f
Version v15.1 of EcoStruxure Control Expert includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/548-ecostruxure-control-expert-unity-pro/#software-and-firmware
Patch: Hitachi ABB Power Grids has published an advisory for eSOMS Telerik and advises users to update to e
Hitachi ABB Power Grids has published an advisory for eSOMS Telerik and advises users to update to eSOMS Version 6.3 as soon as possible.
Mitigation: Recommended security practices and firewall configurations can help protect a process control networ
Recommended security practices and firewall configurations can help protect a process control network from attacks that originate from outside the network. Such practices include ensuring applications and servers are physically protected from direct access by unauthorized personnel, have no direct connections to the Internet, are separated from other networks by means of a firewall system that has a minimal number of ports exposed, and others that must be evaluated case by case. Sensitive application servers should not be used for Internet surfing, instant messaging, or receiving e-mails. Portable computers and removable storage media should be carefully scanned for viruses before they are connected to a control system.
Mitigation: For additional information and support, contact a product provider or Hitachi ABB Power Grids servic
For additional information and support, contact a product provider or Hitachi ABB Power Grids service organization. For contact information, visit Hitachi ABB Power Grids contact-centers.
Mitigation: Schneider Electric recommends users set up network segmentation and implement a firewall to block al
Schneider Electric recommends users set up network segmentation and implement a firewall to block all unauthorized access to Port 2404/TCP and SNMP Port 161/UDP.
Mitigation: For more information, see the Schneider Electric security notification.
For more information, see the Schneider Electric security notification.
Patch: Spacelabs also encourages users and administrators to review the Microsoft Security Advisory and the
Spacelabs also encourages users and administrators to review the Microsoft Security Advisory and the Microsoft Customer Guidance for CVE-2019-0708 and apply the appropriate mitigation measures as soon as possible.
Patch: Spacelabs has determined the recommended remediation is to update to the newest release v1.2.1 or la
Spacelabs has determined the recommended remediation is to update to the newest release v1.2.1 or later. All deployed XTR hardware appliances are capable of update and should be updated. Many Spacelabs products are appliances and users are not intended to perform updates on them. Products or systems that are obsolete or are not able to be patched may use this alternate mitigation step to help protect against BlueKeep:
Patch: For additional information about this vulnerability, please see the Spacelabs Security Advisory.
For additional information about this vulnerability, please see the Spacelabs Security Advisory.
Patch: If you own an XTR device or have any questions about this security advisory, please contact Spacelab
If you own an XTR device or have any questions about this security advisory, please contact Spacelabs at 1-800-522-7025 and select 2 for technical support. XTR is an appliance that has no user interface, so your service representative can help you to determine the installed version of software on your XTR product and will work to coordinate updates as needed.
Mitigation: STEP 2: Update projects in EcoStruxure Machine Expert - Basic
STEP 2: Update projects in EcoStruxure Machine Expert - Basic
Mitigation: Upgrade the functional level of the application to minimum Version 10.2
Upgrade the functional level of the application to minimum Version 10.2
Mitigation: Please see Schneider Electric's publication SEVD-2018-142-01 for more information.
Please see Schneider Electric's publication SEVD-2018-142-01 for more information.
Mitigation: On Modicon M100/M200/M221 Logic controllers, update to latest firmware version.
On Modicon M100/M200/M221 Logic controllers, update to latest firmware version.
Mitigation: Minimize network exposure for all control system devices and systems and ensure they are not accessi
Minimize network exposure for all control system devices and systems and ensure they are not accessible from the Internet.
Mitigation: Never allow mobile devices that have connected to any other network besides the intended network to
Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.
Mitigation: Activate the application protection for both read and write in the project properties.
Activate the application protection for both read and write in the project properties.
Mitigation: Locate control and safety system networks and remote devices behind firewalls and isolate them from
Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.
Mitigation: Never connect programming software to any network other than the network for the devices it is inten
Never connect programming software to any network other than the network for the devices it is intended for.
Mitigation: Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. bef
Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.
Mitigation: On the engineering workstation, update to EcoStruxure Machine Expert - Basic v1.1 SP1 or above.
On the engineering workstation, update to EcoStruxure Machine Expert - Basic v1.1 SP1 or above.
Mitigation: When remote access is required, use secure methods, such as virtual private networks (VPNs). Recogni
When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand VPNs are only as secure as the connected devices.
Mitigation: Place all controllers in locked cabinets and never leave them in the “Program” mode.
Place all controllers in locked cabinets and never leave them in the “Program” mode.
Mitigation: Install physical controls so no unauthorized personnel can access your industrial control and safety
Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.
Mitigation: Transfer applications to Modicon M100/M200/M221 logic controllers. EcoStruxure Machine Expert - Basi
Transfer applications to Modicon M100/M200/M221 logic controllers. EcoStruxure Machine Expert - Basic will perform an integrity check when transferring the application and will display a warning pop-up to the user if the application has been altered during transfer.
Mitigation: STEP 3: Transfer applications.
STEP 3: Transfer applications.
Patch: Schneider Electric has replaced SoMachine Basic with EcoStruxure Machine Expert - Basic. The followi
Schneider Electric has replaced SoMachine Basic with EcoStruxure Machine Expert - Basic. The following steps are recommended for mitigation of this issue:STEP 1: Update software and firmware
Mitigation: For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices docume
For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document.
Patch: The recommendation is to upgrade to latest Foxboro server (V95, H94) and workstations (Dell D96): Pl
The recommendation is to upgrade to latest Foxboro server (V95, H94) and workstations (Dell D96): Please contact your local Service Representative or Schneider Electric Process Automation Global Customer Support Center for information on how to migrate to new hardware.https://pasupport.schneider-electric.com/home2020.asp?code=i1swrtYD1O7YcWYkLo5iZJHxEEY9U-agDBBtcLSP7EXks
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: The BIOS, OS security patches are applied to significantly reduce the exploit possibility. Additional information is available here: https://se.my.site.com/PAkb/s/article/KA000127385 Several layers of defense-in-depth mechanisms available in the recommended security architecture of DCS system, including the computers themselves, and by following the General Security Recommendations specified below mitigate this vulnerability. https://pasupport.schneider-electric.com/Content/Documents/IASeries/b0700_lastrev/b0700hz_f.pdf
Mitigation: Pro-face has released the following module: GP-Pro EX (Ver. 4.05.000 or later). The Update Module in
Pro-face has released the following module: GP-Pro EX (Ver. 4.05.000 or later). The Update Module includes: Editor: Ver.4.05.000, Transfer Tool: Ver.4.05.000, and System/Runtime: Ver.4.5.0
Mitigation: To download the module, free member registration for “Otasuke Pro!” is required at: (http://www.hmis
To download the module, free member registration for “Otasuke Pro!” is required at: (http://www.hmisource.com/otasuke/download/update/proex/)
Mitigation: Update to the latest version. (http://support.advantech.com.tw/Support/SearchResult.aspx?keyword=EKI
Update to the latest version. (http://support.advantech.com.tw/Support/SearchResult.aspx?keyword=EKI-132*&searchtabs=Firmware)
Mitigation: The ST and PT ISAC released the following test string to determine detect vulnerable installations.
The ST and PT ISAC released the following test string to determine detect vulnerable installations.
Mitigation: (http://lists.gnu.org/archive/html/bug-bash/2014-09/threads.html)
(http://lists.gnu.org/archive/html/bug-bash/2014-09/threads.html)
Mitigation: Other helpful resources include: (https://securityblog.redhat.com/2014/09/24/bash-specially-crafted
Other helpful resources include: (https://securityblog.redhat.com/2014/09/24/bash-specially-crafted-environment-variables-code-injection-attack/)
Mitigation: Support Information: Novel/SuSE (http://support.novell.com/security/cve/CVE-2014-6271.html)
Support Information: Novel/SuSE (http://support.novell.com/security/cve/CVE-2014-6271.html)
Mitigation: Patches have been released to fix this vulnerability by major Linux vendors for affected versions
Patches have been released to fix this vulnerability by major Linux vendors for affected versions
Mitigation: Debian (https://www.debian.org/security/2014/dsa-3032)
Debian (https://www.debian.org/security/2014/dsa-3032)
Mitigation: Redhat/Fedora (https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-6271)
Redhat/Fedora (https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-6271)
Mitigation: Mint
Mint
Mitigation: Please see Meinberg’s public notification and mitigation strategies at: (http://www.meinbergglobal.c
Please see Meinberg’s public notification and mitigation strategies at: (http://www.meinbergglobal.com/english/news/meinberg-security-advisory-mbgsa-1403-gnu-bash-environmental-variable-command-injection-vulnerability.htm)
Mitigation: CentOS (http://centosnow.blogspot.com/2014/09/critical-bash-updates-for-centos-5.html)
CentOS (http://centosnow.blogspot.com/2014/09/critical-bash-updates-for-centos-5.html)
Mitigation: Digi says that the vulnerability cannot be exploited remotely on Connectport LTS, Digi Passport, Dig
Digi says that the vulnerability cannot be exploited remotely on Connectport LTS, Digi Passport, Digi CM.
Mitigation: ICS-CERT recommends system administrators review the vendor patches and the NIST Vulnerability Summa
ICS-CERT recommends system administrators review the vendor patches and the NIST Vulnerability Summary for CVE-2014-7169e, to mitigate damage caused by the exploit.
Mitigation: If you are patched, but want to demonstrate that you are still vulnerable, you can use this command:
If you are patched, but want to demonstrate that you are still vulnerable, you can use this command: env X='() { (a)=>\' bash -c "echo date"
Mitigation: Please refer to SSA-86096 for more details at Siemens’ web site: (http://www.siemens.com/cert/adviso
Please refer to SSA-86096 for more details at Siemens’ web site: (http://www.siemens.com/cert/advisories)
Mitigation: echo vulnerable' bash -c "echo this is a test"
echo vulnerable' bash -c "echo this is a test"
Mitigation: (https://www.us-cert.gov/ncas/alerts/TA14-268A)
(https://www.us-cert.gov/ncas/alerts/TA14-268A)
Mitigation: (https://www.us-cert.gov/ncas/current-activity/2014/09/24/Bourne-Again-Shell-Bash-Remote-Code-Execut
(https://www.us-cert.gov/ncas/current-activity/2014/09/24/Bourne-Again-Shell-Bash-Remote-Code-Execution-Vulnerability)
Mitigation: }
}
Mitigation: Moxa is currently investigating a solution.
Moxa is currently investigating a solution.
Mitigation: There are several functional mitigations for this vulnerability including upgrading to a new version
There are several functional mitigations for this vulnerability including upgrading to a new version of bash, replacing bash with an alternate shell, limiting access to vulnerable services, and/or filtering inputs to vulnerable services.
Mitigation: (https://www.cert.gov.uk/resources/alerts/update-bash-vulnerability-aka-shellshock/)
(https://www.cert.gov.uk/resources/alerts/update-bash-vulnerability-aka-shellshock/)
Mitigation: Many UNIX-like operating systems, including Linux distributions, BSD variants, and Apple Mac OS X in
Many UNIX-like operating systems, including Linux distributions, BSD variants, and Apple Mac OS X include bash and are likely to be affected. Contact your respective Linux or Unix-based OS vendor(s) for updated information. A list of vendors can be found in CERT Vulnerability Note VU#252743.Vulnerability Note VU#252743, (http://www.kb.cert.org/vuls/id/252743)
Mitigation: Please see ABB’s public notification and mitigation strategies at: (http://www.abb.com/cawp/abbzh254
Please see ABB’s public notification and mitigation strategies at: (http://www.abb.com/cawp/abbzh254/2c9d1261d9fa1dcfc1257950002e4fbf.aspx)
Mitigation: Mageia (https://forums.mageia.org/en/viewtopic.php?f=5&t=8487)
Mageia (https://forums.mageia.org/en/viewtopic.php?f=5&t=8487)
Mitigation: (https://www.cve.org/CVERecord?id=CVE-2014-7169)
(https://www.cve.org/CVERecord?id=CVE-2014-7169)
Mitigation: however, solutions for CVE-2014-6271 do not completely resolve the vulnerability. It is advised to i
however, solutions for CVE-2014-6271 do not completely resolve the vulnerability. It is advised to install existing patches and pay attention for updated patches to address CVE-2014-7169.Vulnerability Summary for CVE-2014-7169 (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-7169)
Mitigation: Please see Cisco’s advisory for full list of affected products at: (http://tools.cisco.com/security/
Please see Cisco’s advisory for full list of affected products at: (http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140926-bash)
Mitigation: Red Lion Sixnet BT-5000 and 6000 Series, RAM 9000, RAM 6000, SN 6000 and M, A and R Series use the
Red Lion Sixnet BT-5000 and 6000 Series, RAM 9000, RAM 6000, SN 6000 and M, A and R Series use the bash shell but are not considered to be vulnerable or exploitable.
Mitigation: Ubuntu (http://www.ubuntu.com/usn/usn-2362-1/)
Ubuntu (http://www.ubuntu.com/usn/usn-2362-1/)
Mitigation: Please see eWON’s advisory for full list of affected products at: (http://www.talk2m.com/en/shellsho
Please see eWON’s advisory for full list of affected products at: (http://www.talk2m.com/en/shellshock-vulnerability-ewon-and-talk2m-on-the-safe-side.html?cmp_id=7&news_id=54&vID=17)
Mitigation: To check if you are patched, you can use the original test string: env x='() { :
To check if you are patched, you can use the original test string: env x='() { :
Mitigation: This command will return an error on a patched system, but it will still create a file with the outp
This command will return an error on a patched system, but it will still create a file with the output of `date` in a file called "echo".
Mitigation: As bash may be used as a third-party component, asset owners, operators, and ICS software developers
As bash may be used as a third-party component, asset owners, operators, and ICS software developers are encouraged to investigate the use of the affected versions of bash in their environments.
Patch: Update BIOS to V1.0.212N or later version
Update BIOS to V1.0.212N or later version
Mitigation: It can be found at the following location (login required): (https://buildingsdownloads.schneider-el
It can be found at the following location (login required): (https://buildingsdownloads.schneider-electric.com/documents/10807/250220/MPM+Series+-+Installation+Sheet/6b83cb2c-6d93-4e41-9902-2d8e13936727)
Mitigation: If unsure about the risks associated with upgrading MPMs to the new firmware, please contact your ac
If unsure about the risks associated with upgrading MPMs to the new firmware, please contact your account manager or technical support
Mitigation: Please see the MPM installation guide for more details about how to obtain and install firmware Vers
Please see the MPM installation guide for more details about how to obtain and install firmware Version 2.15
Mitigation: It is important to plan and execute the upgrade procedures to avoid unnecessary downtime and re-engi
It is important to plan and execute the upgrade procedures to avoid unnecessary downtime and re-engineering
Mitigation: Schneider Electric encourages all customers to upgrade their MPMs to the new Release 2.15 or higher
Schneider Electric encourages all customers to upgrade their MPMs to the new Release 2.15 or higher to mitigate the risks associated with this vulnerability
Mitigation: Schneider Electric encourages all customers to upgrade their MPMs to the newly released Version 2.15
Schneider Electric encourages all customers to upgrade their MPMs to the newly released Version 2.15 or higher to mitigate the risks associated with this vulnerability. It is important to plan the upgrade procedures before execution to avoid unnecessary downtime and re-engineering. If unsure about the risks associated with upgrading MPMs to the new firmware, please contact your account manager or technical support.
Mitigation: Please see the MPM installation guide for more details about how to obtain and install firmware Vers
Please see the MPM installation guide for more details about how to obtain and install firmware Version 2.15. It can be found at the following location (login required): (https://buildingsdownloads.schneider-electric.com/documents/10807/250220/MPM+Series+-+Installation+Sheet/6b83cb2c-6d93-4e41-9902-2d8e13936727)
Mitigation: For more information on this vulnerability and detailed instructions, please see Schneider Electric’
For more information on this vulnerability and detailed instructions, please see Schneider Electric’s security notification number SEVD-2015-254-01 at the following location: (www.schneider-electric.com/ww/en/download/document/SEVD-2015-254-01)

// References