Showing posts with label Sergey Temnikov. Show all posts
Showing posts with label Sergey Temnikov. Show all posts

Saturday, March 21, 2020

Public ICS Disclosures – Week of 3-14-20


This week we have four vendor disclosures for products from Bosch, Schneider, Moxa and Eaton. There are also two interesting cybersecurity related announcements from Phillips and Meinberg.

Bosch Advisory


Bosch published an advisory describing an improper input validation vulnerability in the Bosch Rexroth S20-PN-BK+/S20-ETH-BK fieldbus couplers. The vulnerability is in a third-party component of the devices from Phoenix Contact that was originally reported in September 2018. Bosch provided generic controls to mitigate the vulnerability. These are the same controls recommended by Phoenix Contact.

Schneider Advisory


Schneider published an advisory describing an injection vulnerability in their Modicon Controllers, EcoStruxure™ Control Expert and Unity Pro Programming Software. The vulnerability was reported by Airbus Cybersecurity. Schneider has hotfixes available to mitigate this vulnerability.

Schneider reports that:

“Since alerting us to the vulnerability, Airbus Cybersecurity and Schneider Electric have collaborated to validate the research and to assess its true impact. Our mutual findings demonstrate that while the discovered vulnerability affects Schneider Electric offers, it equally impacts many other vendors and the global industrial automation market in general, especially when the baseline assumption of the attack technique Airbus Cybersecurity demonstrated is considered. Given certain conditions, and assuming an attacker has access to the network, many devices available from several different industrial control vendors are likewise vulnerable.”

Schneider provides links to the Airbus Cybersecurity site and blog for further details. As of this morning I can find nothing on that site.

Moxa Advisory


Moxa published an advisory describing two vulnerabilities in the Moxa OnCell Central Manager Cellular Management Software. The vulnerability was reported by Sergey Temnikov from Kaspersky ICS CERT. These vulnerabilities are in a third-party component; Apache Flex BlazeDS. Moxa has a security patch that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Deserialization of trusted data - CVE-2019-15696 (Apache CVE-2017-5641); and
• Information exposure - CVE-2019-15697 (Apache CVE-2015-3269)

The CVE links are to the Kaspersky advisories. Kaspersky has provided the original CVE numbers for the underlying vulnerability. There is at least one publicly available exploit for the original information exposure vulnerability.

Eaton Advisory


Eaton published an advisory describing an eval injection vulnerability in the Eaton  UPS Companion software. The vulnerability was reported by Ravjot Singh Samra. Eaton has a new version that mitigates the vulnerability. There is no indication that Samra has been provided an opportunity to verify the efficacy of the fix.

Cybersecurity Announcements


Phillips published a notice announcing that the Philips Security Center of Excellence was named the first medical device manufacturer to receive a new Underwriters Laboratories (UL) product cybersecurity testing certification (UL IEC 62304).

Meinberg published a notice concerning their continued operations during the COVID-19 outbreak.

Commentary


It is not unusual to see third-party vulnerabilities being reported in control systems. The two reports today are disheartening because of the elapsed time between the reporting of the underlying vulnerability and this week’s advisories. The use of third-party software and libraries is almost unavoidable in the current development environment; companies just cannot afford (time or money) to write complex software from scratch.

We expect manufacturers to watch for vulnerability announcements for the equipment and software they use in their manufacturing processes and then conduct a risk assessment to determine if that vulnerability provides an unacceptable risk to their operations. We need to expect control system vendors to perform the same sort of process. Perhaps companies buying control system components should be asking their vendors to describe their process for identifying and fixing third-party vulnerabilities in their products.

Tuesday, November 19, 2019

1 Advisory Published – 11-19-19


Today the CISA NCCIC-ICS published a control system security advisory for products from Flexera.

Flexera Advisory

This advisory describes four vulnerabilities in the Flexera FlexNet Publisher software license manager. The vulnerabilities were reported by Sergey Temnikov of Kaspersky. Flexera has a new version that mitigates the vulnerability. There is no indication that Temnikov has been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Improper input validation (3) - CVE-2018-20031, CVE-2018-20032 and CVE-2018-20034; and
• Memory corruption - CVE-2018-20033

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to deny the acquisition of a valid license for legal use of the product. The memory corruption vulnerability could allow remote code execution.

Previously Reported


These same four CVE#s were reported by Schneider in their Floating License Manager back in May 14th, 2019 followed by an NCCIC-ICS advisory on July 11th, 2019. NIST reported the CVE#s as being in the FlexNet Publisher on March 25th, 2019 with the following link to the Flexera advisory (registration required).

The FlexNet Publisher is fairly obviously being used by Schneider. We have seen this sort of vulnerability pairing between the two products on multiple occasions. I suspect that other vendors are also using FlexNet Publisher in their products. Should we be seeing more vulnerabilities on these 4 CVE’s? Apparently only if other researchers like Temnikov check other license managers to see if they can see the same problem.

Friday, May 17, 2019

9 Advisories and 4 Updates Published – 05-14-19


Tuesday the DHS NCCIC-ICS published nine control system security advisories for products from Siemens (8) and Omron and updated four previously published advisories for Siemens (3) and WIBU-Key.

SIMATIC Panels Advisory


This advisory describes three vulnerabilities in the Siemens SIMATIC WinCC Runtime Advanced, WinCC Runtime Professional, WinCC (TIA Portal); HMI Panels. The vulnerabilities are self-reported. Siemens has updates available for many of the affected products.

The three reported vulnerabilities are:

Use of hard-coded credentials - CVE-2019-6572;
Insufficiently protected credentials - CVE-2019-6576; and
Cross-site scripting - CVE-2019-6577

NCCIC-ICS reports that a relatively low-skilled attacker with network access could remotely exploit these vulnerabilities to allow an attacker with network access to the device to read/write variables via SNMP.

NOTE: The NCCIC-ICS advisory references the incorrect Siemens advisory, it should have been SSA-804486. The incorrect advisory listed is for a different vulnerability in a similar list of products.

SIMATIC PCS7 Advisory


This advisory describes three vulnerabilities in the Siemens SIMATIC PCS 7, WinCC Runtime Professional, WinCC (TIA Portal) products. The vulnerabilities were reported by Vladimir Dashchenko and Sergey Temnikov from Kaspersky Lab, CNCERT/CC, and ChengBin Wang from Guoli Security Technology. Siemens has an update for one of the affected products and has provided generic workarounds for the remainder pending mitigation development. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

SQL injection - CVE-2019-10916;
Uncaught exception - CVE-2019-10917; and
Exposed dangerous method or function - CVE-2019-10918

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to execute arbitrary commands on the affected system.

SCALANCE Advisory


This advisory describes five vulnerabilities in the Siemens SCALANCE W1750D. The vulnerability is self-reported. Siemens has a new version that mitigates the vulnerability.

The five reported vulnerabilities are:

Command injection (2) - CVE-2018-7084 and CVE-2018-7082;
Information exposure (2) - CVE-2018-7083 and CVE-2018-16417; and
Cross-site scripting - CVE-2018-7064

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker execute arbitrary commands within the underlying operating system, discover sensitive information, take administrative actions on the device, or expose session cookies for an administrative session.

Perfect Harmony Advisory


This advisory describes an improper input validation vulnerability in the Siemens SINAMICS PERFECT HARMONY GH180 medium voltage converter. The vulnerability is self-reported. Siemens has an upgrade available to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial-of-service condition.

NXG I and II Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the Siemens SINAMICS PERFECT HARMONY GH180 Drives with NXG I and NXG II controls. The vulnerability is self-reported. Siemens has an upgrade available to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with access to the Ethernet Modbus Interface could exploit the vulnerability to cause a denial-of-service condition exceeding the number of available connections.

LOGO!8 Advisory


This advisory describes three vulnerabilities in the Siemens LOGO!8 BM programmable logic controller. The vulnerability was reported by Manuel Stotz and Matthias Deeg from SySS GmbH. Siemens has provided generic mitigation measures for the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

Missing authentication for critical function - CVE-2019-10919;
Improper handling of extra values - CVE-2019-10920; and
Plain-text storage of a password - CVE-2019-10921

NCCIC-ICS reports that a relatively low-skilled attacker with access to port 10005/tcp could remotely exploit the vulnerability to allow device reconfiguration, access to project files, decryption of files, and access to passwords.

SIMATIC WinCC Advisory


This advisory describes a missing authentication for critical function vulnerability in the Siemens SIMATIC WinCC and SIMATIC PCS 7 products. The vulnerability was reported by Vladimir Dashchenko and Sergey Temnikov from Kaspersky Lab. Siemens has newer versions that along with enabling ‘encrypted communications’ mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an unauthenticated attacker with access to the affected devices to execute arbitrary code.

Omron Advisory


This advisory describes an untrusted search path vulnerability in the Omron Network Configurator for DeviceNet. The vulnerability was anonymously reported by n0b0dy. Omron is working on an update to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to achieve arbitrary code execution under the privileges of the application.

Industrial Products with OPC Update


This update provides additional information on an advisory that was originally published on April 9th, 2019. The new information includes:

Clarifying product names for SIMATIC HMI Products;
Adding solution for SIMATIC S7-1500 CPU family; and
Modifying affected versions for SIMATIC Net PC Software

SIMATIC Update


This update provides additional information on an advisory that was originally published on April 9th, 2019. The new information from Siemens included:

Specification for SINAMICS products;
Adding solution for SIMATIC S7-1500 CPU family; and
Adding solution for SIMATIC S7-PLCSIM Advanced

NCCIC-ICS also added a number of affected products that were missing from their original advisory.

WIBU Key Update


This update provides additional information on an advisory that was originally published on February 12th, 2019 and updated on March 12th, 2019 and again on April 9th, 2019. The new information includes:

A reference to a new Siemens Advisory;
Adding new affected products from Siemens.

S7-400 Update


This update provides additional information on an advisory that was originally published on November 13th, 2018. The new information includes:

Adding the names of the researchers who reported the vulnerabilities; and
Adding solution for S7-400H V6.

Wednesday, April 4, 2018

ICS-CERT Publishes Siemens Advisory


Yesterday the DHS ICS-CERT published a control system advisory for products from Siemens. These are the vulnerabilities I reported on Saturday.

This advisory describes eight vulnerabilities in the Siemens Building Technologies Products. These are Gemalto Sentinel LDK RTE vulnerabilities that have been previously reported by Siemens in other products. The vulnerabilities were reported by Sergey Temnikov and Vladimir Dashchenko from Kaspersky Labs. Siemens has a newer version of the License Management System (LMS) that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The eight reported vulnerabilities are:

• Stack-based buffer overflow (2) - CVE-2017-11496, CVE-2017-11497;
• Security features - CVE-2017-12819;
• Improper restriction of operations within the bounds of a memory buffer - CVE-2017-12821;
• Null pointer dereference - CVE-2017-11498;
• XML entity expansion - CVE-2017-12818;
• Heap-based buffer overflow - CVE-2017-12820; and
Improper access control - CVE-2017-12822

Again, Siemens is not reporting all 14 of the Gemalto vulnerabilities. I would suspect that this is because the Siemens implementation of the license manager does not include the features affected by the other vulnerabilities.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow arbitrary code execution, NTLM-relay attacks, denial of service of the remote process, remote denial of service, and/or allow the administrative interface to be remotely enabled and disabled without authentication.

NOTE: Siemens announced that it had updated this advisory yesterday. The update includes a link to download the LMS.

Saturday, March 31, 2018

Public ICS Disclosures – Week of 03-24-18


This week we have one vendor notification from Siemens and two exploits for previously disclosed vulnerabilities in products from Hikvision and Advantech.

Siemens Advisory


This advisory describes 8 vulnerabilities in Siemens Building Technologies Products. The vulnerabilities were reported by Sergey Temnikov and Vladimir Dashchenko from Kaspersky Lab. The newest version of the license management systems for the affected products mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

These reported vulnerabilities are the Gemalto Sentinel LDK RTE vulnerabilities that have been previously reported by Siemens in other products.

Hikvision Exploit


This exploit provides proof-of-concept code for an attack on IP cameras from Hikvision. The backdoor vulnerability was previously disclosed on May 4th, 2017. The exploit was published by Matamorphosis on Exploit-DB.com.


Advantech Exploit


This exploit provides proof-of-concept code for an attack on the WebAccess products from Advantech. The stack-based buffer overflow vulnerability was previously disclosed on January 14th, 2016. The exploit was published by Chris Lyne on Expoit-DB.com.

Commentary


I noted in an earlier post that this set of Gemalto vulnerabilities probably effects a wide range of ICS products (including products from at least three other major ICS vendors) and suggested that ICS-CERT should have done an alert on these vulnerabilities. It is not too late to do so.

While both of the exploited vulnerabilities describe above were previously reported by ICS-CERT as not having publicly available exploits, ICS-CERT does not make a practice of removing that language from their advisories when exploits do become publicly available. It would probably be valuable to the ICS security community if that practice were changed.

Thursday, January 18, 2018

ICS-CERT Publishes an Advisory and an Update for Siemens Products

Today the DHS ICS-CERT published a new control system security advisory and an updated advisory for products from Siemens.

Siemens Advisory


This advisory describes multiple vulnerabilities in the Siemens SIMATIC WinCC Add-On (license manager software). The vulnerabilities were reported by Sergey Temnikov and Vladimir Dashchenko from Kaspersky Lab. Siemens reports that a third party supplier (Gemalto) has released an updated installer that mitigates the vulnerabilities. The Siemens security advisory reports that SIMATIC WinCC Add-Ons released in 2015 and earlier include a vulnerable version of Gemalto Sentinel LDK RTE. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Stack-based buffer overflow (2) - CVE-2017-11496 and CVE-2017-11497; and
• Improper input validation - CVE-2017-11498

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow remote code execution or a denial of service condition.

NOTE: Looking at the Gemalto product page, it looks like they may have sold this product to multiple vendors. It will be interesting to see if other vendors come forward to recommend installing the same (or similar) updates to their systems.

Siemens Update


This update provides new information for an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th, and most recently November 28th. The update provides new version information and mitigation links for:

• SIMOCODE pro V PROFINET: All versions prior to V2.0.0

NOTE: The latest version of this Siemens security advisory is in their new format which makes checking against previous versions potentially tedious. Fortunately, Siemens (as opposed to ICS-CERT) annotates the specific changes made (as opposed to noting the section in which the changes were made) to their advisories.

Other Siemens Notes



Siemens also published two other advisory documents today that did not make it into the ICS-CERT publication schedule. One was a new advisory and one was an update. Since tomorrow is Friday and ICS-CERT seldom publishes advisories on Friday, I suspect that we will see these two next week.

Friday, November 3, 2017

ICS-CERT Publishes Two Advisories

Yesterday the DHS ICS-CERT published two control system security advisories for products from Advantech and Siemens.

Advantech Advisory


This advisory describes two vulnerabilities in the Advantech WebAccess HMI platform. The vulnerabilities were reported by Steven Seeley via the Zero Day Initiative. Advantech released a new version to mitigate the vulnerability. There is no indication that Seeley has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2017-14016; and
• Untrusted pointer dereference - CVE-2017-12719

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to allow remote code execution.

Siemens Advisory


This advisory describes an improper input validation vulnerability in the Siemens SIMATIC PCS7 distributed control system. The vulnerability was reported by Sergey Temnikov and Vladimir Dashchenko of Kaspersky Labs. Siemens has issued an update for some versions to mitigate the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix. Siemens has provided interim mitigation suggestions pending updates to the other versions.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to crash services on the device. The Siemens security advisory reports that: “The attacker must be member of the group administrators and have network access to an affected system.”


NOTE: Siemens reported this vulnerability on October 18th.

Thursday, August 31, 2017

ICS-CERT Publishes Six Advisories

Today the DHS ICS-CERT published six control system security advisories for products from Automated Logic Corporation, Moxa, OPW Fuel Management Systems, and Siemens (3). The ALC advisory was originally published on the NCCIC Portal on May 30, 2017.

ALC Advisory


This advisory describes an improper restriction of XML external entity reference vulnerability in the ALC ALC WebCTRL, Liebert SiteScan, and Carrier i-VU building automation applications. The vulnerability was reported by Evgeny Ermakov from Kaspersky Lab. ICS-CERT reports that ALC has developed patches for the WebCTRL and Carrier i-VU applications that mitigate the vulnerability. There is no mention of mitigation measures for the Liebert SiteScan. There is no indication that Ermakov has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to the disclosure of confidential data, denial of service (DoS), spoofing of a request from an upstream device, port scanning from the perspective of the machine where the parser is located, and other system impacts.

Moxa Advisory


This advisory describes an improper neutralization of special elements used in an SQL command in the Moxa SoftCMS Live Viewer, a video surveillance software designed for industrial automation systems. The vulnerability was reported by Ziqiang Gu from Huawei WeiRan Labs. Moxa has provided a software update to mitigate the vulnerability. There is no indication that Gu has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerability to access SoftCMS Live Viewer without knowing the user’s password.

OPW Advisory


This advisory describes two vulnerabilities in the OPW Fuel Management Systems SiteSentinel Integra and SiteSentinel iSite consoles. The vulnerabilities were reported by Semen Rozhkov of Kaspersky Lab. OPW has produced a new version to mitigate the vulnerability and recommends that it be applied even if the systems are protected from exploitation by running off-line or located on a protected network. There is no indication that Rozhkov has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Missing authentication for a critical function - CVE-2017-12733; and
• Improper neutralization of special elements used in an SQL command - CVE-2017-12731

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to create an account on the device or access the device’s database.

NOTE: I have never had to update software on an ICS device before, but it seems to me that if it is normally as complicated as the procedures provided for these devices then it would be a wonder if anyone ever upgraded device software.

7KM PAC Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the Siemens 7KM PAC Switched Ethernet PROFINET expansion module. Siemens is self-reporting this vulnerability. They have produced a firmware update to mitigate the vulnerability.

ICS-CERT reports that a relatively low skilled attacker with uncharacterized access could exploit the vulnerability to cause a denial-of-service condition in the affected component that may require a manual restart of the main device to recover. The Siemens security advisory notes that the attacker must have network access to the local Ethernet segment (Layer 2) to exploit the vulnerability.

LOGO Advisory


This advisory describes two vulnerabilities in the Siemens LOGO!8 BM devices. The first vulnerability listed below was reported by Maxim Rupp; the second was self-reported by Siemens. Siemens has developed a new firmware version that mitigates the vulnerabilities. There is no indication that Rupp was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Insufficiently protected credentials - CVE-2017-12734; and
• Channel accessible by non-endpoint - CVE-2017-12735

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to hijack existing web sessions. The Siemens security advisory notes that the first vulnerability requires network access to the integrated web server on port 80/tcp to exploit.

Industrial Products Advisory


This advisory describes an improper restriction of XML external entity reference vulnerability in the Siemens Industrial products using the Discovery Service of the OPC UA protocol stack by the OPC foundation. The vulnerability was reported by Sergey Temnikov of Kaspersky Lab. Siemens has produced new software versions for some of the listed products; other updates are still pending. There is no indication that Temnikov has been provided an opportunity to verify the efficacy of the fix.


ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to access various resources. The Siemens security advisory reports that an attacker must have network access to the affected devices to exploit the vulnerability.

Thursday, March 9, 2017

ICS-CERT Publishes Schneider Advisory

Today the DHS ICS-CERT published a control system security advisory for the Schneider Electric ClearSCADA product. It describes an improper input validation vulnerability. The vulnerability was reported by Sergey Temnikov and Vladimir Dashchenko of Kaspersky Lab’s Critical Infrastructure Defense Team. Schneider has produced new updates to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to cause the ClearSCADA server process and communications driver processes to terminate.


Friday, July 29, 2016

ICS-CERT Publishes Four Advisories

Earlier this week the DHS ICS-CERT published four advisories for industrial control system vulnerabilities in products from Rockwell and Siemens.

Rockwell Advisory


This advisory describes two authentication vulnerabilities in the Rockwell Automation FactoryTalk EnergyMetrix application. These vulnerabilities were self-reported. This advisory was originally released on the US CERT Secure Portal on June 21, 2016.

The two vulnerabilities are:

• Insufficient session expiration - CVE-2016-4531; and
• SQL injection - CVE-2016-4522

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to gain unauthenticated access to the affected system.

Siemens SINEMA Advisory


This advisory describes a cross-site scripting vulnerability in the Siemens SINEMA Remote Connect Server (VPN) application. The vulnerability was reported by Antonio Morales Maldonado of INNOTEC SYSTEM, and Alexander Van Maele and Tijl Deneut of Howest. Siemens has produced an update to mitigate the vulnerability but there is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to gain ongoing access to these devices, but a social engineering attack would be required.

Siemens SIMATIC Net PC Advisory


This advisory describes a denial-of-service vulnerability in the Siemens SIMATIC NET PC-Software. The vulnerability was reported by Vladimir Dashchenko and Sergey Temnikov from Kaspersky Labs. Siemens has produced a new version to mitigate the vulnerability but there is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to cause a denial-of-service of the OPC-Unified Architecture (UA) service. Siemens reports that the attacker would require network access to exploit this vulnerability.

Siemens SIMATIC WinCC Advisory


This advisory describes two separate input validation vulnerabilities in the Siemens SIMATIC WinCC, PCS 7, and WinCC Runtime Professional applications. The vulnerabilities were reported by Sergey Temnikov and Vladimir Dashchenko from Kaspersky Lab. Siemens has produced updates to mitigate these vulnerabilities, but there is no indication that the researchers have been provided an opportunity to verify the efficacy of the fixes.


ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to extract arbitrary files or remotely execute arbitrary code. Siemens reports that the attacker would require network access to exploit this vulnerability.
 
/* Use this with templates/template-twocol.html */