(I)IoT Security News
News, Vulnerabilities

Weidmueller Industrial Ethernet Switches

1. EXECUTIVE SUMMARY

2. RISK EVALUATION

Successful exploitation of these vulnerabilities could allow a remote attacker to gain unauthorized access to the device, affecting the confidentiality, integrity, and availability of the device the attacker is targeting.

3. TECHNICAL DETAILS

3.1 AFFECTED PRODUCTS

The following versions of industrial Ethernet switches are affected:

3.2 VULNERABILITY OVERVIEW

3.2.1    IMPROPER RESTRICTION OF EXCESSIVE AUTHENTICATION ATTEMPTS CWE-307

The authentication mechanism has no brute-force prevention.

CVE-2019-16670 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

3.2.2    UNCONTROLLED RESOURCE CONSUMPTION CWE-400

Remote authenticated users can crash a device by using a special packet.

CVE-2019-16671 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

3.2.3    MISSING ENCRYPTION OF SENSITIVE DATA CWE-311

Sensitive credentials data is transmitted in cleartext.

CVE-2019-16672 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

3.2.4    UNPROTECTED STORAGE OF CREDENTIALS CWE-256

Passwords are stored in cleartext and can be read by anyone with access to the device.

CVE-2019-16673 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

3.2.5    PREDICTABLE FROM OBSERVABLE STATE CWE-341

Authentication information used in a cookie is predictable and can lead to admin password compromise when captured on the network.

CVE-2019-16674 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

3.3 BACKGROUND

3.4 RESEARCHER

CERT@VDE reported these vulnerabilities to CISA.

4. MITIGATIONS

CERT@VDE and Weidmueller report the following mitigations:

Solutions for CVE-2019-16672

Solution for vulnerabilities, valid for switch series IE-SW-VL05M and IE-SW-VL08MT

Solution for vulnerabilities valid for switch series IE-SW-PL08M, IE-SW-PL10M, IE-SW-PL16M, IE-SW-PL18M, and IE-SW-PL09M

Solution for CVE-2019-16670, CVE-2019-16671, CVE-2019-16673, and CVE-2019-16674

Valid for switch series IE-SW-VL05M, IE-SW-VL08MT, IE-SW-PL08M, IE-SW-PL10M, IE-SW-PL16M, IE-SW-PL18M, and IE-SW-PL09M

Note: After disabling the unencrypted search service, the switches can no longer be found or configured with the current “WM Switch Utility.”

Web interface settings are not affected by this configuration.

Below are the patched versions available for the respective industrial ethernet switch model:

For more information see the CERT@VDE advisory located at: https://cert.vde.com/en-us/advisories/vde-2019-018 or contact Weidmueller at www.weidmueller.com/service.

CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Specifically, users should:

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on us-cert.gov. Several recommended practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

Additional mitigation guidance and recommended practices are publicly available on the ICS webpage on us-cert.gov in the Technical Information Paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing any suspected malicious activity should follow their established internal procedures and report their findings to CISA for tracking and correlation against other incidents.

Source:

https://www.us-cert.gov/ics/advisories/icsa-19-339-02

Related posts

Flipping Pages: An analysis of a new Linux vulnerability in nf_tables and hardened exploitation techniques

(I) IoT
8 months ago

Linux Kernel Prior to 5.0.8 Vulnerable to Remote Code Execution

(I) IoT
6 years ago

Siemens EN100 Ethernet Module

milica@ast.co.rs
2 years ago
Exit mobile version