CISA Warns of Critical Software Vulnerabilities in Industrial Devices
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-2060 | Weak Password Requirements vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Seri Weak Password Requirements vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenticated attacker to access to the module via FTP by dictionary attack or password sniffing. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2023-6943 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.9 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 Version1(GOT1000) versions 1.325P and prior, GT Designer3 Version1(GOT2000) versions 1.320J and prior, GX Works2 versions 1.11M to 1.626C, GX Works3 versions 1.106L and prior, MELSOFT Navigator versions 1.04E to 2.102G, MT Works2 versions 1.190Y and prior, MX Component versions 4.00A to 5.007H and MX OPC Server DA/UA all versions allows a remote unauthenticated attacker to execute a malicious code by RPC with a path to a malicious library while connected to the products. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2024-10386 +1 in the same advisory: …10387 | CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages to the device, potentially resulting in database manipulation. NVD description · AI analysis pending | 9.3 group max | 19% |
| — |
Full article378 words · extracted from infosecurity-magazine.com · click to collapse
The US Cybersecurity and Infrastructure Security Agency (CISA) has urged manufacturing companies to apply mitigations after one Rockwell Automation and several Mitsubishi systems were found to be vulnerable to cyber-attacks.
In a new industrial control systems (ICS) security advisory published on October 31, CISA shared details on four sets of recently discovered vulnerabilities affecting ICS systems:
- Rockwell Automation FactoryTalk ThinManager
- Mitsubishi Electric FA Engineering Software Products
- Mitsubishi Electric Multiple FA Engineering Software Products
- Mitsubishi Electric MELSEC iQ-R Series/iQ-F Series
The vulnerabilities affecting Rockwell Automation FactoryTalk ThinManager, CVE-2024-10386 and CVE-2024-10387, are a missing authentication for critical function and an out-of-bounds read, respectively. Successful exploitation of these vulnerabilities could allow an attacker to send crafted messages to the device, resulting in database manipulation or a denial-of-service condition.
These critical vulnerabilities (CVSS scores of 9.3 and 8.7) are exploitable remotely and require low attack complexity.
The major vulnerability affecting Mitsubishi Electric FA Engineering Software Products, CVE-2023-6943, has a CVSS score of 9.8.
It would allow an attacker to execute a malicious code by remotely calling a function with a path to a malicious library while connected to the products. As a result, unauthorized users may disclose, tamper with, destroy or delete product information, or cause a denial-of-service (DoS) condition on the products.
The major vulnerability affecting Mitsubishi Electric MELSEC iQ-R Series/iQ-F Series, CVE-2023-2060, has a CVSS score of 8.7.
This authentication bypass vulnerability in an FTP function on an EtherNet/IP module is due to weak password requirements. It would allow a remote, unauthenticated attacker to access the module via FTP by dictionary attack or password sniffing.
The advisory includes other vulnerabilities with lower severity scores.
CISA Mitigation Recommendations
Rockwell Automation and Mitsubishi shared specific recommendations to mitigate exploitation of all of these vulnerabilities. These can be found in CISA’s advisory.
CISA also recommended users take defensive measures to minimize the risk of exploitation of these vulnerabilities. These include:
- Minimizing network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet
- Locating control system networks and remote devices behind firewalls and isolating them from business networks
- When remote access is required, using more secure methods, such as virtual private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cisa-critical-vulnerabilities-ics/