New vuln discovered in Schneider Electric software, patches already issued
Full article823 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Tenable found a flaw that would allow attackers to execute arbitrary code and move laterally within an organization’s network.
A significant vulnerability in Schneider Electric software used at manufacturing and energy facilities could allow hackers to execute arbitrary code and, “in a worst-case scenario, disrupt or cripple plant operations,” cybersecurity firm Tenable announced Wednesday.
According to the Maryland-based company, an attacker without credentials could use the vulnerability to compromise Schneider Electric software used to develop – and build applications for – the human machine interfaces (HMIs) and supervisory control and data acquisition (SCADA) systems that drive industrial automation. After compromising a machine, a hacker could move laterally within an organization’s network to carry out other attacks, according to Tenable.
Schneider Electric issued patches for the software – versions of InduSoft Web Studio and InTouch Machine Edition – and urged affected customers to swiftly apply them lest an attacker use the vulnerability to “remotely execute code with high privileges.”
“This Schneider Electric vulnerability is particularly concerning because of the potential access it grants cybercriminals looking to do serious damage to mission-critical systems that quite literally power our communities,” Dave Cole, Tenable’s chief product officer, said in a statement that praised Schneider Electric for quickly releasing a patch.
Tenable cast the new vulnerability as another chink in the armor of an increasingly digital infrastructure.
“With the growing adoption of distributed and remote monitoring in industrial environments, [operational technology] and IT are converging,” Columbia, Md.-based Tenable said.
The increasing connectivity of OT systems opens up new vulnerabilities to hacking, the firm added.
Software that supports industrial control systems has been in the security limelight in recent months.
Last August, hackers targeted Schneider Electric’s Triconex safety system software in a rare and sophisticated ICS-tailored attack, causing an unidentified energy plant to shut down. CyberScoop reported that the affected facility was an oil and gas plant in Saudi Arabia, and that the attackers’ malware, dubbed Triton or Trisis, had been stumping security experts.
Schneider Electric won plaudits for its transparency from cybersecurity experts after the energy software giant presented lessons learned from the incident at a popular conference.
Public disclosure of the new HMI/SCADA software vulnerability comes weeks after U.S. officials warned that Russian government hackers were targeting the U.S. energy and manufacturing sectors, among others, in a two-year, multi-stage campaign.
More Scoops
Dragos: Despite AI use, new malware targeting water plants is ‘hype’
ZionSiphon was designed to find and sabotage Israelis’ water supply. An OT expert said it appears to be ineffective and the work of amateurs using AI.
After major Poland energy grid cyberattack, CISA issues warning to U.S. audience
Mitsubishi Electric to acquire Nozomi Networks in $1 billion deal
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/schneider-electric-tenable-hmi-vulnerability/