Microsoft finds vulnerabilities it says could be used to shut down power plants
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-9013 | An issue was discovered in 3S-Smart CODESYS V3 products. An issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials being insufficiently protected during transport. All variants of the following CODESYS V3 products in all versions containing the CmpUserMgr component are affected regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control RTE V3, CODESYS Control RTE V3 (for Beckhoff CX), CODESYS Control Win V3 (also part of the CODESYS Development System setup), CODESYS V3 Simulation Runtime (part of the CODESYS Development System), CODESYS Control V3 Runtime System Toolkit, CODESYS HMI V3. NVD description · AI analysis pending | 8.8 | <1% |
| — |
Full article417 words · extracted from arstechnica.com · click to collapse
Microsoft said exploiting the vulnerabilities required a deep knowledge of Codesys’ proprietary protocol. It also requires attackers clear a tall hurdle in the form of gaining authentication to a vulnerable device. One way to achieve authentication is to exploit an already patched vulnerability tracked as CVE-2019-9013 in the event a PLC hasn’t yet been patched against it.
While the vulnerabilities are difficult to exploit, threat actors have been able to pull off such attacks in the past. Malware tracked as Triton and Trisis have been used in at least two critical facilities. The malware, attributed to the Kremlin, is designed to disable safety systems that detect and remediate unsafe conditions.
Such attacks are rare, however. Combined with the likelihood that the 15 vulnerabilities are patched in most previously vulnerable production environments, the dire consequences Microsoft is warning of appear unlikely.
In an email received after this post went live on Ars, Jimmy Wylie and Sam Hanson, both researchers at industrial control security firm Dragos, provided this assessment of the vulnerabilities:
Given CODESYS’s market share and cross-industry customer base, vulnerabilities like these discovered by Microsoft, should be taken seriously by customers and vendors alike. That said, CODESYS isn’t widely used power generation so much as discrete manufacturing and other types of process control. So that in itself should allay some concern when it comes to the potential to “shut down a power plant”.
When looking specifically at these vulnerabilities and the published advisory from CODESYS, they all require authentication for successful exploitation. But if an adversary is authenticated (has the username and password) to your PLC, you’ve got bigger problems than these CVEs, and they can do all kinds of things that make the CVEs unnecessary.
Either way, simply having an RCE or DOS exploit isn’t the same as having the ability to shut down a power plant or say, make specific changes to a manufacturing process. For example, the TRISIS attack in 2017 included a 0-day exploit for that safety controller, and while we know the attackers were there for quite some time, they were never able to do anything truly disastrous, beyond some financial consequences. The reason is that industrial systems are extremely complex, and being able to access one part doesn’t necessarily mean the whole thing will come crashing down. These things aren’t wobbly jenga towers, where one brick means imminent collapse. They’re more like skyscrapers engineered for resiliency against a variety of factors like wind and earth quakes.
The vulnerabilities are tracked as:
Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2023/08/microsoft-finds-vulnerabilities-it-says-could-be-used-to-shut-down-power-plants/