SB2019060615 - Man-in-the-Middle (MitM) attack in PLCNext AXC F 2152



SB2019060615 - Man-in-the-Middle (MitM) attack in PLCNext AXC F 2152

Published: June 6, 2019

Security Bulletin ID SB2019060615
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Man-in-the-Middle (MitM) attack (CVE-ID: CVE-2019-10997)

The vulnerability allows a remote attacker to conduct man-in-the-middle attack.

The vulnerability exists due to a denial of service condition when PLC service is crashed. An attacker trying to connect to the device using a man-in-the-middle setup may crash the PLC service, so the device must then be rebooted, or the PLC service must be restarted manually via Linux shell. 

Vulnerability affects following PLCNext AXC F 2152 products:
  • AXC F 2152: article number 2404267
  • AXC F 2152: article number 1046568 (Starterkit)

Remediation

Install update from vendor's website.