SB2019091723 - Multiple vulnerabilities in Schneider Electric Modicon Controllers
Published: September 17, 2019 Updated: October 3, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 14 secuirty vulnerabilities.
1) Uncaught exception (CVE-ID: CVE-2019-6809)
2) Reliance on untrusted inputs in a security decision (CVE-ID: CVE-2018-7850)
3) Uncaught Exception (CVE-ID: CVE-2018-7849)
The vulnerability allows a remote attacker to cause a denial of service (DoS) condition on the target system.The vulnerability exists due to improper data integrity check when sending files to the controller over Modbus. A remote attacker can cause a denial of service condition.
4) Information disclosure (CVE-ID: CVE-2018-7848)
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to improper input validation. A remote attacker can gain unauthorized access to SNMP information when reading files from the controller over Modbus.
5) Improper access control (CVE-ID: CVE-2018-7847)
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote attacker can overwrite configuration settings of the controller over Modbus and cause a denial of service condition or potential code execution on the target system.
6) Trust boundary violation (CVE-ID: CVE-2018-7846)
7) Authentication bypass by spoofing (CVE-ID: CVE-2018-7842)
The vulnerability allows a remote attacker to escalate privileges on the system.
8) Improper access control (CVE-ID: CVE-2019-6808)
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote attacker can overwrite configuration settings of the controller over Modbus and execute arbitrary code on the target system.
9) Uncaught Exception (CVE-ID: CVE-2019-6807)
The vulnerability allows a remote attacker to cause a denial of service (DoS) condition on the target system.The vulnerability exists due to uncaught exception vulnerability when writing sensitive application variables to the controller over Modbus. A remote attacker can cause a denial of service condition.
10) Uncaught Exception (CVE-ID: CVE-2018-7855)
The vulnerability allows a remote attacker to cause a denial of service (DoS) condition on the target system.The vulnerability exists due to uncaught exception vulnerability when sending invalid breakpoint parameters to the controller over Modbus. A remote
attacker can cause a denial of service condition.
11) Uncaught Exception (CVE-ID: CVE-2018-7854)
The vulnerability allows a remote attacker to cause a denial of service (DoS) condition on the target system.The vulnerability exists due to uncaught exception vulnerability when sending invalid debug parameters to the controller over Modbus. A remote attacker can cause a denial of service condition.
12) Uncaught Exception (CVE-ID: CVE-2018-7853)
The vulnerability allows a remote attacker to cause a denial of service (DoS) condition on the target system.The vulnerability exists due to uncaught exception vulnerability when reading invalid physical memory blocks in the controller over Modbus. A
remote attacker can cause a denial of service condition.
13) Uncaught Exception (CVE-ID: CVE-2019-6829)
The vulnerability allows a remote attacker to cause a denial of service (DoS) condition on the target system.The vulnerability exists due to uncaught exception vulnerability when writing to specific memory addresses in the controller over Modbus. A remote attacker can cause a denial of service condition.
14) Uncaught Exception (CVE-ID: CVE-2019-6828)
The vulnerability allows a remote attacker to cause a denial of service (DoS) condition on the target system.The vulnerability exists due to uncaught exception vulnerability when reading specific coils and registers in the controller over Modbus. A remote attacker can cause a denial of service condition.
Remediation
Install update from vendor's website.
References
- https://www.schneider-electric.com/en/download/document/SEVD-2019-134-11/
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0743
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0737
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0740
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0742
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0735
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0741
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0771
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0770
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0766
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0767
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0765
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0764