Authentication bypass in TELEM-GWM and TELEM-GW6 - CVE-2018-10603

 

Authentication bypass in TELEM-GWM and TELEM-GW6 - CVE-2018-10603

Published: May 23, 2018


Vulnerability identifier: #VU12988
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10603
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication on the target system.

The vulnerability exists due to the RTU does not perform authentication of IEC-104 control commands. A remote attacker can bypass authentication and which may allow a rogue node a remote control of the industrial process.

Successful exploitation of this vulnerability may result in system compromise.


Affected software

TELEM-GWM
TELEM-GW6
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Opensuse

How to mitigate CVE-2018-10603

In most cases, the vulnerability can be resolved by proper configuration:

  • Using "other side IP" field in RTU configuration for every TCP/IP channel. This will minimize the risk of allowing unauthorized access and control over the communication channels (i.e., only trusted partners are allowed);
  • Using secure VPN channels;
  • Proper packet filtering by enabling firewall in RTU configuration. Note that the "interface" field of every communication channel must be properly set in RTU configuration when firewall is enabled.


External References

Related Security Bulletins