PT-2017-17383 · Siemens · Simatic Cp 44X-1 Rna
Publicado
2017-07-07
·
Atualizado
2017-12-30
·
CVE-2017-6868
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Siemens SIMATIC CP 44x-1 RNA versions prior to 1.4.1
Description
An issue with improper authentication was found, allowing an unauthenticated remote attacker to perform administrative actions on the Communication Process of the RNA series module. This is possible if network access to Port 102/TCP is available and the configuration file for the CP is stored on the RNA's CPU.
Recommendations
For versions prior to 1.4.1, update to version 1.4.1 or later to resolve the issue. As a temporary workaround, consider restricting network access to Port 102/TCP and ensuring the configuration file for the CP is not stored on the RNA's CPU to minimize the risk of exploitation.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Simatic Cp 44X-1 Rna