PT-2017-17383 · Siemens · Simatic Cp 44X-1 Rna
Published
2017-07-07
·
Updated
2017-12-30
·
CVE-2017-6868
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Siemens SIMATIC CP 44x-1 RNA versions prior to 1.4.1
Description
An issue with improper authentication was found, allowing an unauthenticated remote attacker to perform administrative actions on the Communication Process of the RNA series module. This is possible if network access to Port 102/TCP is available and the configuration file for the CP is stored on the RNA's CPU.
Recommendations
For versions prior to 1.4.1, update to version 1.4.1 or later to resolve the issue. As a temporary workaround, consider restricting network access to Port 102/TCP and ensuring the configuration file for the CP is not stored on the RNA's CPU to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simatic Cp 44X-1 Rna