PT-2021-2204 · Siemens · C-Plug+2

Published

2021-01-12

·

Updated

2022-12-13

·

CVE-2020-28391

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions: SCALANCE X-200 switch family (incl. SIPLUS NET variants) versions prior to V5.2.5 SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) versions prior to V5.5.0 SCALANCE X-200RNA switch family versions prior to V3.2.7
Description: A vulnerability has been identified in the SCALANCE X-200 switch family, including SIPLUS NET variants, and other related devices. The issue arises when these devices are used with C-PLUG, as they utilize a hardcoded private RSA-key shipped with the firmware-image instead of creating a new unique key upon factory reset. This situation could be leveraged by an attacker to create a man-in-the-middle situation, allowing them to decrypt previously captured traffic. The vulnerability is related to the use of a hardcoded cryptographic key in the C-PLUG memory module of these industrial switches.
Recommendations: For SCALANCE X-200 switch family (incl. SIPLUS NET variants) versions prior to V5.2.5, update to version V5.2.5 or later to resolve the issue. For SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) versions prior to V5.5.0, update to version V5.5.0 or later to resolve the issue. For SCALANCE X-200RNA switch family versions prior to V3.2.7, update to version V3.2.7 or later to resolve the issue. As a temporary workaround, consider restricting the use of C-PLUG with these devices until a patch is applied.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2021-01113
CVE-2020-28391

Affected Products

C-Plug
Scalance X-200Irt Switch Family
Siplus Net