As has become typical for the weekend following the 2nd Tuesday, we have a Part 2 to cover the disclosures and updates from Schneider and Siemens that were not addressed by NCCIC-ICS.
Schneider Advisories
Schneider published an advisory describing three vulnerabilities in their Easergy T300 RTU. The vulnerabilities are self-reported. Schneider has new firmware versions that mitigate the vulnerabilities.
The three reported vulnerabilities are:
Files or directories accessible to external parties - CVE-2021-22769,
Information exposure - CVE-2021-22770, and
Improper neutralization of formula elements in a CSV file - CVE-2021-22771
Schneider published an advisory describing a deserialization of untrusted data vulnerability in their SoSafe Configurable product. The vulnerability was reported by Amir Preminger of Claroty. Schneider has a new version that mitigates the vulnerability. There is no indication that Preminger has been provided an opportunity to verify the efficacy of the fix.
Schneider published an advisory describing a missing authentication for critical function vulnerability in their Easergy T200 RTU. The vulnerability is self-reported. Schneider has new versions available that mitigate the vulnerability.
Schneider published an advisory describing thirteen vulnerabilities in their EVlink City, Parking and Smart Wallbox products. The vulnerabilities were reported by Tony Marcel Nasr, Wu Ming of BaCde, Chen Huajiang of Kevin2600, Stefan Viehböck of SEC Consult, and Guillaume Jonville of B2EI. Schneider has new versions available that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.
The thirteen reported vulnerabilities are:
Cross-site scripting - CVE-2021-22706,
Use of hard-coded credentials (2) - CVE-2021-22707 and CVE-2021-22730,
Improper verification of cryptographic signature - CVE-2021-22708,
Information exposure (2) - CVE-2021-22721 and CVE-2021-22728,
Stored cross-site scripting - CVE-2021-22722,
Cross-site request forgery - CVE-2021-22723,
Server-side request forgery - CVE-2021-22726,
Insufficient entropy - CVE-2021-22727,
Use of hard-coded password - CVE-2021-22729,
Unverified password change - CVE-2021-22773, and
Use of one-way hash without a salt - CVE-2021-22774
Siemens Advisories
Siemens published an advisory discussing two buffer over-read vulnerabilities in a number of their products that utilize the WIBU CodeMeter Runtime product. WIBU reported these vulnerabilities in June and proof-of-concept code was available at that time. Siemens has new versions for some of the affected products that mitigate the vulnerabilities.
NOTE: NCCIC-ICS has not publish an advisory for the underlying WIBU vulnerabilities either.
Siemens published an advisory discussing a null pointer dereference vulnerability in a number of their products that utilized OpenSSL. OpenSSL reported this vulnerability in March, 2021. Siemens has new versions for some of the affected products that mitigate the vulnerabilities.
Siemens published an advisory discussing the FragAttacks WiFi vulnerabilities in their SCALANCE product line. Siemens provides generic workarounds pending mitigation development.
NOTE: NCCIC-ICS has not published an advisory for the FragAttacks vulnerabilities.
Schneider Updates
Schneider published an update for their Ripple20 advisory that was originally published on June 23, 2020 and most recently updated on May 11th, 2021. The new information includes adding remediation for:
TM3 bus coupler modules – EIP/SL/CANOpen, and
Acti9 Smartlink EL B A9XELC08
Schneider published an update for their APC Ripple20 advisory that was originally published on June 23, 2020 and most recently updated on January 12th, 2021. The new information includes adding remediations for:
Uninterruptible Power Supply (UPS),
Rack Power Distribution Units (rPDU),
Battery Management,
Rack Automatic Transfer Switch (ATS),
Rack Air Removal Unit (RARU) using NMC1, and
All other remaining NMC1 applications
Schneider published an update for their EcoStructure advisory that was originally published on December 8th, 2020. The new information includes:
Adding remediation measures for Ecostruxure Control Expert v15.0 SP1, and
Adding EcoStruxure™ Process Expert and RemoteConnect to the list of affected products.
Schneider published an update for their Triconex advisory that was originally published on May 11th, 2021. The new information includes:
Improving additional mitigations related to the write-protect keyswitch, and
Clarifying affected modules.
Schneider published an update for their Treck TCP/IPv6 advisory that was originally published on December 18th, 2020. The new information includes adding remediations for:
Acti9 Powertag Link/HD and
Acti9 Smartlink SI B
NOTE: NCCIC-ICS never did add affected products to their advisory for the underlying Treck vulnerabilities that were reported on the same day.
Schneider published an update for their PLC Simulator advisory that was originally published on November 10th, 2020 and most recently updated on June 8th, 2021. The new information includes adding a fix of CVE-2020-7559 for PLC Simulator for EcoStruxure™ Control Expert.
Siemens Update
Siemens published an update for their GNU/Linux subsystem advisory advisory that was originally published in 2018 and most recently updated on May 11th, 2021. The new information includes adding: