[Control systems] Rockwell Automation Security Vulnerability

Number: AV17-078
Date: 08 June 2017

Purpose

The purpose of this advisory is to bring attention to a recently discovered vulnerability VulnerabilityA flaw or weakness in the design or implementation of an information system or its environment that could be exploited to adversely affect an organization's assets or operations. to Rockwell Automation PanelView Plus 6 700-1500 graphic terminals and logic module products.

Assessment

Rockwell Automation has issued a security advisory concerning its PanelView Plus 6 700-1500 graphic terminals and logic module products. Rockwell Automation PanelView Plus terminals and logic module products do not perform an authorization AuthorizationAccess privileges granted to a user, program, or process. check on connection requests to TCP port 44818 and UDP 2222. This may allow remote retrieval of data and potential disruption of service.

Affected versions of PanelView Plus 6 700-1500:

  • 6.00.04,
  • 6.00.05,
  • 6.00.42,
  • 6.00-20140306,
  • 6.10.20121012,
  • 6.10-20140122,
  • 7.00-20121012,
  • 7.00-20130108,
  • 7.00-20130325,
  • 7.00-20130619,
  • 7.00-20140128,
  • 7.00-20140310,
  • 7.00-20140429,
  • 7.00-20140621,
  • 7.00-20140729,
  • 7.00-20141022,
  • 8.00-20140730,
  • 8.00-20141023

This vulnerability does not affect graphic terminals running OS 2.31 or greater.

CVE Reference: CVE-2017-7914

Suggested action

CCIRC recommends that system administrators test and deploy the vendor released firmware updates that address this vulnerability at your earliest convenience:

  • V7.00: Apply V7.00-20150209
  • V8.00: Apply V8.00-20160418
  • V8.10: Apply V8.10-20151026 or later
  • V8.20: Apply V8.20-20160308 or later
  • V9.00: Apply V9.00-20170328 or later

Please consult ICS-CERT and manufacturer advisories for additional mitigation advice.

References

https://ics-cert.us-cert.gov/advisories/ICSA-17-157-01
http://compatibility.rockwellautomation.com/Pages/MultiProductDownload.aspx?Keyword=2711P&crumb=112

Date modified: