ICSA-18-107-02
·
Published 2018-12-18
·
View on CISA ICS-CERT ↗
Schneider Electric Triconex Tricon
CVSS 9.0
CRITICAL
Risk Summary
Successful exploitation of these vulnerabilities could misinform or control the safety instrumented system which could result in arbitrary code execution, system shutdown, or the compromise of safety systems.
CVEs (2)
Remediations
- Schneider Electric has released the following security notification: https://www.schneider-electric.com/en/download/document/SEVD-2017-347-01/
- Schneider Electric strongly recommends that users upgrade to the latest Triconex Tricon CX version. Tricon CX v11.4 is now available and is compliant with the IEC 62443 cybersecurity standard and includes multiple security enhancements that meet the challenges posed by HatMan malware techniques and other sophisticated methods of attack. To upgrade your system, contact your field site support representative or contact Schneider Electric support.
- Detect and Respond: Triconex users should contact their local Schneider Electric office for assistance. With this engagement, Schneider Electric will gather data from each Tricon safety system installation, analyze for the presence of the malware, and carry out any necessary malware removal procedures.
- Detect and Respond: For users who choose to gather data from each Tricon safety system installation on their own, instructions and support material is available for download via the Schneider Electric Process Automation customer support portal (login required). The data will still need to be sent to Schneider Electric for analysis. As of February 1, 2019, Schneider Electric will require customers to have a support contract in place to engage with the HatMan malware detection service.
- Detect and Respond: Once Schneider Electric has analyzed this data, Triconex users will receive a report for each Tricon system analyzed. This report will advise whether the malware was detected, and what the next steps are to remove the malware if detected.A YARA rule that matches the binary components of the HatMan malware is available for download at https://ics-cert.us-cert.gov/sites/default/files/file_attach/MAR-17-352-01.yara or by contacting Schneider Electric Customer Support.
- Defend: The HatMan malware requires unrestricted access to the safety network via remote network or physical access. Additionally, the malware requires the Tricon key switch to be in the "PROGRAM" mode to successfully deploy its payload.
- Defend: Schneider Electric continues to recommend users always implement the instructions in the "Security Considerations" section in the standard Triconex documentation (i.e., Planning and Installation Guides and TriStation 1131 Developers Guide), which include the following:
- Ensure the cybersecurity features in Triconex solutions are always enabled.
- Safety systems must always be deployed on isolated networks.
- Physical controls should be in place so that no unauthorized person would have access to the safety controllers, peripheral safety equipment, or the safety network.
- All controllers should reside in locked cabinets and never be left in the "PROGRAM" mode.
- All TriStation engineering workstations should be secured and never be connected to any network other than the safety network.
- All methods of mobile data exchange with the isolated safety network such as CDs, USB drives, DVD's, etc. should be scanned before use in the TriStation engineering workstations or any node connected to this network.
- Laptops and PCs should always be properly verified to be virus and malware free before connecting to the safety network or any Triconex controller.
- Operator stations should be configured to display an alarm whenever the Tricon key switch is in the "PROGRAM" mode.
Affected Vendors
Schneider Electric
Affected Products (1)
Schneider Electric
·
MP Model 3008
>= 10.0 | <= 10.4
Affected Sectors
Multiple Sectors
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more