ICSA-18-107-04
·
Published 2018-04-17
·
View on CISA ICS-CERT ↗
Rockwell Automation Stratix and ArmorStratix Switches
CVSS 9.8
CRITICAL
CISA KEV — Known Exploited
Risk Summary
Successful exploitation of these vulnerabilities could result in loss of availability, confidentiality, and/or integrity caused by memory exhaustion, module restart, information corruption, and/or information exposure.
CVEs (8)
Remediations
- Rockwell Automation recommends users upgrade to FRN 15.2(6)E1 or later.
- Rockwell Automation has provided knowledge base article number 1073268 on their website
- Cisco has released new Snort Rules at https://www.cisco.com/web/software/286271056/117258/sf-rules-2018-03-29-new.htm
- CVE-2018-0171 - Snort Rule 46096 and 46097
- Cisco adds the following notes for the Smart Install vulnerabilities (CVE-2018-0171 and CVE-2018-0156): Smart Install is turned off by express setup; however, upgraded switches but not re-setup may have it enabled. Disable the Smart Install feature with the no vstack configuration command if it is not needed or once setup is complete. Users who do use the feature—and need to leave it enabled—can use ACLs to block incoming traffic on TCP port 4786.
- Help minimize network exposure for all control system devices and/or systems, and confirm that they are not accessible from the Internet.
- Locate control system networks and devices behind firewalls, and isolate them from the business network.
- When remote access is required, use secure methods, such as Virtual Private Networks (VPNs), recognizing that VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize that VPN is only as secure as the connected devices.
- CVE-2018-0156 - Snort Rule 41725
- CVE-2018-0174 - Snort Rule 46120
- CVE-2018-0172 - Snort Rule 46104
- CVE-2018-0173 - Snort Rule 46119
- CVE-2018-0158 - Snort Rule 46110
- CVE-2018-0167 and CVE-2018-0175: have no specific mitigations in place. See the following Cisco Vulnerability advisory for more details
Affected Vendors
Rockwell Automation
Affected Products (5)
Rockwell Automation
·
Allen-Bradley Stratix 5400 Industrial Ethernet Switches
<= 15.2(6)E0a
Rockwell Automation
·
Allen-Bradley Stratix 8000 Modular Managed Ethernet Switches
<= 15.2(6)E0a
Rockwell Automation
·
Allen-Bradley Stratix 5410 Industrial Distribution Switches
<= 15.2(6)E0a
Rockwell Automation
·
Allen-Bradley Stratix 5700 Industrial Managed Ethernet Switches
<= 15.2(6)E0a
Rockwell Automation
·
Allen-Bradley ArmorStratix 5700 Industrial Managed Ethernet Switches for extreme environments
<= 15.2(6)E0a
Affected Sectors
Critical Manufacturing, Energy, Water and Wastewater Systems
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more