ICSA-19-155-01
·
Published 2019-06-04
·
View on CISA ICS-CERT ↗
PHOENIX CONTACT PLCNext AXC F 2152
CVSS 9.8
CRITICAL
Risk Summary
Successful exploitation of these vulnerabilities could allow an attacker to decrypt passwords, bypass authentication, and deny service to the device. In addition, these vulnerabilities could interact with third-party vulnerabilities to cause other impacts to integrity, confidentiality, and availability.
CVEs (46)
CVE-2018-7559
CVE-2019-10998
CVE-2019-10997
CVE-2017-8816
CVE-2016-9953
CVE-2017-8817
CVE-2017-11541
CVE-2017-11542
CVE-2017-11543
CVE-2017-5334
CVE-2017-5336
CVE-2016-9841
CVE-2018-1000120
CVE-2017-5337
CVE-2016-9843
CVE-2017-1000257
CVE-2018-1000122
CVE-2018-1000301
CVE-2018-1000005
CVE-2016-9842
CVE-2016-9840
CVE-2016-9952
CVE-2016-1247
CVE-2017-9023
CVE-2016-6301
CVE-2016-7141
CVE-2016-7444
CVE-2018-1000121
CVE-2017-1000254
CVE-2017-11108
CVE-2017-11185
CVE-2017-3731
CVE-2017-9233
CVE-2017-5335
CVE-2017-9022
CVE-2018-1000117
CVE-2018-5388
CVE-2017-1000101
CVE-2017-1000100
CVE-2016-7103
CVE-2015-9251
CVE-2017-3738
CVE-2018-0737
CVE-2017-3737
CVE-2017-15906
CVE-2017-3735
Remediations
- Phoenix Contact recommends affected users update to firmware release 2019.0 LTS or later, update to PLCNext Engineer release 2019.0 LTS or later, and apply the following specific mitigations below:
- Disable Basic128Rsa15 security policy in OPC Servers configuration. Use only Basic256 or higher.
- Follow the advice concerning SD card usage in the manual “Art.-Nr. 107708: UM EN AXC F 2152 Installing, starting up, and operating the AXC F 2152 controller um_en_axc_f_2152_107708_en_02.pdf” that can be found on the product page below:
- Use the notification manager to monitor SD card exchanges by the application program.
- Subscribe to PSIRT news as updates on the SD card vulnerability will be provided in the future.
- Phoenix Contact also recommends users operate the devices in closed networks or environments protected with a suitable firewall. For detailed information on recommendations for measures to protect network-capable devices, please refer to the Phoenix Contact application note “Art.-Nr. 107913: AH EN INDUSTRIAL SECURITY - Measures to protect network-capable devices with Ethernet connection against unauthorized access,” which can be found at the following link:
- For more information, CERT@VDE has released a security advisory available at the following link:
Affected Vendors
Phoenix Contact
Affected Products (2)
Phoenix Contact
·
AXC F 2152
2404267 version 1.x
Phoenix Contact
·
AXC F 2152
1046568 (Starterkit) version 1.x
Affected Sectors
Commercial Facilities
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more