← Back to home
ICSA-21-021-05  ·  Published 2021-06-17  ·  View on CISA ICS-CERT ↗

WAGO M&M Software fdtCONTAINER (Update C)

CVSS 7.3 HIGH

Risk Summary

If an attacker can socially engineer a valid user into loading a manipulated project file, malicious code can be executed without notice.

CVEs (1)

Remediations

  • Update the fdtCONTAINER component/fdtCONTAINER application to a version that provides a more secure deserialization of the project data. This version will still use a deprecated serialization technology but will fix the currently known attack vector and will be compatible with existing, non-manipulated project files.
  • Update the fdtCONTAINER component/fdtCONTAINER application to a version (fdtCONTAINER component: 3.7 or newer, fdtCONTAINER application: 4.7 or newer) that provides a secure deserialization of the project data with an updated serialization technology. This will break the compatibility to existing, non-manipulated project files.
  • The CERT@VDE advisory for M&M Software also recommends the following mitigation practices:
  • Exchange project data only via secure exchange services.
  • Use appropriate means to protect the project storage from unauthorized manipulation.
  • Do not open project data from an unknown source.
  • Reduce the user rights of the host application to the necessary minimum.
  • Emerson has published a notification (EMR.RMT20004.Rev3) for this vulnerability in RTIS. RTIS users should review this notification for additional information specific to RTIS. CERT@VDE has published an advisory (VDE-2021-001) for this vulnerability in PEPPERL+FUCHS PACTware. CERT@VDE has published an advisory (VDE-2021-002) for this vulnerability in Weidmüller FDT/DTM Software with WI Manager. Mitsubishi Electric has published advisory 2020-020 concerning the vulnerability in MELSOFT FieldDeviceConfigurator.

Affected Vendors

M&M Software GmbH, WAGO Kontakttechnik

Affected Products (11)

M&M Software GmbH, WAGO Kontakttechnik · fdtCONTAINER >= 4.6.0 | =< 4.6.20304.x
M&M Software GmbH, WAGO Kontakttechnik · dtmINSPECTOR 3 (Based on FDT 1.2.x)
M&M Software GmbH, WAGO Kontakttechnik · fdtCONTAINER >= 3.5.0 | =< 3.5.20304.x
M&M Software GmbH, WAGO Kontakttechnik · fdtCONTAINER >= 4.5.0 | =< 3.5.20304.x
M&M Software GmbH, WAGO Kontakttechnik · Weidmüller WI Manager <= 2.5.1
M&M Software GmbH, WAGO Kontakttechnik · Mitsubishi Electric MELSOFT FieldDeviceConfigurator <= 1.05 F
M&M Software GmbH, WAGO Kontakttechnik · fdtCONTAINER < 3.5
M&M Software GmbH, WAGO Kontakttechnik · fdtCONTAINER >= 3.6.0 | <= 3.6.20304.x
M&M Software GmbH, WAGO Kontakttechnik · PEPPERL+FUCHS PACTware => 5.0 | <= 5.0.5.31
M&M Software GmbH, WAGO Kontakttechnik · Emerson Rosemount Transmitter Interface Software (RTIS) SKUs 04088-9000-0001 | 4088-9000-0002 | 7000003-312
M&M Software GmbH, WAGO Kontakttechnik · fdtCONTAINER < 4.5

Affected Sectors

Commercial Facilities, Critical Manufacturing, Energy, Transportation Systems

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more