ICSA-21-021-05
·
Published 2021-06-17
·
View on CISA ICS-CERT ↗
WAGO M&M Software fdtCONTAINER (Update C)
CVSS 7.3
HIGH
Risk Summary
If an attacker can socially engineer a valid user into loading a manipulated project file, malicious code can be executed without notice.
CVEs (1)
Remediations
- Update the fdtCONTAINER component/fdtCONTAINER application to a version that provides a more secure deserialization of the project data. This version will still use a deprecated serialization technology but will fix the currently known attack vector and will be compatible with existing, non-manipulated project files.
- Update the fdtCONTAINER component/fdtCONTAINER application to a version (fdtCONTAINER component: 3.7 or newer, fdtCONTAINER application: 4.7 or newer) that provides a secure deserialization of the project data with an updated serialization technology. This will break the compatibility to existing, non-manipulated project files.
- The CERT@VDE advisory for M&M Software also recommends the following mitigation practices:
- Exchange project data only via secure exchange services.
- Use appropriate means to protect the project storage from unauthorized manipulation.
- Do not open project data from an unknown source.
- Reduce the user rights of the host application to the necessary minimum.
- Emerson has published a notification (EMR.RMT20004.Rev3) for this vulnerability in RTIS. RTIS users should review this notification for additional information specific to RTIS. CERT@VDE has published an advisory (VDE-2021-001) for this vulnerability in PEPPERL+FUCHS PACTware. CERT@VDE has published an advisory (VDE-2021-002) for this vulnerability in Weidmüller FDT/DTM Software with WI Manager. Mitsubishi Electric has published advisory 2020-020 concerning the vulnerability in MELSOFT FieldDeviceConfigurator.
Affected Vendors
M&M Software GmbH, WAGO Kontakttechnik
Affected Products (11)
M&M Software GmbH, WAGO Kontakttechnik
·
fdtCONTAINER
>= 4.6.0 | =< 4.6.20304.x
M&M Software GmbH, WAGO Kontakttechnik
·
dtmINSPECTOR
3 (Based on FDT 1.2.x)
M&M Software GmbH, WAGO Kontakttechnik
·
fdtCONTAINER
>= 3.5.0 | =< 3.5.20304.x
M&M Software GmbH, WAGO Kontakttechnik
·
fdtCONTAINER
>= 4.5.0 | =< 3.5.20304.x
M&M Software GmbH, WAGO Kontakttechnik
·
Weidmüller WI Manager
<= 2.5.1
M&M Software GmbH, WAGO Kontakttechnik
·
Mitsubishi Electric MELSOFT FieldDeviceConfigurator
<= 1.05 F
M&M Software GmbH, WAGO Kontakttechnik
·
fdtCONTAINER
< 3.5
M&M Software GmbH, WAGO Kontakttechnik
·
fdtCONTAINER
>= 3.6.0 | <= 3.6.20304.x
M&M Software GmbH, WAGO Kontakttechnik
·
PEPPERL+FUCHS PACTware
=> 5.0 | <= 5.0.5.31
M&M Software GmbH, WAGO Kontakttechnik
·
Emerson Rosemount Transmitter Interface Software (RTIS) SKUs
04088-9000-0001 | 4088-9000-0002 | 7000003-312
M&M Software GmbH, WAGO Kontakttechnik
·
fdtCONTAINER
< 4.5
Affected Sectors
Commercial Facilities, Critical Manufacturing, Energy, Transportation Systems
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more