ICSA-21-042-01
·
Published 2021-11-11
·
View on CISA ICS-CERT ↗
Multiple Embedded TCP/IP Stacks (Update B)
CVSS 7.5
HIGH
Risk Summary
Successful exploitation of weak initial sequence numbers (ISN) can be used to hijack or spoof TCP connections, cause denial-of-service conditions, inject malicious data, or bypass authentication.
CVEs (9)
Remediations
- uIP-Contiki-OS (end-of-life [EOL]). See general recommendations below.
- uIP-Contiki-NG has a patch in progress. See general recommendations below until a patch is made available.
- uIP (EOL). See general recommendations below.
- The maintainers of picoTCP-NG recommend users update to Version 2.1 or later.
- picoTCP (EOL), See general recommendations below.
- The maintainers of MPLAB Net recommend users update to Version 3.6.4 or later.
- Siemens recommends Nucleus NET users update to the latest version of Nucleus ReadyStart or to protect transmitted data with cryptographic protocols such as Transport Layer Security. Additional information can be found here.
- Siemens recommends Nucleus ReadyStart for ARM, MIPS, and PPC users update to v2012.12 or later or to protect transmitted data with cryptographic protocols such as Transport Layer Security. Additional information can be found here.
- Siemens recommends for Capital VSTAR and Nucleus Source Code users contact Siemens customer support to receive patch and update information. Additional information can be found here.
- Nut/Net has a patch in progress. See general recommendations below until a patch is made available.
- uC/TCP-IP (EOL). See general recommendations below. Patched in the latest version of Micrium OS (successor project).
- The maintainers of CycloneTCP recommend users update to Version 2.0.0 or later.
- Texas Instruments recommends NDKTCPIP users update to Version 7.02 or later
- The maintainer of FNET recommends users update to v4.7.1
Affected Vendors
multiple
Affected Products (15)
multiple
·
MPLAB Net
<= 3.6.1
multiple
·
picoTCP-NG
<= 1.7.0
multiple
·
FNET
4.6.3
multiple
·
picoTCP (EOL)
<= 1.7.0
multiple
·
NDKTCPIP
<= 2.25
multiple
·
uIP-Contiki-OS (end-of-life [EOL])
<= 3.0
multiple
·
Nucleus Source Code
vers:all/*
multiple
·
CycloneTCP
<= 1.9.6
multiple
·
Nucleus NET All
< 5.2
multiple
·
Nut/Net
<= 5.1
multiple
·
Nucleus ReadyStart for ARM MIPS and PPC
< 2012.12
multiple
·
Capital VSTAR
vers:all/*
multiple
·
uC/TCP-IP (EOL)
<= 3.6.0
multiple
·
uIP (EOL)
<= 1.0
multiple
·
uIP-Contiki-NG
<= 4.5
Affected Sectors
Multiple
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more