ICSA-21-173-04
·
Published 2021-06-22
·
View on CISA ICS-CERT ↗
CODESYS Control V2 Linux SysFile library
CVSS 5.3
MEDIUM
Risk Summary
Successful exploitation of this vulnerability may allow the control programmer to call additional OS functions from the PLC logic utilizing the SysFile system library.
CVEs (1)
Remediations
- CODESYS GmbH has released CODESYS Runtime Toolkit 32-bit full Version 2.4.7.55 to solve the noted vulnerability issue for the affected CODESYS products.
- Please visit the CODESYS update area for more information on how to obtain software updates.
- Use controllers and devices only in a protected environment to minimize network exposure, ensuring they are not accessible from outside.
- Use firewalls to protect and separate the control system network from other networks.
- Use VPN (virtual private network) tunnels if remote access is required.
- Activate and apply user management and password features.
- Use encrypted communication links.
- Limit access to both development and control system by physical means, operating system features, etc.
- Protect both development and control system operations by using up to date virus detecting solutions.
- For more information and general recommendations for protecting machines and plants, see also the CODESYS Security Whitepaper.
- Please see CODESYS Advisory 2021-08 for more information.
Affected Vendors
CODESYS, GmbH
Affected Products (1)
CODESYS, GmbH
·
CODESYS reports all runtime systems for Linux based on a CODESYS V2 Runtime Toolkit 32-bit full
< 2.4.7.55
Affected Sectors
Critical Manufacturing
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more