ICSA-22-202-05
·
Published 2022-07-21
·
View on CISA ICS-CERT ↗
AutomationDirect Stride Field I/O
CVSS 9.6
CRITICAL
Risk Summary
Successful exploitation of this vulnerability could allow an attacker to obtain user credentials.
CVEs (1)
Remediations
- AutomationDirect recommends users upgrade the Stride Modbus Field I/O units listed in the affected products section with the firmware associated with the part number. Firmware can be downloaded from the AutomationDirect software downloads page.
- The modules with a listed B/N number in the affected products section have a firmware update issue and must be returned to AutomationDirect for replacement modules; users can create an RMA on the AutomationDirect website.
- Automation networks and systems may have built-in password protection schemes, but this is only one step in securing systems. Automation control system networks must incorporate data protection and security measures at least as robust as a typical business computer system. AutomationDirect recommends users of PLCs, HMI products and SCADA systems perform their own network security analysis to determine the proper level of security required for their application.
- Secure physical access.
- Isolate and air gap networks when possible.
- Follow the security considerations in the Automation Direct Security Considerations document.
- See AutomationDirect product advisory number PA-COM-006 for more information.
Affected Vendors
Automation Direct
Affected Products (14)
Automation Direct
·
SIO- MB04ADS
< 8.4.3.0
Automation Direct
·
SIO-MB04ADS
5714442222
Automation Direct
·
SIO-MB04DAS
< 8.11.3.0
Automation Direct
·
SIO-MB04DAS
4714432222
Automation Direct
·
SIO-MB04RTDS
< 8.3.4.0
Automation Direct
·
SIO-MB04THMS
< 8.5.4.0
Automation Direct
·
SIO-MB04THMS
57141862221
Automation Direct
·
SIO-MB08ADS-1
< 8.6.3.0
Automation Direct
·
SIO-MB08ADS-2
< 8.7.3.0
Automation Direct
·
SIO-MB08THMS
< 8.8.4.0
Automation Direct
·
SIO-MB12CDR
< 8.0.4.0
Automation Direct
·
SIO-MB12CDR
5714442222
Automation Direct
·
SIO-MB16CDD2
< 8.1.4.0
Automation Direct
·
SIO-MB16ND3
< 8.2.4.00
Affected Sectors
Commercial Facilities, Critical Manufacturing, Information Technology
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more