ICSMA-19-274-01
·
Published 2020-01-07
·
View on CISA ICS-CERT ↗
Interpeak IPnet TCP/IP Stack (Update D)
CVSS 9.8
CRITICAL
Risk Summary
Successful exploitation of these vulnerabilities could allow remote code execution.
CVEs (11)
Remediations
- Enea has no IPNet customers on support contract in the United States.
- Green Hills Software has proactively informed affected users and offers consulting services to implement mitigations.
- Microsoft states they have no history of support or integration work to include IPnet and have not released a version of ThreadX bundled with IPnet. Microsoft does caution that some hardware makers could have used ThreadX and a custom set IPnet in the hardware.
- TRON Forum reports they only publish the specification for ITRON RTOS. Various implementations are used by many users world-wide and are created by various implementors (some commercial, and some academic and some government) according the specification document. TRON Forum, the caretaker of the ITRON specification, has not endorsed the use of any particular TCP/IP stack including one from Interpeak. The choice of TCP/IP stack is up to the RTOS vendor and application developers, and thus each application user needs to check whether TCP/IP stack developed by Interpeak is used inside their application. TRON Forum will send out a preliminary warning to members by mailing list to notify implementors of the reported vulnerabilities.
- Wind River has produced controls and patches to mitigate the reported vulnerabilities. To obtain patches, email [email protected] and indicate the VxWorks major version for which you need source patches.
- For more detailed information on the vulnerabilities and the mitigating controls, please see the Wind River advisory.
- Additional vendors affected by the reported vulnerabilities have also released security advisories related to their affected products. Those advisories are as follows:
Affected Vendors
ENEA, Green Hills Software, ITRON, IP Infusion, and Wind River
Affected Products (9)
ENEA, Green Hills Software, ITRON, IP Infusion, and Wind River
·
Ipnet TCP/IP Stack
vers:all/*
ENEA, Green Hills Software, ITRON, IP Infusion, and Wind River
·
OSE
4
ENEA, Green Hills Software, ITRON, IP Infusion, and Wind River
·
OSE
5
ENEA, Green Hills Software, ITRON, IP Infusion, and Wind River
·
INTEGRITY RTOS
>= 2003 | <= 2006
ENEA, Green Hills Software, ITRON, IP Infusion, and Wind River
·
VxWorks under CURRENT support (6.9.4.11, Vx7 SR540, Vx7 SR610)
vers:all/*
ENEA, Green Hills Software, ITRON, IP Infusion, and Wind River
·
Advanced Networking Technology (ANT)
vers:all/*
ENEA, Green Hills Software, ITRON, IP Infusion, and Wind River
·
VxWorks
<= 6.5
ENEA, Green Hills Software, ITRON, IP Infusion, and Wind River
·
VxWorks bootrom network stack
vers:all/*
ENEA, Green Hills Software, ITRON, IP Infusion, and Wind River
·
VxWorks
653 MCE 3.x
Affected Sectors
Critical Manufacturing, Information Technology, Healthcare and Public Health, Transportation Systems, Water and Wastewater Systems
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more