Thứ Hai, Tháng Một 30, 2023
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
No Result
View All Result
Home Tech

Fatal error in Siemens SIMATIC PLC could allow attackers to steal cryptographic keys

15 Tháng Mười, 2022
in Tech
0
Fatal error in Siemens SIMATIC PLC could allow attackers to steal cryptographic keys
585
SHARES
3.2k
VIEWS
Share on FacebookShare on Twitter

Các bài viết liên quan:

How to get travel insurance

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023
5 Best Software to Stream Games

5 Best Software to Stream Games

2 Tháng Một, 2023
IBM Bridge To Cloud For Power

IBM Bridge To Cloud For Power- Everything You Should Know

2 Tháng Một, 2023
Top 10 CRM Software For Construction 

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
What Is IBM Software

What Is IBM Software? 4 Business Segments at IBM You Should Know

26 Tháng Mười Hai, 2022

A vulnerability in the Siemens Simatic programmable logic controller (PLC) could be exploited to obtain hard-coded global private cryptographic keys and take control of devices.

Company network security “An attacker can use these keys to perform a variety of advanced attacks against Siemens SIMATIC devices and related TIA Portals, while bypassing all four measures,” said Claroty industry. protect its access level”.

“A malicious person could use this confidential information to compromise the entire SIMATIC S7-1200/1500 product line in an irreparable way.”

The critical vulnerability, assigned identifier CVE-2022-38465, is rated 9.3 on the CVSS scale and has been addressed by Siemens as part of a security update released on October 11, 2018. 2022.

Below is a list of affected products and versions:

SIMATIC Open Controller family (all versions prior to 2.9.2) SIMATIC ET 200SP 1515SP PC2 Open Controller, including SIPLUS variants (all versions prior to 21.9) SIMATIC ET 200SP CPU Open Controller 1515SP PC, including SIPLUS variants (all versions) SIMATIC S7-1200 CPU family, including SIPLUS variants (all versions prior to 4.5.0) SIMATIC S7-1500 CPU family, including Related ET200 CPU and SIPLUS variants (all versions prior to V2.9.2) SIMATIC S7-1500 Software Controller (all versions prior to 21.9), and SIMATIC S7-PLCSIM Advanced (all versions prior to V2.9.2) version before 4.0)

Claroty said it was able to gain read and write privileges for the controller by exploiting a previously disclosed vulnerability in Siemens PLCs (CVE-2020-15782) that would allow private key recovery.

Doing so will not only allow an attacker to circumvent access controls and overwrite native code, but also gain full control over every PLC on each affected Siemens product family.

CVE-2022-38465 reflects another serious deficiency identified in Rockwell Automation PLC (CVE-2021-22681) last year and could allow an adversary to remotely connect to the controller and upload malicious code, download information from the PLC, or install new firmware.

“The vulnerability is that the Studio 5000 Logix Designer software could allow a secret cryptographic key to be discovered,” Claroty noted in February 2021.

As a workaround and mitigation, Siemens recommends that customers only use legacy PG/PC and HMI communication in trusted network environments and secure access to the TIA Portal and CPU to prevent unauthorized connections.

The German industrial manufacturing company also took the step of encrypting communications between engineering stations, PLCs and HMI control panels using Transport Layer Security (TLS) in TIA Portal version 17, and warned reported that “the possibility of bad actors misusing the global private key increases.”

The discovery is the latest in a series of major flaws that have been discovered in software used in industrial networks. Earlier this June, Claroty detailed more than a dozen issues in the Siemens SINEC network management system (NMS) that could be abused to achieve remote code execution.

Then in April 2022, the company opened two vulnerabilities in Rockwell Automation PLC (CVE-2022-1159 and CVE-2022-1161) that could be exploited to modify user programs and download malicious code. remote controll.

Related Posts

Previous Post

What to play in Ha Long? Top 20 Ha Long tourist attractions should not be missed

Next Post

Beautiful quotes about love and happy life

Megusta

Megusta

Related Posts

5 Best Software to Stream Games

5 Best Software to Stream Games

2 Tháng Một, 2023
Top 10 CRM Software For Construction 

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
Instruction how to use OBS streaming software

Features, settings and how to use OBS streaming software through 9 simple steps

25 Tháng Mười Hai, 2022
What is Trans woman?  What is Transgender Women?

What is Trans woman? What is Transgender Women?

23 Tháng Mười Hai, 2022
Christmas gift: Genuine Windows 10 Pro for only $6.63 and Office 2021 for $14.22

Christmas gift: Genuine Windows 10 Pro for only $6.63 and Office 2021 for $14.22

22 Tháng Mười Hai, 2022
How to get 50 free coins of SkyJoy App to redeem

How to get 50 free coins of SkyJoy App to redeem

21 Tháng Mười Hai, 2022
Load More
Next Post
Beautiful quotes about love and happy life

Beautiful quotes about love and happy life

Trả lời Hủy

Email của bạn sẽ không được hiển thị công khai. Các trường bắt buộc được đánh dấu *

Bài viết mới

How to get travel insurance
Đời sống

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly
Phần mềm

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023
5 Best Software to Stream Games
Software

5 Best Software to Stream Games

2 Tháng Một, 2023
IBM Bridge To Cloud For Power
Software

IBM Bridge To Cloud For Power- Everything You Should Know

2 Tháng Một, 2023
Top 10 CRM Software For Construction 
Tech

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
What Is IBM Software
Software

What Is IBM Software? 4 Business Segments at IBM You Should Know

26 Tháng Mười Hai, 2022
W3Schools

Ads

Contact: [email protected]

DMCA.com Protection Status

Categories

  • Android
  • Cạm bẫy tâm lí
  • Chưa được phân loại
  • Đồ họa
  • Đời sống
  • Gen Z
  • Health
  • iOS
  • Kĩ năng mềm
  • News
  • Nhà mạng
  • Phần mềm
  • Phần mềm đồ họa
  • Review sách
  • Software
  • Tech
  • Thiết kế ảnh
  • Thiết kế video
  • Thủ thuật
  • Travel
  • Văn hóa Nam Bộ
  • Văn học
  • Window

Browse by Tag

ai là triệu phú android Apple browser Bullet Journal bản thân chai pin Chỉnh ảnh data domain download fshare game game show giả lập màu hosting IKEA ios khuyến mãi kinh doanh kiến thức kiểm tra pin messenger miễn phí mua sắm Máy ảnh mạng network nghệ thuật ngôn ngữ nhà Trần pin laptop quảng cáo tiếng anh trạng thái Trần Thủ Độ tên miền tắt hoạt động từ vựng video viettel window 10 word zalo Đơn giản

Recent News

How to get travel insurance

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023

Trang tin nóng hổi - vừa thổi vừa xem

No Result
View All Result
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z

Trang tin nóng hổi - vừa thổi vừa xem