Summary of security related changes for August 2021. Security Enhancement Summary: Firmware C3414-500-S02K5_P5 released with these enhancements: GUI: Configuration – CPU: Additional network service checkbox provided to allow customer to enable the ISaGRAF ETCP task, which will open listening ports to connect with ISaGRAF workbench. Configuration – CPU: Non-secure networking services Telnet and FTP are disabled by default. Customer must enable them to use them and therefore assumes risk of using them. Security Fix Summary: Firmware C3414-500-S02K5_P5 released to fix: VxWorks: Vulnerability CVE-2020-28895 malloc/calloc fix. Applied Wind River patch to bring code libraries current to 6.9.4.12 RCPL3 revision. This corrects issues with overflow causing malloc/calloc to return valid pointer when it should return fail indication NULL pointer. VxWorks: Vulnerabilities CVE-2020-25176, CVE-2020-25182, CVE-2020-25184, CVE-2020-25178, CVE-2020-25180. Provide a way for users to manually disable the comm path the ISaGRAF Workbench uses to communicate with the ISaGRAF Runtime in the RTU when not downloading new ISaGRAF RLL programs or debugging those programs. This prevents unauthorized access using this comm path. Command Log: Fix bug where command log fails to close Syslog socket on RTU side when it detects Syslog server has closed its end. Unclosed sockets could collect eventually to point where it affects system resources, causing RTU reset.
0 Comments
Summary of security related changes for July 2021. |
july_2021_security_update.pdf | |
File Size: | 620 kb |
File Type: |
Security Enhancement Summary:
No security enhancements in firmware release(s).
Security Fix Summary:
Vulnerability found if using ISaGRAF functionality. Fix to resolve vulnerability currently scheduled to release by August 2021. Mitigation instructions are as follows, note that if you are not using ISaGRAF functionality the default is to have all ports disabled and there is no vulnerability.
If you are using ISaGRAF RLL programs in the SAGE RTU, the ports will be open, and the firewall will be needed to block access to those ports. If the Firewall rules are employed, you can verify they are working by trying to connect to the RTU with the ISaGRAF development system. If the Firewall is implemented and working correctly, the ISaGRAF development system will fail to connect.
Firewall rules used to block access to TCP ports 1113 and 1131:
june_2021_security_update.pdf | |
File Size: | 661 kb |
File Type: |
Security Fix Summary:
No security fixes in firmware release(s).
Security Enhancement Summary:
No security enhancements in firmware release(s).
may_2021_security_update.pdf | |
File Size: | 718 kb |
File Type: |
Security Fix Summary:
No security fixes in firmware release(s).
Security Enhancement Summary:
No security enhancements in firmware release(s).
april_2021_security_update.pdf | |
File Size: | 149 kb |
File Type: |
Security Fix Summary:
No security fixes in firmware release(s).
Security Enhancement Summary:
No security enhancements in firmware release(s).
march__2021_security_update.pdf | |
File Size: | 147 kb |
File Type: |
Security Fix Summary:
No security fixes in firmware release(s).
Security Enhancement Summary:
No security enhancements in firmware release(s).
february_2021_security_update.pdf | |
File Size: | 148 kb |
File Type: |
Security Fix Summary:
No security fixes in firmware release(s).
Security Enhancement Summary:
No security enhancements in firmware release(s).
january_2021_security_update.pdf | |
File Size: | 146 kb |
File Type: |
No security fixes in firmware release(s) for December 2020.
Security Enhancement Summary:
No security enhancements in firmware release(s) for December 2020.
December_2020_Security_Update.pdf | |
File Size: | 156 kb |
File Type: |
No security fixes in firmware release(s) for November 2020.
Security Enhancement Summary:
The FTP Push Application in the newly released C3414-500-S02K5 firmware release does now include the option to use SFTP to transfer event files to a centralized server (as opposed to FTP in the previous release).
If you are using FTP Push with the FTP protocol, we recommend using SFTP for added security. If not using the FTP Push application to send event files or log files to a centralized server, no action is needed.
To switch to SFTP, simply update the File Transfer Type in the RTU configuration for your FTP Push Records configuration.
November_2020_Security_Update.pdf | |
File Size: | 176 kb |
File Type: |
Categories
All
Bulletins
Security Updates
Archives
February 2024
January 2024
November 2023
October 2023
August 2023
July 2023
June 2023
May 2023
April 2023
March 2023
February 2023
January 2023
December 2022
November 2022
October 2022
September 2022
August 2022
July 2022
June 2022
May 2022
April 2022
March 2022
February 2022
January 2022
December 2021
November 2021
October 2021
September 2021
July 2021
June 2021
April 2021
March 2021
February 2021
January 2021
November 2020
October 2020
August 2020
July 2020
June 2020
April 2020
March 2020
February 2020
January 2020
November 2019
October 2019
September 2019
August 2019
July 2019
June 2019
April 2019
March 2019
February 2019
January 2019
December 2018
November 2018
October 2018
August 2018
July 2018
June 2018
May 2018