The vendor explicitly identifies these products as affected by this CVE.
- Rockwell Automation ISaGRAF Workbench Versions 6.0 through 6.6.9 optional component of Schneider Electric SAGE RTU C3414 CPU (Current) Versions prior to C3414-500-S02K5_P5
- Rockwell Automation ISaGRAF Workbench Versions 6.0 through 6.6.9 optional component of Schneider Electric SAGE RTU C3413 CPU (Obsolete CPU) All firmware versions
- Rockwell Automation ISaGRAF Workbench Versions 6.0 through 6.6.9 optional component of Schneider Electric SAGE RTU C3412 CPU (Obsolete CPU) All firmware versions
- Summary
- ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Deserialization of Untrusted Data vulnerability. ISaGRAF Workbench does not limit the objects that can be deserialized. This vulnerability allows attackers to craft a malicious serialized object that, if opened by a local user in ISaGRAF Workbench, may result in remote code execution. This vulnerability requires user interaction to be successfully exploited. Note: The CVSS score provided above is calculated in the context of SAGE RTU.
- Remediation
- Version C3414-500-S02K5_P5 of SAGE RTU CPU 3414 includes a mitigation for these vulnerabilities and is available for download here: https://www.sage-rtu.com/downloads.html Reboot of SAGE RTU is required after firmware upgrade. This mitigation disables the ISaGRAF listening TCP ports by default and provides an additional network service checkbox to allow customers to enable the ISaGRAF ETCP task, which will open the TCP listening ports to connect with ISaGRAF workbench when needed, and to disable the TCP listening ports when ISaGRAF Workbench development, debugging, and downloading tasks are complete. These vulnerabilities can only be exploited when users reopen the listening ports and connect with ISaGRAF workbench. These vulnerabilities only apply when a non-secure network is being used to perform development tasks in non-runtime applications. It is our recommendation to mitigate these vulnerabilities by performing all ISaGRAF workbench tasks on a secure network or on a private network when connecting to the device. OR If firmware is not upgraded to C3414-500-S02K5_P5, but customers are running firmware version C3414-500-S02K2 or above, then they should immediately apply the following mitigations to reduce the risk of exploit: If ISaGRAF is configured and in use, the built-in firewall can be used to disable ISaGRAF port 1131 and 1113 when the debugger is not in use. Use the following commands in the Firewall configuration to disable external access to ISaGRAF: Block in proto tcp from any to any port = 1131 Block in proto tcp from any to any port = 1113 If ISaGRAF is NOT configured and in use, the ISaGRAF port is by default not enabled and does not start automatically, therefore there is no impact of these vulnerabilities, and no further action is required by customers.
