Story image

Quick thinking remedies vulnerability in Schneider Electric ICS controller

07 Sep 18

A serious vulnerability in Schneider Electric Modicon Controllers was quickly discovered and mitigated, with the help of the eagle-eyed team at industrial cybersecurity firm Radiflow.

The Schneider Electric Modicon M221 Controller is commonly used in industrial control systems (ICS). Radiflow discovered that a serious vulnerability in the devices put the safety and availability of ICS networks in jeopardy.

The CVE-2018-7789 vulnerability enabled unauthorized users to use packets that could remotely disconnect the device from the ICS network.

“An unauthorized user could have easily exploited this vulnerability to execute a synchronized attack and cause a number of these controllers to stop communicating,” the company explains.

“This type of unauthorized action would allow a cyber-attacker to massively disconnect the effected PLCs from the HMI leaving the operator with no way to view and control the physical processes on the OT network, while instantly harming the safety and reliability of the ICS systems. The recovery from such an attack would require a reboot of the attacked PLCs and physical access to the controllers, which would cause significant downtime to the ICS network.”

Radiflow CTO Yehonatan Kfir discovered the vulnerability as part of his ongoing vulnerability detection research.

The team reverse engineered the affected controller’s control protocol and found the packet structure that caused the shutdown. The company alerted Schneider Electric about the vulnerability, and then incorporated the attack signature into its own industrial threat detection system.

“For this specific vulnerability, we prevented a potentially dangerous exploit that could have caused extensive damage to the safety, security and operations of numerous industrial enterprises and critical infrastructure operators,” comments Kfir.

“Equally as important, we are proud of our threat intelligence research team for its ongoing efforts of detecting new vulnerabilities and improving the cybersecurity protection capabilities of our solutions and the overall operations of our customers.”

Schneider Electric thanked Kfir and Radiflow for their efforts to identify and coordinate on the vulnerability.

Earlier this year Radiflow also detected a cryptocurrency malware attack on a wastewater facility in Europe.

“While it is known that ransomware attacks have been launched on OT networks, this new case of a cryptocurrency malware attack on an OT network poses new threats as it runs in stealth mode and can remain undetected over time,” commented Kfir at the time.

The attack increased CPU and network bandwidth consumption of devices on the customer’s network so that attackers could mine the Monero cryptocurrency.

Hillstone CTO's 2019 security predictions
Hillstone Networks CTO Tim Liu shares what key developments could be expected in the areas of security compliance, cloud, security, AI and IoT.
Can it be trusted? Huawei’s founder speaks out
Ren Zhengfei spoke candidly in a recent media roundtable about security, 5G, his daughter’s detainment, the USA, and the West’s perception of Huawei.
Oracle Java Card update boosts security for IoT devices
"Java Card 3.1 is very significant to the Internet of Things, bringing interoperability, security and flexibility to a fast-growing market currently lacking high-security and flexible edge security solutions."
Sophos hires ex-McAfee SVP Gavin Struther
After 16 years as the APAC senior vice president and president for McAfee, Struthers is now heading the APJ arm of Sophos.
Security platform provider Deep Instinct expands local presence
The company has made two A/NZ specific leadership hires and formed several partnerships with organisations in the region.
Half of companies unable to detect IoT device breaches
A Gemalto study also shows that the of blockchain technology to help secure IoT data, services and devices has doubled in a year.
Stepping up to sell security services in A/NZ
WatchGuard Technologies A/NZ regional director gives his top tips on how to make a move into the increasingly lucrative cybersecurity services market.
Huawei founder publically denies spying allegations
“After all the evidence is made public, we will rely on the justice system.”