ICS/OT

Cisco Finds 8 Vulnerabilities in OAS Industrial IoT Data Platform

Vulnerabilities identified in the OAS Platform could be exploited to bypass authentication, leak sensitive information, and overwrite files.

Vulnerabilities identified in the OAS Platform could be exploited to bypass authentication, leak sensitive information, and overwrite files.

Multiple vulnerabilities in the Open Automation Software (OAS) Platform can be exploited to bypass authentication, leak sensitive information, and overwrite files, Cisco warns.

Enabling communication and data transfer between servers, industrial control systems (ICS), IoT, and other types of devices, the OAS Platform is typically used in industrial operations and enterprise environments. It also supports logging and notifications, and cross-platform integrations.

On Wednesday, Cisco’s Talos security researchers disclosed eight vulnerabilities identified in the OAS Platform’s engine configuration management functionality, which allows users to load and save configurations to a disk and install them on other devices. Three of the bugs are rated high-severity.

The most important of these are CVE-2023-31242 and CVE-2023-34998, two authentication bypass flaws that can be exploited using specially-crafted requests. The first can be triggered using a sequence of requests, while the second through sniffing network traffic.

The first issue is rooted in the fact that, by default, when the OAS engine is installed, no admin user is set and no authentication is required to access functionality such as new user creation. Even if an admin user is created, the configuration needs to be saved before the engine restarts, otherwise it will revert to default.

An attacker could use special requests to check if unauthenticated access is possible and could then create new users, save the configuration, and potentially gain access to the underlying system.

The second flaw allows an attacker to capture a protobuf containing valid administrator credentials and use it to create their own requests. The attacker could then access the user creation and save functionality to gain access to the underlying system.

These authentication bypass flaws, Cisco warns, could be combined with CVE-2023-34317, an improper input validation bug in the user creation functionality, to add “a user with the username field containing an SSH key,” to gain access to the underlying system.

Advertisement. Scroll to continue reading.

Another high-severity authentication bypass, CVE-2023-34353, allows an attacker to perform network sniffing to capture the protobuf containing admin credentials and then decrypt sensitive information.

Two of the remaining vulnerabilities could lead to information disclosure, while the other two may be exploited for arbitrary file creation or overwrite and for arbitrary directory creation.

All issues were identified in OAS Platform version 18 and were addressed with the release of version 19.00.0000 of the solution.

Learn More at SecurityWeek’s ICS Cyber Security Conference
The leading global conference series for Operations, Control Systems and OT/IT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

October 23-26, 2023 | Atlanta
www.icscybersecurityconference.com

Related: High-Severity Memory Corruption Vulnerabilities Patched in Firefox, Chrome

Related: Cisco Patches Vulnerabilities Exposing Switches, Firewalls to DoS Attacks

Related: Critical Vulnerabilities Found in Open Automation Software Platform

Related Content

ICS/OT

Government agencies are sharing recommendations following attacks claimed by pro-Russian hacktivists on ICS/OT systems.

ICS/OT

An analysis conducted by Honeywell shows that much of the USB-borne malware targeting industrial organizations can still cause OT disruption.

ICS/OT

Palo Alto Networks firewall vulnerability CVE-2024-3400, exploited as a zero-day, impacts a Siemens industrial product.

Nation-State

Mandiant summarizes some of the latest operations of Russia’s notorious Sandworm group, which it now tracks as APT44.

ICS/OT

In the past week Rockwell Automation addressed 10 vulnerabilities found in its FactoryTalk, PowerFlex and Arena Simulation products.

Malware & Threats

A suspicious NuGet package likely targets developers working with technology from Chinese firm Bozhon.

ICS/OT

UK’s NCSC releases security guidance for OT organizations considering migrating their SCADA solutions to the cloud.

ICS/OT

Siemens and Schneider Electric publish March 2024 Patch Tuesday advisories to inform customers about over 200 vulnerabilities.

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version