Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

Rockwell ThinManager Vulnerabilities Could Expose Industrial HMIs to Attacks

Rockwell Automation ThinManager ThinServer vulnerabilities could allow remote attackers to  take control of servers and hack HMIs. 

Vulnerabilities discovered by researchers in Rockwell Automation’s ThinManager ThinServer product could be exploited in attacks aimed at industrial control systems (ICS). 

Researchers at cybersecurity firm Tenable discovered one critical and two high-severity vulnerabilities in ThinManager ThinServer, a thin client and RDP server management software offered by Rockwell. The flaws are tracked as CVE-2023-2914, CVE-2023-2915 and CVE-2023-2917.

The security holes have been described as improper input validation issues that can lead to integer overflow or path traversal. The flaws can be exploited by remote attackers — without prior authentication — by sending specially crafted synchronization protocol messages. 

Exploitation of the vulnerabilities can allow causing a denial-of-service (DoS) condition, deleting arbitrary files with system privileges, and uploading arbitrary files to any folder on the drive where ThinServer.exe is installed.

The vulnerabilities were reported to the vendor in May and Tenable released technical details on August 17, the same day Rockwell Automation informed customers about the availability of patches (advisory for registered users). Tenable has also developed proof-of-concept (PoC) exploits, but it has not made them public. 

Tenable told SecurityWeek that the only requirement for exploitation is access to the network hosting the vulnerable server. Exploitation directly from the internet is also possible if the server is connected and exposed to the web, but this goes against the vendor’s recommended best practices.

“Successful exploitation can allow complete attacker control of the ThinServer,” Tenable said. “The real world impact of this access depends on the environment, server configuration and the content types the server is configured on and intended to access.”

The company noted that the product is typically used for human-machine interfaces (HMIs) used to control and monitor industrial equipment. 

Advertisement. Scroll to continue reading.

“An attacker would be able to give themself access to these HMIs. An attacker could also pivot from the server to attack other assets on the network,” Tenable said.

The US Cybersecurity and Infrastructure Security Agency (CISA) also published an advisory this week to inform organizations about these vulnerabilities. 

Rockwell Automation product vulnerabilities could be targeted by threat actors in their operations. It recently came to light that an unnamed APT has set its sights on two ControlLogix vulnerabilities that could be exploited to cause disruption or destruction in critical infrastructure organizations. 

Rockwell discovered what it described as a “new exploit capability”, but there had been no evidence of exploitation in the wild. 

Learn More at SecurityWeek’s ICS Cyber Security Conference
The leading global conference series for Operations, Control Systems and OT/IT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.
ICS Cybersecurity Conference
October 23-26, 2023 | Atlanta
www.icscybersecurityconference.com

Related: New Vulnerabilities Allow Stuxnet-Style Attacks Against Rockwell PLCs

Related: Organizations Informed of Over a Dozen Vulnerabilities in Rockwell Automation Products

Related: US Probing Cybersecurity Risks of Rockwell Automation’s China Operations

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Passwordless authentication firm Hawcx has appointed Lakshmi Sharma as Chief Product Officer.

Matt Hartley has been named Chief Revenue Officer at autonomous security solutions provider Horizon3.ai.

Trustwave has announced the appointment of Keith Ibarguen as Senior Vice President of Engineering.

More People On The Move

Expert Insights

Related Content

ICS/OT

The overall effect of current global geopolitical conditions is that nation states have a greater incentive to target the ICS/OT of critical industries, while...

CISO Strategy

Cybersecurity-related risk is a top concern, so boards need to know they have the proper oversight in place. Even as first-timers, successful CISOs make...

ICS/OT

Municipal Water Authority of Aliquippa in Pennsylvania confirms that hackers took control of a booster station, but says no risk to drinking water or...

ICS/OT

Mandiant's Chief analyst urges critical infrastructure defenders to work on finding and removing traces of Volt Typhoon, a Chinese government-backed hacking team caught in...

Cybercrime

Energy giants Schneider Electric and Siemens Energy confirm being targeted by the Cl0p ransomware group in the campaign exploiting a MOVEit zero-day.

ICS/OT

As smart cities evolve with more and more integrated connected services, cybersecurity concerns will increase dramatically.

ICS/OT

Wago has patched critical vulnerabilities that can allow hackers to take complete control of its programmable logic controllers (PLCs).