SCADA Vulnerabilities & Exposures (SVE)

CRITIFENCE® SCADA Vulnerabilities and Exposures Database (SVE)

[SVE-545043820] Rockwell Automation Stratix Services Router

Date Type Platform Author EDB-ID CVE-ID OSVDB-ID Download App SIS Signature
2018-04-17OtherRockwell AutomationRockwell Automation reported these vulnerabilities to NCCIC from the semi-annual Cisco IOS and IOS XE Software Security AdvisoryN/ACVE-2018-0158 CVE-2018-0151 CVE-2018-0167 CVE-2018-0175 N/AN/AN/A

Source

						
							
								
#

# Rockwell Automation Stratix Services Router

#





### VULNERABLE VENDOR

Rockwell Automation





### VULNERABLE PRODUCT

Allen-Bradley Stratix 5900 Services Router 





### RESEARCHER

Rockwell Automation reported these vulnerabilities to NCCIC from the semi-annual Cisco IOS and IOS XE Software Security Advisory Bundled Publication.





### AFFECTED PRODUCTS

The following versions of Allen-Bradley Stratix Services Router use a vulnerable version of Cisco IOS or IOS XE:



Allen-Bradley Stratix 5900 Services Router, version 15.6.3M1 and earlier





### IMPACT







### VULNERABILITY OVERVIEW

3.2.1   IMPROPER INPUT VALIDATION CWE-20

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (DoS) condition.

The vulnerability is due to incorrect processing of certain IKEv2 packets.

An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device to be processed.

A successful exploit could cause an affected device to continuously consume memory and eventually reload, resulting in a DoS condition.

CVE-2018-0158 has been assigned to this vulnerability.

A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H)





3.2.2   IMPROPER RESTRICTION OF OPERATIONS WITHIN THE BOUNDS OF A MEMORY BUFFER CWE-119

A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated remote attacker to cause a DoS condition or execute arbitrary code with elevated privileges.

The vulnerability is due to incorrect bounds checking of certain values in packets that are destined for UDP port 18999 of an affected device.

An attacker could exploit this vulnerability by sending malicious packets to an affected device.

When the packets are processed, an exploitable buffer overflow condition may occur.

A successful exploit could allow the attacker to execute arbitrary code on the affected device with elevated privileges.

The attacker could also leverage this vulnerability to cause the device to reload, causing a temporary DoS condition while the device is reloading.

The malicious packets must be destined to and processed by an affected device.

Traffic transiting a device will not trigger the vulnerability.

CVE-2018-0151 has been assigned to this vulnerability.

A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)





3.2.3  IMPROPER RESTRICTION OF OPERATIONS WITHIN THE BOUNDS OF A MEMORY BUFFER CWE-119

A buffer overflow vulnerability in the LLDP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an adjacent, unauthenticated attacker to cause a DoS condition or execute arbitrary code with elevated privileges.

CVE-2018-0167 has been assigned to this vulnerability.

A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)





3.2.4   USE OF EXTERNALLY-CONTROLLED FORMAT STRING CWE-134

A format string vulnerability in the LLDP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an adjacent, unauthenticated attacker to cause a DoS condition or execute arbitrary code with elevated privileges.

CVE-2018-0175 has been assigned to this vulnerability.

A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)







### BACKGROUND

Critical Infrastructure Sectors: Critical Manufacturing, Energy, Water and Wastewater Systems

Countries/Areas Deployed: Worldwide

Company Headquarters Location: Wisconsin, USA






### MITIGATION



Rockwell Automation has released knowledge base article 1073313 which can be found at the following location:



https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1073313/





(login required)

Cisco has released Snort Rules 46110 and 46111 to help address CVE-2018-0158 and CVE-2018-0151. See new rules at:



https://www.cisco.com/web/software/286271056/117258/sf-rules-2018-03-29-new.html





CVE-2018-0151: Users who do not use the Adaptive QoS for DMVPN feature can deny all traffic destined to UDP port 18999 on an affected device by using a Control Plane Policing (CoPP) policy. If the Adaptive QoS for DMVPN feature is later configured, the device must be upgraded to an unaffected release of Cisco IOS Software or Cisco IOS XE Software and the CoPP policy must be removed.



CVE-2018-0167 and CVE-2018-0175 have no specific mitigations in place. See the following Cisco Vulnerability advisory for more details:



https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-lldp





Rockwell Automation also recommends that users implement the following general security guidelines:



Help minimize network exposure for all control system devices and/or systems, and confirm that they are not accessible from the Internet.



Locate control system networks and devices behind firewalls, and isolate them from the business network.



When remote access is required, use secure methods, such as Virtual Private Networks (VPNs), recognizing that VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize that VPN is only as secure as the connected devices.