SCADA Vulnerabilities & Exposures (SVE)

CRITIFENCE® SCADA Vulnerabilities and Exposures Database (SVE)

[SVE-82003202] Schneider Electric Magelis Advanced HMI Panel - PanelShock vulnerability

Date Type Platform Author EDB-ID CVE-ID OSVDB-ID Download App SIS Signature
2016-04-13HMISchneider Electric Magelis Advanced HMI PanelEran GoldsteinN/ACVE-2016-8374N/AN/AN/A

Source

						
							
								
#
# Schneider Electric Magelis Advanced HMI Panel - PanelShock vulnerability
#


### OVERVIEW

ICS-CERT is aware of a public report of resource consumption vulnerabilities 
affecting Schneider Electric's Magelis human machine interface (HMI) products. 
The researcher Eran Goldstein released vulnerability information after coordination the vendor and ICS-CERT. 
Schneider Electric has validated the resource consumption vulnerabilities 
and is planning to release new versions to mitigate these vulnerabilities.

These vulnerabilities could be exploited remotely. 
Detailed vulnerability information is publicly available that could be used to develop an exploit that targets these vulnerabilities.




### AFFECTED PRODUCTS

The following Schneider Electric Magelis HMI products are affected:

* Magelis GTO Advanced Optimum panels, all versions
* Magelis GTU Universal panel, all versions
* Magelis STO & STU Small panels, all versions
* Magelis XBT GH Advanced hand-held Panel, all versions
* Magelis XBT GK Advanced Touchscreen Panels with Keyboard, all versions
* Magelis XBT GT Advanced Touchscreen Panels, all versions
* Magelis XBT GTW Advanced Open Touchscreen Panels (Windows XPe)




### IMPACT

Successful exploitation of these vulnerabilities could result in a denial of service for the affected devices.
Impact to individual organizations depends on many factors that are unique to each organization. ICS-CERT recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation.




### BACKGROUND

Schneider Electric's corporate headquarters is located in Paris, France, and maintains offices in more than 100 countries worldwide.
The affected products, Schneider Electric Magelis, are human machine interfaces. According to Schneider Electric, the Magelis HMIs are deployed across several sectors including Critical Manufacturing and Food and Agriculture. Schneider Electric estimates that these products are sold worldwide.




### VULNERABILITY CHARACTERIZATION


# VULNERABILITY OVERVIEW

UNCONTROLLED RESOURCE CONSUMPTION

An attacker may be able to disrupt a targeted web server, resulting in a denial of service, requiring the affected device to be rebooted in order to regain operation. CVE-2016-8374 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H).




### VULNERABILITY DETAILS


# EXPLOITABILITY

These vulnerabilities could be exploited remotely.


# EXISTENCE OF EXPLOIT

Detailed vulnerability information is publicly available that could be used to develop an exploit that targets these vulnerabilities.


# DIFFICULTY

An attacker with low skill would be able to exploit these vulnerabilities.




### MITIGATION

Schneider Electric reports that they are working to release new versions for the affected products that mitigate the identified vulnerabilities, which is planned for release by the end of March 2017:

http://www.schneider-electric.com/ww/en/download/document/SEVD-2016-302-01





### More Information
http://www.critifence.com/blog/panel_shock/
http://www.schneider-electric.com/ww/en/download/document/SEVD-2016-302-01
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8374