Modicon Quantum TFTP Arbitrary File Upload

high Nessus Plugin ID 57600

Synopsis

The remote Modicon Quantum controller allows uploading arbitrary files over TFTP.

Description

The remote device is a Modicon Quantum Controller that allows arbitrary file uploads. This can facilitate other attacks since an arbitrary amount of code can be stored on the device and run at a later time.

Additionally, a denial of service vulnerability exists where an attacker can fill the ramdisk and cause the system to crash.

Solution

Block access to the TFTP port.

Plugin Details

Severity: High

ID: 57600

File Name: scada_modicon_tftp_enabled.nbin

Version: 1.83

Type: remote

Family: SCADA

Published: 1/19/2012

Updated: 2/21/2024

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 8.6

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:C

Vulnerability Information

Required KB Items: ftp/modicon/user, ftp/modicon/pass

Exploit Available: true

Exploit Ease: Exploits are available

Reference Information

BID: 51605

ICS-ALERT: 12-020-03