Siemens LOGO! 8 BM Improper Handling of Extra Values (CVE-2019-10920)

high Tenable OT Security Plugin ID 501674

Synopsis

The remote OT asset is affected by a vulnerability.

Description

A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Project data stored on the device, which is accessible via port 10005/tcp, can be decrypted due to a hardcoded encryption key. The security vulnerability could be exploited by an unauthenticated attacker with network access to port 10005/tcp. No user interaction is required to exploit this security vulnerability. The vulnerability impacts confidentiality of the device. At the time of advisory publication no public exploitation of this security vulnerability was known.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

The following text was originally created by the Cybersecurity and Infrastructure Security Agency (CISA). The original can be found at CISA.gov.

Siemens has released an update for the LOGO! 8 BM (update to v8.3) and recommends that customers update to the latest version.. Notice that in order to update, a new hardware version is required.

To reduce risk, Siemens recommends that users apply defense-in-depth concepts, including protection concept outlined in the system manual.

As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens’ operational guidelines for industrial security and following the recommendations in the product manuals.

Additional information on industrial security for Siemens devices can be found at:
https://www.siemens.com/industrialsecurity

For more information on these vulnerabilities and more detailed mitigation instructions, please see Siemens Security Advisory SSA-542701

See Also

https://cert-portal.siemens.com/productcert/pdf/ssa-542701.pdf

http://www.securityfocus.com/bid/108382

https://seclists.org/bugtraq/2019/May/72

http://www.nessus.org/u?c543cc8a

http://seclists.org/fulldisclosure/2019/May/44

https://www.cisa.gov/news-events/ics-advisories/icsa-19-134-04

Plugin Details

Severity: High

ID: 501674

Version: 1.4

Type: remote

Family: Tenable.ot

Published: 9/21/2023

Updated: 3/4/2024

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2019-10920

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:siemens:logo%218_bm_firmware, cpe:/o:siemens:logo%218_bm_firmware:8

Required KB Items: Tenable.ot/Siemens

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/14/2019

Vulnerability Publication Date: 5/14/2019

Reference Information

CVE: CVE-2019-10920

CWE: 321