Honeywell OT:ICEFALL Multiple Potential Vulnerabilities

info Tenable.ot Plugin ID 500656

Synopsis

The remote OT asset may be affected by a vulnerability.

Description

The device may be vulnerable to flaws related to OT:ICEFALL. These vulnerabilities identify the insecure-by-design nature of OT devices and may not have a clear remediation path. As such, Nessus is unable to test specifically for these vulnerabilities but has identified the device to be one that was listed in the OT:ICEFALL report. Ensure your OT deployments follow best practices including accurate inventory, separation of environments, and monitoring. This plugin will trigger on any device seen by Tenable.OT that matches a family or model listed in the OT:ICEFALL report.

Note: All findings need to be manually verified based on the advisory from the vendor, once released.

This plugin only works with Tenable.ot. Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

http://www.nessus.org/u?4901fbd6

https://www.forescout.com/research-labs/ot-icefall/

Plugin Details

Severity: Info

ID: 500656

Version: 1.1

Type: remote

Family: Tenable.ot

Published: 6/22/2022

Updated: 6/22/2022

Risk Information

VPR

Risk Factor: High

Score: 7.4

Vulnerability Information

CPE: cpe:/h:honeywell:experion

Required KB Items: Tenable.ot/Honeywell

Vulnerability Publication Date: 6/22/2022

Reference Information

CVE: CVE-2022-30313, CVE-2022-30314, CVE-2022-30315, CVE-2022-30316, CVE-2022-30317