Full Report
[Control systems] CISA ICS security advisories (AV26-718)
Analysis Summary
# Vulnerability: Summary of CISA ICS Security Advisories (AV26-718)
## CVE Details
*Note: Due to the high volume of advisories in this period, major CVEs include:*
- **CVE ID:** Multiple (Refer to individual CISA advisories for full list)
- **CVSS Score:** Varies, up to **9.8 (Critical)** in some reported cases.
- **CWE:** Commonly includes CWE-287 (Improper Authentication), CWE-121 (Stack-based Buffer Overflow), and CWE-20 (Improper Input Validation).
## Affected Systems
- **ABB:** 800xA for Advant Master, Edgenius, Control Builder A (v1.4/4 and prior), T-MAC Plus (v4.0-24).
- **AutomationDirect:** Productivity Suite (v4.6.2.2 and prior).
- **NASA:** Core Flight System (cFS) Health & Safety (HS) Application (Prior to v7.0.1).
- **Rockwell Automation:** 1715-AENTR, 1756-EN2/EN3/ENBT adapters, Arena (v17.00.00 and prior), FactoryTalk DataMosaix, Flex 5000 Adapter, and CompactLogix/ControlLogix/GuardLogix lines.
- **SALTO:** ProAccess Space (Prior to v6.13).
- **Siemens:** SICAM 8 CPCI85 and SICORE Base system (Prior to v26.20).
## Vulnerability Description
The advisories cover a wide range of Industrial Control System (ICS) flaws, primarily involving **unauthenticated remote code execution (RCE)**, **Denial of Service (DoS)**, and **Privilege Escalation**. In the case of communication adapters (Rockwell/Siemens), flaws often reside in the network stack or web management interfaces, allowing attackers to disrupt industrial processes or manipulate device configurations.
## Exploitation
- **Status:** Vulnerabilities are disclosed; no confirmed widespread "in the wild" exploitation reported at the time of advisory, though PoCs often follow CISA ICS alerts.
- **Complexity:** Low to Medium.
- **Attack Vector:** Network (Most critical advisories are remotely exploitable via the industrial network).
## Impact
- **Confidentiality:** High (Potential theft of sensitive process data and configurations).
- **Integrity:** High (Risk of unauthorized setpoint changes or firmware modification).
- **Availability:** High (Critical risk of system crashes and disruption of physical processes).
## Remediation
### Patches
- **ABB:** Update to the latest versions specified in the ABB MyControlSystem portal.
- **NASA:** Upgrade cFS Health & Safety Application to **v7.0.1** or later.
- **Rockwell Automation:** Consult the Rockwell Automation Knowledgebase for specific firmware updates (e.g., Flex 5000 v6.012+).
- **SALTO:** Update ProAccess Space to **v6.13** or later.
- **Siemens:** Update SICAM 8 systems to **v26.20**.
### Workarounds
- Minimize network exposure for all control system devices; ensure they are not accessible from the Internet.
- Locate control system networks and remote devices behind firewalls and isolate them from the business network.
- Use secure methods, such as Virtual Private Networks (VPNs), if remote access is required.
## Detection
- **Indicators of Compromise:** Unusual traffic on industrial protocols (EtherNet/IP, CIP, Modbus), unexpected device reboots, or unauthorized configuration changes in PLC logs.
- **Detection methods and tools:** Use ICS-aware Deep Packet Inspection (DPI) firewalls and Intrusion Detection Systems (IDS) to monitor for non-standard commands to PLC adapters.
## References
- CISA ICS Advisories Primary Link: hxxps[://]www[.]cisa[.]gov/news-events/cybersecurity-advisories
- Canadian Centre for Cyber Security Advisory (AV26-718): hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/control-systems-cisa-ics-security-advisories-av26-718