QID 590341

Date Published: 2022-06-23

QID 590341: Rockwell Automation Allen-Bradley Stratix 5950 Multiple Vulnerabilities (ICSA-18-184-01)

AFFECTED PRODUCTS
The Allen-Bradley Stratix 5950 uses the Cisco Systems, Inc., Adaptive Security Appliance (ASA) as its central operating system. Cisco has released advisories disclosing multiple vulnerabilities in the ASA software.
The following Allen-Bradley Stratix 5950 Security Appliances, running the Cisco ASA v9.6.2 and earlier, are affected:
1783-SAD4T0SBK9,
1783-SAD4T0SPK9,
1783-SAD2T2SBK9, and
1783-SAD2T2SPK9

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Rockwell using registry "HKLM\SOFTWARE\Rockwell Software"

Successful exploitation of these vulnerabilities could allow an attacker to bypass client certification to create connections to the affected device or cause the device to crash.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-18-184-01 for affected packages and patching details.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ICSA-18-184-01 URL Logo www.us-cert.gov/ics/advisories/ICSA-18-184-01