QID 590781

Date Published: 2022-06-23

QID 590781: Rockwell Automation AADvance Controller and Micro800 family Multiple Vulnerabilities (ICSA-20-280-01)

AFFECTED PRODUCTS
The following Rockwell Automation products are based on ISaGRAF5 to design integrated automation solutions:
AADvance Controller version 1.40 and earlier
Micro800 family, all versions
GE reports that GE Steam Power's ALSPA S6 MFC3000 and MFC1000 (all versions), a distributed control system, are impacted by vulnerabilities in Rockwell's ISaGRAF runtime.
Xylem reports that MultiSmart Gen-1 devices and MultiSmart Gen-2 devices running firmware prior to Version 3.2.0 contain a version of ISaGRAF 5.x. If ISaGRAF is enabled on those devices, then they might be affected by these vulnerabilities.
Other vendors may also use ISaGRAF5 in their products.

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of these vulnerabilities may result in remote code execution, information disclosure, or a denial-of-service condition.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-20-280-01 for affected packages and patching details.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ICSA-20-280-01 URL Logo www.us-cert.gov/ics/advisories/ICSA-20-280-01