QID 590794
Date Published: 2022-06-30
QID 590794: TURCK BL20 and BL67 Programmable Gateway Hard-Coded User Accounts Vulnerability (ICSA-13-136-01)
AFFECTED PRODUCTS
The following TURCK products are affected:
BL20 Programmable Gateway, all versions, and
BL67 Programmable Gateway, all versions.
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
This vulnerability allows an attacker to remotely access the device by using hard-coded credentials. After gaining administrative access, the attacker can create false communication between remote I/Os, PLCs, or DCS systems. Those false communications could cause adverse actions within the control system, possibly including process shutdown.
Solution
Customers are advised to refer to CERT MITIGATIONS section ICSA-13-136-01 for affected packages and patching details.
Vendor References
- ICSA-13-136-01 -
www.us-cert.gov/ics/advisories/ICSA-13-136-01
CVEs related to QID 590794
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-13-136-01 |
|