Vulnerability Note VU#308556
GE Fanuc CIMPLICITY HMI heap buffer overflow
OverviewGE Fanuc CIMPLICITY HMI contains a remotely accessible heap buffer overflow vulnerability which may allow a remote attacker to execute arbitrary code.
I. DescriptionGE Fanuc CIMPLICITY HMI is software used for monitoring and control in Supervisory Control And Data Acquisition (SCADA) systems. A heap buffer overflow vulnerability exists in a CIMPLICITY process (w32rtr.exe) that listens on the network (32000/tcp). The vulnerable process exists in both servers and clients. An attacker could exploit this vulnerability by sending a specially crafted packet to a vulnerable CIMPLICITY system.
Note that this vulnerability affects GE Fanuc CIMPLICITY HMI versions up to and including version 7.0.
II. ImpactA remote, unauthenticated attacker may be able to execute arbitrary code or cause a denial of service.
III. SolutionApply Patch
This vulnerability is addressed in CIMPLICITY 6.1 SP6 Hot fix - 010708_162517_6106 and CIMPLICITY 7.0 SIM 9. CIMPLICITY customers should refer to GE Fanuc knowledge base article KB2458 for more information.
Upgrade
Users of affected software with versions older than 6.1 are encouraged to upgrade to 6.1 or greater and then apply the patches described above. CIMPLICITY customers should refer to GE Fanuc knowledge base article KB12458 for more information.
Restrict Access
Restrict network access to hosts that require connections to CIMPLICITY. Do not allow access to CIMPLICITY from untrusted networks such as the internet.
Systems Affected
| Vendor | Status | Date Updated |
| GE Fanuc | Vulnerable | 24-Jan-2008 |
References
http://www.securityfocus.com/archive/1/487076/30/0/threaded
http://support.gefanuc.com/support/index?page=kbchannel&id=KB12458
http://www.gefanuc.com/as_en/gefanuc/resource_center/hmi_scada/hmiscada_security.html
Credit
This vulnerability was reported by Eyal Udassin of C4 Security.
This document was written by Chris Taschner.
Other Information
| Date Public | 01/24/2008 |
| Date First Published | 01/25/2008 03:30:28 PM |
| Date Last Updated | 01/25/2008 |
| CERT Advisory | |
| CVE Name | CVE-2008-0176 |
| US-CERT Technical Alerts | |
| Metric | 3.01 |
| Document Revision | 32 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|