OTPulse

Vulnerabilities in CP 1543-1 before V2.0.28

Act Now6.6SSA-672373Nov 18, 2016
Attack VectorNetwork
Auth RequiredHigh
ComplexityHigh
User InteractionNone needed
Summary

SIMATIC CP 1543-1 and SIPLUS NET CP 1543-1 devices before V2.0.28 contain two vulnerabilities (CWE-269, CWE-20) that allow authorized users to escalate their privileges on the CP or create a denial of service condition.

What this means
What could happen
An authorized user with valid engineering credentials could escalate privileges to gain full control of the CP device, potentially accessing or modifying control logic and process parameters, or disable the communication processor entirely, interrupting data flow to PLCs and field devices.
Who's at risk
Any facility using SIMATIC CP 1543-1 or SIPLUS NET CP 1543-1 communication processors, which are commonly found in water treatment, power distribution, and manufacturing plants where they handle network communication for PLCs and process control systems.
How it could be exploited
An attacker with valid engineering workstation credentials accesses the CP device's management interface locally or over the network, then exploits the privilege escalation vulnerability to gain higher-level access to the device. Once privileged, the attacker can run arbitrary commands on the CP, alter process configurations, or crash the device to cause denial of service.
Prerequisites
  • Valid engineering workstation credentials
  • Local or network access to the CP 1543-1 management interface
  • Authorization to access the device (initially non-admin credentials acceptable)
actively exploited (KEV)high EPSS score (14.6%)requires valid credentials but allows privilege escalationaffects industrial communication infrastructuredenial of service possible
Exploitability
Actively exploited — confirmed by CISA KEV
Affected products (2)
2 with fix
ProductAffected VersionsFix Status
SIMATIC CP 1543-1< V2.0.282.0.28
SIPLUS NET CP 1543-1< V2.0.282.0.28
Remediation & Mitigation
0/1
Do now
0/1
SIMATIC CP 1543-1
HOTFIXUpdate SIMATIC CP 1543-1 and SIPLUS NET CP 1543-1 devices to firmware version 2.0.28 or later
↑↓ Navigate · Esc Close
API: /api/v1/advisories/7fd6e4a3-9079-4349-89b0-be2bbc80f162
Vulnerabilities in CP 1543-1 before V2.0.28 | CVSS 6.6 - OTPulse