News: 1691782806

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft: Codesys PLC bugs could be exploited to 'shut down power plants'

(2023/08/11)


Fifteen bugs in Codesys' industrial control systems software could be exploited to shut down power plants or steal information from critical infrastructure environments, experts have claimed.

In a [1]report and more published on GitHub, Microsoft threat intel specialist Vladimir Tokarev says the Windows giant – no stranger to [2]security holes , cough – disclosed details of vulnerabilities in the Codesys V3 SDK to the Germany-based vendor in September 2022. Codesys has since [3]patched the bugs .

The SDK is widely used, we're told, and provides a development environment for engineers to configure and test programmable logic controllers (PLCs) for industrial systems. The firmware in a good deal of PLCs contains library routines from Codesys to run the engineers' programs, and it's this embedded code that is exploitable, resulting in equipment being vulnerable to attack.

[4]

While Microsoft's team focused on the firmware in PLCs made by Schneider Electric and Wago, Codesys V3 is [5]available for about 1,000 device types from more than 500 manufacturers, which totals up to "several million devices" that use Codesys code to implement [6]IEC 61131-3 – the international standard for vendor-neutral industrial equipment programming languages – according to the bug hunters.

[7]

[8]

So if your operational technology (OT) environment uses devices with any of this buggy firmware, update now if you can to avoid remote code execution (RCE) or denial of service (DoS) attacks.

The 15 vulnerabilities, tracked as CVE-2022-47379 through CVE-2022-47393 inclusive, all received CVSS severity ratings of 8.8 out of 10, except for CVE-2022-47391, which earned a 7.5. It's the only one that can't be abused for RCE. Exploitation of any of these holes requires an attacker to be able to authenticate and log in.

[9]

A dozen are buffer-overflow vulnerabilities. In a [10]separate write-up , Microsoft's threat intel team described the exploit process thus:

We were able to apply 12 of the buffer overflow vulnerabilities to gain RCE of PLCs. Exploiting the vulnerabilities requires user authentication as well as bypassing the Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR) used by both the PLCs.

To overcome the user authentication, we used a known vulnerability, [11]CVE-2019-9013 , which allows us to perform a replay attack against the PLC using the unsecured username and password's hash that were sent during the sign-in process, allowing us to bypass the user authentication process.

To be clear, these aren't easy exploits. Not only do they require user authentication or stolen credentials, an intruder will need "deep knowledge of the proprietary protocol of Codesys V3 and the structure of the different services that the protocol uses," Redmond noted.

[12]Microsoft, Intel lead this month's security fix emissions

[13]CISA boss says US alliance with Ukraine over past year is closer than Five Eyes

[14]Microsoft OneDrive a willing and eager 'ransomware double agent'

[15]Want to pwn a satellite? Turns out it's surprisingly easy

But considering how high the stakes are — and the potential for causing disruption by shutting down factories or turning off power — we'd highly suggest patching ASAP. For one thing, the flaws could be exploited to quietly disrupt operations, create unsafe or dangerous situations, or affect machinery in ways outside of their expected programming, a la [16]Stuxnet .

Well, you know, in theory.

As Microsoft warned: "A DoS attack against a device using a vulnerable version of Codesys could enable threat actors to shut down a power plant, while remote code execution could create a backdoor for devices and let attackers tamper with operations, cause a PLC to run in an unusual way, or steal critical information."

We've asked Codesys if it has any further comment. ®

Get our [17]Tech Resources



[1] https://github.com/microsoft/CoDe16

[2] https://www.theregister.com/2023/08/08/microsoft_intel_august_patch_tuesday/

[3] https://store.codesys.com/en/engineering/codesys.html

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZNavia6409qwZ1iR@LUXiAAAAYY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://www.codesys.com/the-system/codesys-inside.html

[6] https://webstore.iec.ch/publication/4552

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZNavia6409qwZ1iR@LUXiAAAAYY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZNavia6409qwZ1iR@LUXiAAAAYY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZNavia6409qwZ1iR@LUXiAAAAYY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://www.microsoft.com/en-us/security/blog/2023/08/10/multiple-high-severity-vulnerabilities-in-codesys-v3-sdk-could-lead-to-rce-or-dos/

[11] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9013

[12] https://www.theregister.com/2023/08/08/microsoft_intel_august_patch_tuesday/

[13] https://www.theregister.com/2023/08/10/cisa_ukraine_black_hat/

[14] https://www.theregister.com/2023/08/10/microsoft_onedrive/

[15] https://www.theregister.com/2023/08/11/satellite_hacking_black_hat/

[16] https://www.theregister.com/2012/06/01/stuxnet_joint_us_israeli_op/

[17] https://whitepapers.theregister.com/



Codesys

thames

Codesys is not in itself a PLC. Rather, it's software which can be used to create programs which are written in PLC style and which are then compiled and run on an embedded system. It's mainly used by a few smaller companies in specialized equipment.

The mainstream PLC vendors all have their own proprietary systems which they sell as complete hardware plus pre-installed run-time software combinations.

Most people who work with PLCs will probably never run into a Codesys at anytime during their career, and I expect that a majority will never have even heard of it. As a consequence of this, any problems created by this will be fairly limited.

As for IEC 61131, it's a farce. It was a vendor driven process and they simply declared that anything and everything was standard, so it provides no cross-system compatibility or portability. Porting a PLC program means a complete re-write.

panic: kernel trap (ignored)