The Cybersecurity and Infrastructure Security Agency (CISA) is aware of a public report, known as OT:ICEFALL, which outlines vulnerabilities found in multiple operational technology vendors. CISA is issuing this advisory to inform people of the reported vulnerabilities and provide baseline mitigations to reduce the risk of these and other cyberattacks. This updated advisory is a follow-up to the original advisory published on June 28, 2022. If exploited, these vulnerabilities could lead to a denial-of-service condition and allow remote code execution. CVE-2022-31204, CVE-2022-31205, CVE-2022-31206, and CVE-2022-31207 have been assigned to these vulnerabilities. Omron recommends users of SYSMAC CS/CJ/CP Series to use the PLC protection password and enable protection against unauthorized write access. They also suggest using different passwords between the CP1W-CIF41 Ethernet Option Board and CP1 PLC itself. CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as minimizing network exposure for all control system devices and/or systems, and ensuring they are not accessible from the Internet. CISA also provides a section for control systems security recommended practices on the ICS webpage at cisa. No known public exploits specifically target these vulnerabilities. CISA encourages people to provide feedback about this product.
This Cyber News was published on us-cert.cisa.gov. Publication date: Thu, 09 Feb 2023 17:49:02 +0000