Rewterz Threat Advisory Siemens SIMATIC RF6XXR Multiple Vulnerabilities

Friday, July 12, 2019

Severity

Medium

Analysis Summary

CVE-2011-3389

The SSL protocol encrypts data by using CBC mode with chained initialization vectors, which may allow a man-in-the-middle attack to obtain plaintext HTTP headers.

CVE-2016-6329

Long-duration TLS sessions used with a 64-bit block cipher may allow remote attackers to obtain cleartext data.

CVE-2013-0169

Outdated versions of TLS and DTLS allow statistical analysis of timing data for crafted packets, which may allow remote attackers to conduct distinguishing and plaintext-recovery attacks.

Impact

Improper Input Validation

Affected Vendors

Siemens

Affected Products

  • Siemens RF615R
  • Siemens RF68XR

Remediation

Siemens recommends users upgrade to Version 3.2.1 or newer for both affected products.

Data Sheets

Corporate Brochure


Our Story


Services


Solutions


Managed Security


Upcoming Rewterz Trainings/Events

Rewterz News

  • 11, October 2019 Rewterz Threat Alert – Kimsuky Group – IOC’s
  • 11, October 2019 Rewterz Threat Advisory – CVE-2019-10936 – Siemens PROFINET Devices Denial of Service Vulnerability
  • 11, October 2019 Rewterz Threat Advisory – CVE-2019-10923 – Siemens Industrial Real-Time (IRT) Devices DoS Vulnerability
  • 10, October 2019 Rewterz Threat Alert – Another Agenttesla campaign using a compromised Iraq Government site

Copyright © Rewterz. All rights reserved.