news.mlab.sh
Back to the feed
vulnerability

ABB T-MAC Plus

High
Summary

ABB has identified and addressed several vulnerabilities in its T-MAC Plus Terminal Management System, primarily related to improper configuration and access controls. These vulnerabilities could allow an attacker to execute arbitrary code, disable card readers, and potentially compromise the system. The issues stem from misconfigured IIS servers, incorrect user privileges, and a lack of encryption in the communication protocol. ABB released a security update (version 4.0-25) to resolve these problems. The vulnerabilities were disclosed responsibly by Angelo Catalani of the Italian National Cybersecurity Agency (ACN) and ABB had not received any reports of exploitation at the time of the advisory's release.

ABB became aware of several vulnerabilities in its T-MAC Plus Terminal Management System. An update is available that resolves the reported vulnerabilities. The vulnerabilities are caused by: - Wrong configuration in T-MAC Plus IIS Server. - Wrong configuration of privileges of users. - Lack of encryption in communication protocol. T-MAC Plus is a Terminal Management System (TMS) that handles the different operations (receipt and dispatch product, access control, product movement in the tank farm, …) in a terminal. It is applicable to different type of products such as chemical and petroleum terminals, pipeline or refinery tankage, bulk plants or hydrogen terminals. The following components are affected: - TMAC Plus Web application - Communication protocol with Card Readers. An attacker who successfully exploited these vulnerabilities could cause the affected system node to stop or become inaccessible and allow the attacker to insert and run arbitrary code. To exploit the vulnerability, an attacker would need to have physical access to an affected system node. These vulnerabilities were disclosed responsibly by Angelo Catalani of the Italian National Cybersecurity Agency (ACN) and ABB had not received any information indicating that this vulnerability had been exploited when this security advisory was originally. The update removes the vulnerability by modifying the way that the T-MAC Plus web application and the communication protocol are configured. ABB recommends that customers apply the update at earliest convenience.

Read the full article at CISA Advisories