news.mlab.sh
Back to the feed
vulnerability

Siemens Opcenter RDnL

Critical
Summary

This advisory details a critical vulnerability in Siemens Opcenter RDnL software, specifically related to missing authentication in the ActiveMQ Artemis component. An attacker within an adjacent network could exploit this flaw to establish a connection to a rogue broker, potentially injecting malicious messages or exfiltrating data. Siemens recommends updating to version 2.52.0 or later to mitigate the risk.

The vulnerability, classified as CWE-306 (Missing Authentication for Critical Function), affects Opcenter RDnL, a software solution primarily used in critical manufacturing. An unauthenticated attacker could leverage the Core protocol to force a target broker to connect to a rogue broker under their control. This could lead to the injection of malicious messages into any queue or the exfiltration of data via the compromised broker. The impact is exacerbated by the default configuration allowing incoming Core protocol connections from untrusted sources. Siemens ProductCERT reported this vulnerability to CISA, and recommends immediate action to address the issue.

Read the full article at CISA Advisories