news.mlab.sh
Back to the feed
vulnerability

Schneider Electric NetBotz 5 750/755

HighCVSS 7.3
Summary

Schneider Electric has released a security advisory addressing critical vulnerabilities in its NetBotz 5 – 750/755 security and environmental monitors. These vulnerabilities, including OS command injection and SQL injection, could allow remote code execution and data access. Version 5.6.0 of the NetBotz 5 devices includes a fix. Organizations are urged to update immediately and implement recommended cybersecurity best practices to minimize risk.

Schneider Electric is aware of multiple vulnerabilities in its NetBotz 5 – 750/755 products, which are security and environmental monitors providing temperature, humidity, leak, smoke, vibration, door contact, and video monitoring capabilities. Failure to apply the remediation provided below may risk arbitrary or remote code execution over the local network, which could result in device manipulation and unauthorized data access. The following versions of Schneider Electric NetBotz 5 750/755 are affected:

  • NetBotz 5 750 versions 5.5.2 and prior,
  • NetBotz 5 755 Versions 5.5.2 and prior

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause execution of Linux Operating system commands when a system back up is restored that has been maliciously modified.

CWE-564:SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when a malicious user is logged into the NetBotz via the web-service interface or web-ui.

Schneider Electric CPCERT reported these vulnerabilities to CISA. Organizations are strongly recommended to implement the following mitigations:

  • Version 5.6.0 of NetBotz 5 750/755 includes a fix for these vulnerabilities and is available for download here: https://www.se.com/ww/en/product-range/61830-netbotz/#software-and-firmware

Reboot needed: Upon install, the offer will automatically restart. A customer can validate a successful install by logging into the GUI and selecting the ‘About NetBotz’ option. This will indicate the installed version.

General Security Recommendations:

  • Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.
  • Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.
  • Place all controllers in locked cabinets and never leave them in the “Program” mode.
  • Never connect programming software to any network other than the network intended for that device.
  • Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.
  • Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.
  • Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.
  • When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.

CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability. Organizations should perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

Read the full article at CISA Advisories