news.mlab.sh
Back to the feed
threat-intel

o6 Automation open62541

Critical
Summary

Multiple vulnerabilities have been identified in o6 Automation open62541, a control system software, potentially allowing for denial of service, arbitrary code execution, and information disclosure. These vulnerabilities stem from integer overflows and use-after-free conditions. The software is used in critical infrastructure sectors like manufacturing, energy, and transportation. Users are strongly advised to update to the latest version or contact o6 Automation for mitigation.

Multiple vulnerabilities have been identified in o6 Automation open62541, a control system software, potentially allowing for denial of service, arbitrary code execution, and information disclosure. These vulnerabilities stem from integer overflows and use-after-free conditions. The software is used in critical infrastructure sectors like manufacturing, energy, and transportation.

Affected Products: o6 Automation open62541 (Windows and Linux) – versions from 1.3.0 to 1.3.17, 1.4.0 to 1.4.16, 1.5.0 to 1.5.4, and master.

An unsigned integer underflow in the PubSub signature verification path may allow a remote attacker to cause a denial of service via a crafted UDP packet. Integer overflows in the UA_Variant arrayDimensions product computation can lead to out-of-bounds heap memory reads, potentially disclosing sensitive information. A heap use-after-free vulnerability in the TransferSubscriptions service can lead to a denial of service or arbitrary code execution.

Background: These vulnerabilities were reported to CISA by Asher Davila of Palo Alto Networks and Abhinav Agarwal. o6 Automation has prepared mitigations and fixes to address these issues and recommends that users update to the newest version. The new version can be obtained by contacting o6 Automation at https://www.o6-automation.com/contact or by downloading from the following locations: https://www.o6-automation.com/contact.

Legal Notice and Terms of Use: This product is provided subject to this Notification and this Privacy & Use policy.

Recommended Practices: CISA recommends users take defensive measures to minimize the risk of exploitation. These include minimizing network exposure for control system devices, isolating them from business networks, and using secure remote access methods like VPNs. Organizations should perform impact analysis and risk assessment prior to deploying defensive measures and implement recommended cybersecurity strategies for proactive defense of ICS assets. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA.

Read the full article at CISA Advisories