Brief

Summary:

The document is a View CSAF (Common Vulnerabilities and Exposures Advisory) for Rockwell Automation's Connected Components Workbench Smart Security Manager. The advisory reports multiple vulnerabilities, including a use-after-free vulnerability, two out-of-bounds write vulnerabilities, and a heap buffer overflow vulnerability. The vulnerabilities have a combined CVSS v3 score of 9.6, 8.8, 8.8, and 8.8, respectively. The vulnerabilities allow a remote threat actor to exploit heap corruption via a crafted HTML page and could potentially lead to a sandbox escape. The affected products are Connected Components Workbench versions prior to R21. Rockwell Automation recommends updating to R21 and later, and implementing security best practices to minimize the risk of exploitation. The advisory also provides mitigation guidance and recommended practices for industrial control systems cybersecurity.

View CSAF

1. EXECUTIVE SUMMARY

  • CVSS v3 9.6
  • ATTENTION: Exploitable remotely/low attack complexity/public exploits are available/known public exploitation
  • Vendor: Rockwell Automation
  • Equipment: Connected Components Workbench
  • Vulnerabilities: Use After Free, Out-of-bounds Write

2. RISK EVALUATION

Successful exploitation of these vulnerabilities could allow an attacker to exploit heap corruption via a crafted HTML.

3. TECHNICAL DETAILS

3.1 AFFECTED PRODUCTS

The following versions of Rockwell Automation Connected Components Workbench Smart Security Manager are affected:

  • Connected Components Workbench: versions prior to R21

3.2 Vulnerability Overview

3.2.1 USE AFTER FREE CWE-416

Connected Components Workbench utilizes CefSharp version 81.3.100 that contains a use after free vulnerability in Google Chrome versions before 86.0.4240.198. If exploited, a remote threat actor could potentially perform a sandbox escape via a crafted HTML page.

CVE-2020-16017 has been assigned to this vulnerability. A CVSS v3 base score of 9.6 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).

3.2.2 USE AFTER FREE CWE-416

Connected Components Workbench utilizes CefSharp version 81.3.100 that contains a use after free vulnerability in Animation within Google Chrome before 98.0.4758.102. This vulnerability could potentially allow a remote threat actor to exploit heap corruption via a crafted HTML page.

CVE-2022-0609 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).

3.2.3 OUT-OF-BOUNDS WRITE CWE-787

Connected Components Workbench utilizes CefSharp version 81.3.100 that contains an inappropriate implementation in V8 of Google Chrome before 86.0.4240.18. This vulnerability allows a remote threat actor to potentially exploit heap corruption via a crafted HTML page.

CVE-2020-16009 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).

3.2.4 OUT-OF-BOUNDS WRITE CWE-787

Connected Components Workbench utilizes CefSharp version 81.3.100 that contains an inappropriate implementation in V8 of Google Chrome before 86.0.4240.198. This vulnerability allows a remote threat actor to potentially exploit heap corruption via a crafted HTML page.

CVE-2020-16013 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).

3.2.5 OUT-OF-BOUNDS WRITE CWE-787

Connected Components Workbench utilizes CefSharp version 81.3.100 that contains a heap buffer overflow vulnerability in Freetype within Google Chrome before 86.0.4240.111. This vulnerability could allow a remote threat actor to potentially exploit heap corruption via a crafted HTML page.

CVE-2020-15999 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).

3.3 BACKGROUND

  • CRITICAL INFRASTRUCTURE SECTORS: Multiple
  • COUNTRIES/AREAS DEPLOYED: Worldwide
  • COMPANY HEADQUARTERS LOCATION: United States

3.4 RESEARCHER

Rockwell Automation reported these vulnerabilities to CISA.

4. MITIGATIONS

Rockwell Automation recommends users to update to R21 and later.

Users with the affected software are encouraged to apply the risk mitigations, if possible.

Additionally, Rockwell Automation encourages users to implement their suggested security best practices to minimize the risk of vulnerability.

CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:

  • Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
  • Locate control system networks and remote devices behind firewalls and isolating them from business networks.
  • When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.

Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

CISA also recommends users take the following measures to protect themselves from social engineering attacks:

5. UPDATE HISTORY

  • September 21, 2023: Initial Publication

Highlights content goes here...

Summary:

The View CSAF document provides an alert to vulnerabilities in Rockwell Automation’s Connected Components Workbench Smart Security Manager. The vulnerabilities have been assigned CVSS v3 scores ranging from 8.8 to 9.6 and can be exploited remotely with low attack complexity.

The vulnerabilities involve use-after-free, out-of-bounds write, and heap corruption attacks. The first vulnerability, CVE-2020-16017, is a use-after-free vulnerability in Google Chrome versions before 86.0.4240.198. This vulnerability could allow a remote threat actor to perform a sandbox escape via a crafted HTML page.

The other vulnerabilities, CVE-2022-0609 and CVE-2020-16009, are also use-after-free vulnerabilities, and CVE-2020-15999 is an out-of-bounds write vulnerability. These vulnerabilities could allow a remote threat actor to exploit heap corruption via a crafted HTML page.

The affected products are versions of Rockwell Automation’s Connected Components Workbench prior to R21. The vendor recommends updating to R21 and later to mitigate the risk of exploitation. Additionally, Rockwell Automation encourages users to implement security best practices, such as minimizing network exposure, locating control system networks behind firewalls, and using secure remote access methods.

The Cybersecurity and Infrastructure Security Agency (CISA) recommends that organizations perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides recommendations for implementing cybersecurity strategies for proactive defense of industrial control systems (ICS) assets.

The vulnerabilities have been deployed globally and affect multiple critical infrastructure sectors. Rockwell Automation reported the vulnerabilities to CISA, and the initial publication date for the View CSAF document was September 21, 2023.

In summary, the View CSAF document alerts users to vulnerabilities in Rockwell Automation’s Connected Components Workbench Smart Security Manager, which can be exploited remotely with low attack complexity. The vulnerabilities involve use-after-free, out-of-bounds write, and heap corruption attacks, and the affected products are versions of Rockwell Automation’s Connected Components Workbench prior to R21. The vendor recommends updating to R21 and later to mitigate the risk of exploitation.

Cybersecurity and Infrastructure Security Agency

Quick Insight
RADA.AI
RADA.AI
Hello! I'm RADA.AI - Regulatory Analysis and Decision Assistance. Your Intelligent guide for compliance and decision-making. How can i assist you today?
Suggested

Form successfully submitted. One of our GRI rep will contact you shortly

Thanking You!

Enter your Email

Enter your registered username/email id.

Enter your Email

Enter your email id below to signup.

Enter your Email

Enter your email id below to signup.
Individual Plan
$125 / month OR $1250 / year
Features
Best for: Researchers, Legal professionals, Academics
Enterprise Plan
Contact for Pricing
Features
Best for: Law Firms, Corporations, Government Bodies