Amnesia:33 –Impact on B&R Products Cyber Security Advisory
2021-10-20
■B&R is aware of a series of vulnerabilities disclosed by Forescout, known as Amnesia:33 (hereafter called “Amnesia”). Amnesia comprises 33 vulnerabilities in 4 open source TCP/IP stacks designed for embedded systems.
■One B&R POWERLINK stack includes a proprietary TCP/IP stack which is related to a TCP/IP stack affected by Amnesia. B&R has discovered that this proprietary TCP/IP stack is affected by two Amnesia vulnerabilities. Since the affected TCP/IP stack is a part of it, the POWERLINK stack is affected too.
■The affected POWERLINK stack is used by a range of B&R field-level products. This means that the following product cate gories are affected by the two Amnesia vulnerabilities discussed in this document:
● B&R Ethernet-based Bus Controllers and related products
●B&R Ethernet-based Customized HMI devices (e.g. Keyboards)
●B&R Motion Control products
●B&R Track Technology products
■Vulnerable B&R field-level products reside in a POWERLINK network. At the network topology level, the POWERLINK network is separated from the control network –illustrated by the example of a typical B&R X20 PLC configuration:
●The control network is connected to Ethernet interface IF2
●The POWERLINK network is connected to Ethernet interface IF3
■One B&R POWERLINK stack includes a proprietary TCP/IP stack which is related to a TCP/IP stack affected by Amnesia. B&R has discovered that this proprietary TCP/IP stack is affected by two Amnesia vulnerabilities. Since the affected TCP/IP stack is a part of it, the POWERLINK stack is affected too.
■The affected POWERLINK stack is used by a range of B&R field-level products. This means that the following product cate gories are affected by the two Amnesia vulnerabilities discussed in this document:
● B&R Ethernet-based Bus Controllers and related products
●B&R Ethernet-based Customized HMI devices (e.g. Keyboards)
●B&R Motion Control products
●B&R Track Technology products
■Vulnerable B&R field-level products reside in a POWERLINK network. At the network topology level, the POWERLINK network is separated from the control network –illustrated by the example of a typical B&R X20 PLC configuration:
●The control network is connected to Ethernet interface IF2
●The POWERLINK network is connected to Ethernet interface IF3
- +1 Like
- Add to Favorites
Recommend
All reproduced articles on this site are for the purpose of conveying more information and clearly indicate the source. If media or individuals who do not want to be reproduced can contact us, which will be deleted.