Amnesia:33 –Impact on B&R Products Cyber Security Advisory

2021-10-20
■B&R is aware of a series of vulnerabilities disclosed by Forescout, known as Amnesia:33 (hereafter called “Amnesia”). Amnesia comprises 33 vulnerabilities in 4 open source TCP/IP stacks designed for embedded systems.
■One B&R POWERLINK stack includes a proprietary TCP/IP stack which is related to a TCP/IP stack affected by Amnesia. B&R has discovered that this proprietary TCP/IP stack is affected by two Amnesia vulnerabilities. Since the affected TCP/IP stack is a part of it, the POWERLINK stack is affected too.
■The affected POWERLINK stack is used by a range of B&R field-level products. This means that the following product cate gories are affected by the two Amnesia vulnerabilities discussed in this document:
● B&R Ethernet-based Bus Controllers and related products
●B&R Ethernet-based Customized HMI devices (e.g. Keyboards)
●B&R Motion Control products
●B&R Track Technology products
■Vulnerable B&R field-level products reside in a POWERLINK network. At the network topology level, the POWERLINK network is separated from the control network –illustrated by the example of a typical B&R X20 PLC configuration:
●The control network is connected to Ethernet interface IF2
●The POWERLINK network is connected to Ethernet interface IF3

B&R Industrial Automation

0AC182.10AC182.1-DAN8I0IF108.400-28I0IF108.400-38I0IF108.400-48I0IF108.400-58I0IF108.400-68I0IF248.300-18SEI0IF248.300-1EMF2191IBLD0BC1083PLCBC0083SE0BC0088SE0BC00H3SE0SLH000SE0SLH000-1SE0SLH001SE0SLH001-1VSBLCP.13PMA-1VSBLCP.15PMA-1VSBLCP.16PMA-1VSBLCP.18PMA-1VSBLCP.1APMA-1VSBLCP.1DPMA-1VSBLCP.1FPMA-1VSBLCP.1HPMA-1VSBLCP.1QPMA-1VSBLCP.1RPMA-1VSBLCP.1SPMA-1VSBLCP.2HPMA-1VSLBMA-1VSLBSTD-1VSLF111Q2.00AP-E01VSS112001.041P-E01VSS112001.041P-E02VSS112001.071P-E02VSS112002.031P-E01VSS112002.051P-E02VSS112821.051P-E01VSS112821.051P-E02VSS112821.052P-E02VSS112831.071P-E02VSS112A31.061P-E02VSS112F11.021P-E02VSS112F21.042P-E02VSS112F21.061P-E02VSS112F31.071P-E02VSS112Q11.022P-E02VSS112Q11.031P-E02VSS112Q11.041P-E01VSS112Q12.021P-E02VSS112Q12.032P-E02VSS112Q21.022P-E02VSS112Q21.042P-E02VSS112Q21.051P-E02VSS112Q21.061P-E01VSS112Q21.061P-E02VSS112Q21.062P-E02VSS112Q21.081P-E01VSS112Q21.121P-E01VSS112Q21.M51P-E01VSS112Q22.031P-E02VSS112Q22.041P-E02VSS112Q22.081P-E01VSS112Q22.121P-E01VSS112Q22.M51P-E02VSS112Q24.061P-E01VSS112Q31.071P-E02VSS112R11.031P-E02VSS112R11.041P-E02VSS112R21.041P-E01VSS112R21.061P-E01VSS112R21.062P-E02VSS112R22.041P-E02VSS112R22.051P-E02VSS112R22.061P-E02VSS112R31.041P-E01VSS112S21.061P-E01VSSCP112.P-1VSSCP112.P-12VSSCP112.P-2VSSCP112.P-22VSSCP122.P-1VSSCP122.P-12VSSCP122.P-2VSSCP122.P-22X20BC0083X20BC0087X20BC0087-10X20BC0087-C01X20BC0088X20BC00E3X20BC00H3X20BC00H3-C01X20BC1083X20BC8083X20BC8084X20CBC0083X20CBC0087X20CBC0088X20CBC00E3X20CBC1083X20CBC8083X20CBC8084X20CHB8815X20CSL8000X20CSL8001X20CSL8100X20CSL8101X20ET8819X20HB8815X20SL8000X20SL8001X20SL8010X20SL8011X20SL8100X20SL8101X20SL8110X67BC81RT.L12X67BC8321.L12X67BC8321-1X67BC8331X67BC8513.L12X67BC8513.L12-1X67BC8591.L12X67BC8780.L12X67BCD321.L12X67BCD321.L12-1X67BCE321.L12X67BCH321.L12X67BCJ321X67BCJ321.L124B1400.00-K214B1400.00-K334B1400.00-K344B1400.00-K354B1400.00-K364B1400.00-K374B1400.00-K384B1400.00-K394B1400.00-K404B1400.00-K424B1400.00-K434B1400.00-K444B1400.00-K454B1400.00-K474B1400.00-K484B1400.00-K504B1400.00-K514B1400.00-K534B1400.00-K564B1400.00-K574B1400.00-K584B1400.00-K624B1400.00-K674B1400.00-K714B1400.00-K724SIM.10-015ACCKP01.215C-C045ACCKPPL.215C-C015ACCKPS0.215C-C015AP1120.1214-C035AP5335.215C-C015AP920.1505-K055AP920.1505-K105AP920.1505-K595AP920.1906-K235AP923.1505-K045AP923.156B-K025AP923.215C-K015AP92D.1214-K015AP92D.1214-K025AP92D.215I-K025AP933.156B-K015AP933.156B-K025AP933.215I-K015AP93D.185B-K015AP93D.215C-K015AP93D.215C-K075AP950.1706-K035AP950.1706-K045AP980.1505-K155AP980.1505-K175AP980.1505-K295AP980.1906-K075AP980.1906-K085E9000.355E9000.445E9000.465E9000.505E9000.535PC720.1505-K188AC114*8B0P*8BVI*8BVP*8CVE*8CVI*8DI*8EI*80VD*8F1I01.AA66.0000-18F1I01.AA66.0100-18F1I01.AB2B.0000-18F1I01.AB2B.0100-18F1I01.BA2B.0000-18F1I01.BA2B.0100-18F1I01.BB4B.0000-18F1I01.BB4B.0100-1

More

Part#

More

More

Development Environment(Software/Firmware)

More

More

Please see the document for details

More

More

English Chinese Chinese and English Japanese

2021-05-27

Version: 1.0

224 KB

- The full preview is over. If you want to read the whole 12 page document,please Sign in/Register -
  • +1 Like
  • Add to Favorites

Recommend

All reproduced articles on this site are for the purpose of conveying more information and clearly indicate the source. If media or individuals who do not want to be reproduced can contact us, which will be deleted.

Contact Us

Email: