🛡 VULNERABILIDADES 🛡

Vulnerabilidades críticas en Siemens SICAM 8 afectan la seguridad industrial

🛡CyberObservatorio
Idioma

Vulnerabilidades críticas en Siemens SICAM 8 afectan la seguridad industrial

Fuente: CISA Alerts

**Vulnerabilidades Críticas en Productos SICAM 8 de Siemens: Un Alerta para la Seguridad en Sistemas Energéticos**

La ciberseguridad es un tema de creciente preocupación en el mundo digital actual, especialmente en sectores críticos como la energía. Recientemente, se han identificado múltiples vulnerabilidades en los productos SICAM 8 de Siemens, un conjunto de dispositivos utilizados para la gestión y supervisión de sistemas eléctricos. Estas vulnerabilidades no solo pueden comprometer la integridad de los sistemas, sino que también representan un riesgo significativo para la continuidad operativa de las infraestructuras críticas. Los operadores de sistemas de energía eléctrica, como los Operadores de Sistemas de Transmisión (TSOs) y los Operadores de Sistemas de Distribución (DSOs), deben estar especialmente atentos a estas amenazas, dado que cualquier interrupción puede tener consecuencias devastadoras para la red y, por extensión, para la sociedad en general.

En total, varios dispositivos del ecosistema SICAM 8 se ven afectados por problemas de seguridad que permiten denegaciones de servicio y otras intrusiones. Los productos implicados incluyen el firmware de los dispositivos SICAM A8000, el CPCI85 para los modelos CP-8031 y CP-8050, así como el SICORE para los modelos CP-8010 y CP-8012, y el firmware del SICAM EGS, entre otros. Siemens ha publicado nuevas versiones para los productos afectados y recomienda encarecidamente a los usuarios que realicen la actualización a las últimas versiones disponibles para mitigar estos riesgos.

Uno de los problemas más graves radica en una interfaz de depuración que está accesible a través de endpoints HTTP. Esta vulnerabilidad permite a un atacante autenticado interrumpir el funcionamiento del sistema, provocando condiciones de denegación de servicio. La capacidad de un atacante para causar un fallo en el proceso web puede poner en riesgo la disponibilidad de servicios críticos, lo que es inaceptable para la infraestructura energética.

Además, el firmware de los productos afectados presenta una debilidad en el mecanismo de validación de firmas durante las actualizaciones. Esta vulnerabilidad puede permitir a un atacante instalar firmware malicioso, lo que podría resultar en la ejecución de código persistente y, en consecuencia, en la compromisión total del sistema. La gestión inadecuada de estas vulnerabilidades puede abrir la puerta a ataques más complejos que podrían poner en jaque la estabilidad y la seguridad de las redes eléctricas.

Otro problema crítico es que la configuración predeterminada de la aplicación desactiva todos los mecanismos de seguridad de OPC UA. Esto habilita a un atacante a obtener acceso no autorizado y controlar funciones críticas del sistema. La falta de validación de las credenciales de autenticación al modificar cuentas administrativas a través de la API web también es alarmante, ya que permite a un atacante autenticado eludir los controles de seguridad y adquirir privilegios elevados de manera no autorizada.

Siemens ha identificado estas vulnerabilidades bajo varias categorías de CWE (Common Weakness Enumeration), siendo la CWE-489 (Código de depuración activo), la CWE-1188 (Inicialización de un recurso con un valor predeterminado inseguro), y la CWE-620 (Cambio de contraseña no verificado). La importancia de corregir estas vulnerabilidades no puede ser subestimada, especialmente para los operadores de sistemas de energía, que deben implementar medidas de protección adecuadas para salvaguardar la integridad de sus redes.

Ante este panorama, Siemens recomienda encarecidamente que los operadores revisen las medidas de protección resilientes que tienen implementadas y que se aseguren de que se apliquen actualizaciones de seguridad de manera regular. Las actualizaciones recomendadas son las versiones V26.20 o posteriores para el firmware CPCI85, disponible en el “Paquete CP-8031/CP-8050”, así como en el “Paquete SICAM EGS”. Para el firmware SICORE, la actualización debe ser a la versión V26.20.0 o posterior, disponible en el “Paquete CP-8010/CP-8012” y en el “Paquete SICAM S8000”.

Además de las actualizaciones de firmware, Siemens aconseja que las organizaciones protejan el acceso a la red utilizando mecanismos apropiados, como cortafuegos y segmentación de red. La configuración del entorno debe seguir las directrices operativas para garantizar que los dispositivos funcionen en un entorno de TI protegido. Las recomendaciones de seguridad se pueden consultar en la página de seguridad de redes de Siemens.

Por su parte, la Agencia de Ciberseguridad e Infraestructura (CISA) de EE. UU. advierte a los usuarios sobre la necesidad de minimizar la exposición de red de los dispositivos de control y asegura que estos no sean accesibles desde Internet. También sugiere el uso de métodos de acceso remoto más seguros, como redes privadas virtuales (VPN), reconociendo que, aunque las VPN son útiles, pueden presentar vulnerabilidades y deben actualizarse regularmente.

La amenaza de ciberincidentes que afecten la fiabilidad de la red es un desafío constante para los operadores de energía. Por ello, se debe realizar un análisis de impacto y una evaluación de riesgos adecuados antes de implementar medidas defensivas. CISA proporciona prácticas recomendadas de seguridad para sistemas de control y alienta a las organizaciones a adoptar estrategias de ciberseguridad proactivas para proteger sus activos de ICS.

En conclusión, las vulnerabilidades detectadas en los productos SICAM 8 de Siemens resaltan la necesidad urgente de que los operadores de sistemas eléctricos implementen medidas de ciberseguridad robustas y actualizaciones de firmware regulares. La integridad y la disponibilidad de la infraestructura energética son esenciales para el funcionamiento de la sociedad moderna, y cualquier descuido en este ámbito podría tener repercusiones graves para la estabilidad de la red eléctrica global.

Siemens SICAM 8

Source: CISA Alerts

View CSAF Multiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: - SICAM A8000 Device firmware - CPCI85 for CP-8031/CP-8050 - SICORE for CP-8010/CP-8012 - SICAM EGS Device firmware - CPCI85 - SICAM S8000 - SICORE Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens SICAM 8 are affected: Expand All + The affected application includes a debugging interface that is accessible through HTTP endpoints. This could allow an authenticated attacker to disrupt the system by crashing the web process causing denial of service conditions. View CVE Details Vendor fixUpdate to V26.20 or later version The firmware CPCI85 V26.20 is present within “CP-8031/CP-8050 Package” V26.20 https://support.industry.siemens.com/cs/ww/en/view/109804985/ and also within “SICAM EGS Package” V26.20 https://support.industry.siemens.com/cs/document/109972536/ Vendor fixUpdate to V26.20.0 or later version The firmware SICORE V26.20.0 is present within “CP-8010/CP-8012 Package” V26.20 https://support.industry.siemens.com/cs/ww/en/view/109972894/ and also within “SICAM S8000 Package” V26.20 https://support.industry.siemens.com/cs/document/109818240 Relevant CWE:CWE-489 Active Debug Code The affected application contains a vulnerability in its firmware update mechanism's signature validation process. This could allow an attacker to install malicious firmware, leading to persistent code execution and system compromise. View CVE Details Vendor fixUpdate to V26.20 or later version The firmware CPCI85 V26.20 is present within “CP-8031/CP-8050 Package” V26.20 https://support.industry.siemens.com/cs/ww/en/view/109804985/ and also within “SICAM EGS Package” V26.20 https://support.industry.siemens.com/cs/document/109972536/ Vendor fixUpdate to V26.20.0 or later version The firmware SICORE V26.20.0 is present within “CP-8010/CP-8012 Package” V26.20 https://support.industry.siemens.com/cs/ww/en/view/109972894/ and also within “SICAM S8000 Package” V26.20 https://support.industry.siemens.com/cs/document/109818240 Relevant CWE:CWE-489 Active Debug Code The affected application ships with a default configuration that disables all OPC UA security mechanisms. This could allow an attacker to gain unauthorized access and control over critical system functions. View CVE Details Vendor fixUpdate to V26.20 or later version The firmware CPCI85 V26.20 is present within “CP-8031/CP-8050 Package” V26.20 https://support.industry.siemens.com/cs/ww/en/view/109804985/ and also within “SICAM EGS Package” V26.20 https://support.industry.siemens.com/cs/document/109972536/ Vendor fixUpdate to V26.20.0 or later version The firmware SICORE V26.20.0 is present within “CP-8010/CP-8012 Package” V26.20 https://support.industry.siemens.com/cs/ww/en/view/109972894/ and also within “SICAM S8000 Package” V26.20 https://support.industry.siemens.com/cs/document/109818240 Relevant CWE:CWE-1188 Initialization of a Resource with an Insecure Default The affected application contains insufficient validation of authentication credentials when processing administrative account modifications through the web API. This could allow an authenticated attacker to bypass security controls and gain unauthorized elevated privileges. View CVE Details Vendor fixUpdate to V26.20 or later version The firmware CPCI85 V26.20 is present within “CP-8031/CP-8050 Package” V26.20 https://support.industry.siemens.com/cs/ww/en/view/109804985/ and also within “SICAM EGS Package” V26.20 https://support.industry.siemens.com/cs/document/109972536/ Vendor fixUpdate to V26.20.0 or later version The firmware SICORE V26.20.0 is present within “CP-8010/CP-8012 Package” V26.20 https://support.industry.siemens.com/cs/ww/en/view/109972894/ and also within “SICAM S8000 Package” V26.20 https://support.industry.siemens.com/cs/document/109818240 Relevant CWE:CWE-620 Unverified Password Change Operators of critical power systems (e.g. TSOs or DSOs) worldwide are usually required by regulations to build resilience into the power grids by applying multi-level redundant secondary protection schemes. It is therefore recommended that the operators check whether appropriate resilient protection measures are in place. The risk of cyber incidents impacting the grid's reliability can thus be minimized by virtue of the grid design. Siemens strongly recommends applying the provided security updates using the corresponding tooling and documented procedures made available with the product. If supported by the product, an automated means to apply the security updates across multiple product instances may be used. Siemens strongly recommends prior validation of any security update before being applied, and supervision by trained staff of the update process in the target environment. As a general security measure Siemens strongly recommends to protect network access with appropriate mechanisms (e.g. firewalls, segmentation, VPN). It is advised to configure the environment according to our operational guidelines in order to run the devices in a protected IT environment. Recommended security guidelines can be found at: https://www.siemens.com/gridsecurity For further inquiries on security vulnerabilities in Siemens products and solutions, please contact Siemens: https://www.siemens.com/cert/advisories The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use. This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. This ICSA is a verbatim republication of Siemens SSA-229470 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens directly for any questions regarding this advisory.