Rewterz

Rewterz Threat Alert – IObit Forums Hacked to Spread DeroHE Ransomware

January 19, 2021
Rewterz

Rewterz Threat Alert – GandCrab Malware – IoCs

January 19, 2021

Rewterz Threat Advisory – ICS: Siemens SCALANCE X Switches

Severity

High

Analysis Summary

CVE-2020-28391 

Devices create a new unique key upon factory reset, except when used with C-PLUG. When used with C-PLUG the devices use the hardcoded private RSA-key shipped with the firmware-image. An attacker could exploit this vulnerability to create a man-in-the-middle situation and decrypt previously captured traffic.

CVE-2020-28395

Devices do not create a new unique private key after factory reset. An attacker could exploit this vulnerability to create a man-in-the-middle situation and decrypt previously captured traffic.

Impact

  • Man-in-the-middle attack
  • Decryption previously captured traffic 

Affected Vendors

Siemens

Affected Products

  • SCALANCE X-200 switch family (incl. SIPLUS NET variants) All versions
  • SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) All versions
  • SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) All versions prior to v4.1.0

Remediation

SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) Update to v4.1.0 or later.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.