<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>CitectSCADA Safety and Security Knowledge Base</title><description>CitectSCADA Safety and Security Knowledge Base RSS 2.0 Feed</description><link>http://knowledgebase.citect.com/SafetyandSecurity/</link><webMaster>support@citect.com</webMaster><lastBuildDate>Sat, 04 Feb 2012 09:23:31 GMT</lastBuildDate><ttl>20</ttl><generator>CitectSCADA Safety and Security Knowledge Base</generator><item><title>Important security notification - Vulnerability in Historian</title><link>http://knowledgebase.citect.com/SafetyandSecurity/article.aspx?id=1005</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;b&gt;Important security notification - Vulnerability in Historian&lt;/b&gt;&lt;p&gt;&lt;b&gt;January 16, 2012: Update - Resolved Issue on the Webclient&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Updated the fix to resolve the following:&lt;ul&gt;&amp;nbsp;&amp;nbsp;&lt;li&gt;The user is no longer prompted to install HistorianWebClient.cab everytime the client is restarted&lt;/li&gt;&amp;nbsp;&amp;nbsp;&lt;li&gt;Updated the third party TeeChart&amp;trade; ActiveX Control&lt;/li&gt;&lt;/ul&gt;We recommend that all customers install the updated fix by clicking on the relevant link below (Links can be found in the notification dated Oct 24th 2011)&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;October 24, 2011&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Schneider Electric® has become aware of multiple vulnerabilities in Vijeo Historian&amp;trade; V4.30 and earlier, CitectHistorian&amp;trade; V4.30 and earlier, and CitectSCADAReports&amp;trade; V4.10 and earlier.&lt;/p&gt;&lt;p&gt;The vulnerabilities identified include:&lt;ul&gt;&amp;nbsp;&amp;nbsp;&lt;li&gt;Cross-site scripting (XSS) vulnerability which allows remote attackers to inject arbitrary web script or HTML via an HTTP request&lt;/li&gt; &amp;nbsp;&amp;nbsp;&lt;li&gt;Directory traversal vulnerability in the web portal allowing remote attackers to read arbitrary files in a HTTP request&lt;/li&gt; &amp;nbsp;&amp;nbsp;&lt;li&gt;Multiple buffer overflows in the third party TeeChart&amp;trade; ActiveX control allowing a remote attacker using social engineering to cause a denial of service and / or execute arbitrary code.&lt;/li&gt;&lt;/ul&gt;&lt;/p&gt;&lt;b&gt;Recommendation&lt;/b&gt;&lt;p&gt;Schneider Electric has developed a fix for the above vulnerabilities.&lt;/p&gt;&lt;p&gt;Please note, this fix &lt;b&gt;WILL NOT&lt;/b&gt; affect the capacities/functionalities of the product or impact the performance of your installation.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Schneider Electric recommends ALL customers using above mentioned software packages to download and apply the fix.&lt;/b&gt;&lt;/p&gt;&lt;p&gt;The fix is available from each version family of the product:&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.citect.com/documents/downloads/fix/V4.30-Combined-Fix-HF43053651.zip"&gt;Version V4.30 of Vijeo Historian / CitectHistorian&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.citect.com/documents/downloads/fix/V4.20-Combined-Fix-HF42053652.zip"&gt;Version V4.20 of Vijeo Historian / CitectHistorian&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.citect.com/documents/downloads/fix/V4.10-Combined-Fix-HF41053653.zip"&gt;Version V4.10 of Vijeo Historian / CitectSCADA Reports&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Schneider Electric has been designing industrial automation software almost 25 years and educating the market about potential security vulnerabilities. Schneider Electric follows, and recommends to its customers, industry best practices in the development and implementation of control systems.&lt;/p&gt;&lt;b&gt;Acknowledgments&lt;/b&gt;&lt;p&gt;Schneider Electric wishes to thank the following for working with us to help protect our customers:&lt;ul&gt;&lt;li&gt;Steema Software for their prompt response and contribution to the resolution of the TeeChart ActiveX control vulnerability&lt;/li&gt;&lt;li&gt;Researcher Kuang-Chun Hung of Security Research and Service Institute - ICST (Information and Communication Security Technology Center) for reporting the Buffer Overflow Vulnerability (ICS-VU-614277).&lt;/li&gt;&lt;/ul&gt;&lt;b&gt;Support&lt;/b&gt;&lt;p&gt;If you are unsure of whether you could be affected by this vulnerability or if you have any questions on this issue please contact the Operation &amp; Optimization Global Support Centre:&lt;a href="http://www.scada.schneider-electric.com/sites/scada/en/login/country-support.page"&gt;http://www.scada.schneider-electric.com/sites/scada/en/login/country-support.page&lt;/a&gt;&lt;p&gt;&lt;/p&gt;&lt;table border="1"&gt;&lt;tr&gt;&lt;td&gt;Version Number&lt;/td&gt;&lt;td&gt;Date&lt;/td&gt;&lt;td&gt;Comment&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;1.0&lt;/td&gt;&lt;td&gt;24 Oct 2011&lt;/td&gt;&lt;td&gt;Orignal notification released&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;2.0&lt;/td&gt;&lt;td&gt;16 Jan 2012&lt;/td&gt;&lt;td&gt;Updated fix to resolve issue on the web client&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description><pubDate>Tue, 17 Jan 2012 02:40:00 GMT</pubDate><dc:creator>Administrator</dc:creator></item><item><title>Important security notification – Vulnerability within UnitelWay Windows Device Driver</title><link>http://knowledgebase.citect.com/SafetyandSecurity/article.aspx?id=1004</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;b&gt;Important security notification – Vulnerability within UnitelWay Windows Device Driver&lt;/b&gt;&lt;p&gt;    Schneider Electric has become aware of a vulnerability within all versions of the UnitelWay Windows Device Driver, which may have been installed when choosing specific drivers, or by installing all available drivers by default together with the following Schneider Electric software packages:&amp;nbsp;&amp;nbsp;&lt;ul&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;li&gt;Vijeo Citect V7.20 and all previous versions run on Windows XP&lt;/li&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;li&gt;OPC Factory Server V3.34 run on Windows XP&lt;/li&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;li&gt;Telemecanique Driver Pack V2.6 and below&lt;/li&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;li&gt;Unity Pro V6.0 and all previous versions run on Windows XP&lt;/li&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;li&gt;Monitor V7.6 and all previous version run on Windows XP&lt;/li&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;li&gt;PL7 Pro V4.5 SP5 and all previous run on Windows XP&lt;/li&gt;&amp;nbsp;&amp;nbsp;&lt;/ul&gt;&lt;/p&gt;&lt;p&gt;    The vulnerability has been identified as an internal exploit risk, which may cause a buffer overflow allowing arbitrary code to be executed.&lt;/p&gt;&lt;b&gt;What is the associated cyber security risk?&lt;/b&gt;&lt;p&gt;    According to our experts, the vulnerability can only exist if the following conditions are accumulated:     &lt;ul&gt;        &lt;li&gt;A HTTP server has been installed on the engineering station&lt;/li&gt;        &lt;li&gt;The workstation is externally accessible, without firewall protection&lt;/li&gt;        &lt;li&gt;The security level of the internet browser has been unlocked&lt;/li&gt;    &lt;/ul&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;The potential impact for our customers is then dependant on the nature of their application and the content of the arbitrary code.&lt;/p&gt;&lt;p&gt;    The conditions allowing the vulnerability to exist are in direct contradiction to our basic architecture recommendations, thus the likelihood of arbitrary code being executed as a result of the vulnerability is very low.&lt;/p&gt;&lt;b&gt;Recommendation&lt;/b&gt;&lt;p&gt;    Schneider Electric has developed a fix for the vulnerability which will modify one of the libraries of the UnitelWay Windows Device Driver. Please note, this fix &lt;b&gt;WILL NOT&lt;/b&gt; affect the capacities/functionalities of the driver or, therefore, impact the performance of your installation.  &lt;/p&gt;&lt;b&gt;Schneider Electric recommends ALL customers using above listed software packages to download and apply the fix.&lt;/b&gt;&lt;p&gt;    The fix is available from here: &lt;a href="http://www.scada.schneider-electric.com/download/security/HFPEP0047398R.zip"&gt;http://www.scada.schneider-electric.com/download/security/HFPEP0047398R.zip&lt;/a&gt;&lt;/p&gt;&lt;p&gt;    If you are unaware as to whether you have installed this driver or not, the fix will first conduct a scan to detect the presence of the driver. If the driver has not been installed, you will be informed and the fix will not be installed. If the driver has been installed, you will be informed, and will then be able to install the fix.&lt;/p&gt;&lt;p&gt;    Schneider Electric has been designing industrial automation software almost 25 years and educating the market about potential security vulnerabilities. Schneider Electric follows, and recommends to its customers, industry best practices in the development and implementation of control systems. &lt;/p&gt;&lt;b&gt;Support&lt;/b&gt;&lt;p&gt;    If you are unsure of whether you could be affected by this vulnerability or if you have any questions on this issue please contact our support centres.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&lt;b&gt;Vijeo Citect&lt;/b&gt; customers please contact the Operation &amp; Optimization Global Support Centre: &amp;nbsp;&amp;nbsp;&lt;a  href="http://www.scada.schneider-electric.com/sites/scada/en/login/country-support.page"&gt;http://www.scada.schneider-electric.com/sites/scada/en/login/country-support.page&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;All other customers please select your local Customer Care Center:&amp;nbsp;&amp;nbsp;&lt;a  href="http://www2.schneider-electric.com/sites/corporate/en/support/operations/local-operations/local-operations.page"&gt;http://www2.schneider-electric.com/sites/corporate/en/support/operations/local-operations/local-operations.page&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Fri, 30 Sep 2011 00:59:00 GMT</pubDate><dc:creator>Administrator</dc:creator></item><item><title>Important notification about a possible vulnerability on the CitectSCADA Batch Server installed by CitectSCADA&amp;trade; V7.10 and below</title><link>http://knowledgebase.citect.com/SafetyandSecurity/article.aspx?id=1003</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;html&gt;&lt;head&gt;&lt;meta http-equiv="Content-Type" content="text/html; charset=windows-1252"&gt;&lt;body&gt;&lt;font FACE="Arial"&gt;&lt;p DIR="LTR"&gt;Schneider Electric&lt;sup&gt;®&lt;/sup&gt; has become aware of a possible vulnerability within CitectSCADA Batch Server installed by CitectSCADA V7.10 and below.&lt;/p&gt;&lt;b&gt;&lt;p DIR="LTR"&gt;IMPORTANT NOTICE: THE CITECTSCADA SOFTWARE V7.20 AND ALL VERSIONS OF VIJEO CITECT ARE NOT AFFECTED BY THIS POTENTIAL VULNERABILITY. &lt;/p&gt;&lt;/b&gt;&lt;p DIR="LTR"&gt;The vulnerability has been identified as an internal exploit risk, which may result in a buffer overflow allowing arbitrary code to be executed.&lt;/p&gt;&lt;p DIR="LTR"&gt;CitectSCADA Batch has not, for the last five years, been under active enhancement and was only provided to assist customers with existing installations. The vulnerability is contained within a third-party control used in the CitectSCADA Batch product.&lt;/p&gt;&lt;p DIR="LTR"&gt;Schneider Electric has identified all existing licenses of CitectSCADA Batch and we are working individually with our customers to ensure they are not at risk from this vulnerability. Schneider Electric recommends customers who are actively using Batch to contact support and upgrade to its new platform for Batch. We also advise any customers who may have installed CitectSCADA Batch but are not using it, to remove it by using the uninstaller provided on our website &lt;/font&gt;&lt;a href="http://wwwstage.citect.com/citectscada-batch-uninstaller"&gt;&lt;font FACE="Arial" COLOR="#3f803f"&gt;http://www.citect.com/citectscada-batch-uninstaller&lt;/font&gt;&lt;/a&gt;&lt;font FACE="Arial"&gt;.&lt;/p&gt;&lt;p&gt;Schneider Electric has been designing industrial automation software almost 25 years and educating the market about potential security vulnerabilities. Schneider Electric follows, and recommends to its customers, industry best practices in the development and implementation of control systems.&lt;/p&gt;&lt;/font&gt;&lt;/body&gt;&lt;/html&gt;</description><pubDate>Wed, 24 Aug 2011 01:54:00 GMT</pubDate><dc:creator>Geoff Leach</dc:creator></item><item><title>The Modnet Driver May Allow Random Writes To Individual Bits In A Word Using "Read Modify Write" Process</title><link>http://knowledgebase.citect.com/SafetyandSecurity/article.aspx?id=1002</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;FONT size=2 face=Arial&gt;&lt;FONT size=2 face=Arial&gt;&lt;P align=left&gt;We would like to draw your attention to an issue which has been reported to SCADA Global Support regarding the Modnet communication driver.&lt;BR&gt;The issue was reported on Modnet Driver version 2.6.19.0 (release), but is likely to exist on all versions of the driver and is fixed in Modnet Driver version 2.06.025.001 (release).&lt;/P&gt;&lt;P align=left&gt;The issue is independent of the version of SCADA.&lt;BR&gt;The issue has so far only been noted when communicating with Unity Quantum PLCs.&lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;B&gt;&lt;FONT size=2 face=Arial&gt;&lt;FONT size=2 face=Arial&gt;&lt;P align=left&gt;Symptoms:&lt;/P&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=2 face=Arial&gt;&lt;FONT size=2 face=Arial&gt;&lt;P align=left&gt;The Modnet driver allows users to write to individual bits in a word using a process known as "read modify write". &lt;BR&gt;Under certain circumstances other bits in the word being written to can be affected in a random manner.&lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;B&gt;&lt;FONT size=2 face=Arial&gt;&lt;FONT size=2 face=Arial&gt;&lt;P align=left&gt;Circumstances:&lt;/P&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=2 face=Arial&gt;&lt;FONT size=2 face=Arial&gt;&lt;P align=left&gt;The issue only occurs when using the write to bit in a word as described above; other write operations are not affected. &lt;/P&gt;&lt;P align=left&gt;For example, writing to addresses such as 400007.3 or %MW500.5&lt;/P&gt;&lt;P align=left&gt;The issue can only occur when the following parameters are used in the CITECT.INI file:&lt;/P&gt;&lt;P align=left&gt;[Modnet] MaxPending greater than 1&lt;BR&gt;and&lt;BR&gt;[Modnet] MaxOutstanding greater than 1&lt;/P&gt;&lt;P align=left&gt;Please note: the default installed values of these parameters in the current version of the driver are:&lt;/P&gt;&lt;P align=left&gt;[Modnet] MaxPending = 2&lt;BR&gt;[Modnet] MaxOutstanding = 1&lt;/P&gt;&lt;P align=left&gt;Older versions have higher values for both parameters.&lt;BR&gt;Only devices capable of processing requests out of order can demonstrate this issue.&lt;BR&gt;The issue only occurs under increased load conditions when multiple requests are likely to be processed out of order.&lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;B&gt;&lt;FONT size=2 face=Arial&gt;&lt;FONT size=2 face=Arial&gt;&lt;P align=left&gt;&lt;BR&gt;Workaround:&lt;/P&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=2 face=Arial&gt;&lt;FONT size=2 face=Arial&gt;&lt;P align=left&gt;This issue can be avoided by setting the following parameter to be used in the CITECT.INI file:&lt;/P&gt;&lt;P align=left&gt;[Modnet] MaxOutstanding = 1&lt;/P&gt;&lt;P align=left&gt;Note that this workaround can result in a degradation of the communications performance to the Modnet device(s) if you have higher values for this parameter.&lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;P align=left&gt;&lt;B&gt;&lt;FONT size=2 face=Arial&gt;&lt;FONT size=2 face=Arial&gt;&lt;BR&gt;Solution:&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=2 face=Arial&gt;&lt;FONT size=2 face=Arial&gt;&lt;/P&gt;&lt;P align=left&gt;This problem is rectified in the Modnet Release version 2.06.25.001. &lt;BR&gt;Download from DriverWeb and Install.&lt;/P&gt;&lt;P align=left&gt;If you want to receive updates on Modnet driver notifications and discussions you may subscribe to the Modnet forum of DriverWeb or check our website for updated information.&lt;/P&gt;&lt;P align=left&gt;For assistance:&lt;FONT size=2 face=SymbolMT&gt;&lt;FONT size=2 face=SymbolMT&gt;&lt;/P&gt;&lt;P align=left&gt;• &lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=2 face=Arial&gt;&lt;FONT size=2 face=Arial&gt;Vijeo Citect customers, contact your local Schneider office.&lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=2 face=SymbolMT&gt;&lt;FONT size=2 face=SymbolMT&gt;&lt;P align=left&gt;• &lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=2 face=Arial&gt;&lt;FONT size=2 face=Arial&gt;CitectSCADA and CitectFacilities customers, contact the SCADA Global Support Centre on the appropriate number for your country listed below.&lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;B&gt;&lt;FONT size=2 face=Arial&gt;&lt;FONT size=2 face=Arial&gt;&lt;P align=left&gt;SCADA Global Support Centre contact details:&lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=1 face=Arial&gt;&lt;FONT size=1 face=Arial&gt;&lt;P align=left&gt;OCEANIA&lt;BR&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=1 face=Arial&gt;&lt;FONT size=1 face=Arial&gt;Australia: 1300 131 631&lt;BR&gt;New Zealand: 0800 880 026&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;B&gt;&lt;FONT size=1 face=Arial&gt;&lt;FONT size=1 face=Arial&gt;AFRICA&lt;BR&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=1 face=Arial&gt;&lt;FONT size=1 face=Arial&gt;South Africa: 0800 998 887&lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;B&gt;&lt;FONT size=1 face=Arial&gt;&lt;FONT size=1 face=Arial&gt;&lt;P align=left&gt;LATIN AMERICA&lt;BR&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=1 face=Arial&gt;&lt;FONT size=1 face=Arial&gt;Brazil: 800 891 2162&lt;BR&gt;Mexico: 001 866 522 0285&lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;B&gt;&lt;FONT size=1 face=Arial&gt;&lt;FONT size=1 face=Arial&gt;&lt;P align=left&gt;MIDDLE EAST&lt;BR&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=1 face=Arial&gt;&lt;FONT size=1 face=Arial&gt;Israel: 1 809 216 065&lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;B&gt;&lt;FONT size=1 face=Arial&gt;&lt;FONT size=1 face=Arial&gt;&lt;P align=left&gt;NORTH AMERICA&lt;BR&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=1 face=Arial&gt;&lt;FONT size=1 face=Arial&gt;USA/Canada: 866 589 6855&lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;B&gt;&lt;FONT size=1 face=Arial&gt;&lt;FONT size=1 face=Arial&gt;&lt;P align=left&gt;GREATER CHINA&lt;BR&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=1 face=Arial&gt;&lt;FONT size=1 face=Arial&gt;China: 10 800 712 1587&lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;B&gt;&lt;FONT size=1 face=Arial&gt;&lt;FONT size=1 face=Arial&gt;&lt;P align=left&gt;NORTH ASIA&lt;BR&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=1 face=Arial&gt;&lt;FONT size=1 face=Arial&gt;Japan: 00531 121 985&lt;BR&gt;South Korea: 00798 14 800 7112&lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;B&gt;&lt;FONT size=1 face=Arial&gt;&lt;FONT size=1 face=Arial&gt;&lt;P align=left&gt;SOUTH EAST ASIA&lt;BR&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=1 face=Arial&gt;&lt;FONT size=1 face=Arial&gt;Singapore: 0800 120 4562&lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;B&gt;&lt;FONT size=1 face=Arial&gt;&lt;FONT size=1 face=Arial&gt;&lt;P align=left&gt;EUROPE&lt;BR&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=1 face=Arial&gt;&lt;FONT size=1 face=Arial&gt;Belgium 0800 40 710&lt;BR&gt;Czech Republic 0800 134 466&lt;BR&gt;Denmark 808 87 453&lt;BR&gt;Finland 0800 913 065&lt;BR&gt;France 04 72 15 84 50&lt;BR&gt;Germany: +49 8931901445&lt;BR&gt;Hungary: 06 800 18490&lt;BR&gt;Italy: 800 986 902&lt;BR&gt;Norway: 800 11979&lt;BR&gt;Spain: 800 098 944&lt;BR&gt;Sweden: 0200 882 612&lt;BR&gt;Switzerland: 0800 001 241&lt;BR&gt;Netherlands: 0800 020 0498&lt;BR&gt;UK: 0800 376 2869&lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;B&gt;&lt;FONT size=1 face=Arial&gt;&lt;FONT size=1 face=Arial&gt;&lt;P align=left&gt;ALL OTHER COUNTRIES&lt;BR&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=1 face=Arial&gt;&lt;FONT size=1 face=Arial&gt;Reverse call charges: +61 2 9496 7400&lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;B&gt;&lt;FONT size=1 face=Arial&gt;&lt;FONT size=1 face=Arial&gt;&lt;P align=left&gt;EMAIL&lt;BR&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=1 face=Arial&gt;&lt;FONT size=1 face=Arial&gt;support@citect.com&lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=1 face=Arial&gt;&lt;FONT size=1 face=Arial&gt;&lt;/FONT&gt;&lt;/FONT&gt;</description><pubDate>Wed, 24 Feb 2010 00:50:00 GMT</pubDate><dc:creator>Geoff Leach</dc:creator></item><item><title>IDC &amp; FTP security recommendations</title><link>http://knowledgebase.citect.com/SafetyandSecurity/article.aspx?id=1001</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;P&gt;&lt;STRONG&gt;Products:&lt;/STRONG&gt; CitectSCADA / Vijeo Citect / CitectFacilities&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Versions:&lt;/STRONG&gt; All&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Related area:&lt;/STRONG&gt; IDC (Internet Display Clients) using FTP only&lt;/P&gt;&lt;P&gt;&lt;P&gt;&lt;HR&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Background Information:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;CitectSCADA currently ships with an FTP server, which is installed, but not activated, by default and is used in order to configure and correctly utilise Internet Display Client (IDC) functionality.  &lt;/P&gt;&lt;P&gt;(note: If you are not using the CitectSCADA IDC functionality, do not have your server set-up as a Citect Internet Server - see below - and hence the FTP server is not running, this information will not pertain to your installation and you will need take no further action)&lt;/P&gt;&lt;P&gt;FTP (File Transfer Protocol) provides the capability of transferring files between a client and a server. In the case of CitectSCADA it is used to download project files to the IDC.  You may also use remote command capabilities to submit commands to the server. Consequently, FTP is very useful for working with remote systems, or to move files between systems. However, the use of FTP across the Internet, or other untrusted networks can expose you to certain security risks.&lt;/P&gt;&lt;P&gt;You must understand these risks to ensure that your security policy describes how you will minimize these risks.&lt;/P&gt;&lt;P&gt;Whilst the CitectSCADA FTP server is designed to operate in a 'read-only' mode (that is, files can only be downloaded, not uploaded), FTP communications are, by default, not encrypted. In an unsecure network situation this could expose data or the traffic to sniffing and injection attacks.  The FTP server may be open to a Denial of Service or memory leak attack should an attacker supply invalid format specifiers during login.  This would cause the FTP server to fail and render the IDC's unable to operate until the FTP server was brought back up.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;How do I know if I'm running the CitectSCADA FTP server?&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;If you are using the CitectSCADA IDC functionality you will have to have enabled your server as an 'Internet Server', which will activate the FTP server.  If you are unsure as to whether a server is an Internet Server, please use the Computer Setup Wizard to check the Internet Server setting or see your citect.ini file (paramater will be: [Internet] Server=1).  &lt;/P&gt;&lt;P&gt;&lt;IMG border=0 hspace=0 src="http://knowledgebase.citect.com/SafetyandSecurity/Attachments/483d71e6-5564-4a3f-8260-f21a.JPG"&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Recommendations&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Citect's recommendations for customers who may be concerned about using FTP are as follows:&lt;/P&gt;&lt;P&gt;- switch from using the IDC to the CitectSCADA Web Client.  There are no licensing restrictions in doing this, and minimal functional changes result.  Some set-up is required, including activating a web server (IIS or Apache) and installing a supporting application.  Using the Web Client negates the need for using FTP.  Upgrades from IDC to Web Client are free.  Note that the Web Client is only available for version 6.0 of CitectSCADA and above.  If you are running an earlier version of CitectSCADA, we recommend that you upgrade to the latest version.&lt;/P&gt;&lt;P&gt;- switch from using the IDC to a traditional CitectSCADA desktop client.  There will be a small license key configuration change needed to do this, but again this negates the need to use FTP.  Furthermore, you will need to consider how project files will be deployed to remote clients.&lt;/P&gt;&lt;P&gt;- in circumstances where swapping from the IDC is not an option, we recommend securing your FTP traffic through the use of appropriate firewall rules, SSH and optionally VPN.  Ensure that the network on which the FTP server is running is inaccesible from non-controlled and non-trusted networks and that network logons are tightly controlled.  If possible, use secure IP, which may involve some hardware upgrades.&lt;/P&gt;&lt;P&gt;- if IDCs are not in use, turn off the FTP service (by ensuring a server is not marked as an 'Internet Server' - see above) and/or block FTP traffic at the firewall.&lt;/P&gt;&lt;P&gt;The recommendations above still stand, but in addition we recommend customers still requiring to run IDCs and FTP to also upgrade to version 7.1.  &lt;/P&gt;&lt;P&gt;Release 7.1 of CitectSCADA (Q4 2008) contains an updated version of the FTP server with additional security features.  These features remove the ability to attempt a DOS or memory leak attack, and also address an issue with a hardcoded username and password [v7.0 SP1 and v7.1+ only].  &lt;/P&gt;&lt;P&gt;Alternatively, please install an updated version of the FTP server for your version of CitectSCADA, which will be made available shortly from Citect Support as a separate executable file.  Service Pack 1 for CitectSCADA v7.0, planned for Q4 2008, will also contain the relevant updates.&lt;/P&gt;&lt;P&gt;If you have any questions or concerns, please &lt;A href="http://www.citect.com/index.php?option=com_content&amp;amp;task=view&amp;amp;id=65&amp;amp;Itemid=69"&gt;contact our support department&lt;/A&gt; in the first instance.&lt;/P&gt;&lt;P&gt;[Credits:  our thanks goes to Netragard for their help in identifying the above issues and working with us on recommended actions]&lt;/P&gt;</description><pubDate>Wed, 22 Oct 2008 21:38:00 GMT</pubDate><dc:creator>Administrator</dc:creator></item><item><title>SCADA and Process Control Network Security</title><link>http://knowledgebase.citect.com/SafetyandSecurity/article.aspx?id=1000</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;P&gt;&lt;SPAN id=_ctl0_ArticleRepeater__ctl1_ArticleText&gt;&lt;SPAN id=_ctl0_ArticleRepeater__ctl1_ArticleText&gt;&lt;STRONG&gt;Products:&lt;/STRONG&gt; CitectSCADA / Vijeo Citect / CitectFacilities&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Versions:&lt;/STRONG&gt; All&lt;/P&gt;&lt;P&gt;&lt;P&gt;&lt;HR&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;A security vulnerability has been found in CitectSCADA which could expose the system to a buffer overflow attack.&lt;/P&gt;&lt;P&gt;The issue affects customers running ODBC by targeting an open port (20222) which can cause the system to crash, opening up the possibility of arbitrary code execution.&lt;/P&gt;&lt;P&gt;This vulnerability has been patched for version 6.0A, 6.1A, 6.1B, and version 7.0 of CitectSCADA.  Please see the information below with reference to specific hotfix numbers, or contact our support department for further information.  For customers not requiring ODBC connectivity we recommend closing port 20222 in addition to applying the relevant patch.&lt;/P&gt;&lt;DIV&gt;Patch references:&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;7.0 Patch is HF700R138255&lt;BR&gt;Bug 38255 - Security vulnerability on citect port 20222 (ODBC port).&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;6.1B Patch is HF610B38255&lt;BR&gt;Bug 38255 - Security vulnerability on citect port 20222 (ODBC port). &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;6.1A Patch is HF610A38255&lt;/DIV&gt;&lt;DIV&gt;Bug 38255 - Security vulnerability on citect port 20222 (ODBC port). &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;6.0A Patch is HF600A39160 (yes)&lt;/DIV&gt;&lt;DIV&gt;Bug 38255 - Security vulnerability on citect port 20222 (ODBC port)&lt;BR&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;[note, the hotfixes have been re-tested following the publication of metasploit code designed to target this vulnerability.  We can confirm that the fixes will work against this code.  Also note that closing port 20222 in itself will also work]&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;To obtain Security Hotfixes contact &lt;A href="http://www.citect.com/index.php?option=com_content&amp;amp;task=view&amp;amp;id=65&amp;amp;Itemid=69"&gt;Citect support &lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;For further information please see our website, contact support or your local Citect representative.&lt;/DIV&gt;&lt;P&gt;Further general information:&lt;/P&gt;&lt;P&gt;The following advice is communicated for the benefit and enhancement of the use of our software.&lt;/P&gt;&lt;P&gt;CitectSCADA is not designed to reside on a public network. &lt;/P&gt;&lt;P&gt;We recommend robust protection which may include firewall, intrusion detection systems, VPN and segmentation between the enterprize network and the internet to prevent unauthorized communications to your servers. &lt;/P&gt;&lt;P&gt;Most importantly, we advice that process control networks which typically use open, published communication protocols, should not be accessible from a public network.&lt;/P&gt;Further information is provided in the whitepaper that can be download from our website  &lt;A href="http://www.citect.com/documents/whitepapers/SCADASecurity.pdf"&gt;&lt;FONT color=#6699ff&gt;Technical Whitepaper on SCADA system security&lt;/FONT&gt;&lt;/A&gt;. &lt;P&gt;Additional information on the security and protection of SCADA and PCN is currently available through several established government associated sources such as: &lt;/P&gt;&lt;P&gt;&lt;U&gt;USA&lt;/U&gt;&lt;BR&gt;&lt;A href="http://www.us-cert.gov/control_systems/csstandards.html#estab"&gt;&lt;FONT color=#6699ff&gt;US-CERT&lt;/FONT&gt;&lt;/A&gt;: United States Computer Emergency Readiness Team&lt;BR&gt;&lt;BR&gt;&lt;U&gt;Europe&lt;/U&gt;&lt;BR&gt;&lt;A href="http://www.enisa.europa.eu/"&gt;&lt;FONT color=#6699ff&gt;ENISA&lt;/FONT&gt;&lt;/A&gt;: European Network Information Security Agency&lt;BR&gt;&lt;BR&gt;&lt;U&gt;UK&lt;/U&gt;&lt;BR&gt;&lt;A href="http://www.govcertuk.gov.uk/"&gt;&lt;FONT color=#6699ff&gt;GovCertUK&lt;/FONT&gt;&lt;/A&gt;: Computer Emergency Response Team &lt;BR&gt;(previous responsibility with NISCC: National Infrastructure Security Co-ordination Centre) &lt;/P&gt;&lt;DIV&gt;&lt;A href="http://www.cpni.gov.uk/"&gt;&lt;FONT color=#6699ff&gt;CPNI&lt;/FONT&gt;&lt;/A&gt;: Centre for the Protection of National Infrastructure&lt;BR&gt;&lt;A href="http://www.cpni.gov.uk/docs/re-20050223-00157.pdf"&gt;&lt;FONT color=#6699ff&gt;SCADA Security publication&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;U&gt;&lt;BR&gt;Australia&lt;/U&gt;&lt;BR&gt;&lt;A href="http://www.tisn.gov.au/"&gt;&lt;FONT color=#6699ff&gt;TISN&lt;/FONT&gt;&lt;/A&gt;: Trusted Information Sharing Network&lt;BR&gt;&lt;A href="http://www.tisn.gov.au/agd/WWW/rwpattach.nsf/VAP/%28930C12A9101F61D43493D44C70E84EAA%29~SCADA+Security.pdf/$file/SCADA+Security.pdf"&gt;&lt;FONT color=#6699ff&gt;SCADA Security publication&lt;/FONT&gt;&lt;/A&gt;&lt;BR&gt;&lt;BR&gt;Further sources of information such as, standards association publications, papers and references can been found within the above links.&lt;/DIV&gt;</description><pubDate>Sat, 20 Sep 2008 02:27:00 GMT</pubDate><dc:creator>Administrator</dc:creator></item></channel></rss>
