Ethernet Vulnerabilities in Safety Instrumented Systems (SIS): A Key Difference
ID: 7790b123-4337-504f-946b-b5c45a0e0edf
STIX ID: report--7790b123-4337-504f-946b-b5c45a0e0edf
Feed Name: Dragos Blog
Dragos reported multiple undocumented security defects in Schneider Electric's Triconex Tricon Communication Module (TCM) that enable denial-of-service (CVE-2020-7486) and firmware/root compromise (CVE-2020-7491). These flaws permit attackers to fault the TCM or overwrite its firmware to stage or inject malicious logic (e.g., TRISIS) into SIS processors, and can be exploited even with the SIS keyswitch set to "Run"; recommended mitigations include blocking undocumented TCM services, restricting engineering workstation access, and monitoring for unexpected communications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
