{
  "document": {
    "acknowledgments": [
      {
        "organization": "CERT@VDE",
        "summary": "coordination",
        "urls": [
          "https://certvde.com"
        ]
      },
      {
        "organization": "Positive Technologies",
        "summary": "discovered and reported",
        "names": [
          "Sergey Fedonin",
          "Denis Goryushev",
          "Anton Dorfman"
        ]
      },
      {
        "organization": "SCADAfence",
        "names": [
          "Yossi Reuven"
        ],
        "summary": "discovered and reported"
      }
    ],
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "notes": [
      {
        "category": "summary",
        "text": "The affected products contain a CODESYS Control runtime system in version V2. They are therefore affected by the\nvulnerability described in CODESYS Advisory 2021-06. It provides a communication server for the communication with clients like the CODESYS Development System.\n\nThe 9400 servo inverters is only affected if the communication Path via the inserted EtherNet Module E94AYCEN on slot MXI1 or MXI2 is used. If the Module E94AYCEN is used, the following Versions are affected.\n\nProduct Identification: E94xSHxxx (Single Drive, High Line)\nProduct Identification: E94xMHxxx (Multi Drive, High Line)\n\nRemark: If the product identification of your 9400 product does not fit to the above mentioned identification, please contact Lenze at Security.de@Lenze.com.\n\nThe Versions P (power supply module) and R (regenerative power supply module) are not affected. Furthermore, the Variant P (PLC) and the Variant S (StateLine) are not affected. The communication paths via the diagnostic interface X6, the system bus (CAN) X1 or the field buses (other than the named Ethernet module) that can be plugged into the module slots MXI1 or MXI2 are not affected.\n\nThe focus is therefore on 9400 servo inverters with the product-identification E94x{S/M}{H}... with a plugged in Ethernet module E94AYCEN... in module slot MXI1 or MXI2 and communication with the Engineer-Tools via exactly this channel.\n\nIn addition to the standard tool Engineer, there is also a special Version of the PLC Designer (Version 0.x). The communication path to the PLC Designer is not considered with the planned update and the vulnerabilities here remain even after the update. Here, the customer must provide a secure Environment, see Mitigation.",
        "title": "Summary"
      },
      {
        "category": "description",
        "title": "Impact",
        "text": "A crafted request may cause a heap-based, a stack-based buffer overflow or a buffer over-read in the affected products, resulting in a denial-of-service condition or being utilized for remote code execution.\n\nThe crafted requests are only processed on the products, if no online password is configured on the products or if the attacker has previously successfully authenticated himself at the affected products."
      },
      {
        "title": "Mitigation",
        "text": "As part of a security strategy, Lenze SE recommends the following general defense measures to reduce the risk of exploits:\n\n- Only use the products in a protected and controlled environment to minimize network impact and to ensure that they are inaccessible from outside.\n- Use firewalls to protect the automation system network and to separate it from other networks.\n\n\nRemark: One Measure should be to Block port 1200 via the firewall and open this port for authenticated access only.\n\n- Use Virtual Private Networks (VPN) tunnels when remote access is required.\n- Use IDS (Intrusion Detection Systems) where possible to detect anomalies in the network.\n- Activate and use user administration and password functions.\n- Use encrypted communication links.\nRestrict access to both the development tools and their projects and the products of the automation system by physical means, operating system functions, etc.\n- Protect the development tool by using the latest virus detection solutions.",
        "category": "description"
      },
      {
        "text": "The affected products\n\n- Embedded Line EL 1800-9800\n- Command Station CS 5800-9800\n- Control Cabinet PC 2800\n- EL100 PLC\n\nare at the end of life and are no longer available. A further development or adaption of the\nproducts is no longer planned and no longer possible from the process of discontinuation.\n\nThe affected product\n\n- 9400 servo inverters\n\nin the constellation described above will be revised in the next product release. An update is\nplanned for Q2 2022.",
        "title": "Remediation",
        "category": "description"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "psirt@lenze.com",
      "name": "Lenze SE",
      "namespace": "https://www.lenze.com"
    },
    "references": [
      {
        "category": "external",
        "summary": "Lenze advisory overview at CERT@VDE",
        "url": "https://certvde.com/de/advisories/vendor/lenze/"
      },
      {
        "category": "self",
        "summary": "VDE-2021-048: Lenze: Multiple Vulnerabilities in CODESYS Control V2 communication - HTML",
        "url": "https://certvde.com/en/advisories/VDE-2021-048"
      },
      {
        "summary": "VDE-2021-048: Lenze: Multiple Vulnerabilities in CODESYS Control V2 communication - CSAF",
        "url": "https://lenze.csaf-tp.certvde.com/.well-known/csaf/white/2021/vde-2021-048.json",
        "category": "self"
      }
    ],
    "title": "Lenze: Multiple Vulnerabilities in CODESYS Control V2 communication",
    "tracking": {
      "aliases": [
        "VDE-2021-048"
      ],
      "current_release_date": "2021-10-04T12:33:00.000Z",
      "generator": {
        "date": "2025-03-24T12:03:41.535Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.5.21"
        }
      },
      "id": "VDE-2021-048",
      "initial_release_date": "2021-10-04T12:33:00.000Z",
      "revision_history": [
        {
          "date": "2021-10-04T12:33:00.000Z",
          "number": "1",
          "summary": "Initial revision."
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "product_groups": [
      {
        "group_id": "CSAFGID-0001",
        "summary": "Affected Products.",
        "product_ids": [
          "CSAFPID-31001",
          "CSAFPID-31002",
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005"
        ]
      }
    ],
    "branches": [
      {
        "category": "vendor",
        "name": "Weidmueller",
        "branches": [
          {
            "category": "product_family",
            "name": "Hardware",
            "branches": [
              {
                "name": "Command Station CS 5800-9800",
                "category": "product_name",
                "product": {
                  "name": "Command Station CS 5800-9800",
                  "product_id": "CSAFPID-11001"
                }
              },
              {
                "name": "Control Cabinet PC 2800",
                "category": "product_name",
                "product": {
                  "name": "Control Cabinet PC 2800",
                  "product_id": "CSAFPID-11002"
                }
              },
              {
                "name": "EL100 PLC",
                "category": "product_name",
                "product": {
                  "name": "EL100 PLC",
                  "product_id": "CSAFPID-11003"
                }
              },
              {
                "name": "Embedded Line EL 1800-9800",
                "category": "product_name",
                "product": {
                  "name": "Embedded Line EL 1800-9800",
                  "product_id": "CSAFPID-11004"
                }
              },
              {
                "name": "EtherNet Module E94AYCEN on slot MXI1 or MXI2 in 9400 servo inverters",
                "category": "product_name",
                "product": {
                  "name": "EtherNet Module E94AYCEN on slot MXI1 or MXI2 in 9400 servo inverters",
                  "product_id": "CSAFPID-11005",
                  "product_identification_helper": {
                    "model_numbers": [
                      "E94xSHxxx"
                    ]
                  }
                }
              },
              {
                "name": "EtherNet Module E94AYCEN on slot MXI1 or MXI2 in 9400 servo inverters",
                "category": "product_name",
                "product": {
                  "name": "EtherNet Module E94AYCEN on slot MXI1 or MXI2 in 9400 servo inverters",
                  "product_id": "CSAFPID-11006",
                  "product_identification_helper": {
                    "model_numbers": [
                      "E94xMHxxx"
                    ]
                  }
                }
              }
            ]
          },
          {
            "name": "Firmware",
            "category": "product_family",
            "branches": [
              {
                "name": "<=V15.02.04",
                "category": "product_version_range",
                "product": {
                  "name": "Firmware <=V15.02.04",
                  "product_id": "CSAFPID-21001"
                }
              },
              {
                "name": "vers:all/*",
                "category": "product_version_range",
                "product": {
                  "name": "Firmware vers:all/*",
                  "product_id": "CSAFPID-21002"
                }
              }
            ]
          }
        ]
      }
    ],
    "relationships": [
      {
        "relates_to_product_reference": "CSAFPID-11001",
        "product_reference": "CSAFPID-21002",
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware vers:all/* installed on Command Station CS 5800-9800",
          "product_id": "CSAFPID-31001"
        }
      },
      {
        "relates_to_product_reference": "CSAFPID-11002",
        "product_reference": "CSAFPID-21002",
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware vers:all/* installed on Control Cabinet PC 2800",
          "product_id": "CSAFPID-31002"
        }
      },
      {
        "relates_to_product_reference": "CSAFPID-11003",
        "product_reference": "CSAFPID-21002",
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware vers:all/* installed on EL100 PLC",
          "product_id": "CSAFPID-31003"
        }
      },
      {
        "relates_to_product_reference": "CSAFPID-11004",
        "product_reference": "CSAFPID-21002",
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware vers:all/* installed on Embedded Line EL 1800-9800",
          "product_id": "CSAFPID-31004"
        }
      },
      {
        "relates_to_product_reference": "CSAFPID-11005",
        "product_reference": "CSAFPID-21001",
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware <=V15.02.04 installed on EtherNet Module E94AYCEN on slot MXI1 or MXI2 in 9400 servo inverters",
          "product_id": "CSAFPID-31005"
        }
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2021-30188",
      "title": "CVE-2021-30188",
      "cwe": {
        "id": "CWE-787",
        "name": "Out-of-bounds Write"
      },
      "notes": [
        {
          "title": "Vulnerability Description",
          "category": "description",
          "text": "CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow."
        }
      ],
      "product_status": {
        "known_affected": [
          "CSAFPID-31001",
          "CSAFPID-31002",
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005"
        ]
      },
      "remediations": [
        {
          "category": "mitigation",
          "details": "As part of a security strategy, Lenze SE recommends the following general defense measures to reduce the risk of exploits:\n\n- Only use the products in a protected and controlled environment to minimize network impact and to ensure that they are inaccessible from outside.\n- Use firewalls to protect the automation system network and to separate it from other networks.\n\n\nRemark: One Measure should be to Block port 1200 via the firewall and open this port for authenticated access only.\n\n- Use Virtual Private Networks (VPN) tunnels when remote access is required.\n- Use IDS (Intrusion Detection Systems) where possible to detect anomalies in the network.\n- Activate and use user administration and password functions.\n- Use encrypted communication links.\nRestrict access to both the development tools and their projects and the products of the automation system by physical means, operating system functions, etc.\n- Protect the development tool by using the latest virus detection solutions.",
          "group_ids": [
            "CSAFGID-0001"
          ]
        },
        {
          "details": "The affected products\n\n- Embedded Line EL 1800-9800\n- Command Station CS 5800-9800\n- Control Cabinet PC 2800\n- EL100 PLC\n\nare at the end of life and are no longer available. A further development or adaption of the\nproducts is no longer planned and no longer possible from the process of discontinuation.\n\nThe affected product\n\n- 9400 servo inverters\n\nin the constellation described above will be revised in the next product release. An update is\nplanned for Q2 2022.",
          "group_ids": [
            "CSAFGID-0001"
          ],
          "category": "vendor_fix"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "temporalScore": 9.8,
            "temporalSeverity": "CRITICAL",
            "environmentalScore": 9.8,
            "environmentalSeverity": "CRITICAL",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "availabilityImpact": "HIGH"
          },
          "products": [
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-30195",
      "title": "CVE-2021-30188",
      "cwe": {
        "id": "CWE-125",
        "name": "Out-of-bounds Read"
      },
      "notes": [
        {
          "title": "Vulnerability Description",
          "category": "description",
          "text": "CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation."
        }
      ],
      "product_status": {
        "known_affected": [
          "CSAFPID-31001",
          "CSAFPID-31002",
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005"
        ]
      },
      "remediations": [
        {
          "category": "mitigation",
          "details": "As part of a security strategy, Lenze SE recommends the following general defense measures to reduce the risk of exploits:\n\n- Only use the products in a protected and controlled environment to minimize network impact and to ensure that they are inaccessible from outside.\n- Use firewalls to protect the automation system network and to separate it from other networks.\n\n\nRemark: One Measure should be to Block port 1200 via the firewall and open this port for authenticated access only.\n\n- Use Virtual Private Networks (VPN) tunnels when remote access is required.\n- Use IDS (Intrusion Detection Systems) where possible to detect anomalies in the network.\n- Activate and use user administration and password functions.\n- Use encrypted communication links.\nRestrict access to both the development tools and their projects and the products of the automation system by physical means, operating system functions, etc.\n- Protect the development tool by using the latest virus detection solutions.",
          "group_ids": [
            "CSAFGID-0001"
          ]
        },
        {
          "details": "The affected products\n\n- Embedded Line EL 1800-9800\n- Command Station CS 5800-9800\n- Control Cabinet PC 2800\n- EL100 PLC\n\nare at the end of life and are no longer available. A further development or adaption of the\nproducts is no longer planned and no longer possible from the process of discontinuation.\n\nThe affected product\n\n- 9400 servo inverters\n\nin the constellation described above will be revised in the next product release. An update is\nplanned for Q2 2022.",
          "group_ids": [
            "CSAFGID-0001"
          ],
          "category": "vendor_fix"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "temporalScore": 7.5,
            "temporalSeverity": "HIGH",
            "environmentalScore": 7.5,
            "environmentalSeverity": "HIGH",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "availabilityImpact": "HIGH"
          },
          "products": [
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-30186",
      "title": "CVE-2021-30186",
      "cwe": {
        "id": "CWE-787",
        "name": "Out-of-bounds Write"
      },
      "notes": [
        {
          "title": "Vulnerability Description",
          "category": "description",
          "text": "CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow."
        }
      ],
      "product_status": {
        "known_affected": [
          "CSAFPID-31001",
          "CSAFPID-31002",
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005"
        ]
      },
      "remediations": [
        {
          "category": "mitigation",
          "details": "As part of a security strategy, Lenze SE recommends the following general defense measures to reduce the risk of exploits:\n\n- Only use the products in a protected and controlled environment to minimize network impact and to ensure that they are inaccessible from outside.\n- Use firewalls to protect the automation system network and to separate it from other networks.\n\n\nRemark: One Measure should be to Block port 1200 via the firewall and open this port for authenticated access only.\n\n- Use Virtual Private Networks (VPN) tunnels when remote access is required.\n- Use IDS (Intrusion Detection Systems) where possible to detect anomalies in the network.\n- Activate and use user administration and password functions.\n- Use encrypted communication links.\nRestrict access to both the development tools and their projects and the products of the automation system by physical means, operating system functions, etc.\n- Protect the development tool by using the latest virus detection solutions.",
          "group_ids": [
            "CSAFGID-0001"
          ]
        },
        {
          "details": "The affected products\n\n- Embedded Line EL 1800-9800\n- Command Station CS 5800-9800\n- Control Cabinet PC 2800\n- EL100 PLC\n\nare at the end of life and are no longer available. A further development or adaption of the\nproducts is no longer planned and no longer possible from the process of discontinuation.\n\nThe affected product\n\n- 9400 servo inverters\n\nin the constellation described above will be revised in the next product release. An update is\nplanned for Q2 2022.",
          "group_ids": [
            "CSAFGID-0001"
          ],
          "category": "vendor_fix"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "temporalScore": 7.5,
            "temporalSeverity": "HIGH",
            "environmentalScore": 7.5,
            "environmentalSeverity": "HIGH",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "availabilityImpact": "HIGH"
          },
          "products": [
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005"
          ]
        }
      ]
    }
  ]
}