An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance 3.10 and earlier. An incomplete firmware signature allows a local attacker to upgrade the equipment (kernel, file system) with unsigned, attacker controlled, data.
Incomplete firmware signature
Belden Hirschmann
Tofino Xenon Security Appliance - 3.10 and earlier
USB firmware
Local
Yes
Attacker has physical access to the device and ability tu plug USB device into it
https://www.belden.com/hubfs/support/security/bulletins/Belden-Security-Bulletin-BSECV-2017-14-1v1-1.pdf https://www.belden.com/support/security-assurance
Julien Lenoir of Airbus
An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance 3.10 and earlier. Improper handling of the mbap.length field of ModBus packets in the ModBus DPI filter allows an attacker to send malformed/crafted packets to a protected asset, bypassing function code filtering.
DPI ModBus filter bypass
Belden Hirschmann
Tofino Xenon Security Appliance Firmware 3.10 and prior
Modbus enforcer DPI filter
Remote
Bypass DPI filter on industrial firewall
To exploit the vulnerability, attacker is able to send UDP or TCP packets to a protected asset, on a LAN.
https://www.belden.com/hubfs/support/security/bulletins/Belden-Security-Bulletin-BSECV-2017-14-1v1-1.pdf https://www.belden.com/support/security-assurance
Julien Lenoir of Airbus
An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance 3.10 and earlier. Design flaws in OPC classic and in custom netfilter modules allow an attacker to remotely activate rules on the firewall and to connect to any TCP port of a protected asset, thus bypassing the firewall.
Firewall bypass
Belden Hirschmann
Tofino Xenon Security Appliance Firmware 3.10 and prior
Netfilter custom filter combined with OPC Classic DPI filter
Remote
To exploit the vulnerability, someone must connect to a protected asset over OPC Classic port
https://www.belden.com/hubfs/support/security/bulletins/Belden-Security-Bulletin-BSECV-2017-14-1v1-1.pdf https://www.belden.com/support/security-assurance
Julien Lenoir of Airbus