Hi ICS followers
in the last several weeks, we add/improved 2 important protections to our IPS signatures related to Omron CX-One vulnerabilities.
https://www.checkpoint.com/defense/advisories/public/2018/CPAI-2018-0484.html
https://www.checkpoint.com/defense/advisories/public/2018/CPAI-2018-1210.html
why it is so important? that I bother to inform you about it.
with the CX-One Omron present unique approach by providing one software suite allows users to build, configure, and program a host of devices such as PLCs, HMIs, motion-control systems and networks using just one software package with one installation and license number. This greatly reduces the hassle of software maintenance and management at both the End-User and OEM level.
While we all can acknowledge the operational benefit of having one software to configure all ICS systems. From cyber perspective it might be extremely dangerous, when this software suffer from vulnerabilities which allow the attacker to damage the projects files outcome.