Synopsis
The remote Modicon Quantum controller allows uploading arbitrary files over TFTP.
Description
The remote device is a Modicon Quantum Controller that allows arbitrary file uploads. This can facilitate other attacks since an arbitrary amount of code can be stored on the device and run at a later time.
Additionally, a denial of service vulnerability exists where an attacker can fill the ramdisk and cause the system to crash.
Solution
Block access to the TFTP port.
Plugin Details
File Name: scada_modicon_tftp_enabled.nbin
Supported Sensors: Nessus
Vulnerability Information
Required KB Items: ftp/modicon/user, ftp/modicon/pass
Exploit Ease: Exploits are available
Reference Information
BID: 51605