According to ICS-CERT, the “GHOST" vulnerability (CVE-2015-0235) in the “glibc” library could affect industrial systems. An authenticated local administrator could cause a denial of service of the targeted system by exploiting this vulnerability.
ICS-CERT recommends the three following general defensive measures to protect against this and other cybersecurity risks:
- Minimize network exposure for all control system devices and/or systems, and ensure that they are not accessible from the Internet.
- Locate control system networks and remote devices behind firewalls, and isolate them from the business network.
- When remote access is required, use secure methods, such as Virtual Private Networks (VPNs), recognizing that VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize that VPN is only as secure as the connected devices.
Moxa's Cyber Security Response Team (CSRT) is fully engaged in this matter and we are taking appropriate action. If there are any updates to the status of the vulnerabilities or how these affect Moxa's products, we will provide an update immediately.
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/moxas-response-regarding-the-gnu-glibc-gethostbyname-function-buffer-overflow-vulnerability-ghost-cve-2015-0235