StruxureWare DCE或 NetBotz會受到 CVE-2016-5195 (Dirty COW Vulnerability)感染入侵嗎?
NetBotz
Current NetBotz releases are based on Linux 2.6.12 and this vulnerability was introduced in Linux kernel versions 2.6.22 and newer. This indicates that NetBotz products are not vulnerable to this specific vulnerability.
StruxureWare DCE
DCE 7.x is vulnerable to this issue based on its kernel version within current shipping versions of the appliance. Based on documentation made available by multiple sources, it appears that this can only be exploited as a local user. Schneider Electric does not allow local console access to DCE, so under normal circumstances, the vulnerability would not be exploitable. DCE’s kernel version will be updated in a future version/update of the DCE appliance software, which is not yet available.
Cyber Security is an important element of Schneider Electrics’ commitment to software quality. Regular vulnerability assessment and further investigation is ongoing on other Schneider Electric platforms in addition to the above and will be detailed if discovered.