Motorola Solutions Alert
2668Warning Date
Severity Level
Warning Number
Target Sector
30 June, 2022
● High
2022-5024
All
Description:
Motorola Solutions has released security updates to address multiple vulnerabilities in the following products:
- MOSCAD IP gateway (IPGW): All versions
- ACE IP gateway (CPU 4600): All versions
- MDLC: Versions 4.80.0024, 4.82.004, and 4.83.001
- Motorola Solutions ACE1000: All versions
Threats:
An attacker could exploit these vulnerabilities by doing the following:
- Authentication bypass
- Unauthorized disclosure of information
Best practice and Recommendations:
The CERT team encourages users to review the following practices:
- When remote access is required, use secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available.
- Locate control system networks and remote devices behind firewalls and isolate them from the business network.
- Minimize network exposure for all control system devices and/or systems, use IP filter functions to allow only specific personal computer/device to connect, and ensure they are not accessible from the Internet.