PatchSiren

PatchSiren cyber security CVE debrief

CVE-2019-14855 Red Hat CVE debrief

CVE-2019-14855 is a HIGH severity vulnerability (CVSS 7.5) affecting Rockwell Automation DataMosaix Private Cloud versions 7.07 and earlier. The vulnerability stems from the product's use of GnuPG, which contains a certificate signature weakness in the SHA-1 algorithm. A threat actor could exploit this to create forged certificate signatures, potentially enabling unauthorized viewing of customer data. The CVE was published on October 10, 2024, with the advisory ICSA-24-284-16 issued by CISA on the same date. Rockwell Automation has addressed this issue in version 7.09 and strongly encourages users to update to the newest available version.

Vendor
Red Hat
Product
DataMosaix Private Cloud
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-10-10
Original CVE updated
2024-10-10
Advisory published
2024-10-10
Advisory updated
2024-10-10

Who should care

Organizations operating Rockwell Automation DataMosaix Private Cloud environments, particularly industrial and manufacturing entities using this platform for data management. Security teams responsible for OT/ICS infrastructure, certificate management administrators, and compliance officers monitoring cryptographic standards in industrial environments should prioritize this update.

Technical summary

The vulnerability exists because DataMosaix Private Cloud utilizes GnuPG, which implements the SHA-1 algorithm for certificate signatures. SHA-1 has known cryptographic weaknesses that enable collision attacks, allowing a threat actor to create forged certificate signatures. Successful exploitation could result in a malicious user viewing customer data. The attack vector is network-based with low attack complexity and no required privileges or user interaction. The vulnerability affects confidentiality through potential unauthorized data access.

Defensive priority

HIGH

Recommended defensive actions

  • Update DataMosaix Private Cloud to version 7.09 or later to address the GnuPG SHA-1 certificate signature vulnerability.
  • Review and implement Rockwell Automation security best practices as referenced in their security advisory documentation.
  • Monitor certificate validation processes and consider additional certificate pinning or verification mechanisms for sensitive data access.
  • Apply network segmentation and defense-in-depth strategies to limit exposure of DataMosaix Private Cloud instances.

Evidence notes

The vulnerability description and remediation guidance are sourced from CISA CSAF advisory ICSA-24-284-16, which identifies DataMosaix Private Cloud <=7.07 as affected and version 7.09 as the remediation release. The CVSS score of 7.5 (HIGH) is provided in the source material.

Official resources

2024-10-10