Article No° | Product Name | Affected Version(s) |
---|---|---|
Promag 300 with EtherNet/IP | <= 01.01.02 | |
Promag 300 with Foundation Fieldbus | <= 01.00.01 | |
Promag 300 with HART | <= 01.01.01 | |
Promag 300 with MODBUS | <= 01.00.02 | |
Promag 300 with Profibus PA | <= 01.00.03 | |
Promag 300 with PROFINET | <= 01.00.01 | |
Promag 400 with HART | <= 02.00.01 | |
Promag 500 with EtherNet/IP | <= 01.01.02 | |
Promag 500 with Foundation Fieldbus | <= 01.00.01 | |
Promag 500 with HART | <= 01.01.01 | |
Promag 500 with MODBUS | <= 01.00.02 | |
Promag 500 with Profibus PA | <= 01.00.03 | |
Promag 500 with PROFINET | <= 01.00.01 | |
Promass 300 with EtherNet/IP | <= 01.01.02 | |
Promass 300 with Foundation Fieldbus | <= 01.00.01 | |
Promass 300 with HART | <= 01.01.02 | |
Promass 300 with MODBUS | <= 01.00.02 | |
Promass 300 with Profibus PA | <= 01.00.03 | |
Promass 300 with PROFINET | <= 01.00.01 | |
Promass 500 with EtherNet/IP | <= 01.01.02 | |
Promass 500 with Foundation Fieldbus | <= 01.00.01 | |
Promass 500 with HART | <= 01.01.02 | |
Promass 500 with MODBUS | <= 01.00.02 | |
Promass 500 with Profibus PA | <= 01.00.03 | |
Promass 500 with PROFINET | <= 01.00.01 | |
Spare Display for Promag 300 | <= 01.01.00 | |
Spare Display for Promag 400 | <= 01.01.00 | |
Spare Display for Promag 500 | <= 01.01.00 | |
Spare Display for Promass 300 | <= 01.01.00 | |
Spare Display for Promass 500 | <= 01.01.00 | |
Spare Transmitter for Promag 300 with EtherNet/IP | <= 01.01.02 | |
Spare Transmitter for Promag 300 with Foundation Fieldbus | <= 01.00.01 | |
Spare Transmitter for Promag 300 with HART | <= 01.01.01 | |
Spare Transmitter for Promag 300 with MODBUS | <= 01.00.02 | |
Spare Transmitter for Promag 300 with Profibus PA | <= 01.00.03 | |
Spare Transmitter for Promag 300 with PROFINET | <= 01.00.01 | |
Spare Transmitter for Promag 400 with HART | <= 02.00.01 | |
Spare Transmitter for Promag 500 with EtherNet/IP | <= 01.01.02 | |
Spare Transmitter for Promag 500 with Foundation Fieldbus | <= 01.00.01 | |
Spare Transmitter for Promag 500 with HART | <= 01.01.01 | |
Spare Transmitter for Promag 500 with MODBUS | <= 01.00.02 | |
Spare Transmitter for Promag 500 with Profibus PA | <= 01.00.03 | |
Spare Transmitter for Promag 500 with PROFINET | <= 01.00.01 | |
Spare Transmitter for Promass 300 with EtherNet/IP | <= 01.01.02 | |
Spare Transmitter for Promass 300 with Foundation Fieldbus | <= 01.00.01 | |
Spare Transmitter for Promass 300 with HART | <= 01.01.02 | |
Spare Transmitter for Promass 300 with MODBUS | <= 01.00.02 | |
Spare Transmitter for Promass 300 with Profibus PA | <= 01.00.03 | |
Spare Transmitter for Promass 300 with PROFINET | <= 01.00.01 | |
Spare Transmitter for Promass 500 with EtherNet/IP | <= 01.01.02 | |
Spare Transmitter for Promass 500 with Foundation Fieldbus | <= 01.00.01 | |
Spare Transmitter for Promass 500 with HART | <= 01.01.02 | |
Spare Transmitter for Promass 500 with MODBUS | <= 01.00.02 | |
Spare Transmitter for Promass 500 with Profibus PA | <= 01.00.03 | |
Spare Transmitter for Promass 500 with PROFINET | <= 01.00.01 |
The feasibility of modifying the configuration of the device depends on the configuration settings regarding the used protocol (for example: OPC UA, http) to communicate via WLAN.
General Security Recommendations
As a general security measure Endress+Hauser strongly recommends protecting network access to the WLAN network with appropriate mechanisms. It is advised to configure the environment according to best practices to run the devices in a protected IT environment. Further general recommendations apply for the affected products:
Temporary Fix/ Mitigation
If an immediate firmware update is not possible, the WLAN on the unit can also be switched off as a precautionary measure.
Remediation
Endress+Hauser provides updated firmware versions for all related products from the Proline portfolio which fixes the vulnerability and recommends customers to update to the new fixed version. For support, please contact your local service center.
Mathy Vanhoef of imec-DistriNet, KU Leuven published this vulnerability on https://www.krackattacks.com
Coordinated by CERT@VDE