HighPublished 2023-10-12 · 8d ago

ICSA-23-285-11 · CVE-2023-46123

CENTUM VP improper certificate validation

CENTUM VP DCS does not validate the certificate chain on Vnet/IP Open sessions, enabling MITM attackers to intercept setpoint changes.

Mitigations

  1. 01Apply Vnet/IP Open patch R6.09.50
  2. 02Pin field controller CA to engineering workstation only