Remarks regarding SSB-201698 for the Discovery and Basic Configuration Protocol
Siemens is aware of the behavior that is described in the PROFINET Security Advisory PISA-001 by the PI Organization and published a related Security Bulletin containing possible mitigations.
The Discovery and Basic Configuration Protocol (DCP) is a protocol which is widely used in the industrial context. In the specification of the protocol several functions are described which are intended to be used for special operational cases like initial setup or reset of a component. As DCP was not designed as a security protocol, it could be abused by an attacker to affect the availability of affected products. The protocol is also used in PROFINET communication in case no security class configuration is used.
In general, Siemens recommends to implement the defense-in-depth approach for plant operations and to configure the environment according to Siemens’ Operational Guidelines for Industrial Security.
Note: Please be aware that links in the Blog Post may refer to external websites and content.