Advisory
On 23.05.2023 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within SAP Plant Connectivity.
SAP Note 3301942 addresses "[CVE-2023-2827] Missing Authentication in SAP Plant Connectivity and Production Connector for SAP Digital Manufacturing" to prevent missing authentication check with a high risk for exploitation.
A workaround does exist, according to SAP Security Advisory team. It is advisable to implement the correction as project, the team suggests.
Risk specification
SAP Plant Connectivity 15.5 (PCo) or the Production Connector for SAP Digital Manufacturing do not validate the signature of the JSON Web Token (JWT), allowing an unauthenticated attackerSolution
After the installation of the support package or patch, respectively, there will be a new tab JWT Validation in the configuration UI for the cloud integration. Here you will have to maintain the parameters for the JWT signature validation. Circumstances exist that prevent the timely installation of a patch provided by the manufacturer. In such cases, you may consider applying the suggested workaround as a temporary or compensating mitigation: "If Plant Connectivity or the Production Connector reside on the same machine as the Cloud Connector, you may be able to reduce the risk of this vulnerability being exploited by blocking access to the port of the cloud services hosted by the main service for external service calls, e.g. by using a firewall. If the Cloud Connector is installed on a different machine, you may block the port of the cloud services for all remote computers except for the computer on which the Cloud Connector is running.".
The advisory is valid for
- PLANTCONNECT 15.5
- PRODUCTIONCONNECT 1.0
- 10.0 [CVE-2020-6207] Missing Authentication Check in SAP Solution Manager (User-Experience Monitoring)
- 10.0 [CVE-2020-26829] Missing Authentication Check in SAP NetWeaver AS JAVA (P2P Cluster Communication)
- 9.9 [CVE-2023-23857] Improper Access Control in SAP NetWeaver AS for Java
- 9.8 [CVE-2024-41730] Missing Authentication check in SAP BusinessObjects Business Intelligence Platform
- 9.8 [CVE-2020-6198] Missing Authentication check in SAP Solution Manager (Diagnostics Agent)