<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
</head>
<body bgcolor="#FFFFFF" text="#000000">
*** As far as I know, this notification is for distribution in the
US ONLY. If you know of colleagues using the WAGO System 758
outside of the US please do not forward this message or the link to
DHS. I am sure it is OK to have them check with WAGO or their own
CERT organization for advice and tech support.<br>
<br>
<br>
<pre> <a class="moz-txt-link-freetext" href="http://www.us-cert.gov/control_systems/pdf/ICSA-12-249-02.pdf">http://www.us-cert.gov/control_systems/pdf/ICSA-12-249-02.pdf</a> </pre>
<br>
A PR search did not turn up WAGO controllers in the JLab PR system.
However, I know for a fact that these are used in some EPICS
installations around the world because they run Linux. It is also
possible that they are installed as OEM equipment in things like
power supplies and magnet controllers. <br>
<br>
It is often the case that an early alert on a specific product also
applies to a broader line of products from the same manufacturer or
rebranded models from the same OEM. Similarly, the OS is almost
always a third part product. <br>
<div class="moz-forward-container"><br>
<br>
Two other messages:<br>
1.) Before buying programmable controllers, smart cards, PC104's,
smart panels etc... verify with the manufacturer that there are no
hard coded log-in credentials. (And always keep a copy of the
password(s) in a secure location).<br>
2.) Make sure you change default log-in credentials on any
equipment you manage.<br>
<br>
Kelly Mahoney<br>
<br>
<br>
<br>
-------- Original Message --------
<table class="moz-email-headers-table" border="0" cellpadding="0"
cellspacing="0">
<tbody>
<tr>
<th align="RIGHT" nowrap="nowrap" valign="BASELINE">Subject:
</th>
<td>Medium-[ICS-CERT] ICSA-12-249-02 - WAGO IO 758 Default
Linux Credentials</td>
</tr>
<tr>
<th align="RIGHT" nowrap="nowrap" valign="BASELINE">Date: </th>
<td>Wed, 5 Sep 2012 17:35:17 -0400 (EDT)</td>
</tr>
<tr>
<th align="RIGHT" nowrap="nowrap" valign="BASELINE">From: </th>
<td>ICS CERT (CS) <a class="moz-txt-link-rfc2396E" href="mailto:notifications@espgroup.net"><notifications@espgroup.net></a></td>
</tr>
<tr>
<th align="RIGHT" nowrap="nowrap" valign="BASELINE">Reply-To:
</th>
<td><a class="moz-txt-link-abbreviated" href="mailto:ics-cert@dhs.gov">ics-cert@dhs.gov</a></td>
</tr>
<tr>
<th align="RIGHT" nowrap="nowrap" valign="BASELINE">To: </th>
<td><a class="moz-txt-link-abbreviated" href="mailto:mahoney@jlab.org">mahoney@jlab.org</a></td>
</tr>
</tbody>
</table>
<br>
<br>
<pre>ICS-CERT has released the Advisory titled ICSA-12-249-02 - WAGO IO 758 Default Linux Credentials, that can be accessed at <a class="moz-txt-link-abbreviated" href="http://www.ics-cert.org">www.ics-cert.org</a> or directly through the following link:
<a class="moz-txt-link-freetext" href="http://www.us-cert.gov/control_systems/pdf/ICSA-12-249-02.pdf">http://www.us-cert.gov/control_systems/pdf/ICSA-12-249-02.pdf</a>
</pre>
</div>
<br>
</body>
</html>