Now Meltdown patches are making industrial control systems lurch
Summary
Rockwell Automation revealed that the same patch had caused issues with Studio 5000, FactoryTalk View SE, and RSLinx Classic (a widely used product in the manufacturing sector). Patching against CVE-2017-5753, CVE-2017-5715 (Spectre) and CVE-2017-5754 (Meltdown) affected both the PulseSecure VPN client and Sandboxie, the sandbox-based isolation program developed by Sophos. The flaws potentially allow malicious apps in the user space to access protected areas of kernel memory on the same machine or shared system in the cloud. And theres no patch for Spectre; the microprocessors have to be redesigned to prevent the attack, and that will take years," infosec guru Bruce Schneier warned over the weekend. Moritz Lipp of Graz Technical University, a security researchers credited in the discovery of both Meltdown and Spectre, praised the vendor response during the disclosure period.