Showing posts with label 7-Technologies. Show all posts
Showing posts with label 7-Technologies. Show all posts

Saturday, February 18, 2012

ICS-CERT Publishes Two Nearly Identical Advisories

Yesterday ICS-CERT published two nearly identical advisories for products made by 7-Technologies; TERMIS and AQUIS. They also published an update for the Advantech Alert published on Thursday.

7-Technologies Advisories


Both advisories identify a DLL Hijacking vulnerability in the systems that would allow a moderately skilled attacker to remotely exploit these vulnerabilities with the potential for execution of arbitrary code. 7T has developed separate patches for both systems.

Interestingly the TERMIS patch was released almost a month before the AQUIS patch, but ICS-CERT is publishing both advisories at the same time (and published both on their secure server on the same date last month). I would assume that 7T did not notify ICS-CERT about the earlier patch until the second patch was also available. This was probably done because a relatively intelligent hacker would have been able to quickly realize that the TERMIS vulnerability was also present in AQUIS.

The differences between the two advisories are trivial; the name and description of the affected software and the link to the patch are just about the limit of difference. ICS-CERT even provides the same (not yet active) CVE link for both advisories.

Advantech Alert


The update to the Advantech Alert adds two additional researchers, Rios and McCorkle, to the list of security researchers responsible for identifying the 18 vulnerabilities in the BroadWin WebAccess application.

ICS-CERT Terms of Use


ICS-CERT recently changed the working in the grey box at the bottom of the first page of these alerts and advisories. As late as February 14th the wording was: “Please see the DHS Disclaimer notice, available here: http://www.us-cert.gov/privacy.html#notify”. That probably wasn’t getting much click through so it was changed on the February 15th generic ICS alert to read: “This product is provided subject to the Terms of Use as indicated here: http://www.us-cert.gov/privacy.html#notify”.

Now I know (Sarcasm Alert) that everyone diligently reads and complies with all ‘Terms of Use’ requirements on every web site that that they click through. I do want to specifically note two items in their (US-CERT) “Terms of Use” section of the US-CERT Website Policies web site; their ‘permission to link’ requirements and ‘copywrite’ notice.

Their permission to link notice is relatively short so I’ll reproduce it in its entirety here:

“You may link to the US-CERT website by using "US-CERT" as a text hyperlink, provided the following text is included on the website: "This link is provided for informational purposes only and does not represent an endorsement by or affiliation with the Department of Homeland Security (DHS)." You are not permitted to use the US-CERT or DHS wordmark, logo, seal, or icon.”

I’m sorry, that doesn’t work for me (nor I’m assuming, very many other people). So, I am hereby providing public notice that I refuse to comply with the ‘permission to link’ requirements of US-CERT. I am relatively sure that the way I provide links to documents in this blog does not lead anyone to believe that I have or am claiming any affiliation with US-CERT or ICS-CERT. Using “US-CERT” as the text base for those alerts is just plain silly, it would interfere with readers clear understanding of what I was writing, and requiring me to use it is an infringement on my freedom of speech and/or expression.

Now as to the copyright permission limitations, I have always been taught that the Federal government cannot copyright any information that it produces. Now I have no intention of commercially reproducing the alerts or such that I find on the ICS-CERT web site nor would I typically consider posting a full copy of such documents on this blog or my web site (http://chemicalfacilitysecuritynews.com; not much there but I do use it to publish documents from time to time). I do provide quotes from US-CERT and ICS-CERT documents from time to time, but those would be governed by the fair use doctrine in any case and I think my attribution of those quotes is adequately clear to my readers.

So, in-short, I am pretty much going to ignore the ‘Copyright Permission’ as well. But I did think that these two requirements should be made clear to the remainder of the cybersecurity community so they could make their own determination of how they wanted to deal with this situation and didn’t run afoul of the Terms of Use by accident.

Thursday, December 22, 2011

New ICS-CERT Monitor and 2 Advisories

Yesterday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published the December edition of their Monthly Monitor and two new Advisories for control system vulnerabilities affecting WellinTech’s KingView and 7-Technologies IGSS SCADA systems.

Monthly Monitor


ICS-CERT continues to produce a brief but valuable monthly newsletter that should be widely read in the control system community. The latest issue contains:

• A neat new logo (okay that’s not so important, but it is good graphics design);

• Another overview of the ‘Water System Hack’;

• A good summary of generic malware analysis and mitigation techniques;

• A summary of the ‘latest’ Gleg Agora SCADA release (probably more appropriate here than as an alert)

• A lengthier listing of control system security articles and blog posts (including one by SCADAHacker, a nice response to my comment last month about the lack of bloggers); and

• Their standard listing of Alerts and Advisories and plug for Coordinated Vulnerability Disclosure

WellinTech


This Advisory describes a heap based buffer overflow vulnerability reported by Luigi through ZDI (so it was coordinated) in the WellinTech KingView system. It appears to be a common remotely exploitable vulnerability that allows execution of arbitrary code by an attacker with an intermediate skill level. WellinTech has a patch available. The CVE number provided in the Advisory is not yet active.

Two interesting things here. First ICS-CERT includes a link to the Chinese language instructions for the patch in addition to the English language instructions (multiculturalism at its best). More importantly the Advisory notes that there are no known exploits available. Luigi typically develops and publishes exploit code, though I can’t find a reference to this vulnerability on his web page. Since this is part of the ZDI project I wonder if he provided them with the code and they just haven’t released it.

7-Technologies


7-Technologies seems to be catching it this week. Earlier there was an advisory for their data server and yesterday a new advisory for similar buffer overflow vulnerability discovered by a separate researcher Celil Unuver (SignalSEC LLC). It appears that the same product update will solve both problems. The CVE file on this vulnerability is also not yet active.

Tuesday, December 20, 2011

Two New ICS-CERT Advisories

Today the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published two new control system advisories; one for Invensys Wonderware, and the other for 7-Technologies Data Server. Both advisories were previously published in the limited distribution on the US-CERT secure portal.

Invensys


The three buffer overflow vulnerabilities described in this Advisory were reported by Kuang-Chun Hung of the Security Research and Service Institute−Information and Communication Security Technology Center (ICST). They would allow a low skilled attacker to execute a denial of service attack and a more skilled attacker to execute arbitrary code on the system. The US-CERT/NIST vulnerability summary is available for these vulnerabilities (Note: The link does work).

Invensys has developed software updates for the affected Wonderware InBatch systems.

7-Technologies


The second advisory involved another buffer overflow vulnerability that was discovered in the 7-Technologies IGSS Data Server by UCQ from the Cyber Defense Institute, Inc. A moderately skilled attacker could use this vulnerability to execute a DOS attack on the system. A CVE number has been assigned to this vulnerability, but it is not yet live on the US-CERT/NIST site.

7T has developed a patch to address this vulnerability and it is currently available on the IGSS web site (NOTE: This link is to a .ZIP file).

Cyber Security Evaluation Tool


The ICS-CERT web page also contains a link to version 4.0.1 of the Cyber Security Evaluation Tool (CSETTM). There is no indication when exactly that new version became available nor is there any explanation on the CSET web site of how the new version differs from version 4.0; though one would expect the differences to be relatively minor.

Tuesday, March 29, 2011

IGSS White Paper Published

Yesterday Eric and Joel published the second white paper in their series of publications dealing with the multiple-system vulnerabilities discovered/publicized by Luigi last week. This document, published on TofinoSecurity.com, deals with the vulnerabilities identified in the 7-Technologies IGSS platform.

There will be some that will point out the similarities between this white paper and initial publication on the ICONICS Genesis vulnerabilities. This was to be expected on a couple of levels; there are common vulnerabilities in the two systems, and many of the security responses would be the same for a variety of vulnerabilities. A closer look at this new publication shows the work done on identifying the differences between the vulnerabilities in the two systems.

One of the main differences here is that the vulnerable system is not just a HMI program, but is an actual Supervisory Control and Data Acquisition (SCADA) system. Additionally, the vulnerabilities affect two different executable programs within the systems communicating on two different ports.

This new white paper also includes six ‘compensating controls’ that owners/users should take to protect their systems pending the publication of patches by 7-Technologies. Five of these controls are the same as those found in the initial white paper, which is not surprising since they should already be in place in any ICS security program.

The one new control replaces the recommendation to change the default port used in the Genesis system. The new control recommends the installation of an intrusion detection system to help the user/owner to detect someone trying to exploit these (and any other un-reported) vulnerabilities. This recommendation was made possible by the recent release of IDS signatures for the IGSS platform by the two IDS systems identified in this white paper (and no, neither is produced by Byres Security).

Another good piece of work by Joel and Eric. I look forward to seeing the two white papers on the remaining systems identified by the Luigi vulnerability release.

Wednesday, February 9, 2011

ICS-CERT Releases 7-Technologies Advisory

Yesterday, the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published an advisory concerning a confirmed remote heap corruption vulnerability in the Interactive Graphical SCADA System (IGSS) ODBC Server (ver. 8 & 9) from 7-Technologies (7T).

ICS-CERT reports that an intermediate skill level attacker could send specially crafted packet to the targeted server’s listening port (20222/TCP) causing the server to crash or perhaps cause arbitrary code execution. There are no known publicly available exploits for this vulnerability.

7T has verified this vulnerability and produced a software update.

In addition to installing the patch, ICS-CERT recommends the following mitigation strategy (with the standard impact analysis and risk assessment caveat):

• Users should minimize network exposure for all control system devices.

• Critical devices should not directly face the Internet.

• Control system networks and remote devices should be located behind firewalls and be isolated from the business network.

• If remote access is required, ICS-CERT recommends the use of secure methods, such as Virtual Private Networks (VPNs).
 
/* Use this with templates/template-twocol.html */