Showing posts with label 9SG Security Team. Show all posts
Showing posts with label 9SG Security Team. Show all posts

Thursday, October 31, 2019

4 Advisories Published – 10-31-19


Today the CISA NCCIC-ICS published four control system security advisories for products from Honeywell (3) and Advantech.

Cameras and Recorder Advisory


This advisory describes an authentication bypass by capture-replay vulnerability in the Honeywell equIP series and Performance series IP cameras and recorders. The vulnerability is self-reported. Honeywell has a firmware update that mitigates the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to result in unauthenticated access.

NOTE: I briefly reported on this vulnerability on September 14th, 2019.

Cameras Advisory


This advisory describes a missing authentication for critical function vulnerability in the Honewell equIP series and Performance series IP cameras. The vulnerability is self-reported. Honeywell has a firmware update that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to could result in unauthenticated access.

 

equip Advisory


This advisory describes an improper input validation vulnerability in the Honeywell equIP series IP cameras. This vulnerability is self-reported. Honeywell has a firmware update that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to result in a denial of service.

NOTE: I briefly reported on this vulnerability on September 14th, 2019.

Advantech Advisory


This advisory describes four vulnerabilities in the Advatech WISE-PaaS/RMM IoT device remote monitoring and management platform. The vulnerabilities were reported by rgod of 9sg Security Team and trendytofu via the Zero Day Initiative (ZDI). The product is out-of-support and Advantech recommends replacing the product with EdgeSense and DeviceOn.

The four reported vulnerabilities are:

Path traversal - CVE-2019-13551;
Missing authorization - CVE-2019-13547;
Improper restriction of an XML external entity reference - CVE-2019-18227; and
SQL injection - CVE-2019-18229

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow information disclosure, remote code execution, and compromise system availability.

Tuesday, October 29, 2019

1 Advisory Published – 10-29-19


Today the CISA NCCIC-ICS published a control system security advisory for products from Phoenix Contact.

Phoenix Contact Advisory


This advisory describes an improper input validation vulnerability in the Phoenix Contact Automation Worx Software Suite. The vulnerability was reported by the 9sg Security Team via the zero day initiative.
Phoenix Contact provided generic workarounds while it continues to work on an update to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to compromise the availability, integrity, or confidentiality of an application programming workstation. Automated systems programmed using one of the affected products are not impacted.

NOTE: I briefly reported on this vulnerability on October 19th, 2019.

Saturday, October 19, 2019

Public ICS Disclosures – Week of 10-12-19


This week we have four vendor disclosures for products from Phoenix Contact, ABB, Gemalto and Eaton. We also have an updated disclosure from Schneider and a report of a cyberattack from Pilz.

Phoenix Contact Advisory


Phoenix Contact published an advisory [.PDF download link] for an out-of-bounds read vulnerability in their Automationworx Suite. The vulnerability was reported by the 9sg Security Team via the Zero Day Initiative. Phoenix Contact has provided generic workarounds pending publication of a new version.

NOTE: The vulnerability was reportedly coordinate through NCCIC-ICS so an advisory from them should be forthcoming.

ABB Advisory


ABB published an advisory describing an improper authentication vulnerability in their UnoDM. The vulnerability was reported by Maxim Rupp. ABB has updates that mitigate the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

Gemalto Advisory


Gemalto announced that they have published an advisory (customer registration required for access) for a vulnerability in their Sentinel LDK License Manager when installed as a service.

NOTE: I suspect that owners of systems from other vendors that use the LDK License Manager will have to wait for notification from those vendors before they will be able to learn about this vulnerability and fixes available for it.

Eaton Advisory


Eaton published an advisory describing an undisclosed vulnerability in their CGLine+ when connected to CGVision. The vulnerability is self-reported. Eaton has a new version that mitigates the vulnerability.

Schneider Update


Schneider published an update of their URGENT/11 advisory. The new information includes updated version information and mitigation links for:

SCADAPack 57x RTUs; and
SAGE RTU

Pilz Cyberattack


Pilz is currently reporting that: “Since Sunday, October 13, 2019, all server and PC workstations including the communication network of the automation company have been affected worldwide. The website is currently only partially functional.”

They also note that: “Data sent to us by partners and customers have not been lost or misappropriated by third parties. At the current time, however, we cannot completely exclude this.”

NOTE: Both quotes are Google Translations from German.

Tuesday, September 10, 2019

6 Advisories and 3 Updates Published – 09-10-19


The DHS NCCIC-ICS published six control system security advisories for products from OSIsoft, Siemens (4), and Delta Electronics. They also updated two previously published advisories for products from Siemens and an alert from Mitsubishi Electric Europe.

OSIsoft Advisory


This advisory describes an integer overflow or wraparound vulnerability in the OSIsoft PI SQL Client. The vulnerability is self-reported. OSIsoft has a new version that mitigates the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow remote code execution or cause a denial of service, resulting in disclosure, deletion, or modification of information.

SIMATIC Advisory


This advisory describes an improper input validation vulnerability in the Siemens SIMATIC TDC CP51M1 multiprocessor automation system. The vulnerability is self-reported. Siemens has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to create a denial-of-service condition within UDP communication.

WirelessHart Gateway Advisory


This advisory describes a cross-site scripting vulnerability in the Siemens IE/WSN-PA Link WirelessHART Gateway. The vulnerability is self-reported. Siemens has provided generic mitigation measures for the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow information disclosure, code execution, or denial-of-service.

Comment: Usually a vendor provides generic mitigation measures for a vulnerability when they are forced to disclose a vulnerability due to the disclosure process. With this being a self-disclosed vulnerability, Siemens was not forced to disclose this vulnerability with a generic mitigation. That takes a certain amount of integrity, but it does place some of their customers at an unusual level of risk. The generic mitigation measure is not unusual or even an unexpected requirement, but some customers will not have taken the standard precaution and are unlikely to implement it now.

Industrial Product Advisory


This advisory describes three vulnerabilities in the Siemens Industrial Products. The vulnerabilities were self-reported. Siemens has new versions that mitigate the vulnerabilities is some of the affected products.

The three reported vulnerabilities are:

Integer overflow or wraparound - CVE-2019-11477;
Uncontrolled resource consumption (2) - CVE-2019-11478, and CVE-2019-11479

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to cause denial-of-service condition.

SINETPLAN Advisory


This advisory describes an improper authorization vulnerability in the Siemens Network Planner (SINETPLAN). The vulnerability is self-reported. Siemens has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow information disclosure, code execution, and denial-of-service. The Siemens Advisory notes that the vulnerability can only be exploited “local users”.

Delta Electronics Advisory


This advisory describes three vulnerabilities in the Delta Electronics TPEditor. The vulnerabilities were reported by kimiya of 9sg Security Team vis the Zero Day Initiative. Delta has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

Stack-based buffer overflow - CVE-2019-13540;
Heap-based buffer overflow - CVE-2019-13536; and
Out-of-bounds write - CVE-2019-13544

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow information disclosure, remote code execution, or may crash the application.

PCS7 Update


This update provides new information on an advisory that was originally reported on July 9th, 2019 and last updated on August 13th, 2019. The new information includes updated version information and mitigation links for SIMATIC WinCC Runtime Professional V14 and V15.

WinCC Update


This update provides new information on an advisory that was originally reported on July 11th, 2019 and updated on August 13th, 2019.

Mitsubishi Update


This update provides new information on an alert that was originally published on August 13, 2019. The revised alert changes the name of the vendor to “Mitsubishi Electric Europe B.V.”.

Other Siemens Advisories


Today was disclosure Tuesday for Siemens. They published six advisories and three updates. Two of those advisories are for third-party vulnerabilities (DejaBlue and Urgent/11). The Urgent/11 advisory could be added to the NCCIC-ICS advisory on those vulnerabilities via an update on Thursday. To date, NCCIC-ICS has not addressed DejaBlue, so I suspect that this Siemens advisory will be ignored. The last advisory will probably be addressed by NCCIC-ICS on Thursday.

Wednesday, September 4, 2019

2 Advisories Published – 09-03-19


Yesterday the DHS NCCIC-ICS published two control system security advisories for products from EZAutomation.

PLC Editor Advisory


This advisory describes an improper restriction of operations within the bounds of a memory buffer vulnerability in the EZAutomation EZ PLC Editor. The vulnerability was reported by 9sg Security Team via the Zero Day Initiative. EZAutomation has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to execute code under the privileges of the application.

EZ Touch Editor Advisory


This advisory describes a stack-based buffer overflow vulnerability in the EZAutomation EZ Touch Editor. The vulnerability was reported by 9sg Security Team via the Zero Day Initiative. EZAutomation has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to execute code under the privileges of the application.

Tuesday, August 13, 2019

1 Alert, 3 Advisories and 4 Updates Published – 08-13-19


Today the DHS NCCIC-ICS published a control system security alert for products from Mitsubishi Electric; three control system security advisories for products from Siemens, OSIsoft, and Delta Industrial; and four control system advisory updates for products from Siemens.

Mitsubishi Alert


This alert describes a report of seven vulnerabilities in the Mitsubishi smartRTU and INEA ME-RTU. The vulnerabilities were reported (with exploit code) by Mark Cross (@xerubus) (NCCIC-ICS did provide the link to the report, a first). Cross disclosed the vulnerabilities to CISA and published the public disclosure under the 45-day disclosure policy.

The seven reported vulnerabilities are:

OS command injection - CVE-2019-14931;
Unauthenticated download of configuration file - CVE-2019-14927;
Stored cross-site script - CVE-2019-14928;
Use of hard-coded cryptographic keys - CVE-2019-14926;
Hard-coded user passwords - CVE-2019-14930;
Plaintext password storage - CVE-2019-14929; and
Incorrect default permissions - CVE-2019-14925


Siemens Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the Siemens SCALANCE X switches. The vulnerability was reported by Younes Dragoni from Nozomi Networks. Siemens has provided generic workarounds. There is no indication that Dragoni has been provided an opportunity to verity the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial-of-service condition.

OSIsoft Advisory


This advisory describes two vulnerabilities in the OSIsoft PI Web API. The vulnerabilities are self-reported. OSIsoft has an update to mitigate the vulnerability.

The two reported vulnerabilities are:

Inclusion of sensitive information in log files - CVE-2019-13515; and
Protection mechanism failure.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerabilities to allow direct attacks against the product and disclose sensitive information.

Delta Advisory


This advisory describes two vulnerabilities in the Delta DOPSoft Human Machine Interface (HMI) editing software. The vulnerability was reported by kimiya of 9SG Security Team via the Zero Day Initiative. Delta has a new version that mitigates the vulnerabilities. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Out-of-bounds read - CVE-2019-13513; and
Use after free - CVE-2019-13514

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow information disclosure, remote code execution, or crash of the application.

SIMATIC WinCC Update


This update provides additional information on an advisory that was originally reported on July 11th, 2019. The update provides new affected version information and mitigation links for:

SIMATIC WinCC V7.3;
SIMATIC PCS 7 V8.1, and
SIMATIC WinCC Runtime Professional V14

Spectrum Power Update


This update provides additional information on an advisory that was originally reported on July 9th, 2019. The update provides corrected version information for Spectrum Power 5.

SIPROTEC Update


This update provides additional information on an advisory that was originally reported on July 9th, 2019. The update provides additional mitigation information.

SIMATIC PCS7 Update


This update provides additional information on an advisory that was originally reported on July 9th, 2019. The update provides corrected version information and mitigation links for:

SIMATIC WinCC V7.3; and
SIMATIC PCS 7 V8.1
NOTE: Siemens published an additional two advisories and two updates today that were not reported by NCCIC-ICS. They may be reported on Thursday, if not, I will report on them on Saturday.

Friday, August 2, 2019

6 Advisories Published – 08-01-19


Yesterday the DHS NCCIC-ICS published six control system advisories for products from Leão Consultoria e Desenvolvimento de Sistemas (LCDS), Rockwell, 3S (2), Fuji Electric and Advantech.

LCDS Advisory


This advisory describes two vulnerabilities in the LCDS LAquis SCADA software. The vulnerabilities were reported by Francis Provencher (PRL) via the Zero Day Initiative. LCDS has an update available that mitigates the vulnerability. There is no indication that Provencher has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Out-of-bounds read - CVE-2019-10994; and
Type confusion - CVE-2019-10980


NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to obtain confidential information or execute remote code.

Rockwell Advisory


This advisory describes two vulnerabilities in the Rockwell Arena Simulation Software. The vulnerabilities were reported by kimiya of 9SG Security Team via ZDI. Rockwell has a new version that mitigates the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

Use after free - CVE-2019-13510; and
Information exposure - CVE-2019-13511

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to cause a current Arena session to fault or enter a denial-of-service (DoS) state, allowing the attacker to run arbitrary code.

First CODESYS Advisory


This advisory describes an insufficiently protected credentials vulnerability in the CmpUserMgr component of 3S CODESYS products. The vulnerability was reported by JunYoung Park. 3S will correct this vulnerability in a new version to be released in February. The 3S advisory strongly recommends activating and using encryption of online communication whenever possible.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow for an attacker with access to PLC traffic to obtain user credentials.

NOTE: Is it just me or is this advisory just a seven-month zero-day announcement?

Second CODESYS Advisory


This advisory describes two vulnerabilities in the CmpGateway component of the 3S CODESYS products. These vulnerabilities are self-reported. 3S has a new version that mitigates the vulenrabilities.

The two reported vulnerabilities are:

Unverified ownership - CVE-2019-9010; and
Uncontrolled memory allocation - CVE-2019-9012 

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow a remote attacker to close existing communication channels or to take over an already established user session to send crafted packets to a PLC.

NOTE 1: There were six other advisories published by 3S at the same time as the two referenced in these two NCCIC-ICS advisories. I will address them this weekend.

NOTE 2: A reminder that the CODESYS operating system is used in a wide variety of devices and systems. These vulnerabilities will have widespread application. Few vendors are expected to publish updates referencing these vulnerabilities.

Fuji Advisory


This advisory describes and out-of-bounds read vulnerability in the Fuji  FRENIC Loader. The vulnerability was reported by kimiya of 9SG Security Team via ZDI. Fuji has a new version that mitigates the vulnerability. There is no indication that the kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow information disclosure.

Advantech Advisory


This advisory describes an out-of-bounds write vulnerability in the Advantech WebAccess HMI Designer. The vulnerability was reported by Mat Powell via ZDI. Advantech has a new version that mitigates the vulnerability. There is no indication that Powell has been provided an opportunity to verify the efficacy of the fix.

Friday, July 12, 2019

7 Advisories Published – 07-11-19


Yesterday the DHS NCCIC-ICS published six industrial control system advisories for products from Schneider Electric (2), AVEVA, Siemens (3) and Delta Industrial. They also published a medical device security advisory for products from Philips.

Interactive Graphical SCADA Advisory


This advisory describes an out-of-bounds write vulnerability in the Schneider Interactive Graphical SCADA System (IGSS). The vulnerability was reported by mdm and rgod of 9SG Security Team via the Zero Day Initiative. Schneider has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerability to  allow an attacker to achieve arbitrary code execution or crash the software.

Floating License Manager Advisory


This advisory describes four vulnerabilities in the Schneider Floating License Manager. The vulnerabilities are self-reported. According to the Schneider advisory, the vulnerabilities are in a third-party component (Flexera FlexNet Publisher) of their product. Schneider has a patch available that mitigates the vulnerability.

The four reported vulnerabilities are:

Improper input validation (3) - CVE-2018-20031, CVE-2018-20032, and CVE-2018-20034; and
Memory corruption - CVE-2018-20033

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to deny the acquisition of a valid license for legal use of the product.

NOTE: There are still three other advisories published by Schneider on Tuesday that have not been reported by NCCIC-ICS; all for Modicon controllers. I will address these on Saturday.;

AVEVA Advisory


This advisory describes the same four vulnerabilities reported above, this time in the AVEVA Vijeo Citect and Citect SCADA Floating License Manager. These vulnerabilities have not yet been reported by AVEVA. A new version is available from Schneider to mitigate the vulnerabilities.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to deny the acquisition of a valid license for legal use of the product.

SIMATIC Advisory


This advisory describes three vulnerabilities in the Siemens SIMATIC RF6XXR. The vulnerabilities are in older, third-party SSL and TLS applications still in use by these products. The vulnerabilities were reported by Wendy Parrington from United Utilities. Siemens reports that newer versions mitigate the vulnerabilities.

The three reported vulnerabilities are:

Improper input validation - CVE-2011-3389; and
Cryptographic issues (2) - CVE-2016-6329 and CVE-2013-0169

NCCIC-ICS reports that an uncharacterized attacker could use publicly available exploits (two of these are older, well recognized vulnerabilities) to remotely exploit the vulnerabilities to allow access to sensitive information.

TIA Portal Advisory


This advisory describes an improper access control vulnerability in the Siemens TIA Administrator (TIA Portal). The vulnerability was reported (with proof of concept code) by Joseph Bingham of Tenable. Siemens has an update that mitigates the vulnerability. There is no indication that Bingham has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an execution of some commands without proper authentication.

SIMATIC WinCC Advisory


This advisory describes an unrestricted upload of file with dangerous type vulnerability in the Siemens SIMATIC WinCC and SIMATIC PCS7 devices. The vulnerability was reported by Xuchen Zhu from ZheJiang Guoli Security Technology. Siemens has updates available that mitigates the vulnerability. There is no indication that Xuchen has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to cause a denial-of-service condition on the affected service or device. The Siemens advisory notes that the attacker has to be authenticated with a valid user account.

NOTE: There is still one new advisory that Siemens published on Tuesday that has not been reported by NCCIC-ICS. I will cover it tomorrow.

Delta Industrial Advisory


This advisory describes two vulnerabilities in the Delta Electronics CNCSoft ScreenEditor. The vulnerability was reported by Natnael Samson (@NattiSamson) via ZDI. Delta has a new version that mitigates the vulnerabilities. There is no indication that Samson was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Heap-based buffer overflow - CVE-2019-10982; and
Out-of-bounds read - CVE-2019-10992

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause buffer overflow conditions that may allow information disclosure, remote code execution, or crash the application.

Philips Advisory


This advisory describes a use of obsolete function vulnerability in the Philips Holter 2010 Plus, a 12-lead EKG analysis software program. The vulnerability is self-reported. Philips provides generic measures to mitigate the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit this vulnerability to lead to a product feature escalation.

Wednesday, July 10, 2019

5 Advisories and 4 Updates Published – 07-09-19


Yesterday the DHS NCCIC-ICS published four control system security advisories {Siemens (2), Schneider Electric, Rockwell and Emerson}, one medical device security advisory for products from GE, and updated four previously published advisories for products from Siemens.

SIPROTEC Advisory


This advisory describes two improper input validation vulnerabilities in the Siemens SIPROTEC 5 and DIGISI 5 products. The vulnerability was reported by Pierre Capillon, Nicolas Iooss, and Jean-Baptiste Galet from Agence Nationale de la Sécurité des Systèmes d’Information (ANSSI). Siemens has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a denial-of-service condition and limited control of file upload, download, and delete functions.

Spectrum Power Advisory


This advisory describes a cross-site scripting vulnerability in the Siemens Spectrum Power product. The vulnerability was reported by Ismail Mert AY AK of Biznet Bilisim AS. Siemens has an update available that mitigates the vulnerability. There is no indication that Mert has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to inject arbitrary code in a specially crafted HTTP request and monitor information.

NOTE 1: The Siemens advisory uses new terminology for reporting NCCIC-ICS coordination efforts, it cites “CISA-Industrial Control System Vulnerability Disclosure team” as the coordinating agency. I am wondering if this is an official designation of a specific group of people operating at NCCIC or just another smoke and mirrors name change.

NOTE 2: Siemens published four other advisories yesterday in addition to these two. If they are not addressed by NCCIC-ICS later this week, I will be looking at them Saturday.

Schneider Advisory


This advisory describes a use after free vulnerability in the Schneider Zelio Soft programming platform. The vulnerability was reported by 9sg Security Team via the Zero Day Initiative. Schneider has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow remote code execution through the opening of a specially crafted project file.

NOTE 1: NCCIC-ICS does not provide a link to the Schneider Zelio Soft advisory.

NOTE 2: Schneider published five other advisories yesterday as well as the Zelio Soft advisory. It was a busy ICS security day.

Rockwell Advisory


This advisory describes an improper access control vulnerability in the Rockwell PanelView 5510 HMI. This vulnerability is self-reported. Rockwell has new versions that mitigate the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit this vulnerability to allow a remote unauthenticated user to gain root privileges on the device.

Emerson Advisory


This advisory describes a hard-coded credential vulnerability in the Emerson DeltaV Distributed Control System (DCS) software platform. The vulnerability was reported by Benjamin Crosasso of Sanofi. Emerson has a patch available to mitigate the vulnerability. There is no indication that Crosasso has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to gain administrative access to DeltaV Smart Switches.

GE Advisory


This advisory describes an improper authentication vulnerability in the GE Aestiva and Aespire Anesthesia Machines. The vulnerability was reported by Elad Luz of CyberMDX. GE has provided generic workarounds to mitigate the vulnerability. The FDA has not published a safety communication on this vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker the ability to remotely modify GE Healthcare anesthesia device parameters.

SIMATIC PCS Update


This update provides additional information on an advisory that was originally published on May 14th, 2019. The new information includes updated version data and links to mitigation measures for:

SIMATIC WinCC V7.4;
SIMATIC PCS 7 V8.2; and
SIMATIC PCS 7 V9.0

SIMATIC Update


This update provides additional information on an advisory that was originally published on April 9th, 2019 and updated on May 14th, 2019 and June 11th, 2019. The new information includes updated version data and links to mitigation measures for:

SIMATIC RF600R;
SIMATIC RF185C;
SIMATIC RF186C; and
SIMATIC RF188C

Industrial Products Update


This update provides additional information on an advisory that was originally published on April 9th, 2019 and updated on May 14th, 2019 and June 11th, 2019. The new information includes updated version data and links to mitigation measures for:

SIMATIC RF600R;
SIMATIC RF188C; and
SINEMA Server

CP 1604 Update


This update provides additional information on an advisory that was originally published on February 12th, 2019. The new information includes:

Update version information and mitigations; and
Add fixes for older product versions for CVE-2018-13808

NOTE: Siemens published four additional advisory updates yesterday. NCCIC-ICS is unlikely to address them so I will on Saturday.

Thursday, June 20, 2019

1 Advisory Published – 06-20-19


Today the DHS NCCIC-ICS published a control system security advisory for products from Phoenix Contact.

Phoenix Contact Advisory

This advisory describes three vulnerabilities in the Phoenix Contact Automation Worx Software Suite. The vulnerabilities were reported by 9sg Security Team via the Zero Day Initiative. Phoenix Contact is working on an update to mitigate the vulnerabilities.

The three reported vulnerabilities are:

Access of an uninitialized pointer - CVE-2019-12870;
Out-of-bounds read - CVE-2019-12869; and
Use after free - CVE-2019-12871

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker, with access to an original PC Worx or Config+ project file, to perform remote code execution.

Friday, June 7, 2019

Two Advisories Published – 06-06-19


This advisory describes two vulnerabilities in the Panasonic Control FPWIN Pro PLC programming software. The vulnerability was reported by kimiya of 9sg Security Team via the Zero Day Initiative. Panasonic has a new version that mitigates the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Heap-based buffer overflow - CVE-2019-6530; and
Type Confusion - CVE-2019-6532

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to crash the device and allow remote code execution.

Optergy Advisory


This advisory describes eight vulnerabilities in the Optergy Proton/Enterprise Building Management System. The vulnerabilities were reported by Gjoko Krstic of Applied Risk. Optergy has a new version that mitigates the vulnerability. There is no indication that Krstic has been provided an opportunity to verity the efficacy of the fix.

The eight reported vulnerabilities are:

Information exposure (2) - CVE-2019-7272 and CVE-2019-7277;
Cross-site request forgery - CVE-2019-7273;
Unrestricted upload of file with dangerous type - CVE-2019-7274;
Open redirect - CVE-2019-7275;
Hidden functionality - CVE-2019-7276
Exposed dangerous method or function - CVE-2019-7278; and
Use of hard-coded credentials - CVE-2019-7279

NOTE: I briefly reported on these vulnerabilities last month. Interestingly, the Applied Risk advisory describes six vulnerabilities but provided all eight of the above CVE’s.

Saturday, May 18, 2019

2 Advisories Published – 05-16-19


On Thursday the DHS NCCIC-ICS published two control system security advisories for products from Fuji Electric and Schneider Electric.

Fuji Advisory


This advisory describes an out-of-bounds read vulnerability in the Fuji Alpha7 PC Loader motor controller. The vulnerability was reported by kimiya of 9SG Security Team via the Zero Day Initiative. Fuji has a new version that mitigates the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to crash the device..

Schneider Advisory


This advisory describes a use of insufficiently random values vulnerability in the Schneider Modicon M580, Modicon M340, Modicon Premium, and Modicon Quantum products. The vulnerability was reported by David Formby and Raheem Beyah of Fortiphyd Logic and Georgia Tech. Schneider has a firmware update available for one of the products and has provided generic workarounds for the others. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to to hijack TCP connections or cause information leakage.

Tuesday, January 8, 2019

2 Advisories and an Update Published – 01-08-19


Today the DHS NCCIC-ICS published two control system security advisories and an update for a previously published advisory; all for products from Schneider Electric.

IIoT Monitor Advisory


This advisory describes three vulnerabilities in the Schneider IIoT Monitor monitoring platform. The vulnerabilities were reported by rgod via the Zero Day Initiative. Schneider has new software available that mitigates the vulnerabilities. There is no indication that rgod has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Path traversal - CVE-2018-7835;
• Unrestricted upload of a file with dangerous type - CVE-2018-7836; and
XXE - CVE-2018-7837

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to

Zelio Soft 2 Advisory


This advisory describes a use after free vulnerability in the Schneider Zelio Soft programing platform. The vulnerability was reported by rgod and mdm of 9SG Security Team via ZDI. Schneider has a new version that mitigates the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow for remote code execution when opening a specially crafted project file.

NOTE: I briefly discussed this vulnerability last Saturday.

U.motion Builder Update


This update provides additional information on an advisory that was originally published on June 29th, 2017. The new information includes:

• Adding the other 17 vulnerabilities that I mentioned in the original post; and
• Report of a firmware update that mitigates ‘most of these vulnerabilities’;

NOTE: The latest revised Schneider advisory (v5) that was published on November 20th, 2018 reports that the firmware update only mitigates six of the vulnerabilities.

Siemens Update


This is the second Tuesday in January and Siemens published five new advisories and seven updates this morning. None made it to the NCCIC-ICS site today. I expect that we should start seeing most of them tomorrow.

Saturday, December 29, 2018

Public ICS Disclosures – Week of 12-22-18


This week we have one vendor disclosure from Schneider Electric and there is of course the federal funding fiasco.

Schneider Advisory


Schneider published an advisory for a use after free vulnerability in their Zelio Soft software product. The vulnerability was reported by mdm and rgod, of the 9SG Security Team. Schneider has an update available to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Federal Funding Fiasco


This is the first week of the FFF and it looks like it could last for a while. The NCCIC-ICS landing page does not include the FFF banner that is found on web sites for other Cybersecurity and Infrastructure Security Agency (CISA) organizations. I would like to think that that would mean that NCCIC-ICS is up and functioning like the main National Cybersecurity and Communications Integration Center (NCCIC) presumably is.

Unfortunately, the lack of publication of any advisories this week leads me to conclude that if NCCIC-ICS is functioning, it is doing so in a limited fashion. It would be helpful if NCCIC-ICS were to delineate which of its functions were deemed to be essential enough to continue during the FFF.

Thursday, December 13, 2018

5 Advisories and 2 Updates Published – 12-13-18

Today the DHS NCCIC-ICS published four control system security advisories for products from GE, Geutebruck, Siemens and Schneider and one medical device security advisory for products from Medtronic. They also published an update for a previously published control system security advisory for products from Siemens and a medical device security advisory for products from Philips.

GE Advisory


This advisory describes a path traversal vulnerability in the GE Mark VIe, EX2100e, EX2100e_Reg, and LS2100e distributed control systems. The vulnerability was reported by Can Demirel of Biznet Bilisim. GE has a new version that mitigates the vulnerability. There is no indication that Demirel has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to access system data, which could result in escalation of privilege and unauthorized access to the controller.

Geutebruck Advisory


This advisory describes an OS command injection vulnerability in the Geutebruck E2 Camera Series. The vulnerability was reported by Davy Douhine of RandoriSec. Geutebruck has a new version that mitigates the vulnerability. There is no indication that Douhine has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a remote attacker to inject OS commands as root.

Siemens Advisory


This advisory describes two improper input validation vulnerabilities in the Siemens EN100 Ethernet Communication Module and SIPROTEC 5 relays. These vulnerabilities were reported by Victor Nikitin, Vladislav Suchkov, and Ilya Karpov from ScadaX. Siemens has updates for some of the affected products and continues to work on updates for the remaining products.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to cause a denial-of-service condition of the network functionality of the device, compromising the availability of the system.

NOTE: This advisory was published when Siemens published an update last Tuesday. The original Siemens advisory was reported here back in July, 2018.

Schneider Advisory


This advisory describes three vulnerabilities in the Schneider Electric GUIcon. The vulnerabilities were reported by mdm and rgod of 9SG Security Team. Schneider has a new version that mitigates the vulnerabilities. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Type confusion (2) - CVE-2018-7813 and CVE-2018-7815; and
• Stack-based buffer overflow - CVE-2018-7814

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to execute code with privileges within the context of the application.

NOTE: I briefly reported the Schneider advisory last Saturday.

Medtronic Advisory


This advisory describes a missing encryption of sensitive data vulnerability in the Medtronic 9790 CareLink Programmer, 2090 CareLink Programmer, 29901 Encore Programmer; programmers for Medtronic cardiac devices. The vulnerabilities were reported by Researchers Billy Rios and Jonathan Butts of Whitescope LLC. Medtronic has provided generic workarounds for two of the devices and reports that the 9970 is out of support and all use should be discontinued. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an relatively low-skilled attacker with physical access to the devices could exploit the vulnerability to access PHI or PII stored on the device.

Siemens Update

This update provides additional information for an advisory that was originally published on March 29th, 2018 and updated on April 24th, 2018, June 12th, 2018 and again on November 14th, 2018. The update provides updated affected version information and mitigation links for SIMATIC NET PC-Software.

NOTE: Siemens updated their advisory on Tuesday and then again today. This NCCIC-ICS update reflects the corrected information published by Siemens today.

Philips Update


This update provides additional information for an advisory that was originally published on March 27th, 2018 and subsequently updated on December 11th, 2018. The updated information includes revised affected version data.

More Missing Siemens Updates


Siemens published four more updates today; only one of those was addressed by NCCIC-ICS today. It will be a long blog post here on Saturday. 

Saturday, December 8, 2018

Public ICS Disclosures – Week of 12-01-18


This week we have vendor notifications for products from OSIsoft and Schneider Electric and a researcher report of vulnerabilieis in products from Pilz. We also have two exploit publications for products from Rockwell Automation (one may be a 0-day).

OSIsoft Vulnerabilities


In their Release Notes for the latest version of PIProcessbook OSIsoft reports that there are three vulnerabilities being corrected by this release. Those vulnerabilities are related to an included older version of Microsoft’s VBA 6.5. A separate security advisory is being (was?) released to provide further details on these ‘high impact’ vulnerabilities. If it has been released, then my limited (non-customer) access to the OSIsoft site does not provide access to the advisory. The Release Notes do credit the Australian Energy Market Operator (AEMO) with reporting the vulnerabilities.

Schneider Advisory


This advisory describes three vulnerabilities in the Eurotherm by Schneider Electric GUIcon product. The vulnerabilities were reported by mdm and rgod (9SG Security Team). Schneider has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fixes.

The three reported vulnerabilities are:

• Type confusion (2) - CVE-2018-7813 and CVE-2018-7815; and
Stack-based buffer overflow - CVE-2018-7814

Pilz Advisory


Applied Risk has published an advisory for a clear-text storage of sensitive information vulnerability in the Pilz Pilz PNOZmulti Configurator, a safety system tool. This is a coordinated disclosure. Pilz has a new version that mitigates the vulnerability.

Rockwell Exploits


Luca.Chiou published an exploit for an incorrect access control authentication bypass vulnerability in the Rockwell Allen-Bradley PowerMonitor 1000. A CVE has been reserved for this vulnerability (CVE-2018-19616, no further information available) which may indicate that Rockwell has been notified of this vulnerability.

Luca.Chiou published an exploit for a cross-site scripting vulnerability in the Rockwell Allen-Bradley PowerMonitor 1000. No CVE is provided in the exploit documentation. This may indicate that this is a 0-day vulnerability.

Thursday, October 18, 2018

Omron Advisory Published


Yesterday the DHS NCCIC-ICS published a control system security advisory for products from Omron. The advisory describes four vulnerabilities in the Omron CX-Supervisor. The vulnerabilities were reported by Mat Powell, Ariele Caltabiano (kimiya) of 9SG Security Team, and b0nd @garage4hackers via the Zero Day Initiative. Omron has a new version that mitigates the vulnerabilities. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Improper restriction of operations within the bounds of a memory buffer - CVE-2018-17905;
• Out-of-bounds read - CVE-2018-17907;
• Use after free - CVE-2018-17909; and
Incorrect type version or cast - CVE-2018-17913

NCCIC-ICS reports that an uncharacterized hacker with uncharacterized access could exploit these vulnerabilities to execute code under the context of the application, corrupt objects, and force the application to read a value outside of an array.

Friday, October 12, 2018

3 Advisories and 4 Updates


Yesterday the DHS NCCIC-ICS published three control system security advisories for products from Delta Industrial Automation and NUUO (2). They also updated a previously published control system security advisory for products from Yokogawa medical device security advisories for products from Medtronic, BD and Phillips.

Delta Advisory


This advisory describes two vulnerabilities in the Delta Industrial Automation TPEditor. The vulnerabilities were reported by Ariele Caltabiano (kimiya) of 9SG Security Team and Mat Powel. Delta has a new version that mitigates the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-17929; and
Out-of-bounds write - CVE-2018-17927

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to crash the accessed device, resulting in a buffer overflow condition that may allow remote code execution.

CMS Advisory


This advisory describes four vulnerabilities in the NUUO CMS software management platform. The vulnerabilities were reported by Pedro Ribeiro. NUUO has a firmware update that mitigates the vulnerabilities. There is no indication that Ribeiro has been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Use of insufficiently random values - CVE-2018-17888;
• Use of obsolete function - CVE-2018-17890;
• Incorrect permission assignment for critical resource - CVE-2018-17892; and
• Use of hard-coded credentials - CVE-2018-17894

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to result in arbitrary remote code execution.

NVRmini2 Advisory


This advisory describes two vulnerabilities in the NUUO NVRmini2, NVRsolo network video recorders. The vulnerabilities were reported by Jacob Baines of Tenable. NUUO has a firmware update that mitigates the vulnerabilities. There is no indication that Baines has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-1149; and
• Leftover debug code - CVE-2018-1150

NCCIC-ICS reports that a relatively low-skilled attacker using publicly available exploit code could remotely exploit the vulnerabilities to achieve remote code execution and user account modification.

Yokogawa Update


This update provides additional information on an advisory that was originally reported on May 31st, 2018. The new information includes:

• Addition of four new vulnerabilities;
• Revision of exploit consequences;
• Addition of new products affected; and
• Addition of mitigation information for newly identified products.

NOTE: All of this new information was reported in a separate Yokogawa advisory that I discussed here last month. That new advisory was not referenced in this update.

Medtronic Update


This update provides additional information on an advisory that was originally published on February 27th, 2018 and updated on June 27th, 2018. The new information includes:

• Addition of a new affected product;
• Addition of statement on possible remote access exploitation;
• Addition of a third vulnerability;
• Addition of report of new mitigation measure implemented by Medtronic

An FDA notice was published for the revised Medtronic advisory.

BD Update


This update provides additional information on an advisory that was originally published on May 22nd, 2018. The new information includes a report of implementation of the promised mitigation measures.

Phillips Update


This update provides additional information on an advisory that was originally published on August 21st, 2018 and updated on August 30th, 2018. The new information includes the announcement of future mitigation measures to be undertaken by Phillips.

 
/* Use this with templates/template-twocol.html */