Showing posts with label Aaron Portnoy. Show all posts
Showing posts with label Aaron Portnoy. Show all posts

Friday, November 10, 2017

ICS-CERT Publishes Two Advisories

Yesterday the DHS ICS-CERT published two control system security advisories for products from Schneider and AutomationDirect.

Schneider Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Schneider InduSoft Web Studio and InTouch Machine Edition. The vulnerabilities were reported by Aaron Portnoy, formerly of Exodus Intelligence. Schneider has produced new versions that mitigate the vulnerability. There is no indication that Portnoy has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could use a publicly available exploit to remotely exploit this vulnerability to remotely execute code with high privileges. The Schneider security bulletin notes that the vulnerability exists during tag subscription.

AutomationDirect Advisory


This advisory describes and uncontrolled search path element vulnerability in a number of AutomationDirect products. The vulnerability was reported by Mark Cross of RIoT Solutions. Newer software versions are available from AutomationDirect that mitigate the problem. There is no indication that Cross has been provided an opportunity to verify the efficacy of the fix.


ICS-CERT reports that an uncharacterized attacker with uncharacterized access to execute arbitrary code on the system.

Friday, September 22, 2017

ICS-CERT Publishes 5 Advisories

Yesterday the DHS ICS-CERT published five control system security advisories for products from Schneider, Ctek, Digium, iniNet Solutions, and Saia Burgess Controls. The advisory for the products from Saia Burgess Controls was originally posted to the NCCIC Portal on August 22, 2017.

Saia Burgess Controls Advisory


This advisory describes an information exposure vulnerability in the Saia Burgess Controls PCD Controllers. The vulnerability was reported by Davide Fauri of Eindhoven University of Technology. The latest version of the firmware mitigates the vulnerability. There is no indication that Fauri has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to to obtain information in memory.

The SBC upgrade notes also report that the current version makes the following security changes:

• Protective functions are activated by default;
• Improved password protection associated with the role-based user management;
• Access filter using "white" and "black" lists;
• Removed hardcoded password [NOT mentioned in ICS-CERT advisory].

Similar changes were also apparently made to the SBC PG5 Controls Suite.

iniNet Solutions Advisory


This advisory describes an improper authentication vulnerability in the iniNet Solutions SCADA Webserver. The vulnerability was reported by Matthias Niedermaier and Florian Fischer, both of Augsburg University of Applied Sciences. iniNet has released a new version that allows users to implement basic authentication. There is no indication that the researchers were afforded an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability  to access human-machine interface (HMI) pages or to modify programmable logic controller (PLC) variables without authentication.

Digium Advisory


This advisory describes an OS command injection vulnerability in the Digium Asterisk GUI. The vulnerability was reported by Davy Douhine of RandoriSec. Asterisk GUI is no longer maintained and should not be used. Digium recommends affected users to migrate to Digium’s SwitchVox product.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability  to execute arbitrary code on the device.

Interesting Questions: Would owners of a control system that uses an HMI configured with Digium’s Asterix GUI even know that it had been used, particularly if the system had been designed by a contractor or vendor? Would it take a complete system redesign to change out the GUI for an HMI?

Ctek Advisory


This advisory describes an improper authentication vulnerability in the Ctek SkyRouter. The vulnerability was reported by Maxim Rupp. The latest firmware version mitigates this and “additional security requirements”. NOTE: “Ctek, Inc., reports that due to industry demand, wireless carriers are rapidly eliminating 2G and 3G CDMA service and they will not be creating any additional update releases for those products.” There is no indication that Rupp was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to view and edit settings without authenticating.

Schneider Advisory


This advisory describes a missing authentication for critical function vulnerability in the Schneider InduSoft Web Studio products. The vulnerability was reported by Aaron Portnoy, formerly of Exodus Intelligence. Schneider has created a patch to mitigate the vulnerability. There is no indication that Portnoy was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability  to remotely execute arbitrary commands with high privileges.


NOTE: The Schneider security bulletin was published last Friday. Maybe Dale Peterson was right, it looks like ICS-CERT is doing ‘ICS-vuln Thursday’.

Tuesday, February 19, 2013

ICS-CERT Publishes CoDeSys Server Advisory


This afternoon the DHS ISC-CERT published an advisory for multiple vulnerabilities in the 3S CoDeSys Gateway-Server application. The vulnerabilities were reported by Aaron Portnoy of Exodus Intelligence in a coordinated disclosure.

The Advisory

The reported vulnerabilities include:

• Improper access of indexable resource, CVE-2012-4704;
• Directory or path traversal, CVE-2012-4705;
• Heap-based buffer overflow, CVE-2012-4706;
• Improper restriction of operations within the bounds of a memory buffer, CVE-2012-4707; and
• Stack-based buffer overflow, CVE-2012-4708.

NOTE: the CVE links may not be active for a couple of days; NIST uses this report to populate the CVE file.

ICS-CERT reports that a moderately skilled attacker could remotely exploit these vulnerabilities to crash the system or exploit arbitrary code. 3S has produced a patch that ICS-CERT reports mitigates these vulnerabilities.

Exploits Code Available?

The advisory states that there are no publicly available exploits for these vulnerabilities. Given that they were reported by Exodus Intelligence, I am not so sure that that is the case. Readers will remember my comment on the Exodus business model in an earlier blog post. EI provides their customers with exploit code for all of their ‘responsibly reported’ discoveries either just after the vulnerabilities are reported or when the vendor reports the vulnerabilities. Now this might not fit the ‘publicly available’ definition that ICS-CERT is using this week, but it looked like it did last week with the Schneider advisory.

Wednesday, February 13, 2013

ICS-CERT Publishes Two More Buffer Overflow Advisories


Yesterday (lost in the cybersecurity EO and State of the Union hoopla) the DHS ICS-CERT published two advisories addressing buffer overflow vulnerabilities in industrial control systems. The advisories addressed vulnerabilities in products from Schneider and WellinTech.

Schneider Advisory

This advisory addresses a heap-based buffer overflow in the Accutech Manager application from Schneider. The vulnerability was reported by Aaron Portnoy of Exodus Intelligence in a coordinated disclosure (more about this later) and according to the advisory Aaron has verified that the update provided by Schneider effectively mitigates the vulnerability.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability using publicly available code and it could allow the attacker to execute arbitrary code on the system.

The advisory also notes that Schneider recommends closing Accutech Manager when not actually using it. ICS-CERT (apparently) also recommends ensuring that the vulnerable port (2537/TCP) is not accessible from the internet

WellinTech Advisory

This advisory addresses a memory corruption buffer overflow in the kingMess application within the KingView product. The vulnerability was reported by Lucas Apa and Carlos Mario Penagos Hollman of IOActive in a coordinated disclosure. They have also verified that the patch produced by WellinTech fixes the vulnerability.

ICS-CERT reports that a highly skilled attacker could remotely exploit this vulnerability to execute arbitrary code on the system.

It’s interesting to note that WellinTech reportedly released the patch on November 15th of last year and ICS-CERT is just now publishing the advisory. This may be because WellinTech did not disclose the vulnerability to ICS-CERT until recently.

New Twist on Coordinated Disclosure

The Schneider advisory has something that I don’t recall seeing in a coordinated disclosure advisory before, a report that there is publicly available exploit code for the vulnerability. Typically the researcher keeps any exploit code they developed tightly held, only sharing it with the vendor. There is nothing specific about who has released the exploit, so I can’t tell from the advisory if it was Aaron who released the exploit code or some other researcher who independently discovered the vulnerability.

A look at the Exodus Intelligence (Aaron’s employer) web site sheds some light on the situation. Exodus Intelligence offers their customer two different types of ‘vulnerability intelligence data feeds’. A ‘Zero-day Feed’ offers to their customers information on vulnerabilities (including exploit code) just after Exodus notifies the vendor of the vulnerability. I’m assuming that there is some sort of non-disclosure agreement that goes along with this feed.

A separate (and presumably cheaper) ‘Day of Disclosure Feed’ provides the same information to Exodus customers the same day as the vendor publicly announces the availability of the mitigation for the vulnerability. Again this includes a copy of the exploit code for the vulnerability. I’m assuming that this is the exploit code for the Schneider vulnerability that is referenced in the advisory.

It is interesting to me to see how many different business models are beginning to grow out of the white hat side the cybersecurity universe. Researchers need to make money to support their nasty habits like eating and bathing and these varied business models will make it easier for these folks to keep plying their trade keeping software vendors on their toes.
 
/* Use this with templates/template-twocol.html */