Showing posts with label Acorn Network Security. Show all posts
Showing posts with label Acorn Network Security. Show all posts

Tuesday, August 2, 2016

ICS-CERT Publishes Two Advisories

This morning the DHS ICS-CERT published two industrial control system security advisories for products from Siemens and Moxa.

Siemens Advisory


This advisory describes a privilege escalation vulnerability in the Siemens SINEMA Server. The vulnerability was reported by rgod via the Zero Day Initiative. Siemens has developed a temporary fix for the vulnerability while a new version is being developed. There is no indication that rgod has been provided an opportunity to verify the efficacy of the temporary fix.

ICS-CERT reports that a relatively low skilled attacker with local access could exploit the vulnerability with a social engineering attack to escalate their privileges.

Moxa Advisory


This advisory describes an SQL injection vulnerability in the Moxa SoftCMS. The vulnerability was reported by Zhou Yu of Acorn Network Security via the Zero Day Initiative. Moxa has produced an update to mitigate the vulnerability, but there is no indication that Yu has been provided the opportunity to verify the efficacy of the fix.


ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to execute arbitrary commands on the target system.

Tuesday, July 12, 2016

ICS-CERT Publishes Two Advisories

Today the DHS ICS-CERT published two control system security advisories for products from GE and Tollgrade.

GE Proficy Advisory


This advisory describes an improper privilege management vulnerability in earlier versions of the GE Proficy HMI/SCADA CIMPLICITY application. The vulnerability was reported by Zhou Yu of Acorn Network Security. GE notes that subsequent versions of the application do not contain the vulnerability, having been corrected by August 2014.

ICS-CERT reports that local access is required or that a remote exploit would require a social engineering attack. Exploit code is publicly available (link not provided in ICS-CERT Advisory).

The GE Product Security Advisory for this vulnerability recommends upgrading to a newer version of the application, but it also provides commands that serve to mitigate the vulnerability in the affected versions.

Tollgrade Advisory


This advisory describes three vulnerabilities in the Tollgrade Communications, Inc. Smart Grid LightHouse Sensor Management System (SMS) Software EMS. The vulnerabilities were reported by Ashish Kamble of Qualys, Inc. Tollgrade has produced a new version that mitigates the vulnerabilities. ICS-CERT reports that Kamble has tested the new version to verify the efficacy of the fix.

The vulnerabilities are:

• Missing authentication for critical application - CVE-2016-5790;
• Information exposure through an error message - CVE-2016-5797; and
• Forced browsing - CVE-2016-5807

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerabilities to restart the system, brute force a login, or change privileged parameters.

Tuesday, June 21, 2016

ICS-CERT Publishes Two Advisories

This afternoon the DHS ICS-CERT published two control system advisories for products from Schneider and Advantech.

Schneider Advisory


This advisory describes a cross-site scripting vulnerability in the Schneider Electric PowerLogic PM8ECC communications add-on module for the Series 800 PowerMeter. The vulnerability is apparently self-reported. Schneider has produced a firmware update for the module.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to inject arbitrary JavaScript in a specially crafted URL request where the response containing user data is returned to the web browser without being made safe to display.

Schneider published their Security Notice on this vulnerability on May 11th, 2016.

Advantech Advisory


This advisory describes multiple vulnerabilities in the Advantech WebAccess product. The vulnerabilities were reported by Zhou Yu of Acorn Network Security. Advantech has produced a new version that mitigates the vulnerabilities. ICS-CERT reports that Zhou has had a chance verify the efficacy of the fix.

The vulnerabilities include:

• Unsafe ActiveX controls marked as safe for scripting - CVE-2016-4525; and
• Classic buffer overflow - CVE-2016-4528.

ICS-CERT reports that a social engineering attack is required to exploit these vulnerabilities, but a successful exploit could allow an attacker to insert and run arbitrary code on an affected system.

The Advantech version notes for the new version (8.1_20160519) produced to correct these vulnerabilities mentions ‘buffer-overrun’ vulnerabilities in BwAspObj.dll and cellvision.ocx, but it does not mention any ActiveX vulnerabilities. It does, however, mention a vulnerability to reveal password in Project User web page that was not mentioned in the ICS-CERT advisory.

Another Schneider Product Vulnerability



When looking for the Schneider Security Note mentioned above I also found another Schneider product vulnerability reported on the Schneider web site. This Security Note was for an elevation of privilege vulnerability in the – Pelco Digital Sentry Video Management System.
 
/* Use this with templates/template-twocol.html */