Showing posts with label ActiveX Vulnerability. Show all posts
Showing posts with label ActiveX Vulnerability. Show all posts

Monday, September 16, 2013

Another ICS-CERT Alert for Blake

The DHS ICS-CERT just released their second alert in less than a week, for another ActiveX control, this time in the Mitsubishi MC-WorkX Suite; another SCADA/HMI application. Further pushing the similarities with the previous alert, ICS-CERT again failed to give Blake credit for the discovery of this vulnerability (two thumbs down). ICS-CERT does get credit for publishing faster, this uncoordinated disclosure was made yesterday on Exploit-DB.com (one thumb up).

ICS-CERT notes that this vulnerability is reportedly remotely exploitable and could result in arbitrary code execution.

Looking at Blake’s history on Exploit-DB it looks like he has come back to hackery after a hiatus of some sort. He seems to have a penchant for ActiveX vulnerabilities, though he is certainly more versatile that just that. It does seem that he has just started targeting control systems. I wonder how many more ActiveX vulnerabilities he will be reporting?


BTW: Can someone answer a question about ActiveX controls for me? Is it possible that we could see the same control in multiple applications? And, if it is vulnerable in one, will it be vulnerable in the others?

Saturday, September 14, 2013

ICS-CERT Publishes WellinTech Alert

Yesterday the DHS ICS-CERT published in its first control system alert in three months. It identifies two ActiveX vulnerabilities in the WellinTech KingView SCADA/HMI interface. While not credited in the Alert, the vulnerabilities were reported by Blake in twin reports (here and here) on Exploit-DB.com on September 4th in an uncoordinated disclosure. 

There is also news about an ICS certification program being developed.

WellinTech Alert

The ICS-CERT alert notes that the reports state that the twin vulnerabilities (KChartXY and SuperGrid) are both remotely exploitable with exploit code publicly available and would apparently allow for overrighting arbitrary code. The alert also notes that the researcher provided mitigation measures (setting the kill-bits on the controls) but does not provide links for those claims (here and here).

I am disappointed that ICS-CERT has reverted to their old policy of not identifying researchers responsible for uncoordinated disclosures. While ICS-CERT would certainly prefer that disclosures are coordinated with vendors so that fixes could be put into place before the vulnerabilities are publicly disclosed, they must be aware that independent researchers rely on either public accolades or on selling their discovered vulnerabilities for the reward for their work. I would much rather see them get public accolades for uncoordinated disclosure than have them sell the vulnerabilities on the black market.

This is not the first ActiveX control vulnerability found in the KingView product. An earlier ICS-CERT Alert was released in 2011 and the subsequent Advisory was released later that year.

BTW: ICS-CERT now provides sorting of Advisories and Alerts by vendor.

Control System Certification


ICS-CERT also added a brief new article to their web site about a DarkReading.com article about the recent announcement by Global Information Assurance Certification (GIAC) that they were developing the Global Industrial Cyber Security Professional (GICSP) certification to be released this fall.

Friday, February 22, 2013

ICS-CERT Publishes Honeywell EBI Advisory


Late this afternoon the DHS ICS-CERT published an advisory for an ActiveX vulnerability for the Honeywell Enterprise Buildings Integrator (EBI). The vulnerability was reported by Juan Vazquez of Rapid7 in a coordinated disclosure.

The Advisory

ICS-CERT reports that a moderately skilled attacker using a social engineering attack could remotely exploit this vulnerability to execute arbitrary code on the system. ICS-CERT maintains that the need to use a social engineering attack vector “decreases the likelihood of a successful exploit” (pg 3). Recent reports on the success rates for social engineering attacks don’t seem to support that assertion.

Honeywell recommends that the HscRemoteDeploy.dll be disabled on “any client or server computers on affected systems”. They have an update package that accomplishes this, but recommend that it be only run by a “qualified, trained resource”. Honeywell has also asked Microsoft to “issue a kill bit for the HscRemoteDeploy.dll in a future monthly Microsoft Windows security update”. This will disable the DLL on any machines running the automated Windows update.

No Public Exploit Code, Yet

The advisory reports that there is no known exploit code publicly available at this time. It also notes that Rapid7 plans on releasing a Metasploit module for this vulnerability next month. This continues a trend upon which I have recently reported that white hat researchers are publishing exploit code even on coordinated disclosure vulnerabilities. Rapid 7 is more forgiving in their publication process than is Exodus Intelligence since they are giving owners a reasonable chance to install their system updates before the exploit code is published. It would be even more forgiving if they held off their publication until Microsoft publishes the DLL kill bit in their Windows update.
 
/* Use this with templates/template-twocol.html */