Showing posts with label Aditya K Sood. Show all posts
Showing posts with label Aditya K Sood. Show all posts

Thursday, March 17, 2016

ICS-CERT Updates KACO Alert

Two days ago ICS-CERT published a minor update to their alert from August, 2015 for a hard-coded password vulnerability in KACO HMI products. The revised version added a single sentence to the summary portion of the Alert:

“According to this report, the password is easily found in the client code.”

I have no idea why ICS-CERT thought that this was important enough to add to the alert seven months after it was originally published. I suppose that it could be because KAKO has not been responsive enough in addressing this vulnerability.

Readers of this blog might be more than a little surprised that it has taken me two days to report on this update. The reason for that is simple, I just received an email this morning from ICS-CERT advising me of the recent update; this notification is a service that anyone can sign up for and I have previously mentioned it. A couple of months ago ICS-CERT changed their policy of listing updates to their alerts and advisories on their landing page. They had been making Twitter® notifications of these revisions, but did not do so in this case.

There are a couple of other oddities about how they handled this update. Normally ICS-CERT annotates changed versions of alerts and advisories by sequentially adding a letter to the end of the advisory number; for example, a first update would be labeled ICS-ALERT-16-074-XXA. They did not do that in this case. Another thing that they normally do is to highlight the changed areas in the body of the alert or advisory. Again, they did not do so in this case.

Now, none of these irregularities has a real impact on the information presented and in this case the change to the document is so minor that perhaps they thought that all of these additional details were not needed.

Just for the record here is the personal web site of the researcher, Aditya K Sood, who reported this vulnerability and a link to video of his presentation where he publicly disclosed this (and at least 3 other) HMI zero-days.


In any case there are muckrakers and nitpickers like me to keep the public informed, so now you know about this minor change and the oddities that go with it. I’ll leave it to the reader to figure out what this all means.

Tuesday, December 15, 2015

ICS-CERT Updates Advantech Advisory and Publishes New Advisory

The afternoon the DHS ICS-CERT updated the Advantech advisory that they published last week. Additionally a new advisory was published for vulnerabilities in an Adcon telemetry gateway.

Advantech Update

This update corrects the name of the researcher who reported the vulnerability in an uncoordinated disclosure. The researcher is now being reported as HD Moore. The confusion apparently arose because Tod Beardsley authored the blog post that publicly disclosed the vulnerability, but even that post credited HD Moore with the discovery.

Adcon Advisory

This advisory describes multiple vulnerabilities in the Adcon Telemetry A840 Telemetry Gateway Base Station. The vulnerabilities were reported by Aditya K. Sood. Adcon has contacted all known customers to offer an upgrade to a more secure and stable version. There is no indication that Sood has verified that the newer version is free of the indicated vulnerabilities.

The vulnerabilities are:

• Hard-coded credentials - CVE-2015-7930;
• Improper authentication - CVE-2015-7931;
• Clear text transmission of sensitive information - CVE-2015-7932; and
• Information exposure - CVE-2015-7934

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to gain administrative access to the target.

The reason for the unusual mitigation measure is that Adcon describes the affected device as obsolete and no longer supports the device.
 
/* Use this with templates/template-twocol.html */