Showing posts with label Aditya Sood. Show all posts
Showing posts with label Aditya Sood. Show all posts

Thursday, December 8, 2016

ICS-CERT Publishes Four Advisories

Today the DHS ICS-CERT published four control system security advisories for products from INTERSCHALT, Adcon, Sauter and Moxa.

INTERSCHALT Advisory


This advisory describes a path traversal vulnerability the INTERSCHALT Maritime Systems (INTERSCHALT) VDR G4e application. The vulnerability was reported by Maxim Rupp. INTERSCHALT has produced a patch to mitigate this vulnerability. ICS-CERT reports that Maxim has verified the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to read/download arbitrary files from the target host.

Adcon Advisory


This advisory describes a cross-site scripting vulnerability in the Adcon Telemetry A850 Telemetry Gateway Base Station. The vulnerability was reported by the Aditya K. Sood. Adcon has produced a new firmware version to mitigate the vulnerability. There is no indication that Sood has been provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to allow the injection of arbitrary JavaScript that may affect the integrity of the system.

Sauter Advisory


This advisory describes an authentication bypass vulnerability in the Sauter NovaWeb web HMI application. The vulnerability was reported by Maxim Rupp. The HMI application is no longer supported so there will be no fix for the vulnerability.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to gain authorized access to the application.

Moxa Advisory


This advisory describes two vulnerabilities in the Moxa MiiNePort. The vulnerabilities were reported by Aditya Sood. Moxa has produced new firmware versions to mitigate the vulnerabilities. There is no indication that Sood was provided an opportunity to verify the efficacy of the fix.

The reported vulnerabilities are:

• Permissions, privileges, and access controls - CVE-2016-9344; and

• Cleartext storage of sensitive information - CVE-2016-9346

Thursday, March 3, 2016

ICS-CERT Publishes Moxa Advisory and Latest Monitor

This afternoon the DHS ICS-CERT published an advisory for multiple vulnerabilities in equipment from Moxa, thus updating an Alert from August. It also published the latest version of the ICS-CERT Monitor for the January-February time frame.

Moxa Advisory


This advisory describes two vulnerabilities in the Moxa ioLogik E2200 Ethernet Micro RTU controllers. Like Tuesday’s Rockwell advisory these vulnerabilities were reported by Aditya Sood via last summer’s DefCon. Moxa has issued a firmware update and an associated update for their Active OPC Server software that mitigates the vulnerability. There is no indication that Sood has been given the opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Insufficiently protected credential - CVE-2016-2282; and
• Inadequate encryption strength - CVE-2016-2283

ICS-CERT reports that a relatively low skilled attacker could use existing public exploits to remotely exploit these vulnerabilities to gain access to settings and data on the devices.

It is interesting to note that Moxa reports in their release notes that the new version of the OPC Server software will continue to support Windows 2003 and Windows XP systems. Both of these are long out of support at Microsoft and their continued use potentially puts operations at risk for any number of vulnerabilities.


ICS-CERT Monitor


The 2016 January-February Monitor was published this afternoon and I was impressed with the increased level of interesting and usable information. I am definitely recommending that people download and read this issue; not something that I have done in a while.

I expected the opening incident investigation report to touch on the Ukraine power outage and I was wrong. Instead they described a visit to a combined water and electric power utility and actually discussed some control system issues. Nice note that they found a wireless router in one network that operators incorrectly thought was disconnected and an unknown cellular modem (vendor installed) in the other.

There were two things reported in this article that deserved a little more attention; a brief report that ‘low-level malware' was spotted on one network, and the initial comment that the utility was planning on merging their two operations networks. A little discussion could have turned both of these observations into important teaching points.

There was a good overview article on incident response and a description of the changes that went into the newly released CSET v7.1. There was also a favorable write up on the ICS-CERT attendance at Digital Bonds S4x16 conference. The ICSJWG Spring Conference in May also got a plug.

They also provided links to eight updated ICS-CERT fact sheets. I would like to suggest that ICS-CERT date these fact sheets so they can be readily differentiated from the predecessors and any follow-on updates. Those fact sheets were:

Training; and


All in all, I think this was a very well done issue; certainly much more informative that the last couple of issues have been. PLEASE keep up this caliber of reporting.

Tuesday, March 1, 2016

ICS-CERT Publishes Two Advisories

This morning the DHS ICS-CERT published two advisories for control system vulnerabilities in systems from Rockwell and Schneider.

Rockwell Advisory


This advisory describes a cross-site scripting vulnerability in the Rockwell Automation CompactLogix application that was first reported in an ICS-CERT Alert last August (and updated here). The vulnerability was reported by Aditya Sood. Rockwell has produced a firmware update to mitigate the vulnerability. There is no indication that Sood was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to deliver an attack to the connected web browser and thus affect availability.

Schneider Advisory

 

This advisory describes an OS command injection vulnerability in the Schneider StruxureWare Building Operations software. The vulnerability was reported by Karn Ganeshen. Schneider has produced a new version that mitigates the vulnerability. There is no indication that Ganeshen has been provided the opportunity to verify the efficacy of the fix. The Schneider Security Notification also reports a weak credential management vulnerability addressed by the same “Automation Server firmware” update that addresses the command injection vulnerability.

ICS-CERT reports that a relatively unskilled attacker who was an authenticated user could remotely exploit this vulnerability to circumvent access controls.

NOTE: Ran across an interesting blog post by Karn Ganeshen while researching for this post. See also ICSA-12-249-02 for a similar vulnerability reported a while back.

Tuesday, January 19, 2016

ICS-CERT Publishes Siemens Advisory

This morning the DHS ICS-CERT published an advisory for a cross-site scripting vulnerability in building controller communications modules from Siemens. The vulnerability was reported by Aditya Sood. Siemens has produced a firmware update that mitigates the vulnerability, but there is no indication that Sood has had a chance to verify the efficacy of the fix.

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to change data and settings on the target device.

The Siemens Advisory does mention the web server login form as being associated with this vulnerability that the ICS-CERT advisory describes. On the other hand, the ICS-CERT advisory does not mention needing to use a social engineering attack (usually prominently featured in ICS-CERT advisories) to get the user to access a specially crafted web site to exploit the vulnerability that the Siemens Advisory describes. It is almost as if the two advisories are describing different vulnerabilities using the same CVE.

NOTE: The different CVSS base scores is more easily explained because of the different versions of the scoring system used by the two organizations to calculate those scores.

NOTE: Siemens announced this vulnerability on TWITTER® last Friday.

Tuesday, September 16, 2014

ICS-CERT Publishes ClearSCADA Advisory

Today the DHS ICS-CERT published an advisory for three vulnerabilities reported in the Schneider Electric ClearSCADA system. Two of the vulnerabilities were reported by Aditya Sood and Schneider self-reported the third. Schneider continues to work on producing a patch to mitigate these vulnerabilities, but the advisory does provide some specific interim mitigation measures that owner/users can take. The patches are scheduled to be released later this month.

The three vulnerabilities are:

● Cross-site scripting, CVE-2014-5411;
● Authentication bypass, CVE-2014-5412;
● Weak hashing algorithim, CVE-2014-5413

ICS-CERT reports that a low to moderately skilled attacker could remotely exploit two of these vulnerabilities while the third would require a social engineering exploit to get a local user with administrative access to exploit the cross-site scripting vulnerability.

Interestingly the ClearSCADA support page linked to in the advisory contains a link to their system security page which in turn provides a link to a page entitled “List of ClearSCADA Vulnerabilities”. The three vulnerabilities listed in this advisory are not listed on that page.

Neither are the vulnerabilities reported in two other ICS-CERT advisories (here and here) from this earlier this year.
 
/* Use this with templates/template-twocol.html */