Showing posts with label Advantech Studio. Show all posts
Showing posts with label Advantech Studio. Show all posts

Friday, January 4, 2013

ICS-CERT Issues Advantech Studio Alert


This afternoon the DHS ICS-CERT published an alert for a directory traversal vulnerability in the Advantech Studio Web server. The vulnerability, with proof of concept code, was reported by Nin3 in an uncoordinated disclosure (it’s been a while since we’ve seen one of these).

Exploitation of this vulnerability could result in ‘data leakage’. The alert doesn’t provide any details on what types of data might be leak able, but from a security perspective the data of concern would be credential information. The readability of that data would have a major impact on the seriousness of this vulnerability. Of course the business folks might be just as concerned about the exfiltration of process data.

Actually an Indusoft Vulnerability?


Interestingly ICS-CERT notes that:

“ICS-CERT has shared this report with Advantech. Advantech has phased out the Advantech Studio product. As this is a rebranded Indusoft Web Studio product, full support and upgrades are available through Indusoft Web Studio.” (pg 1)

Why, then, does ICS-CERT refer to this as an Advantech Alert instead of an Indusoft Alert, one doesn’t really know. My guess is that if Nin3 named this as an Advantech issue, then ICS-CERT is just going along with that initial identification while it is working with both organizations to resolve the vulnerability.

Monday, January 3, 2011

DHS ICS-CERT Advantech Studio Test Web Server Advisory

This afternoon the DHS Industrial Control System Cyber Emergency Response Team  (ICS-CERT) published an advisory covering a confirmed buffer overflow vulnerability in the test web server bundled with Advantech Studio Version 6.1. According to the advisory the “Advantech Studio is a collection of automation tools that includes components required to develop Human-Machine Interfaces (HMIs), and Supervisory Control and Data Acquisition System (SCADA) applications that run on various Windows platforms”.

While Advantech does not intend for the test web server to be used for anything other than testing, if it were used in a production environment it would be vulnerable to a stack-based buffer overflow that could allow an attacker with intermediate skill levels to execute arbitrary code. There is no known exploit publicly available for this vulnerability.

DHS ICS-CERT recommends, with the standard impact analysis and risk assessment caveat, the following mitigation measures:

• Upgrade to the latest version and install the patch. The patch can be applied to Advantech Studio Version 6.1 and any earlier version. Users can get more information and download the patch at: http://www.advantechdirect.com/emarketingprograms/AStudio_Patch/AStudio_Patch.htm
• Minimize network exposure for all control system devices. Control system devices should not directly face the Internet. 1
• Control system networks and devices should be located behind firewalls, and be isolated from the business network. If remote access is required, secure methods such as Virtual Private Networks (VPNs) should be utilized.
 
/* Use this with templates/template-twocol.html */