Showing posts with label Airbus Cybersecurity. Show all posts
Showing posts with label Airbus Cybersecurity. Show all posts

Saturday, August 15, 2020

Public ICS Disclosure – Week of 8-8-20


This week we have 9 vendor disclosures for products from Schneider(6), Meinberg, B&R Automation and SICK. There were 7 updated vendor disclosures for products from Schneider (4), Siemens, GE Healthcare and Rockwell.

Schneider Advisories


Schneider published an advisory describing an improper privilege management vulnerability in their Modbus Serial Driver Component. The vulnerability was reported by Nicolas Delhaye of Airbus Cybersecurity. Schneider has a new version that mitigates the vulnerability. There is no indication that Delhaye has been provided an opportunity to verify the efficacy of the fix.

Schneider has published an advisory describing an improper restriction of excessive authentication attempts vulnerability in their spaceLYnk and Wiser for KNX products. The vulnerability was reported by Ismail Tasdelen. Schneider has a new version that mitigates the vulnerability. There is no indication that Tasdelen has been provided an opportunity to verify the efficacy of the fix.

Schneider has published an advisory describing an out-of-bounds write vulnerability in their Modicon M218 Logic Controller product. The vulnerability is self-reported. Schneider has a new firmware version that mitigates the vulnerability.

Schneider has published an advisory describing an improper input validation vulnerability in their PowerChute Business Edition software. The vulnerability was reported by Mateus Riad. Schneider has new versions that mitigate the vulnerability. The is no indication that Riad has been provided an opportunity to verify the efficacy of the fix.

Schneider has published an advisory describing the SweynTooth  Bluetooth vulnerabilities in their Harmony® eXLhoist product. Schneider has a new base station firmware version that mitigates the vulnerability.

Schneider has published an advisory describing an incorrect default permission vulnerability in their SoMove application. The vulnerability was reported by Luis Alvernaz. Schneider has a new version that mitigates the vulnerability. There is no indication that Alvernaz has been provided an opportunity to verify the efficacy of the fix.

Meinberg Advisories


Meinberg published an advisory describing nine vulnerabilities in their LANTIME product including third-party vulnerabilities in ntp (4: Sec 3592, Sec 3596, Sec 3610, and Sec 3661) and OpenSSL (2: CVE-2019-1551 and CVE-2020-1967) services. The vulnerabilities are self-reported. Meinberg has new firmware that mitigates the vulnerabilities.

NOTE: There is publicly available exploit code for one of the OpenSSL vulnerabilities.

B&R Automation Advisory


B&R Automation published an advisory describing a TFTP Service DoS vulnerability in their  Automation Runtime products. The vulnerability is self-reported. B&R has new versions that mitigate the vulnerability.

SICK Advisory


SICK published an advisory describing the Microsoft® SMB/RCE vulnerability in their MEAC central emission monitoring computer (EPC). SICK recommends implementing the appropriate Microsoft patch.

Schneider Updates


Schneider published an update for their Ripple20 advisory that was originally published on June 23, 2020 and most recently updated on July 29th, 2020. The new information includes updated affected version data and mitigation measures for Uninterruptible Power Supply (UPS) using NMC2.

Schneider published an update for their Vijeo Designer and Vijeo Designer Basic Software advisory that was originally published on May 12th, 2020. The new information includes updated mitigation measures for Vijeo Designer.

Schneider published an update for their Vijeo Designer and Vijeo Designer Basic that was originally published on April 14th, 2020 and most recently updated on April 30th, 2020. The new information includes updated mitigation measures for Vijeo Designer V6.2 SP10.

Schneider published an update for their Modicon Controllers that was originally published on May 14th, 2019 and most recently updated on May 12th, 2020. The new information includes:

• Additional fixes available for M580 v3.10
• Quantum & Premium previous fix is not enough to correct the CVE and requires the additional mitigations proposed

Siemens Update


Siemens published an update for their GNU/Linux subsystem advisory that was originally published on November 27th, 2018 and most recently updated on July 14th, 2020. The new information includes adding the following CVE’s:

• CVE-2019-19462,
• CVE-2019-20812,
• CVE-2019-20907,
• CVE-2020-0305,
• CVE-2020-10690,
• CVE-2020-10720,
• CVE-2020-10766,
• CVE-2020-10767,
• CVE-2020-10768,
• CVE-2020-12062,
• CVE-2020-12826,
• CVE-2020-13434,
• CVE-2020-13435, and
• CVE-2020-13871

NOTE: At this point it looks like Siemens is just adding new CVE’s to this advisory without providing any information about fixes to the underlying product (SIMATIC S7-1500 CPU).

GE Healthcare Update


GE published an update for their SigRed  advisory that was originally reported on July 16th, 2020. The new information is a note that GE Healthcare will provide a workaround for affected versions of products  using unsupported versions of Windows Server.

Rockwell Update


Rockwell published an update for their Studio 5000 Logix Designer advisory that was originally published on July 8th, 2020. The new information includes a new version of the product that mitigates the vulnerability.

Saturday, March 21, 2020

Public ICS Disclosures – Week of 3-14-20


This week we have four vendor disclosures for products from Bosch, Schneider, Moxa and Eaton. There are also two interesting cybersecurity related announcements from Phillips and Meinberg.

Bosch Advisory


Bosch published an advisory describing an improper input validation vulnerability in the Bosch Rexroth S20-PN-BK+/S20-ETH-BK fieldbus couplers. The vulnerability is in a third-party component of the devices from Phoenix Contact that was originally reported in September 2018. Bosch provided generic controls to mitigate the vulnerability. These are the same controls recommended by Phoenix Contact.

Schneider Advisory


Schneider published an advisory describing an injection vulnerability in their Modicon Controllers, EcoStruxure™ Control Expert and Unity Pro Programming Software. The vulnerability was reported by Airbus Cybersecurity. Schneider has hotfixes available to mitigate this vulnerability.

Schneider reports that:

“Since alerting us to the vulnerability, Airbus Cybersecurity and Schneider Electric have collaborated to validate the research and to assess its true impact. Our mutual findings demonstrate that while the discovered vulnerability affects Schneider Electric offers, it equally impacts many other vendors and the global industrial automation market in general, especially when the baseline assumption of the attack technique Airbus Cybersecurity demonstrated is considered. Given certain conditions, and assuming an attacker has access to the network, many devices available from several different industrial control vendors are likewise vulnerable.”

Schneider provides links to the Airbus Cybersecurity site and blog for further details. As of this morning I can find nothing on that site.

Moxa Advisory


Moxa published an advisory describing two vulnerabilities in the Moxa OnCell Central Manager Cellular Management Software. The vulnerability was reported by Sergey Temnikov from Kaspersky ICS CERT. These vulnerabilities are in a third-party component; Apache Flex BlazeDS. Moxa has a security patch that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Deserialization of trusted data - CVE-2019-15696 (Apache CVE-2017-5641); and
• Information exposure - CVE-2019-15697 (Apache CVE-2015-3269)

The CVE links are to the Kaspersky advisories. Kaspersky has provided the original CVE numbers for the underlying vulnerability. There is at least one publicly available exploit for the original information exposure vulnerability.

Eaton Advisory


Eaton published an advisory describing an eval injection vulnerability in the Eaton  UPS Companion software. The vulnerability was reported by Ravjot Singh Samra. Eaton has a new version that mitigates the vulnerability. There is no indication that Samra has been provided an opportunity to verify the efficacy of the fix.

Cybersecurity Announcements


Phillips published a notice announcing that the Philips Security Center of Excellence was named the first medical device manufacturer to receive a new Underwriters Laboratories (UL) product cybersecurity testing certification (UL IEC 62304).

Meinberg published a notice concerning their continued operations during the COVID-19 outbreak.

Commentary


It is not unusual to see third-party vulnerabilities being reported in control systems. The two reports today are disheartening because of the elapsed time between the reporting of the underlying vulnerability and this week’s advisories. The use of third-party software and libraries is almost unavoidable in the current development environment; companies just cannot afford (time or money) to write complex software from scratch.

We expect manufacturers to watch for vulnerability announcements for the equipment and software they use in their manufacturing processes and then conduct a risk assessment to determine if that vulnerability provides an unacceptable risk to their operations. We need to expect control system vendors to perform the same sort of process. Perhaps companies buying control system components should be asking their vendors to describe their process for identifying and fixing third-party vulnerabilities in their products.

 
/* Use this with templates/template-twocol.html */