Showing posts with label Alexander Bolshev. Show all posts
Showing posts with label Alexander Bolshev. Show all posts

Thursday, April 19, 2018

ICS-CERT Publishes Advisory and Three Updates for Siemens Products

Today the DHS ICS-CERT published one new control system security advisory for products from Siemens. They also provided updates for three previously published Siemens control system security advisories.

Siemens Advisory


This advisory describes a file and directory information exposure vulnerability in the Siemens Simatic WinCC OA iOS App. The vulnerability was reported by Alexander Bolshev of IOActive and Ivan Yushkevich of Embedi. Siemens has identified workarounds to mitigate the vulnerability. There is no indication that either researcher was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that an uncharacterized attacker with physical access to the mobile device could exploit the vulnerability to read sensitive data located in the app’s directory.

SIMATIC Update


This update provides additional information on an advisory that was originally published on March 18th, 2018. The update provides links to the updates for all of the affected products.

SIPROTEC Update #1


This update provides additional information on an advisory that was originally published on March 8th, 2018. The ICS-CERT update provided a link to the updated version of the EN100 Ethernet module DNP3 variant with additional mitigation measures. The Siemens update also provided corrected affected version information on the same product.

SIPROTEC Update #2


This update provides additional information on an advisory that was originally published on March 8th, 2018. The ICS-CERT update provided a link to the updated version of the EN100 Ethernet module DNP3 variant with additional mitigation measures. The Siemens update also provided corrected affected version information on the same product.

Friday, March 23, 2018

ICS-CERT Publishes 2 Advisories and Siemens Update


Yesterday the DHS ICS-CERT published two control system security advisories for products from Beckhoff and Siemens. They also updated a previously published advisory for products from Siemens. The two Siemens products were mentioned in a previous blog post.

Beckhoff Advisory


This advisory describes an untrusted pointer dereference vulnerability in the Beckhoff TwinCAT PLC products. The vulnerability was reported by Steven Seeley of Source Incite. According to the Beckhoff security advisory, the company has updates available that mitigate the vulnerability. There is no indication that Seeley has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to escalate privileges. ICS-CERT reports that Matlab modules need to be recompiled after updating.

Siemens Advisory


This advisory describes an improper access control vulnerability in the Siemens SIMATIC WinCC OA UI mobile app. The vulnerability was reported by Alexander Bolshev from IOActive, and Ivan Yushkevich from Embedi. Siemens has updates available that mitigate the vulnerability. There is no indication that the researchers have verified the efficacy of the fix.

ICS-CERT reports that an uncharacterized attacker on an adjacent network could exploit the vulnerability to read and write data from and to the app’s project cache folder. The Siemens security advisory notes that a social engineering attack is required to convince the App user to connect to an attacker-controlled WinCC OA server

Siemens Update


This update provides new information on an advisory that was originally published on January 25th, 2018 and updated on February 6th. The update removes a product from the affected product list.

Thursday, February 15, 2018

ICS-CERT Publishes 4 Advisories and One ABB Update


Today the DHS ICS-CERT published four new control system security advisories for products from Schneider Electric (2), GE and Nortek. Additionally, they provided an update for a previously published advisory for products from ABB.

StructureOn Advisory


This advisory describes an unrestricted upload of file with dangerous type vulnerability in the Schneider StruxureOn Gateway software management program. The vulnerability is being self-reported.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to upload a malicious file to any directory on the device, which could lead to remote code execution. The Schneider security advisory reports that the file must be a .zip file with specifically modified metadata for this vulnerability to be exploited.

IGSS Mobile Advisory


This advisory describes two vulnerabilities in the Schneider IGSS Mobile application (iOS and Android). The vulnerabilities were reported by Alexander Bolshev (IOActive) and Ivan Yushkevich (Embedi). Schneider has produced updates for both versions. There is no indication that either researcher has been provided an opportunity to verify the efficacy of the fix.



The two reported vulnerabilities are:

• Improper certificate validation - CVE-2017-9968; and
Plaintext storage of password - CVE-2017-9969

ICS-CERT reports that a relatively low-skilled attacker with local access (okay they, actually said: “Locally exploitable”; that may not mean ‘local access’) could exploit the vulnerability to execute a man-in-the-middle attack. In addition, passwords can be accessed by unauthorized users.

NOTE: Marc Ayala pointed out to me that anyone can download these apps from the appropriate (iOs/Android) app store. This means that it would be easy to exploit a compromised mobile password. All the attacker needs to do is to get access to the IGSS configuration file on an oh so secure smart phone to compromise the password.

GE Advisory


This advisory describes two vulnerabilities in the GE D60 Line Distance Relay. The vulnerabilities were reported by Kirill Nesterov of Kaspersky Labs. GE has released new firmware that mitigates the vulnerability. There is no indication that Nesterov was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-5475; and
• Improper restriction of operations within bounds of memory buffer - CVE-2018-5473

ICS-CERT reports that relatively low-skilled attacker could remotely exploit the vulnerability to execute arbitrary code on the device.

Nortek Advisory


This advisory describes a command injection vulnerability in the Nortek Linear eMerge E3 Series access control interface. The vulnerability was reported by Evgeny Ermakov and Sergey Gordeychik. Nortek recommends upgrading the system using established procedures. There is no indication that either researcher was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability  to execute malicious code on the system with elevated privileges, allowing for full control of the server.

ABB Update


This update provides additional information on an advisory that was originally published on November 14th, 2017. The update reports that the new update of Mesh OS mitigates the KRACK vulnerability in these devices.

NOTE: The updated ABB security advisory that forms the basis for this ICS-CERT update was published on January 11th, 2018.

Thursday, September 24, 2015

ICS-CERT Publishes Update and 2 New Advisories

ICS-CERT Publishes an update to an N-Tron advisory published earlier this year and two new advisories for products from EasyIO and Endress+Hauser.

N-Tron Update

This update reports that Red Lion has produced a firmware update that mitigates the vulnerability and that the researcher who initially reported the vulnerability, Neil Smith, has verified the efficacy of the fix. The update reports that the update allows the end user to upload unique keys/certificates to the unit and this required a re-write of the user manual. The new manual is available here.

NOTE: This update is not on the main ICS-CERT web page so, unless you follow @ICSCERT on Twitter (or of course read this blog) you would not know about this update.

EasyIO Advisory

This advisory describes a hard-coded credential vulnerability in the EasyIO-30P-SF controller. The vulnerability was reported by Maxim Rupp. EasyIO has produced a patch that mitigates the vulnerability and Rupp has verified the efficacy of the fix. This advisory was originally released on the US-CERT Secure Portal on August 25th and is probably one of the advisories on that Portal that I reported on earlier this month.

ICS-CERT notes that this controller is “used in a number of DDC systems worldwide”. With this in mind a supplement has been issued to this advisory that lists a number of the OEM partners (and their devices) that are affected by this vulnerability. It also lists separate actions taken by those partners to mitigate this vulnerability.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to gain complete access to the controller.

Endress+Hauser Advisory

This advisory describes an XML code injection vulnerability in Endress+Hauser Fieldcare used in conjunction with CodeWright HART Comm DTM. The vulnerability was reported by Alexander Bolshev of Digital Security. Endress+Hauser and CodeWright have each produced updates that work together to mitigate this vulnerability. Bolshev has verified the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker on an adjacent network that receives HART DTM packets could exploit this vulnerability.


Question: How many other device manufacturers have a similar problem that would interact with the CodeWright HART Comm DTM to produce the same vulnerability? I am afraid that there is nothing in this advisory that would allow anyone to answer that question with any accuracy.

Tuesday, August 11, 2015

ICS-CERT Publishes Schneider Advisory

This afternoon the DHS ICS-CERT published a new advisory for a memory corruption vulnerability in the Schneider Electric IMT25 DTM component. The vulnerability was originally reported by Alexander Bolshev, Gleb Cherbov, and Svetlana Cherkasova of Digital Security. Schneider has produced a patch that mitigates the vulnerability and ICS-CERT reports that the researchers have validated the efficacy of the fix.

ICS-CERT reports that it would be moderately difficult to craft an exploit for this vulnerability and notes that access to an adjacent network is required to exploit this vulnerability. The vulnerability is remotely exploitable.


The Schneider Security Notification for this vulnerability explains that the vulnerability “includes a potential buffer overflow that possibly could lead to memory corruption and cause Denial of Service or permit remote code execution”.
 
/* Use this with templates/template-twocol.html */