Showing posts with label Alexey Osipov. Show all posts
Showing posts with label Alexey Osipov. Show all posts

Thursday, January 25, 2018

ICS-CERT Publishes 3 Advisories and 5 Siemens Updates

Today the DHS ICS-CERT published two control system security advisories for products from Siemens and Nari as well as a medical control system security advisory for products from Philips. They also updated five control system security advisories from Siemens.

Philips Advisory


This advisory describes an insufficient session expiration advisory for the Philips IntelliSpace Cardiovascular cardiac image and information management systems. According to the Philips product security page this vulnerability was identified based upon a customer submitted complaint. Philips plans on releasing an updated version to mitigate the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker with local access could exploit the vulnerability  to gain unauthorized access to sensitive information stored on the system and modify this information.

NOTE: This vulnerability was not reported on the FDA medical device safety communications page, probably because an exploit would only reveal personally identifiable information making this more of a HIPAA problem. Unfortunately, I cannot find (after an admittedly brief search) a software vulnerability reporting page on the HHS HIPAA site.

Siemens Advisory


This advisory describes an improper authentication vulnerability in the Siemens Desigo PXC. The vulnerability was reported by Can Demirel and Melih Berk Eksioglu from Biznet Bilisim. Siemens has provided an updated version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability to  allow unauthenticated remote attackers to upload malicious firmware without prior authentication.

BTW: Siemens tweeted this morning about another new advisory that they have just published. That will probably show up next week on the ICS-CERT site.

Nari Advisory


This advisory describes an improper input validation vulnerability in the Nari PCS-9611 relay, a control and monitoring unit. The vulnerability was reported by Kirill Nesterov and Alexey Osipov from Kaspersky Labs. Nari has not responded to ICS-CERT about this reported vulnerability.

ICS-CERT reports that a relatively low-skilled attacker could use a publicly available exploit to remotely exploit the vulnerability to gain arbitrary read/write abilities on the system.

Industrial Products (older advisory) Update



• SINEMA Remote Connect Client: All versions prior to V1.0 SP3;

NOTE: The revised Siemens security notice also changed the temporary mitigation measures for SIMATIC PCS 7 V8.1, but that was not mentioned in the ICS-CERT update.

S7-300 Update


This update provides new information for an advisory that was originally published on December 13th, 2016 and then updated on May 9th, 2017, July 25th, 2017, and again on November 28th, 2017. The new information includes the addition of two new affected products along with mitigation links:

• SIMATIC S7-400 V7 CPU family; and
• SIMATIC S7-410 V8 CPU family
NOTE: The revised Siemens security notice reports that the S7-410 V8 CPU family is only affected by the inadequate encryption strength vulnerability.

PROFINET Update


This update provides new information for an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th,  November 28th, 2017, and most recently January 18th, 2018. The new information includes new affected version data and mitigation links for:

• S7-400 PN/DP V7 Incl. F: All versions prior to V7.0.2
• SINAMICS DCP w. PN: All versions prior to V1.2 HF 1

SCALANCE Update


This update provides new information for an advisory that was originally published on November 14th, 2017 and updated on December 5th, 2017, and again on December 19th, 2017. The new information includes new affected version data and mitigation links for:


• SCALANCE WLC711: All versions prior to V9.21.19.003; and
• SCALANCE WLC712: All versions prior to V9.21.19.003


Industrial Products (newer advisory) Update


This update provides new information for an advisory that was originally published on December 5th, 2017 and updated on December 19th, 2017 and again on January 23rd, 2018. The new information includes new affected version data and mitigation links for:


• SIMATIC S7-400 PN/DP V7: All versions prior to V7.0.2; and
• SIMATIC ET 200MP: All versions prior to V4.0.2

Commentary


Even if Siemens does not issue any more multiple product advisories in the near future (not likely, they have obviously shared a bunch of code across product lines over the years) we will continue to see large numbers of these advisory updates over the next year or so. Unfortunately, while vulnerable code is relatively easy to share, fixes cannot be cut and pasted so easily; too many dependencies, loops, etc. to check and modify as necessary. These time and resource-consuming exercises being undertaken by Siemens are a good example of why secure coding practices are so important; it really is easier over the life of the product to do it right the first time.


It would really be a good cybersecurity grad-student project to look at the costs that Siemens is expending to go back and correct mistakes that should have been caught before they ever made it to market.

Thursday, January 5, 2017

ICS-CERT Published Two Rockwell Advisories

Today the DHS ICS-CERT published two control system security advisories for products from Rockwell Automation. Both advisories were previously published on the NCCIC Portal library (formerly US-CERT Secure Portal) to provide critical infrastructure owners time to implement mitigation measures before the vulnerabilities were publicly reported.

MicroLogix Advisory


This advisory describes two vulnerabilities in the Rockwell Allen-Bradley MicroLogix 1100 and 1400 programmable logic controller (PLC) systems. The vulnerabilities were reported by Alexey Osipov and Ilya Karpov of Positive Technologies. Rockwell has developed new firmware versions to mitigate the vulnerabilities. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Clear-text transmission of sensitive information - CVE-2016-9334; and
• Incorrect permission assignment for critical resource - CVE-2016-9338;

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to gain unauthorized access to affected devices, as well as impact the availability of affected devices.

Logix Advisory


This advisory describes a buffer overflow vulnerability in the Rockwell Automation Logix5000 Programmable Automation Controller product line. The vulnerability is apparently self-reported. Rockwell has developed new firmware versions to mitigate the vulnerability.


ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to cause a denial of service at a controller or execute code on a target controller.

Saturday, May 24, 2014

ICS-CERT Publishes Emersion Advisory

Note: It’s been a busy week at my real job, so some stuff is being posted much later than normal.

On Thursday DHS ICS-CERT published an advisory for two vulnerabilities in the DeltaV product from Emerson. The vulnerabilities were reported to Emerson in a coordinated disclosure by a team (Kirill Nesterov, Alexander Tlyapov, Dmitry Nagibin, Alexey Osipov, and Timur Yunusov) from Positive Technologies. Emerson has produced a patch to mitigate the vulnerabilities, but there is no indication in the advisory if Positive Technologies has had a chance to validate the efficacy of the patch.

The two vulnerabilities are:

• Improper authorization - CVE-2014-2349;
• Hard-coded credentials - CVE-2014-2350.


ICS-CERT reports that a relatively unskilled attacker with local access and a successful social engineering attack could exploit these vulnerabilities to conduct a denial of service attack or read/replace configuration files, or log into accounts.

Emerson only releases their advisories to customers so no other information on this vulnerability is publicly available.

Thursday, October 10, 2013

ICS-CERT Publishes Two Advisories

In the midst of a dysfunctional government’s fiscal fiasco the DHS ICS-CERT published two control system security advisories yesterday, one a DNP3 advisory for Alstom e-Terracontrol and another HMI advisory for Wonderware InTouch.

Alstom Advisory

This advisory is for an improper input validation vulnerability reported by Adam Crain and Chris Sistrunk in a coordinated disclosure (#9 of 25 listed on the Project Robus web page). Alstom has produced a patch to mitigate this vulnerability and Adam and Chris have verified the efficacy of that patch.

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to execute a denial of service attack on the system.

Wonderware Advisory

This advisory is for an improper input validation vulnerability reported by Timur Yunusov, Alexey Osipov, and Ilya Karpov of the Positive Technologies Research Team in a coordinated disclosure. Wonderware has produced an updated version of InTouch that mitigates this vulnerability and the team from Positive Technologies has verified the efficacy of the new version. ICS-CERT had released this advisory to the US-CERT secure Portal library on October 03, 2013.

ICS-CERT reports that a relatively low skilled attacker could exploit this vulnerability to gain access to system information or execute a denial of service attack. ICS-CERT says that this vulnerability cannot be remotely exploited; they note that the “exploit is only triggered when a local user runs the vulnerable application and loads the malformed XML files” {page 2}. It seems clear that a remote exploit would be possible through a social engineering attack.

According to the Positive Technologies web site that organization reported this vulnerability to Invensys on 12-16-13 along with three other vulnerabilities in the same system. Those reported vulnerabilities were:

• PT-2013-40: Resource Exhaustion;
• PT-2013-38: Multiple SQL Injection vulnerabilities; and
• PT-2013-37: Multiple Cross Site Scripting (XSS).


Positive Technologies reported that Invensys publicly reported all four vulnerabilities on October 6th. It is not clear why ICS-CERT did not include these other, more serious, vulnerabilities in this advisory especially since Positive Technologies reports that the same Invensys update fixed all four vulnerabilities. The Wonderware notifications are only available to registered system owners so I cannot verify the Positive Technologies claims.

Tuesday, August 6, 2013

ICS-CERT Publishes Schneider Electric Advisory

Yesterday the DHS ICS-CERT published an advisory for an XML external entity vulnerability in three Schneider Electric products. The vulnerability was reported to Schneider by Timur Yunusov, Alexey Osipov, and Ilya Karpov of Positive Technologies.

ICS-CERT reports that a moderately skilled attacker with local access to affected systems could exploit this vulnerability to gain access to information on the system. Schneider reports that the vulnerability could also lead to a denial of service attack.

Schneider has produced a series of patches for this vulnerability for the affected systems. There is no indication in the Advisory that there has been any outside verification of the efficacy of the patches. Interestingly, the Schneider disclosure document reminds users that if they must re-install or repair the affected products that the “should first uninstall the fix, re-install\repair the affected product(s) and then reinstall the fix”. Hopefully customers will be able to ensure that this information remains prominently available over the lifetime of the product.


NOTE: Schneider publicly released their vulnerability disclosure on July 28th after making it available on their secure portal on May 9th.  The ICS-CERT Advisory does not provide links to either the disclosure document or the vulnerability report.

Tuesday, May 7, 2013

ICS-CERT Issues Wonderware Advisory


Earlier today the DHS ICS-CERT published an advisory covering multiple vulnerabilities in Invensys Wonderware Information Server products. The coordinated disclosure was made by Timur Yunusov, Alexey Osipov, and Ilya Karpov of the Positive Technologies Research Team. The multiple vulnerabilities included:

• Cross-site scripting, CVE-2013-0688;
• SQL injection, CVE-2013-0684;
• Inproper input validation, CVE-2013-0686; and
• Resource exhaustion, CVE-2013-0685.

NOTE: These CVE links will not be functional for a couple of days.


ICS-CERT reports that a moderately skilled attacker could remotely exploit these vulnerabilities to execute remote code, disclose information, or perform session credential high jacking. The advisory notes that Invensys has developed a software update (registration required) that has been verified by PTR to mitigate the identified vulnerabilities.

These are old school vulnerabilities that should have been identified a long time back. I think the reason they are just turning up now is that they are in an ICS server. It looks like researchers are expanding the areas in which they are searching for ICS vulnerabilities. How many other types of ICS equipment will have similar vulnerabilities that would allow access to the control system?

BTW: A couple of posts back I noted that ICS-CERT had changed their format for these advisories and that one of the changes was the removal of the Traffic Light Protocol (TLP) markings. I just noticed that this advisory still includes a description of the TLP white marking that shows up near the top of page 3 on the .PDF saved version of the advisory. This is the first time this FAQ has shown up on an advisory since the format change.
 
/* Use this with templates/template-twocol.html */