Showing posts with label Andrea Micalizzi. Show all posts
Showing posts with label Andrea Micalizzi. Show all posts

Thursday, January 4, 2018

ICS-CERT Publishes 2 Advisories and Siemens Update

Today the DHS ICS-CERT published two control system security advisories for products from Advantech and Delta Electronics. It also updated a previously published advisory for products from Siemens

Advantech Advisory


This advisory describes multiple vulnerabilities in the Advantech WebAccess products. The vulnerabilities were reported by Steven Seeley of Offensive Security, Zhou Yu and Andrea Micalizzi working with the Zero Day Initiative, and Michael Deplante. Advantech has released a new version that mitigates the vulnerabilities. There is no indication that any of the researchers were provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Untrusted pointer deference - CVE-2017-16728;
• Stack-based buffer overflow - CVE-2017-16724;
• Path traversal - CVE-2017-1672;
• SQL injection - CVE-2017-16716; and
• Improper input validation - CVE-2017-16753

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to cause the device to crash, remotely execute arbitrary code or bypass authentication.

Delta Advisory


This advisory describes multiple vulnerabilities in the Delta Industrial Automation Screen Editor. The vulnerabilities were reported by Steven Seeley of Source Incite. The affected product has been discontinued and Delta recommends upgrading to DOPSoft, Version 2. There is no indication that Seeley has verified the efficacy of the fix.

The three reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2017-16751;
• Use after free - CVE-2017-16749; and
• Out-of-bounds write - CVE-2017-16747

ICS-CERT reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to remotely execute arbitrary code.

Siemens Update


This update provides new information on an advisory that was was originally published on July 6th, 2017, and updated on July 18th, on July 28th, on October 10th, and then again on November 30th. Siemens is providing updated version information and mitigation measures for their SIPROTEC 7UT686.


NOTE: This is the update that I mentioned last Saturday.

Thursday, October 12, 2017

ICS-CERT Publishes 5 Advisories and 1 Update

Today the DHS publishes five control system security updates for products from ProMinent, WECON, Envitech, NXP Semiconductor, and Siemens. They also updated a previously published control system security advisory for products from Marel Food Processing Systems.

Siemens Advisory


This advisory describes two vulnerabilities in the Siemens BACnet Field Panels. The vulnerabilities are self-reported. Siemens has developed a new firmware version that mitigates the vulnerabilities.

The two reported vulnerabilities are:

• Authentication bypass using an alternate path or channel - CVE-2017-9946; and
• Path traversal - CVE-2017-9947

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to allow unauthenticated attackers with access to the integrated webserver to download sensitive information. The Siemens security advisory notes that the first vulnerability requires network access to exploit.

NXP Advisory


This advisory describes two vulnerabilities in the NXP MQX real time operating system (RTOS). The vulnerability was reported by Scott Gayou. ICS-CERT reports that NXP intends to issue a new version in January to mitigate the vulnerabilities. NXP provides a work around for the first vulnerability in the latest version (the second does not exist in that version) and recommends that users upgrade to that newer version pending the January update.

The two reported vulnerabilities are:

• Classic buffer overflow – CVE-2017-12718; and
• Out-of-bounds read – CVE-2017-12722

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerabilities to cause a buffer overflow condition that may, in turn, cause remote code execution or out-of-bounds read conditions, resulting in a denial of service.

Envitech Advisory


This advisory describes an improper authentication vulnerability in the Envitech EnviDAS Ultimate web application. The vulnerability was reported by Can Demirel and Deniz Çevik of Biznet Bilisim. Envitech has a new version that mitigates the vulnerability. ICS-CERT reports that the researchers have verified the efficacy of the fix.

ICS-CERT reports that relatively low skilled attacker could remotely exploit the vulnerability  to view and edit settings without authenticating and execute code remotely.

WECON Advisory


This advisory describes a stack-based buffer overflow vulnerability in the WECON LeviStudio HMI Editor. The vulnerability was reported by Andrea “rgod” Micalizzi, working with iDefense Labs. WECON has developed a new version that mitigates the vulnerability. There is no indication that Micalizzi was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to effect a denial of service and arbitrary code execution.

ProMinent Advisory


This advisory describes multiple vulnerabilities in the ProMinent MultiFLEX M10a Controller. The vulnerabilities were reported by Maxim Rupp. ICS-CERT reports that ProMinent has not mitigated the vulnerabilities.

The reported vulnerabilities are:

• Client-side enforcement of server-side security - CVE-2017-14013l;
• Insufficient session expiration - CVE-2017-14007;
• Cross-site request forgery - CVE-2017-14011;
• Information exposure - CVE-2017-14009; and
• Unverified password change - CVE-2017-14005

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerabilities  to bypass protection mechanisms, assume the identity of authenticated users, and change the device configuration.

Marel Update


This update provides additional information on an advisory originally published on April 4th, 2017 and updated on August 17th. This update provides information on the firewall update for the Pluto platform that Marel has released.


The advisory still states that “Marel has created an update for Pluto-based applications, which was scheduled for release in October, 2017. This update will restrict remote access by implementing SSH authentication”.

Friday, September 16, 2016

ICS-CERT Publishes 4 Advisories

Yesterday the DHS ICS-CERT published four new control system security advisories for products from Rockwell, Trane, ABB and Yokogawa. The Rockwell advisory had previously been published on the US CERT Secure Portal back on August 11th.

Rockwell Advisory  


This advisory describes a parser buffer overflow vulnerability in the Rockwell RSLogix 500 and RSLogix Micro products. The vulnerability was reported by Ariele Caltabiano (kimiya) via the Zero Day Initiative (ZDI). Rockwell has produced an update that mitigates the vulnerability but there is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that it would be relatively easy to create an exploit that would allow malicious code to execute on the target computer at the same privilege level as the logged-in user. They also report that a social engineering attack would be required to cause an operator to load and execute the malformed RSS file.

Trane Advisory  


This advisory describes an information exposure vulnerability in the Trane Tracer SC field panel. The vulnerability was reported by Maxim Rupp. Trane has produced an update to mitigate this vulnerability and ICS-CERT reports that Maxim Rupp has verified the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to obtain sensitive information from the contents of configuration files not protected by the web server.

ABB Advisory  


This advisory describes a credential management vulnerability in the ABB DataManagerPro application. The vulnerability was reported by Andrea Micalizzi via ZDI. ABB has produced a new version to mitigate the vulnerability, but there is no indication that Micalizzi has been afforded an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker with local system access could exploit the vulnerability to insert and run arbitrary code on a computer where the affected product is used. The ABB Security Advisory reports that an “attacker that manages to get malicious code to a specific directory in the file system of a computer where DataManagerPro is used, could get this code executed by an authenticated and legitimate user of DataManagerPro”.

Yokogawa Advisory


This advisory describes an authentication bypass vulnerability in the Yokogawa STARDOM controller. This vulnerability is apparently being self-reported. Yokogawa has produced a new version that mitigates the vulnerability. The Yokogawa Security Advisory reports that the STARDOM controller does not require authentication to connect to the device.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to execute commands such as stop application program, change values, and modify application.

Cybersecurity for Building Control Systems



ICS-CERT reported that the National Institute of Building Sciences will be holding a series of workshops in Arlington, VA on cybersecurity for building control systems. The ICS-CERT announcement does not provide much in the way of support details (Date, location, cost, etc) but the provided web link to the NIBS workshop site does provide all of the necessary details.

Tuesday, November 24, 2015

ICS-CERT Publishes Two Advisories

This afternoon the DHS ICS-CERT published two control system advisories for systems from Eaton’s Cooper and Moxa.

Eaton’s Cooper Advisory

This advisory describes an IEEE conformance issue involving improper frame padding in Eaton’s Cooper Power Systems Form 6 controls and Idea/IdeaPLUS relays equipped with Ethernet. The vulnerability was reported by David Formby and Raheem Beyah of Georgia Tech. An updated version of the systems (associated with another recent ICS-CERT Advisory) has been confirmed by the researchers to be free of the vulnerability.

ICS-CERT reports that a relatively unskilled attacker with network access to unencrypted packets would be able to read the leaked data.

This advisory was published on the US CERT Secure Portal on October 22nd, 2015. Again, the early notification is available to all critical infrastructure owners and legitimate researchers granted access by ICS-CERT. See bottom of the ICS-CERT landing page for information on how to apply for this access.

This is the second advisory for this sort of issue. Both were based upon reports by Formby and Beyah. How many more systems will they find with this vulnerability? Who knows, perhaps vendors should start looking themselves? Or not. Maybe Formby and Beyah can build a startup business on their technique for finding this vulnerability and then expand it into other areas of vulnerability research. I seem to recall another team that started out in a similar manner.

BTW: Eaton’s Cooper calls this a TCP/IP protocol stack vulnerability. It sounds a little bit more impressive, but perhaps not quite as descriptive.

Moxa Advisory

This advisory describes two vulnerabilities in the Moxa OnCell Central Manager Software. The vulnerabilities were reported through the Zero Day Initiative by Andrea Micalizzi. Moxa has produced a new version but there is no indication that Micalizzi has been provided an opportunity to verify the efficacy of the fix.

The two vulnerabilities are:

• Use of hard-coded credentials - CVE-2015-6481; and
• Authentication by-pass issues - CVE-2015-6480.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to gain full system access.


BTW: The Moxa release notes on the new version do list the authentication by-pass issue, but does not mention the hard-coded credentials

Thursday, November 19, 2015

ICS-CERT Publishes Tibbo Advisory –

This afternoon the DHS ICS-CERT published a control system advisory for the Tibbo AggreGate SCADA/HMI package. The twin unrestricted upload of file with dangerous type vulnerabilities were reported through the Zero Day Initiative by Andrea Micalizzi (rgod). Tibbo has produced a new version to mitigate the vulnerability, but there is no indication that Micalizzi has been provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that at least one of the vulnerabilities can be remotely exploited by a relatively unskilled attacker. A successful exploit if either vulnerability could allow the attacker to execute arbitrary code and commands.


There seems to be an irregularity between the version number of the updated version reported in the advisory and the updates available on the Tibbo web site. ICS-CERT reports that owners should upgrade to 5.30.06. The Tibbo web site indicates that 5.30.06 is a pre-release version of the program. I suspect that that is because Tibbo has not updated their web site to account for people needing to upgrade due to the vulnerabilities reported in this advisory. Certainly there is nothing on their web site about the problem.

Thursday, November 12, 2015

ICS-CERT Publishes Unitronics Advisory

This afternoon DHS ICS-CERT published a control systemadvisory for two vulnerabilities reported in the Unitronics VisiLogic OPLC IDE. The vulnerabilities were reported (through ZDI) by Steven Seeley of Source Incite, Fritz Sands of ZDI, and Andrea Micalizzi. Unitronics has produced an update package but there is no indication that any of the researchers were provided the opportunity to verify the efficacy of the fix.

The two vulnerabilities were:

• Unsafe ActiveX control marked safe for scripting – CVE-2015-6478; and
• Code injection – CVE-2015-7905

ICS-CERT reports that a moderately skilled attacker could remotely exploit these vulnerabilities to execute arbitrary code.

There is nothing on the Unitronics web site or in the version documentation that describes the security vulnerabilities. There is the possibility that Unitronics directly contacted their customers during the period that this vulnerability was listed on the US CERT Secure Portal (posted November 3rd, 2015).

Actually, looking at the vulnerability ID number assigned by ICS-CERT (ICSA-15-274-02) it would seem that the advisory was probably placed on the Secure Portal on October 1st when the Omron advisory (ICSA-15-274-01) was published. Either that, or something happened at the last minute to cause ICS-CERT to hold the advisory for more than a month.


BTW: If you had been following the ICS-CERT notices on the Secure Portal, you would have already known about this vulnerability. If you are a critical infrastructure owner or cybersecurity officer see the bottom of the ICS-CERT landing page for instructions on how to apply for access.

Thursday, September 11, 2014

ICS-CERT Publishes Two Advisories; Ecava and Schneider

Today the DHS ICS-CERT published to control system security advisories for systems from Ecava and Schneider. Both advisories are based upon coordinated disclosures.

Ecava Advisory

This advisory addresses multiple vulnerabilities in the IntegraXor SCADA Server. An Improper Privilege Management vulnerability was reported by Andrea Micalizzi and three other vulnerabilities were identified by Alain Homewood. Alain has verified the efficacy of the patch produced by Ecava to resolve the vulnerabilities that he identified. No information was provided on the efficacy of the fix for resolving the vulnerability identified by Andrea.

The four vulnerabilities identified in this system are:

● External control of file name or path, CVE-2014-2375;
● SQL injection, CVE-2014-2376;
● Sensitive information disclosure, CVE-2014-2377; and
● Improper privilege management, CVE-2014-2386.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities.

NOTE: This advisory was originally released to the US-CERT secure portal on August 12th. This was the advisory that I had referred to earlier. Readers that had access to the secure portal would have already known about this vulnerability.

Schneider Advisory

This advisory address a buffer overflow vulnerability (been a while since we’ve seen one of those) in the VAMPSET software reported by Aivar Liimets of Martem AS. Schneider has produced an update that according to Aivar mitigates the vulnerability.


ICS-CERT reports that direct access to the relay is required for a successful attack. Schneider provides a more detailed description of the way the vulnerability works in their report on the vulnerability. That report also describes additional mitigation measures that can be taken by the system owner/operator.
 
/* Use this with templates/template-twocol.html */