Showing posts with label Anil Parmar. Show all posts
Showing posts with label Anil Parmar. Show all posts

Wednesday, March 4, 2020

1 Alert and 4 Advisories Published – 3-3-20

Yesterday the CISA NCCIC-ICS published a control system security alert for products from SweynTooth and four security advisories for products form Moxa, Omron, Phoenix Contact, and Emerson.

SweynTooth Alert


This alert describes multiple Bluetooth Low Energy (BLE) vulnerabilities known as the SweynTooth vulnerabilities. The vulnerabilities were reported by Matheus E. Garbelini, Sudipta Chattopadhyay, and Chundong Wang of the Singapore University of Technology and Design. NCCIC-ICS is coordinating with chip vendors on a resolution of these vulnerabilities.

Last month I briefly reported on an advisory issued by Philips for these vulnerabilities.

Moxa Advisory


This advisory describes twelve vulnerabilities in the Moxa Moxa AWK-3131A wireless networking appliance. The vulnerabilities were reported by Jared Rittle, Carl Hurd, Patrick DeSantis, and Alexander Perez Palma of Cisco Talos. Moxa has a patch that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker using publicly available code could remotely exploit the vulnerabilities to allow an attacker to gain control of the device and remotely execute arbitrary code.

NOTE: Last Saturday I reported briefly on these vulnerabilities and provided links to the individual Talos reports that provide the proof-of-concept exploit code for these vulnerabilities.

Omron Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the Omron PLC CJ Series. The vulnerability was reported by Jipeng You (XDU). Omron provided generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial-of-service condition.

Phoenix Contact Advisory


This advisory describes an incorrect permission assignment for critical resource vulnerability in the Phoenix Contact Emalytics Controller ILC 2050 BI(L). The Phoenix Contact advisory notes that the vulnerability was reported by Anil Parmar. Phoenix Contact has a new version that mitigates the vulnerability. There is no indication that Parmar has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to change the device configuration and start or stop services.

NOTE: I briefly reported on this vulnerability last month.

Emerson Advisory


This advisory describes an improper access control vulnerability in the Emerson ValveLink. The vulnerability is self-reported. Emerson has a new version that mitigates the vulnerability.


NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow arbitrary code execution.

Saturday, February 22, 2020

Public ICS Disclosure – Week of 2-15-20


This week we have four vendor disclosures for products from Phoenix Contact, Philips, BD and Belden. We also have one researcher report on products from Siemens.

Phoenix Contact Advisory


Phoenix Contact published an advisory [.PDF download link] describing an unauthenticated web server access vulnerability in their Emalytics Controllers ILC 2050 BI. The vulnerability was reported by Anil Parmar. Phoenix Contact has a new version that mitigates the vulnerability. There is no indication that Parmar has been provided an opportunity to verify the efficacy of the fix.

Philips Advisory


Philips published an advisory on the SweynTooth Bluetooth vulnerabilities. Philips is looking to see if any of their products are affected.

NOTE: The 12 disclosed vulnerabilities affect the Bluetooth Low Energy chipsets sold by major SoC vendors, such as Texas Instruments, NXP, Cypress, Dialog Semiconductors, Microchip,
STMicroelectronics and Telink Semiconductor.

BD Advisory


BD published an advisory describing Windows® 32K graphics vulnerabilities (CVE-2019-1458 and CVE-2019-1468) in their products using Windows operating systems. BD is currently working to test and validate the Microsoft patch for BD products. Microsoft included fixes for these vulnerabilities in their December 10th, 2019 updates.

Belden Advisory


Belden published an advisory describing a buffer overflow vulnerability in their Hirschmann HiOS and HiSecOS devices. The vulnerability was reported by Sebastian Krause and Toralf Gimpel of GAI NetConsult. Belden has updates available that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Siemens Report


Tenable published a report describing a denial of service vulnerability in the Siemens TIA Portal. Siemens published their advisory on this vulnerability earlier this month. The Tenable report includes proof of concept code.

Saturday, February 15, 2020

Public ICS Disclosure – Week of 2-7-20


This week we have eight vendor disclosures for products from Siemens (2), Schneider Electric, Phoenix Contact, HMS, ABB (2) and Moxa. We also have three advisory updates from Siemens and one from Schneider.

Siemens Advisories


Siemens published an advisory describing three vulnerabilities found in Intel chips used in Siemens products. The vulnerabilities were identified and reported (advisory links below) by Intel. Siemens has provided generic workarounds to mitigate the vulnerabilities.

The three reported vulnerabilities are:

• Insufficient memory protection (2) - CVE-2019-0151 and CVE-2019-0152; and
• Heap-based buffer overflow - CVE-2019-0169

Siemens published an advisory describing a resource allocation vulnerability in their Profinet-IO stack. The vulnerability was reported by Yuval Ardon and Matan Dobrushin from OTORIO. Siemens has updates that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Schneider Advisory


Schneider Published an advisory describing an uncontrolled search path element vulnerability in their ProSoft Configurator. The vulnerability was reported by Yongjun Liu from nsfocus. Schneider has a new version that mitigates the vulnerability. There is no indication that Yongiun has been provided an opportunity to verify the efficacy of the fix.

Phoenix Contact Advisory


Phoenix Contact has published an advisory [.PDF download link] describing a remote configuration vulnerability in their Emalytics Controllers. The vulnerability was reported by Anil Parmar. Phoenix Contact has a new firmware version that mitigates the vulnerability. There is no indication that Parmar has been provided an opportunity to verify the efficacy of the fix.

HMS Advisory


HMS has published an advisory describing a cross-site scripting vulnerability in their Flexy and Cosy products. The vulnerability was reported by Ander Martínez from Titanium Industrial Security. HMS has a new firmware version that mitigates the vulnerability. There is no indication that Martinez has been provided an opportunity to verify the efficacy of the fix.

ABB Advisories


ABB published an advisory describing a direct object reference vulnerability in their Asset Suite product. The vulnerability is self-reported. ABB has a new version that mitigates the vulnerability.

ABB published an advisory describing 14 vulnerabilities in their eSOMS product. The vulnerabilities are self-reported. ABB has a new version that mitigates the vulnerabilities.

Moxa Advisory


Moxa published an advisory describing 8 vulnerabilities in their OnCell cellular gateway. The vulnerabilities were reported by Alexander Zaytsev from Kaspersky Lab. Moxa has new firmware versions that mitigate the vulnerabilities. There is no indication that Zaytsey has been provided an opportunity to verify the efficacy of the fix.

Siemens Updates


Siemens published an update to their  Linux TCP SACK PANIC advisory for Industrial Products that was originally published on September 10th, 2019 and most recently updated on November 14th, 2019. The new information includes revised version data and mitigation links for:

• TIM 1531 IRC;
• SIMATIC CP 1242-7, CP 1243-7 LTE (EU andUS versions), CP 1243-1, CP 1243-8 IRC, CP 1543-1, CP 1542SP-1, CP 1542SP1 IRC, CP 1543SP-1; and
• SCALANCE W1700.

NOTE: NCCIC-ICS updated their advisory on February 11th, but did not list it on their web site.

Siemens published an update for their ZombieLoad advisory that was originally published on July 9th, 2019 and most recently updated on December 10th, 2019. The new information includes updated version data and mitigation links for:

• SIMATIC IPC547E;
• SIMATIC IPC347E; and
• SIMATIC IPC3000 SMART V2
Siemens published an update for their GNU/Linux subsystem vulnerabilities advisory that was originally published on November 27th, 2018 and most recently updated on January 14th, 2020. The new information includes adding the following new vulnerabilities;

• CVE-2019-5188;
• CVE-2019-11190;
• CVE-2019-19956;
• CVE-2019-20054,
• CVE-2019-20079;
• CVE-2019-20388; and
• CVE-2020-7595

Schneider Update


Schneider published an update for their U.motion Builder advisory that was originally published on April 5th, 2018. The new information includes an updated remediation section.

 
/* Use this with templates/template-twocol.html */