Showing posts with label Ariele Caltabiano (kimiya). Show all posts
Showing posts with label Ariele Caltabiano (kimiya). Show all posts

Thursday, November 29, 2018

One Advisory Published – 11-29-18


Today the DHS NCCIC-ICS published a control system security advisory for products from INVT Electric.

The advisory describes two vulnerabilities in the INVT VT-Designer. The vulnerabilities were reported by Ariele Caltabiano (kimiya) via the Zero Day Initiative. No mitigation measures are currently available for these vulnerabilities.

The two reported vulnerabilities are:

• Deserialization of untrusted data - CVE-2018-18987; and
Heap-based buffer overflow - CVE-2018-18983

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities cause the program to crash and may allow remote code execution.

NOTE: It looks like another Chinese ICS company is not quite responsive to NCCIC-ICS vulnerability coordination efforts.

Thursday, October 18, 2018

Omron Advisory Published


Yesterday the DHS NCCIC-ICS published a control system security advisory for products from Omron. The advisory describes four vulnerabilities in the Omron CX-Supervisor. The vulnerabilities were reported by Mat Powell, Ariele Caltabiano (kimiya) of 9SG Security Team, and b0nd @garage4hackers via the Zero Day Initiative. Omron has a new version that mitigates the vulnerabilities. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Improper restriction of operations within the bounds of a memory buffer - CVE-2018-17905;
• Out-of-bounds read - CVE-2018-17907;
• Use after free - CVE-2018-17909; and
Incorrect type version or cast - CVE-2018-17913

NCCIC-ICS reports that an uncharacterized hacker with uncharacterized access could exploit these vulnerabilities to execute code under the context of the application, corrupt objects, and force the application to read a value outside of an array.

Friday, October 12, 2018

3 Advisories and 4 Updates


Yesterday the DHS NCCIC-ICS published three control system security advisories for products from Delta Industrial Automation and NUUO (2). They also updated a previously published control system security advisory for products from Yokogawa medical device security advisories for products from Medtronic, BD and Phillips.

Delta Advisory


This advisory describes two vulnerabilities in the Delta Industrial Automation TPEditor. The vulnerabilities were reported by Ariele Caltabiano (kimiya) of 9SG Security Team and Mat Powel. Delta has a new version that mitigates the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-17929; and
Out-of-bounds write - CVE-2018-17927

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to crash the accessed device, resulting in a buffer overflow condition that may allow remote code execution.

CMS Advisory


This advisory describes four vulnerabilities in the NUUO CMS software management platform. The vulnerabilities were reported by Pedro Ribeiro. NUUO has a firmware update that mitigates the vulnerabilities. There is no indication that Ribeiro has been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Use of insufficiently random values - CVE-2018-17888;
• Use of obsolete function - CVE-2018-17890;
• Incorrect permission assignment for critical resource - CVE-2018-17892; and
• Use of hard-coded credentials - CVE-2018-17894

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to result in arbitrary remote code execution.

NVRmini2 Advisory


This advisory describes two vulnerabilities in the NUUO NVRmini2, NVRsolo network video recorders. The vulnerabilities were reported by Jacob Baines of Tenable. NUUO has a firmware update that mitigates the vulnerabilities. There is no indication that Baines has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-1149; and
• Leftover debug code - CVE-2018-1150

NCCIC-ICS reports that a relatively low-skilled attacker using publicly available exploit code could remotely exploit the vulnerabilities to achieve remote code execution and user account modification.

Yokogawa Update


This update provides additional information on an advisory that was originally reported on May 31st, 2018. The new information includes:

• Addition of four new vulnerabilities;
• Revision of exploit consequences;
• Addition of new products affected; and
• Addition of mitigation information for newly identified products.

NOTE: All of this new information was reported in a separate Yokogawa advisory that I discussed here last month. That new advisory was not referenced in this update.

Medtronic Update


This update provides additional information on an advisory that was originally published on February 27th, 2018 and updated on June 27th, 2018. The new information includes:

• Addition of a new affected product;
• Addition of statement on possible remote access exploitation;
• Addition of a third vulnerability;
• Addition of report of new mitigation measure implemented by Medtronic

An FDA notice was published for the revised Medtronic advisory.

BD Update


This update provides additional information on an advisory that was originally published on May 22nd, 2018. The new information includes a report of implementation of the promised mitigation measures.

Phillips Update


This update provides additional information on an advisory that was originally published on August 21st, 2018 and updated on August 30th, 2018. The new information includes the announcement of future mitigation measures to be undertaken by Phillips.

Tuesday, March 6, 2018

ICS-CERT Publishes 3 Advisories and One Siemens Update


Today the DHS ICS-CERT published three new control system security advisories for products from Eaton, Schneider Electric, and Hirschmann Automation. The also updated a previously issued advisory for products from Siemens.

Eaton Advisory


This advisory describes an improper input validation vulnerability in the Eaton ELCSoft programming software. The vulnerability was reported by Ariele Caltabiano (kimiya) and axt working with the Zero Day Initiative. Eaton has produced a new version of the software (ICS-CERT mistakenly refers to ‘firmware’) to mitigate this vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to execute arbitrary code. The Eaton Security Update Advisory [.PDF Download] notes that the vulnerability only affects the Windows® based PCs that run the software, not the programmable logic controllers being programed.

Schneider Advisory


This advisory describes an uncontrolled search path element vulnerability in the Schneider SoMove software and DTM software components. The vulnerability was reported by ADLab of Venustech (NOTE: The Schneider security notification credits Haojun Hou from Adon with reporting the vulnerability). Schneider has produced new software versions that mitigate the vulnerabilities. There is no indication that the researchers have been afforded an opportunity to verify the efficacy of the fix.

ICS-CERT reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerability to execute arbitrary code.

Hirschmann Advisory


This advisory describes multiple vulnerabilities in the Hirschmann Classic Platform Switches. These vulnerabilities were reported by Ilya Karpov, Evgeniy Druzhinin, Mikhail Tsvetkov, and Damir Zainullin of Positive Technologies. Hirschmann provides workarounds to mitigate the vulnerabilities; there is no indication that additional mitigation measures are forthcoming. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Session fixition - CVE-2018-5465;
• Information exposure through query strings in get requests - CVE-2018-546;
• Cleartext transmission of sensitive information - CVE-2018-5471;
• Inadequate encryption strength - CVE-2018-5461; and
Improper restriction of excessive authentication requests - CVE-2018-5469

ICS-CERT reports that a highly-skilled attacker could remotely exploit these vulnerabilities to hijack web sessions, impersonate a legitimate user, receive sensitive information, and gain access to the device.

Siemens Update


This update provides new information on an advisory that was was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th,  November 28th, 2017, and most recently January 18th, 2018, January 25th, 2018, and most recently on January 27th, 2018. The new information is a link to mitigation measures for SCALANCE X-200IRT. ICS-CERT did not update the affected version information for this product to include the latest information in the Siemens security advisory; all versions before V5.4.0 are affected.

Friday, February 2, 2018

ICS-CERT Publishes 3 Advisories and 1 Update


Yesterday the DHS ICS-CERT published three control system security advisories for products from Gemalto, Smart Software Solutions (3S), and Fuji Electric. They also updated a previously published control system security advisory for products from NXP Semiconductor.

Gemalto Advisory


This advisory describes multiple vulnerabilities in the Gemalto Sentinel License Manager. The vulnerabilities were reported by Kaspersky Labs. The latest version of the software mitigates the vulnerability. There is no indication that Kaspersky Labs has been provided an opportunity to verify the efficacy of the fix.

The seven reported vulnerabilities are:

• Null pointer dereference - CVE-2017-11498;
• Stack-based buffer overflow (4) - CVE-2017-11497, CVE-2017-11496, CVE-2017-12818 and CVE-2017-12821;
• Heap-based buffer overflow - CVE-2017-12820; and
Improper access control - CVE-2017-12822

NOTE: This is essentially the same vulnerability that I have discussed previously (here and here). The Kaspersky article on this problem actually list 14 vulnerabilities not the seven being reported here. I mentioned earlier that there may be as many as 40,000 products (not all being ICS, obviously) being affected by this issue. If the Gemalto dongle is clearly identified as being a ‘Sentinel License Manager’, then this advisory is clearly a much more effective means of addressing the issue rather than issuing advisories on each of the affected product lines. If the using vendors, however, have relabeled their dongles, then this advisory will not be effective in those cases. But that is not ICS-CERT’s fault.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities and that could lead to remote code execution or cause a denial-of-service condition, rendering the Sentinel LDK License Manager service unavailable (and the supported product also being unavailable).

3S Advisory


This advisory describes a stack-based buffer overflow in the 3S CODESYS Web Server. The vulnerability was reported by Zhu WenZhe of Istury IOT security lab. 3S has released a security patch to mitigate this vulnerability. There is no indication that Zhu was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability causing the device to crash, resulting in a buffer overflow condition that may allow remote code execution.

Fuji Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Fuji V-Server VPR. The vulnerability was reported by Ariele Caltabiano (kimiya) via the Zero Day Intitiative. Fuji has produced a new firmware version that mitigates the vulnerability. There is no indication that Caltabiano has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability  to view sensitive information and disrupt the availability of the device.


NXP Update


This update provides new information for an advisory that was originally published on October 12th, 2017. The update provides links to the new version of the single remaining product that was not previously fixed.

Wednesday, August 16, 2017

ICS-CERT Publishes Two Advisories

Yesterday the DHS ICS-CERT published a medical device security advisory for products from BMC Medical and 3B Medical (one advisory). They also published a control system security advisory for products from Advantech

BMC Medical Advisory


This advisory describes an improper input validation vulnerability in the Luna continuous positive airway pressure (CPAP) therapy machine produced jointly by BMC Medical and 3B Medical. The vulnerability was reported by MedSec. Newer versions (after July 2017) have had the problem corrected; ICS-CERT reports that the company’s do not plan on providing mitigation measures for ‘older’ (before July 2017) machines.

ICS-CERT reports that a relatively low skilled attacker with adjacent network access could exploit the vulnerability to cause a crash of the device’s Wi-Fi module resulting in a denial-of-service condition affecting the Wi-Fi module chipset. This does not affect the device’s ability to deliver therapy.

NOTE: Buyers of CPAP devices should take careful note of the lack of post-production cybersecurity support demonstrated for this brand of devices.

Advantech Advisory


This advisory describes a heap-based buffer overflow vulnerability in the Advantech WebOP operator panels. The vulnerability was reported by Ariele Caltabiano (kimiya) via the Zero Day Initiative. ICS-CERT reports that Advantech was unable to verify the validity of this vulnerability. (NOTE: this obviously means that no mitigation measures appear to be forthcoming.)

ICS-CERT reports that a relatively low skilled attacker with uncharacterized access could use publicly available exploits to exploit this vulnerability to cause the target device to crash and may allow arbitrary code execution.


NOTE: There are a large number of ‘pending’ vulnerability reports on Advantech products currently listed on the ZDI web site.

Saturday, August 5, 2017

ICS-CERT Publishes Eaton Alert

Yesterday the DHS ICS-CERT published a control system security alert for products from Eaton. The alert describes two buffer overflow vulnerabilities in the Eaton ELCSoft, a PLC programming software for Eaton Logic Control (ELC) controllers. The vulnerabilities were reported by Ariele Caltabiano (kimiya) via the Zero Day Initiative. ZDI has published advisories on these vulnerabilities (here and here) due to the lack of mitigation response from Eaton.

Thursday, February 23, 2017

ICS-CERT Publishes Three Advisories

Today the DHS ICS-CERT published three control system security advisories for products from Schneider Electric, Red Lion Controls and VIPA Controls.

Schneider Advisory


This advisory describes a resource exhaustion vulnerability in the Schneider Electric Modicon M340 PLC. The vulnerability was reported by Luis Francisco Martin Liras. Schneider has released a new firmware version that mitigates the vulnerability. There is no indication that Liras has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to render the device unresponsive requiring a physical reset of the PLC.

Red Lion Controls Advisory


This advisory describes a hard-coded cryptographic key vulnerability in the Red Lion Controls Sixnet-Managed Industrial Switches and the AutomationDirect STRIDE-Managed Ethernet Switch models. The vulnerability was reported by Mark Cross of RIoT Solutions. New firmware versions have been made available for both sets of devices. There is no indication that Cross has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to effect the loss of data confidentiality, integrity, and availability.

VIPA Controls Advisory


This advisory describes a stack-based buffer overflow vulnerability in the VIPA Controls WinPLC7. The vulnerability was reported by Ariele Caltabiano (kimiya) through ZDI. VIPA Controls has developed a patch to mitigate the vulnerability. There is no indication that kimiya has been provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to crash the device; a buffer overflow condition may allow remote code execution.


NOTE: Yesterday Siemens announced on TWITTER® the publication of two security notification updates (here and here) and the publication of a new security notification (here). I had almost expected ICS-CERT to publish their updates and advisory today; maybe tomorrow.

Friday, September 16, 2016

ICS-CERT Publishes 4 Advisories

Yesterday the DHS ICS-CERT published four new control system security advisories for products from Rockwell, Trane, ABB and Yokogawa. The Rockwell advisory had previously been published on the US CERT Secure Portal back on August 11th.

Rockwell Advisory  


This advisory describes a parser buffer overflow vulnerability in the Rockwell RSLogix 500 and RSLogix Micro products. The vulnerability was reported by Ariele Caltabiano (kimiya) via the Zero Day Initiative (ZDI). Rockwell has produced an update that mitigates the vulnerability but there is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that it would be relatively easy to create an exploit that would allow malicious code to execute on the target computer at the same privilege level as the logged-in user. They also report that a social engineering attack would be required to cause an operator to load and execute the malformed RSS file.

Trane Advisory  


This advisory describes an information exposure vulnerability in the Trane Tracer SC field panel. The vulnerability was reported by Maxim Rupp. Trane has produced an update to mitigate this vulnerability and ICS-CERT reports that Maxim Rupp has verified the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to obtain sensitive information from the contents of configuration files not protected by the web server.

ABB Advisory  


This advisory describes a credential management vulnerability in the ABB DataManagerPro application. The vulnerability was reported by Andrea Micalizzi via ZDI. ABB has produced a new version to mitigate the vulnerability, but there is no indication that Micalizzi has been afforded an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker with local system access could exploit the vulnerability to insert and run arbitrary code on a computer where the affected product is used. The ABB Security Advisory reports that an “attacker that manages to get malicious code to a specific directory in the file system of a computer where DataManagerPro is used, could get this code executed by an authenticated and legitimate user of DataManagerPro”.

Yokogawa Advisory


This advisory describes an authentication bypass vulnerability in the Yokogawa STARDOM controller. This vulnerability is apparently being self-reported. Yokogawa has produced a new version that mitigates the vulnerability. The Yokogawa Security Advisory reports that the STARDOM controller does not require authentication to connect to the device.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to execute commands such as stop application program, change values, and modify application.

Cybersecurity for Building Control Systems



ICS-CERT reported that the National Institute of Building Sciences will be holding a series of workshops in Arlington, VA on cybersecurity for building control systems. The ICS-CERT announcement does not provide much in the way of support details (Date, location, cost, etc) but the provided web link to the NIBS workshop site does provide all of the necessary details.
 
/* Use this with templates/template-twocol.html */