Showing posts with label Ariele Caltabiano. Show all posts
Showing posts with label Ariele Caltabiano. Show all posts

Wednesday, September 12, 2018

ICS-CERT Publishes 5 Advisories and 4 Updates


Yesterday the DHS ICS-CERT published five control system security advisories for products from Siemens (3) and Fuji electric (2). They also updated three previously published advisories for products from Siemens and the Meltdown/Spectre alert.

SCALANCE Advisory


This advisory describes an improper input validation vulnerability in the Siemens SCALANCE X Switches. The vulnerability is being self-reported. Siemens has updates available for two of the three affected products and has identified mitigation measures.

ICS-CERT reports that a relatively low-skilled attacker could use publicly available exploits to remotely exploit the vulnerability to cause a denial-of-service condition.

SIMATIC Advisory


This advisory describes an improper access control vulnerability in the Siemens SIMATIC WinCC OA HMI. The vulnerability is being self-reported. Siemens has an update available to mitigate the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to escalate their privileges in the context of the program.

TD Keypad Designer Advisory


This advisory describes an unprotected search path element vulnerability in the Siemens TD Keypad Designer. The vulnerability is being self-reported. Siemens has identified generic mitigation measures for the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker with local access could exploit the vulnerability  to escalate their privileges.

V-Server Lite Advisory


This advisory describes a classic buffer overflow vulnerability in the Fuji V-Server Lite. The vulnerability was reported by Ariele Caltabiano (kimiya) via the Zero Day Initiative (ZDI). Fuji has a firmware update available to mitigate the vulnerability. There is no indication that Caltabiano has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to view sensitive information and disrupt the availability of the device.

V-Server Advisory


This advisory describes seven vulnerabilities in the Fuji V-Server. The vulnerabilities were reported by Steven Seeley (mr_me) of Source Incite via ZDI. Fuji has a new software version that mitigates the vulnerabilities. There is no indication that Seeley has been provided an opportunity to verify the efficacy of the fix.

The seven reported vulnerabilities are:

• Use after free - CVE-2018-14809;
• Untrusted pointer dereference - CVE-2018-14811;
• Heap-based buffer overflow - CVE-2018-14813;
• Out-of-bounds write - CVE-2018-14815;
• Integer underflow- CVE-2018-14817;
• Out-of-bounds read - CVE-2018-14819; and
Stack-based buffer overflow - CVE-2018-14823

ICS-CERT reports that a relatively low-skilled attacker could use publicly available exploits to remotely exploit the vulnerabilities to allow for remote code execution on the device, causing a denial of service condition or information exposure.

Industrial Products Update


This update provides new information on an advisory that originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th, November 28th, February 27th, 2018, May 3rd, 2018 and most recently on May 15th, 2018. The new information includes revised affected versions data and mitigation measures for:

• SINAMICS DCP w. PN; and
• SINAMICS DCM w. PN

SIMATIC Update


This update provides new information on an advisory that was originally published on May 17th, 2018. The new information includes additional mitigation measures that can be used.

OpenSSL Update


This update provides new information on an advisory that was originally published on August 14th, 2018. The new information includes revised affected versions data and mitigation measures for WinCC OA.

Meltdown/Spectre Update


This update provides new information on an alert that was originally published on January 11th, 2018 and updated on January 16th, 2018, January 17th, 2018, January 30th, 2018, February 20th, 2018, February 22nd, 2018, March 1st, 2018, and most recently on July 10th, 2018. The new information includes a link to a new Meltdown/Spectre advisory from Siemens.

Note: While this newly added advisory from Siemens and another Siemens advisory on the older versions of Meltdown/Spectre address newer versions of the vulnerability, ICS-CERT has failed to provide any information (or links to information) about these new problems.

Thursday, May 10, 2018

ICS-CERT Publishes 3 Advisories and 1 Siemens Update


Today the DHS ICS-CERT published three control system security advisories for products from Rockwell Automation (2) and MatrikonOPC. The also updated a Siemens advisory; this is the update that I mentioned in passing last Thursday [changed link and day; 05-11-18, 0624 EDT]. The Factory Talk advisory was originally released to the HSIN ICS-CERT library on April 12, 2018.

Factory Talk Advisory


This advisory describes two vulnerabilities in the Rockwell Factory Talk Activation Manager. I described these vulnerabilities in a blog post on April 14th. At that time I was not aware that ICS-CERT had published a restricted release advisory for the publicly available Rockwell notification (registration required). The ICS-CERT advisory does not mention the publicly available exploits for these vulnerabilities.

Arena Advisory


This advisory describes a use after free vulnerability in the Rockwell Arena simulation software for manufacturing. The vulnerability was reported by Ariele Caltabiano via the Zero Day Initiative. Rockwell has a newer version that mitigates the vulnerability. There is no indication that Caltabiano has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that an uncharacterized attacker with uncharacterized access could exploit this vulnerability to cause the software application to crash. The Rockwell notice explains that a social engineering attack would be required to get an authorized user to open a maliciously crafted Arena file to exploit this vulnerability.

MatrikonOPC Advisory


This advisory describes a files or directories accessible to external parties vulnerability in the MatrikonOPC Explorer. The vulnerability was reported by Ilya Kapov of Positive Technologies. MatrikonOPC has a patch available to mitigate the vulnerability. There is no indication that Kapov has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker with local access could exploit this vulnerability to transfer unauthorized files from the host system. The MatrikonOPC security notification reports that the vulnerability exists in the Microsoft MSXML libraries that have ‘known vulnerabilities’ but does not provide the version number being used. This raises the inevitable questions about whether or not all of the appropriate Microsoft patches have been applied. Again, this is an inevitable problem with the use of third party libraries.

Siemens Update


This update provides information on an advisory that was originally published on November 28th, 2017 and updated on April 5th, 2018. This update provides mitigation measures for  SCALANCE M-800 and S615.

Tuesday, July 11, 2017

ICS-CERT Publishes 6 Advisories and 2 Updates

Today the DHS ICS-CERT published six control system advisories for products from Schweitzer Engineering Laboratories, OSIsoft (2), ABB, Fuji Electric, and Siemens. They also published updates for two other control system advisories for products from OSIsoft and Siemens.

SEL Advisory


This advisory describes an improper access control vulnerability in the SEL SEL-3620 and SEL-3622 Ethernet Security Gateways. The vulnerability was reported by Jason Holcomb with Revolutionary Security. SEL has developed a firmware update. ICS-CERT reports that Holcomb has verified the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to effect unauthorized communications through the SEL-3620 and SEL-3622 to configured NAT port forwarding destinations.

PI ProcessBook Advisory


This advisory describes (unspecified) third party software {Microsoft Visual Basic for Applications (VBA) v6.5} vulnerabilities in ealier versions of OSIsoft PI ProcessBook and PI ActiveView. There is no specific listing of the individual vulnerabilities involved. These vulnerabilities were self-reported by OSIsoft. Newer versions of the OSIsoft products contain newer versions of the VBA, but do not remove the dll files in which the vulnerabilities reside when upgraded, these must be removed manually.

OSIsoft reports that the affected VBA version would still be required if the workstation was also running MS Office 2003 or MS Office 2007.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerabilities to access arbitrary code.

PI Coresight Advisory


This advisory describes a cross-site request forgery vulnerability in the OSIsoft PI Coresight product. The vulnerability is self-reported. OSIsoft has produced a new version that mitigates the vulnerability.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to access the PI System resulting in unauthorized viewing or alteration of PI System data.

ABB Advisory


This advisory describes two vulnerabilities in the ABB VSN300 WiFi Logger Card. The vulnerability was reported by Maxim Rupp. Newer versions are not affected by the vulnerabilities. There is no indication that Rupp was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to allow attackers to gain unauthorized access to privileged information.

Fuji Electric Advisory


This advisory describes an improper restrictions of operations within the bounds of a memory buffer vulnerability in the Fuji V-Server. The vulnerability was reported by Ariele Caltabiano via the Zero Day Initiative. Fuji has produced a patch to mitigate the vulnerability. There is no indication that Caltabiano has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that an uncharacterized attacker could remotely exploit the vulnerability  to remotely execute arbitrary code.

Siemens Advisory


This advisory describes an out-of-bounds write vulnerability in the Siemens SIMATIC Logon Remote Access product. The vulnerability was reported by Tenable Security. Siemens has produced a new version to mitigate the vulnerability. There is no indication that Tenable has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to cause a denial of service of the SIMATIC Logon Remote Access service under certain conditions.

OSIsoft Update


This update provides new information on the advisory that was originally published on January 10th, 2017. It reports that the new version of PI ProcessBook described above also mitigates this vulnerability. There is no indication that the researcher (Vint Maggs) has been provided an opportunity to verify the efficacy of the fix.

Siemens Update



This update provides new information on the advisory that was originally published on June 29th, 2017. Firmware updates are now available for all affected products. The updated Siemens security advisory reports that SINUMERIK products have been removed from the affected products list available on the Siemens website.

Tuesday, November 1, 2016

ICS-CERT Publishes 3 Advisories and Malware Trends Paper

Today the DHS ICS-CERT published three new control system security advisories and an in-house paper on malware trends. The three new advisories are for control system products from Schneider and IBHsoftec. One of the Schneider advisories addresses a vulnerability I discussed on Saturday. Neither of the Schneider advisories listed here are the ones referenced in a TWEET® from Critifence that I retweeted this morning.

Schneider Unity Pro Advisory


This advisory describes an insufficient control flow management vulnerability in the Schneider Electric Unity PRO Software product. The vulnerability was reported by Avihay Kain and Mille Gandelsman of Indegy. Schneider produced a new version of the software that mitigates the vulnerability. There is no indication that the Indegy researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that while this vulnerability could be exploited remotely, since a two-stage social engineering attack would be required to exploit the vulnerability, developing a working exploit would be difficult. The Schneider Security Notification implies that direct loading of the corrupted file by the attacker could be possible “when the application program loaded in the simulator is not password protected”.

IHBsoftec Advisory


This advisory describes a buffer overflow vulnerability in the IBHsoftec S7-SoftPLC. The vulnerability was reported by Ariele Caltabiano (kimiya) through ZDI. IHBsoftec has produced a new version to mitigate the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that relatively unskilled attacker could remotely exploit the vulnerability to “be able to affect integrity, confidentiality, and availability of the target device”.

Schneider ConneXium Advisory


This advisory describes a buffer overflow vulnerability in the Schneider Electric ConneXium firewall product. The vulnerability was reported by Nir Giller. According to ICS-CERT,Schneider is developing a firmware update, but the Schneider Security Notification (not listed in the ICS-CERT advisory) indicates that an update is currently available through “your local Schneider Electric representative”.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to execute code during the SNMP (Simple Network Management Protocol) login authentication process.

The Schneider document also provides workaround information for the vulnerability.

Malware Trends


This white paper was produced by the ICS-CERT Advanced Analytic Laboratory (AAL). It is a 24-page review of the current state of malware. Once again ICS-CERT has produced a nice review document suitable for updating non-technical management on cybersecurity issues. It covers the following topics:

• Attacker tactic changes;
• Malware evolution;
• Persistence methods;
• Infection vectors;
• Defensive tactics; and
• Platform challenges

Unfortunately, like most recent ICS-CERT technical documents, it is very light on data specific to the control system (ICS) security community. It is not until page 17 where we see the first specific ICS discussion in a subsection of the platform challenges discussion. Even that discussion is very brief and very light on the details. For example, half of the discussion about Black Energy consists of the following paragraph:

“BlackEnergy is an interesting case of malware that has undergone a dramatic change in its design and target depending on the groups that use it. Initially, BlackEnergy was a DDoS bot primarily used by the Russian hacker underground to take down sites. Support for plugins was added in the next major revision (BlackEnergy2), changing the exclusively DDoS box into a powerful multi-tool. Years later, researchers discovered that threat actors utilized zero-day exploits and spear phishing, combined with BlackEnergy 2 and specially-tailored plugins, to target and compromise ICS networks.”


This is a good overview document that I would have been proud to have authored. The technical skills and experience of the AAL deserve a much better showcase.

Tuesday, December 1, 2015

ICS-CERT Publishes Three Advisories

This afternoon the DHS ICS-CERT published three advisories for industrial control system vulnerabilities in systems from Siemens, Schneider and Saia Burgess Controls. ICS-CERT also announced an alternative method for notification of the release of advisories, alerts, and other publications.

Siemens Advisory

This advisory describes an authentication bypass vulnerability in a number of Siemens SIMATIC Communications Processor devices. The vulnerability was reported by Lei ChengLin (Z-0ne) from the Fengtai Technologies’ Security Research Team. Siemens has produced a firmware update for one of the devices (SIMATIC CP 343-1) and the other updates are in the works. There is no indication that Lei has been provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to perform administrative operations on the Communication Processor. Network access to Port 102/TCP is required and the Communication Processor’s configuration must be stored on its corresponding CPUs for the vulnerability to be exploited. Siemens notes that firewall functionality of Advanced-CPs must be turned off for port 102/TCP for the vulnerability to be exploited.

NOTE: This vulnerability was announced by Siemens on TWITTER last Friday.
                                       
Schneider Advisory

This advisory describes eleven ActiveX code injection vulnerabilities (listed under a single CVE) in the Schneider ProClima F1 Bookview ActiveX control application. The vulnerabilities were reported through the Zero Day Initiative by Ariele Caltabiano and Fritz Sands ( Sands was mentioned in the Schneider advisory but not the ICS-CERT Advisory). Schneider has produced an update to mitigate these vulnerabilities but there is no indication that Caltabiano was provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to modify arbitrary memory and lead to remote code execution.

Schneider reports that the vulnerabilities reside in the thermal calculation software.

Saia Burgess Controls Advisory

This advisory describes a hard-coded password vulnerability in the Saia Burgess Controls family of PCD controllers. The vulnerability was reported by Artyom Kurbatov. Saia has produced a new firmware version that mitigates the vulnerability and Kurbatov has validated the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to gain administrative access to the target device and resources.

Saia cautions that the upgraded firmware will still not protect the PCD controllers if they are connected directly to the Internet. Their Security Rules document provides recommended details for protecting the security of these controllers.

GovDelivery

You can now get ICS-CERT publications sent directly to your email via GovDelivery. Simply register for the service, click on which publications you want and wait for the emails. Publications from National Cyber Awareness System Mailing Lists and the Critical Infrastructure Cyber Community Voluntary Program (C3VP) are also available from this system.


DHS has tried these email notification systems for a number of their web sites. I’ve signed up for a bunch of them and the notifications seem to dry up after a while. Maybe this one will be different. Go ahead, give it a try; I did. We all take perverse pride in our inflated inboxes.

Tuesday, April 7, 2015

ICS-CERT Publishes Surveillance Software Advisory

This morning the DHS ICS-CERT published an advisory for the  Moxa VPort ActiveX SDK Plus IP video surveillance application. The advisory is for a stack-based buffer overflow vulnerability reported by Ariele Caltabiano. Moxa has produced a new version that corrects the vulnerability but there is no indication that Caltabiano has been given the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to execute arbitrary code on the system. Moxa reports that the new version was available almost a month ago.


On an unrelated side note, Moxa reports that it continues to support this product on systems running Windows XP and Windows Vista. That would seem to indicate that they expect a significant number of their customers to still be using these outdated and unsupported systems for video surveillance purposes. This vulnerability may be the least of their security problems.
 
/* Use this with templates/template-twocol.html */