Showing posts with label Ashish Kamble. Show all posts
Showing posts with label Ashish Kamble. Show all posts

Tuesday, July 12, 2016

ICS-CERT Publishes Two Advisories

Today the DHS ICS-CERT published two control system security advisories for products from GE and Tollgrade.

GE Proficy Advisory


This advisory describes an improper privilege management vulnerability in earlier versions of the GE Proficy HMI/SCADA CIMPLICITY application. The vulnerability was reported by Zhou Yu of Acorn Network Security. GE notes that subsequent versions of the application do not contain the vulnerability, having been corrected by August 2014.

ICS-CERT reports that local access is required or that a remote exploit would require a social engineering attack. Exploit code is publicly available (link not provided in ICS-CERT Advisory).

The GE Product Security Advisory for this vulnerability recommends upgrading to a newer version of the application, but it also provides commands that serve to mitigate the vulnerability in the affected versions.

Tollgrade Advisory


This advisory describes three vulnerabilities in the Tollgrade Communications, Inc. Smart Grid LightHouse Sensor Management System (SMS) Software EMS. The vulnerabilities were reported by Ashish Kamble of Qualys, Inc. Tollgrade has produced a new version that mitigates the vulnerabilities. ICS-CERT reports that Kamble has tested the new version to verify the efficacy of the fix.

The vulnerabilities are:

• Missing authentication for critical application - CVE-2016-5790;
• Information exposure through an error message - CVE-2016-5797; and
• Forced browsing - CVE-2016-5807

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerabilities to restart the system, brute force a login, or change privileged parameters.

Tuesday, June 16, 2015

ICS-CERT Publishes GarrettCom Advisory

This afternoon the DHS ICS-CERT published an advisory for GarrettCom Ethernet switches. The advisory describes multiple vulnerabilities in GarrettCom’s Magnum 6k and Magnum 10k product lines. The vulnerabilities were reported by Ashish Kamble of Qualys Security and Eireann Leverett. GarrettCom has produced new firmware versions to correct these vulnerabilities and ICS-CERT reports that Kamble has validated the efficacy of the fixes.

The reported vulnerabilities are:

Use of hard-coded credentials, CVE-2015-3960 and CVE-2015-3959; and
External control of assumed-immutable web parameter, CVE-2015-3961

It looks like there is a typo in the advisory where ICS-CERT usually reports the difficulty of exploiting the vulnerabilities; they repeat the previous comment about no known public exploits. Based upon past reports, however, I would suspect that a relatively low skilled attacker could remotely exploit the vulnerability.

Interestingly the Belden GarrettCom release note calls one of the hard-coded credential vulnerabilities an ‘SSL key exposure’ vulnerability. They explain that it is “possible for certain security keys of the Belden Garrettcom 10K and 6K products to be deciphered potentially posing a man-in-the-middle security threat when using HTTPS to communicate with the device”. The also maintain that the remaining hard-coded credential vulnerability only applies to a privileged account that “is actually not enabled in the operating switch”.


ICS-CERT notes that these two new firmware releases were made available in December of last year and January of this year. It is possible that some of these devices have already been fixed. The earlier release contained a number of other, non-security bug fixes. It is interesting that it has taken so long for this advisory to be published by ICS-CERT. I would assume that it was due to communications issues.
 
/* Use this with templates/template-twocol.html */