Showing posts with label Automatak. Show all posts
Showing posts with label Automatak. Show all posts

Tuesday, October 25, 2016

ICS-CERT Publishes Siemens SICAM Advisory

Today the DHS ICS-CERT published a control system security advisory describing a denial-of-service vulnerability in Siemens SICAM products. The vulnerability was reported by Adam Crain of Automatak LLC. Siemens has produced a firmware update to mitigate the vulnerability. There is no indication that Adam has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to cause a denial of service. The Siemens Security Advisory reports that the vulnerability exist in the SM-2558 and SM-2556 IEC 60870-5-104 COM Modules used in the SICAM products.


Siemens announced their advisory on TWITTER® last Friday.

Tuesday, November 19, 2013

Identical Twin ICS-CERT DNP3 Advisories Published

Today the DSH ICS-CERT published two virtually identical DNP3 advisories for twin improper input validation vulnerabilities in Catapult Software DNP3 Drivers and GE Proficy platform. The reason that they are nearly identical is because the Proficy vulnerability is due to the use of the Catapult Software drivers. Since these are familiar DNP3 vulnerabilities, it should come as no surprise that they were first reported by the team of Crain and Sistrunk. Technically, GE self-reported their vulnerability when notified of the problem by Catapult Software.

These are the same IP-based and serial-based validation vulnerabilities that we have seen before in similar Crain-Sistrunk based advisories. ICS-CERT reports that the IP-based vulnerability has a higher CVSS v2 base score (7.1 vs 4.7) but that reflects the fact that the IP-based vulnerability can be more easily exploited remotely. Many cybersecurity commentators (though certainly not all) note that physically accessing the serial connection may actually be easier at remote, low-security sites.

Catapult Software has produced updated software that mitigates both their system vulnerabilities and the Proficy vulnerabilities. The Catapult advisory does report that Crain and Sistrunk have validated the efficacy of the new software version. While that is not specifically mentioned in the GE advisory, I would assume that the same validation applies to the Proficy issues.

The Automatak web site reports these vulnerabilities as numbers 10 and 11 of the 25 vulnerable systems that they have discovered. I wonder how many of the remaining 14 are also based upon either the Catapult system or the earlier Triangle Microworks library. Both have obviously been made available (sold) to other vendors. Of course, it is also possible that Crain and Sistrunk have not yet found all of the system vulnerabilities since they have apparently stopped looking for these vulnerabilities; no challenge left I suppose.

Hopefully, any unidentified DNP3 vendors will take the leads posted by these two and self-correct and self-report their problems without being identified by Project Robus.

NOTE: A quick update from an Adam Crain Tweet® - None of the remaining vulns are catapult related. Should probably read 11/26 now, but we've kinda stopped counting.

Friday, September 13, 2013

Tools for Testing DNP3 – Aegis Platform

I got an interesting email from Adam Crain today. It was part of a continuing message chain, but he tossed off a new subject:

“FYI, I just announced the release of the DNP3 fuzzer at SANS SCADA in March 2014”

He then provided a link to a new page on his Automatak.com web site - http://www.automatak.com/aegis/.

Adam and his compatriot, Chris Sistrunk, have demonstrated a talent for finding vulnerabilities in DNP3 applications. They have made a name for themselves in the last couple of weeks from their being listed as the responsible researcher on 8 ICS-CERT advisories. I don’t know the details of their disclosure agreements with the affected vendors, but I seriously doubt that they have made much, if any, money off of these disclosures.

BTW: There are now 17 ‘pending’ disclosures on the Project Robus web site; two more than earlier this week. So, contrary to my earlier supposition, they haven’t stopped their testing efforts.

This is the problem that most ‘ethical researchers’ have run in to; there is little or no money to be made from coordinated disclosures. This is one of the reasons that so many cybersecurity researchers have turned to selling vulnerabilities on either the black or grey markets; it’s a way to pay the bills and keep food on the table. The rub, of course, is that these markets put owner/operators at risk.

Adam, it seems has come up with a slightly different marketing angle. Instead of selling vulnerabilities he is effectively going to sell tools he develops to find vulnerabilities. It is not explicitly pointed out on his web site, but his email makes clear that he is looking to vendors and utility owner/operators to be members of his “consortium of industrial control system (ICS) stakeholders” thus staying on the side of ‘ethical hackers’.

BTW: I made the comment in an earlier blog post that other ICS protocols might undergo examination by Crain-Sistrunk. A side-bar on the AEGIS page points out that there is a “Modbus master/slave” under development. I suspect that we will shortly begin seeing ICS-CERT advisories pointing out vulnerabilities in Modbus related applications. Fortunately (sarcasm warning) there aren’t too many of those out there. In fact, some of those 17 pending disclosures might be Modbus related instead of DNP3. Some people would be happy to see that.


It will be interesting to see how well Automatak does with this project. I hope that he succeeds, we need more owner/operator-friendly hacker business-models.

Thursday, August 29, 2013

ICS-CERT Publishes Another Crain-Sistrunk Advisory

Today ICS-CERT published an advisory for a buffer overflow vulnerability on the MatrikonOPC SCADA DNP3 OPC Server. Actually the document published today is a revised version of an advisory published on the US-CERT secure Portal back on August 2nd. The vulnerability was reported by Adam Crain and Chris Sistrunk in a coordinated disclosure.

The Advisory

ICS-CERT reported that the vulnerability can be remotely exploited by a moderately skilled attacker to execute a DOS attack. MatrikonOPC insists that an exploit would require “in-depth technical knowledge of the DNP3 protocol and the specific vulnerability in the MatrikonOPC software”. I guess (sarcasm alert) that Adam and Chris were just lucky to be able to find the ‘specific vulnerability’.

MatrikonOPC has developed a new version of the OPC Server for DNP3 that eliminates this vulnerability. ICS-CERT reports that Adam has verified the efficacy of the update.

The Update

As I noted earlier this publicly available version of the advisory is actually an update of the earlier, limited release version. There are two changes listed in the update; a more detailed explanation of the mechanism of the vulnerability and an additional suggested mitigation to prevent the vulnerability from being remotely accessible.

The update notes that the server only stops communication because of this vulnerability after receiving a malformed DNP3 packet from a device. In an unusual move ICS-CERT added additional language indicating that Adam and Chris suggested that an additional mitigation measure would be to block “DNP3 traffic from traversing onto business or corporate networks through the use of an IPS or firewall with DPN3-specific (sic) rule sets”.


This is actually a pretty specific expansion of a standard ICS-CERT recommendation to protect control systems from unauthorized access via the use of a firewall or IPS. It is not surprising that Adam and Chris would focus on DNP3 communications since this is an area that they have been spending a great deal of time investigating here recently. It might be interesting if they were to post on the Automatak blog a more detailed discussion about the types of DNP3 rule sets that would provide additional control system protections for DNP3 servers in general.

Wednesday, August 14, 2013

ICS-CERT Publishes Kepware DNP Advisory

Today the DHS ICS-CERT published an advisory for an improper input validation vulnerability in the Kepware Technologies DNP Master Driver. The vulnerability was reported by Adam Crain and Chris Sistrunk in a coordinated disclosure.

ICS-CERT reports that a moderately skilled attacker could exploit this vulnerability to conduct a denial of service attack or possibly execute arbitrary code on the system. Kepware has produced an updated version of the software that has been validated by Crain and Sistrunk.


The Project Robus page now shows four DNP3 related ICS-CERT advisories published that were based upon work by Adam and Chris with 15 advisories ‘pending’. Based upon Adam’s work on the open source implementation of DNP3 that I discussed yesterday, I would bet that a number of the ‘pending’ advisories will also deal with DNP3 vulnerabilities. It might behoove vendors that utilize the DNP protocol to start taking a hard look at their potential vulnerabilities. 

Friday, August 9, 2013

Robus – More ICS Vulnerability Reports to Come

Thanks to Chris Jager (via Twitter®) for pointing me at the web site of Robus, the collaboration of  Adam Crain and Chris Sistrunk that has already brought us the latest ICS-CERT advisory on SEL. This is a deceptively simple web site with only a single page and the only external links going to the ICS-CERT web site, the LinkedIn® profiles of the two principles and the web site of Automatak, their corporate sponsor.

The real interesting part of the site is the listing of the ICS-CERT advisories that there research has been responsible for initiating. There are currently three advisories listed and the word pending shown a number of times. Yesterday when I first saw this site there were 12 ‘pendings’, this morning there are 16; each one reflects (as I understand it) coordinated disclosures for ICS vulnerabilities that have already been made.

It looks like we are going to be hearing a lot from these two young men.

Keeping in mind that free suggestions are typically worth what you pay for them; I have two suggestions for the web site. First put a date on each ‘pending’ signifying when the disclosure was actually made; this could help the industry track the general responsiveness of vendors. Second establish an internal standard (the ICS-CERT 45 day limit for instance) for a reasonable time to fix a vulnerability and then add the vendor’s name to the pending listing. This could be followed by a second time limit to add the generic vulnerability description to the pending listing.


BTW: Suggested reading: Here be Dragons

Wednesday, August 7, 2013

ICS-CERT Publishes SEL Advisory

This afternoon the DHS ICS-CERT published an advisory for dual improper input validation vulnerabilities in the Schweitzer Engineering Laboratories’ (SEL) real-time automation controllers (RTAC). The vulnerabilities were reported by Adam Crain of Automatak and Chris Sistrunk in coordinated disclosures.

ICS-CERT reports that these vulnerabilities (one for serial connections and a separate one for IP-based connections; NOTE links will not work for a day or two) could be remotely exploited by a moderately skilled attacker, executing a denial of service attack. SEL has developed a CD-ROM based upgrade packet to mitigate the vulnerabilities. ICS-CERT reports that Crain and Sistrunk have validated the efficacy of the upgrades.


I tried to review the SEL information on these vulnerabilities, but it was not directly available on their web site. Instead SEL allows people with corporate email accounts to sign up to receive distributed information on SEL security notices. Anyone owning any SEL control system equipment should sign up for this service.

Friday, August 2, 2013

ICS-CERT Issues Three Advisories – Two for Siemens

After a three-week breather advisories start coming hot and heavy from ICS-CERT. There are two Siemens’ advisories (one self-reported) and a coordinated disclosure advisory for IOServer.

Siemens Scalance

The first advisory addresses two Siemens’ reported two vulnerabilities in their Scalance W-7xx product family. They are:

• Key management errors, CVE-2013-4651, hard-coded SSL certificate;
• Improper authentication, CVE-2013-4652, network access required.
NOTE: CVE Links may not be active for a couple of days.

ICS-CERT notes that a relatively low skilled attacker could remotely exploit these vulnerabilities to conduct a man-in-the-middle attack or take over complete control of the system. Siemens has produced an update that mitigates the vulnerability (since they self-reported they get to self-validate). The Siemens-CERT advisory also provides a work-around for the second vulnerability.

Siemens WinCC

The second advisory addresses two vulnerabilities reported by Timur Yunusov and Sergey Bobrov of Positive Technologies in a coordinated disclosure. The vulnerabilities are:

• Cross-site request forgery, CVE-2013-4911,
• Url redirection to untrusted site, CVE-2013-4912,
NOTE: CVE Links may not be active for a couple of days.

According to the Siemens-CERT advisory, both vulnerabilities require that a web be activated on the affected devices during set up. The attacker must then use a social engineering attack to get a user to access a malicious web page.

ICS-CERT notes that a moderately skilled attacker could remotely exploit these vulnerabilities to compromise the integrity (execute arbitrary code?) and availability (DoS attack?). Siemens has produced a product update that mitigates the vulnerabilities and has validated the fix (oops, that should have been the researchers, Yunusov and Borov, doing the validation).

IOServer Advisory

The third advisory of the day reports on an improper input validation vulnerability in the IOServer Master Station product reported by Adam Crain of Automatak and Chris Sistrunk in a coordinated disclosure.


ICS-CERT notes that a moderately skilled attacker could remotely exploit this vulnerability to execute a denial of service attack. IOServer has produced a Beta Driver (beta2042.exe) that mitigates these vulnerabilities. There is no indication that the researchers have validated the efficacy of the updated driver. NOTE: an even more recent Beta Driver is available.

Monday, June 10, 2013

ICS-CERT Publishes IOServer Advisory

This afternoon the DHS ICS-CERT published an advisory concerning an improper input validation vulnerability in the IOServer’s DNP3 driver reported by Adam Crain of Automatak and independent research Chris Sistrunk in a coordinated disclosure.

ICS-CERT reports that a moderately skilled attacker could craft a remotely exploitable attack using this vulnerability resulting in a denial of service attack. IOServer has provided an updated version of the software (http://www.ioserver.com/beta2040.exe) which has been confirmed by Crain and Sistrunk to correct the problem.


NOTE: I’m not sure that I would like clicking on an .EXE file for a file on a different web site. Personally, I would prefer to click to a page that provides some sort of explanation of what the changed software would do before I would be comfortable clicking on the executable file.
 
/* Use this with templates/template-twocol.html */