Showing posts with label BINOM3. Show all posts
Showing posts with label BINOM3. Show all posts

Wednesday, February 8, 2017

ICS-CERT Updates Another Advisory

I missed it last night, but yesterday the DHS ICS-CERT updated a controls system security advisory for products from BINOM3. That advisory was originally published on January 31st, 2017.

The new update greatly expands the impact assessment of the multiple vulnerabilities. Instead of just allowing inaccurate reporting of electric quality measurements, the new impact statement reports:


“Successful exploitation of these vulnerabilities could cause unauthorized access to the device, sensitive information leakage, arbitrary script/code execution, unauthorized functional configuration and data changes, and denial-of-service attacks.”

Tuesday, January 31, 2017

ICS-CERT Publishes Two Advisories and Updates Another

Today the DHS ICS-CERT published two control system security advisories for products from Ecava and BINOM3. They also updated a previously published advisory for products from Moxa; that advisory was originally published on October 13th, 2016.

Ecava Advisory


This advisory describes an SQL injection vulnerability in the Ecava IntegraXor. The vulnerability was reported by Brian Gorenc and Juan Pablo Lopez via the Zero Day Initiative. Ecava has produced a software update to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability. That exploit could lead to arbitrary data leakage, data manipulation, and remote code execution.

BINOM3 Advisory


This advisory describes multiple vulnerabilities in the BINOM3 Electric Power Quality Meter. The vulnerability was reported by Karn Ganeshen. ICS-CERT reports that BINOM3 has not provided any mitigation measures for these vulnerabilities.

The reported vulnerabilities are:

• Cross-site scripting - CVE-2017-5164;
• Improper access control - CVE-2017-5162;
• Cross-site request forgery - CVE-2017-5165;
• Information exposure - CVE-2017-516; and
• Hard-coded password - CVE-2017-5167.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities. Such an exploit could cause the device to inaccurately report a range of electrical quality measurements.

Format Update


Just a quick note that ICS-CERT has made another modification to their new advisory format. They have added a new section; Background. It provides information about the vulnerable device/application including affected sectors, where the device/application is used, and where the vendor is located.

Moxa Update


This update provides new information, including:

• Notification that the vulnerabilities also affect the ioLogik E2200 series devices;
• Provides affected version information for the ioLogik E2200 series devices; and
• Links for downloads of the firmware updates for the ioLogik E2200 series devices.


Tuesday, September 20, 2016

ICS-CERT Publishes BINOM3 Alert

Yesterday the DHS ICS-CERT published an alert for publicly disclosed control system vulnerabilities in the BINOM3 Electric Power Quality Meter. The vulnerabilities had previously been disclosed to ICS-CERT by Karn Ganeshen, but ICS-CERT has not been able to get a response from BINOM3 about the vulnerabilities.

The reported vulnerabilities include:

• Reflected and stored Cross-site Scripting;
• Clear Text Passwords;
• Sensitive information leakage in GET request; and
• Access Control Issues


These are the same vulnerabilities that I reported on Saturday.

Saturday, September 17, 2016

Public ICS Vulnerability Disclosure – 09-10-16

This week there was one public disclosure of an industrial control system on the Full Disclosure mailing list. Karn Ganeshen reported a number of vulnerabilities in the BINOM3 Electric Power Quality Meter. Karn reports submitting a vulnerability notification to ICS-CERT on May 25th, 2016, noting that there has been no reply from the Russian vendor to date.

The reported vulnerabilities include:

• Reflected cross-site scripting;
• Stored cross-site scripting;
• Weak credentials;
• Undocumented root account;
• Sensitive information stored in clear text;
• Vulnerable to cross-site request forgery;
• Sensitive data leakage; and
• Access control issues


With their 45-day non-response disclosure policy it seems odd that ICS-CERT has not issued an advisory on this vulnerability.
 
/* Use this with templates/template-twocol.html */