Showing posts with label BSI. Show all posts
Showing posts with label BSI. Show all posts

Tuesday, February 16, 2021

3 Advisories and 1 Update Published – 2-16-21

Today CISA’s NCCIC-ICS published two control system security advisories for products from Rockwell and Open Design Alliance, as well as a medical device security advisory for products from Hamilton Medical. They also updated an advisory from M&M Software (WAGO).

Rockwell Advisory

This advisory describes an improper handling of length parameter inconsistency vulnerability in the Allen-Bradley MicroLogix 1100 Programmable Logic Controller. The vulnerability was reported by Talos. Rockwell advises upgrading to the Micrologic 1400, firmware v21.006 or higher.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to result in denial-of-service conditions.

NOTE: I briefly discussed this vulnerability on Saturday.

Open Design Alliance Advisory

This advisory describes six vulnerabilities in the Open Design Alliance Drawings SDK software development kit. The vulnerabilities were reported by Michael DePlante and rgod via the Zero Day Initiative. ODA has a newer version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2021-25178,

• Type confusion - CVE-2021-25177,

• Untrusted pointer dereference - CVE-2021-25176,

• Incorrect type conversion or cast - CVE-2021-25175, and

• Memory allocation with excessive size value (2) - CVE-2021-25174 and CVE-2021-25173

NCCIC-ICS reported that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to allow code execution in the context of the current process or cause a denial-of-service condition.

NOTE: These vulnerabilities were reported last week in NCCIC’s Siemens JT2Go and Teamcenter Visualization (ICSA-21-040-06) advisory and the Siemens advisory (SSA-663999) upon which it was based. Both advisories provided links to the ODA advisory. It will be interesting to see what other vendors use this ODA tool.

Hamilton Advisory

This advisory describes three vulnerabilities in the Hamilton-T1 Ventilator. The vulnerabilities were reported by Julian Suleder, Raphael Pavlidis, Nils Emmerich and Dr. Oliver Matula of ERNW Research. Hamilton recommends updating to newer versions to mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Use of hard-coded credentials - CVE-2020-27278,

• Missing XML validation - CVE-2020-27282, and

• Exposure of sensitive information - CVE-2020-27290

NCCIC-ICS reports that a relatively low-skilled attacker with physical access to the device could exploit the vulnerability to obtain sensitive information or crash the device being accessed.

NOTE: For those that are interested, here is the German BSI’s report on a whole slew of these vulnerabilities that were reported by ERNW Research for this BSI project. Not a lot of detail, but there are a lot of vulnerable devices.

WAGO Update

This update provides additional information on an advisory that was originally published on January 21st, 2021 and most recently updated on February 4th, 2021. The new information includes adding the Mitsubishi Electric MELSOFT FieldDeviceConfigurator as an affected product with a link to the Mitsubishi advisory.

Thursday, January 7, 2021

5 Advisories Published – 1-7-21

Today the CISA NCCIC-ICS published four control system security advisories for products from Delta Industrial, Eaton, Omron, and Hitachi-ABB Power Grids. They also published a medical device security advisory for products from Innokas Yhtyma Oy.

Delta Advisory

This advisory describes four vulnerabilities in the Delta CNCSoft-B software management platform. The vulnerabilities were reported by Kimiya via the Zero Day Initiative (ZDI). Delta has a new version that mitigates the vulnerability. There is no indication that Kimiya has been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Out-of-bounds write - CVE-2020-27287,

• Out-of-bounds read - CVE-2020-27291,

• Untrusted pointer dereference - CVE-2020-27289, and

• Type confusion - CVE-2020-27293

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to lead to arbitrary code execution.

Eaton Advisory

This advisory describes two vulnerabilities in the Eaton EASYsoft product. The vulnerabilities were reported by Francis Provencher via ZDI. Eaton is continuing to work on developing mitigation measures.

The two reported vulnerabilities are:

• Type confusion - CVE-2020-6656, and

• Out-of-bounds read - CVE-2020-6655

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit these vulnerabilities to modify or crash the program.

Omron Advisory

This advisory describes three vulnerabilities in the Omron CX-One automation software suite. The vulnerabilities were reported by rgod via ZDI. Omron has an update available to mitigate the vulnerability. There is no indication that rgod has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Untrusted pointer dereference - CVE-2020-27259,

• Stack-based buffer overflow - CVE-2020-27261, and

• Type confusion - CVE-2020-27257

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to crash the device being accessed. In addition, a buffer overflow condition may allow remote code execution.

Hitachi-ABB Advisory

This advisory describes an improper authentication vulnerability in the Hitachi-ABB FOX615. This is reported as a third-party vulnerability in the Libssh service. The vulnerability was self-reported. Hitachi-ABB has firmware updates that mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker remote access to the device without authentication.

NOTE: This vulnerability was reported by Libssh.org in 2018. An exploit was reported for this vulnerability by DAYANÇ SOYADLI in October 2018.

Innokas Advisory

This advisory describes two vulnerabilities in the Innokas Vital Signs Monitor VC150. The vulnerabilities were reported by Julian Suleder, Nils Emmerich, Birk Kauer, and Dr. Oliver Matula of ERNW via the German BSI. Innokas has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Cross-site scripting - CVE-2020-27262,

• Improper neutralization of special elements in output used by a downstream component - CVE-2020-27260

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to modify communications between downstream devices or cause some features of the affected devices to become disabled.

Thursday, October 22, 2020

2 Advisories Published – 10-22-20

Today the CISA NCCIC-ICS published two medical device security advisories for products from B. Braun Melsungen AG.

SpaceCom Advisory X

This advisory describes eleven vulnerabilities in the B. Braun SpaceCom, Battery Pack SP with Wi-Fi, and Data module compactplus products. The vulnerabilities were reported by Julian Suleder, Nils Emmerich, and Birk Kauer of ERNW Research, and Dr. Oliver Matula of ERNW Enno Rey Netzwerke via the German Federal Office for Information Security (BSI). B. Braun has updates that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The eleven reported vulnerabilities are:

• Cross-site scripting - CVE-2020-25158,

• Open redirect - CVE-2020-25154,

• XPath injection - CVE-2020-25162,

• Session fixation - CVE-2020-25152,

• Use of one-way hash without a salt - CVE-2020-25164,

• Relative path traversal - CVE-2020-25150,

• Improper verification of cryptographic signature - CVE-2020-25166,

• Improper privilege management - CVE-2020-16238,

• Use of hard-coded credentials - CVE-2020-25168,

• Active debug code - CVE-2020-25156, and

• Improper access control - CVE-2020-25160

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to compromise the security of the Space or compactplus communication devices, allowing an attacker to escalate privileges, view sensitive information, upload arbitrary files, and perform remote code execution.

OnlineSuite Advisory

This advisory describes three vulnerabilities in the B. Braun OnlineSuite product. The vulnerabilities were reported by the same researchers mentioned in the first advisory. B. Braun has an update that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Relative path traversal - CVE-2020-25172,

• Uncontrolled search path element - CVE-2020-25174,

• Improper neutralization of formula elements in a CSV file - CVE-2020-25170

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to escalate privileges, download and upload arbitrary files, and perform remote code execution.

NOTE: Neither of the company advisories are listed on the US web site for B. Braun.

Tuesday, September 8, 2020

9 Advisories Published – 9-8-20


Today the CISA NCIC-ICS published nine control system security advisories for products from Wibu-Systems and Siemens (8). The Wibu advisory was originally published with restricted access on the HSIN ICS library on July 21st, 2020. It has been a little over 22 months since NCCIC-ICS last published an advisory on HSIN before releasing it to the general public.

NOTE: NCCIC-ICS also updated seven advisories from Siemens. I will address those in a separate blog post, probably tomorrow.

Wibu-Systems Advisory


This advisory describes six vulnerabilities in the Wibu-Systems CodeMeter. These vulnerabilities were reported by Sharon Brizinov and Tal Keren of Claroty. Wibu has a new version that, along with other specific measures mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Buffer access with incorrect length value - CVE-2020-14509,
• Inadequate encryption strength - CVE-2020-14517,
• Origin validation error - CVE-2020-14519,
• Improper input validation - CVE-2020-14513,
• Improper verification of cryptographic signature - CVE-2020-14515, and
• Improper resource shutdown or release - CVE-2020-16233

NOTE: The CVE links are to the respective Wibu advisory. They apparently publish a separate advisory for each vulnerability. These advisories provide a bit more detail than does the NCCIC-ICS advisory.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to alter and forge a license file, cause a denial-of-service condition, potentially attain remote code execution, read heap data, and prevent normal operation of third-party software dependent on the CodeMeter.

NOTE: NCCIC-ICS provided links to two vendor advisories for products affected by this vulnerability:

Siemens, and


Polarian Advisory


This advisory describes two vulnerabilities in the Siemens Polarion Subversion Webclient. The vulnerabilities were reported by Li Yifan. Siemens considers the product shareware, distributed “as is,” and will be no fix as it is no longer supported.

The two reported vulnerabilities are:

• Basic XSS - CVE-2020-15788, and
• Cross-site request forgery - CVE-2020-15789

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to to induce the victim to issue an HTTP request could lead to a state-changing operation.

Industrial Products Advisory


This advisory describes an exposure of sensitive information to an unauthorized actor vulnerabilities in the Siemens Industrial Products. The Siemens advisory notes that this is the third-party (Intel) Crosstalk vulnerability. The vulnerability was reported by Alyssa Milburn, Hany Ragab, Kaveh Razavi, Herbert Bos, and Cristiano Giuffrida from the VUSec group. Siemens is working on an update and currently only provides generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with local access could exploit this vulnerability to allow an authenticated user to enable information disclosure via local access.

SIMATIC Advisory #1


This advisory describes two vulnerabilities in the Siemens SIMATIC HMI Products. The vulnerabilities were reported by Joseph Gardiner from Bristol Cyber Security Group. Siemens is working on an update and currently only provides generic workarounds to mitigate the vulnerability.

The two reported vulnerabilities are:

• Improper restriction of excessive authentication attempts - CVE-2020-15786, and
• Authentication bypass by primary weakness - CVE-2020-15787.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow a remote attacker to discover user passwords and obtain access to the Sm@rt Server via a brute-force attack.

Siveillance Advisory


This advisory describes a cleartext transmission of sensitive information vulnerability in the Siemens Siveillance Video Client IP video management software. The vulnerability is self-reported. Siemens has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to obtain valid administrator login names and use this information to launch further attacks.

Spectrum Advisory


This advisory describes two vulnerabilities in the Siemens Spectrum Power products. The vulnerabilities were reported by Can Demirel of Cyberwise. Siemens has updates that mitigate the vulnerabilities. There is no indication that Demirel has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Cleartext storage of sensitive information - CVE-2020-15784, and
• Exposure of information through directory listing - CVE-2020-15790

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerabilities to allow an unauthorized attacker to retrieve a list of software users, or in certain cases to list the contents of a directory.

License Management Advisory


This advisory describes an execution with unnecessary privileges vulnerability in the Siemens License Management Utility (LMU). The vulnerability was reported by Bundesamt für Sicherheit in der Informationstechnik (BSI). Siemens has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow local users to escalate privileges.

SIMATIC Advisory #2


This advisory describes an insufficiently protected credentials vulnerability in the Siemens SIMATIC S7-300 and S7-400 CPUs. The vulnerability was reported by Hyunguk Yoo from University of New Orleans and Irfan Ahmed and Adeen Ayub from Virginia Commonwealth University. Siemens has provided generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow credential disclosure.

SIMATIC Advisory #3


This advisory describes three vulnerabilities in the Siemens SIMATIC RTLS Locating Manager. The vulnerabilities were self-reported. Siemens has an update that mitigates the vulnerabilities.

The three reported vulnerabilities are:

• Incorrect default permissions - CVE-2020-10049 and CVE-2020-10050, and
• Unquoted search path or element -CVE-2020-10051

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow a privileged local user to escalate privileges.

Saturday, June 13, 2020

Public ICS Disclosures – Week of 6-6-12


This week we have seven vendor disclosures from Schneider (3), WAGO (2), Moxa and Medtronic as well as four vendor updates for advisories from Schneider (3) and Siemens. There were three researcher reports about vulnerabilities from Siemens.

Schneider Advisories


Schneider published an advisory describing an out-of-bounds write vulnerability in their Modicon M218 Logic Controller. The vulnerability was reported by CNCERT. Schneider provides generic workarounds to mitigate the vulnerability.


Schneider published an advisory describing a use of hard-coded credentials vulnerability in their Unity Loader and OS Loader Software. The vulnerability was reported by Yang Dong of DingXiang Dongjian Security Lab. Schneider provides workarounds to mitigate the vulnerability, noting that: “Hardcoded credentials are kept for compatibility with legacy products.”


Schneider published an advisory describing a null pointer dereference vulnerability in their Modicon LMC078 Logic Controller. This vulnerability is self-reported. Schneider provides generic workarounds to mitigate the vulnerability.

NOTE: This vulnerability is in a third-party (Wind River) component (IGMP) and was introduced in a patch applied to mitigate the Urgent/11 vulnerabilities. This vulnerability should be able to be found in a large number of products. I expect that we will be seeing more of this one.

WAGO Advisories


CERT-VDE published an advisory describing an improper privilege management vulnerability in the WAGO Web Based Management products. This vulnerability was reported by CISCO Talos; the report includes proof-of-concept code. WAGO provides generic workarounds to mitigate this ‘feature’.


CERT-VDE published an advisory describing a classic buffer overflow vulnerability in the WAGO Series PFC100 and Series PFC200 PLC’s. This vulnerability was reported by BSI. WAGO has new firmware that mitigates the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

NOTE: This is the third-party (LINUX) PPP daemon vulnerability that has been previously reported in other products.

MOXA Advisory


Moxa has published an advisory describing a command injection vulnerability in their VPort 461 Series Industrial Video Servers. The vulnerability was reported by Xinjie Ma from Beijing Chaitin Future Technology Co. Moxa has a patch for this phased-out product. There is no indication that Xinjie has been provided an opportunity to verify the efficacy of the fix.

Medtronic Advisory


Medtronic has published an advisory describing the Bluetooth Impersonation Attacks (BIAS) vulnerabilities in their FA Controller and  Patient Telemetry Module products. Medtronic has not yet determined what mitigation measures it will take.

NOTE: These vulnerabilities may (probably?) affect any medical device or control system component that uses Bluetooth connectivity.

Schneider Updates


Schneider published an update for their Urgent/11 advisory that was originally published on August 2nd, 2020 and most recently updated on May 12th, 2020. The new information includes updated mitigation measures for:

 • Easergy T300 and
• Magelis HMI - HMIGTO Series, HMISCU Series,  HMIGTUX Series, and HMIGTU Series (Except Open BOX) products


Schneider published an update for their EcoStruxure™ Operator Terminal Expert advisory that was originally published on May 12th, 2020. The new information includes an update of CVE-2020-7495.


Schneider published an update for their GoAhead Web Server Vulnerability that was originally published on December 10th, 2015. The new information includes:

• A note that proof-of-concept code is publicly available,
• Updated remediation informtation.

NOTE: ICS-CERT (now NCCIC-ICS) published an advisory for this vulnerability, it will be interesting to see if they get around to updating it.

Siemens Update


Siemens published an update for their Urgent/11 advisory that was originally published on May 12th, 2020. The new information includes updated version data and mitigation measures for Siemens Power Meters Series 9810.

Researcher Reports – Siemens


CISCO Talos published three research reports (here, here and here) describing vulnerabilities in the Seiemens LOGO! Products. The reports each claim CVE# CVE-2020-7589 which was reported by Siemens (and NCCIC-ICS) earlier this week as a single missing authentication for critical function vulnerability. Each Talos report includes separate proof-of-concept code.

 
/* Use this with templates/template-twocol.html */