Showing posts with label Ben Seri. Show all posts
Showing posts with label Ben Seri. Show all posts

Tuesday, July 30, 2019

2 Advisories and 1 Alert Published – 07-30-19


Today the DHS NCCIC-ICS published a control system security alert for CAN bus network implementation in avionics and two control system security advisories for products from Prima Systems ad Wind River.

CAN Bus Alert


This alert briefly describes a public report about insecure implementation of CAN bus networks affecting aircraft. The report was published by Patrick Kiley of Rapid7.

Prima Systems Advisory


This advisory describes nine vulnerabilities in the Prima Systems FlexAir access control platform. The vulnerabilities were reported by Gjoko Krstic of Applied Risk. Prima Systems has a new version that mitigates the vulnerabilities. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

The nine reported vulnerabilities are:

OS command injection - CVE-2019-7670;
Unrestricted upload of file with dangerous type (2) - CVE-2019-7669 and CVE-2019-9189;
Cross-site request forgery - CVE-2019-7281;
Small space of random values - CVE-2019-7280;
Cross-site scripting - CVE-2019-7671;
Exposure of a backup file to an unauthorized control sphere - CVE-2019-7667;
Improper authentication - CVE-2019-7666; and
Use of hard-coded credentials - CVE-2019-7672

NOTE 1: NCCIC-ICS does not include a default credentials vulnerability, CVE-2019-7668, reported by Krstic.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to execute commands directly on the operating system, upload malicious files, perform actions with administrative privileges, execute arbitrary code in a user’s browser, discover login credentials, bypass normal authentication, and have full system access.

NOTE 2: I briefly described the Rapid7 report back in May.

Wind River Advisory


This advisory describes eleven vulnerabilities in the Wind River VxWorks operating system. The vulnerabilities were reported by Armis researchers Gregory Vishnepolsky, Dor Zusman, and Ben Seri. Wind River has patches to mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The eleven reported vulnerabilities are:

Stack-based buffer overflow - CVE-2019-12256;
Heap-based buffer overflow - CVE-2019-12257;
Integer underflow - CVE-2019-12255;
Improper restrictions of operations within the bounds of a memory buffer (2) - CVE-2019-12260 and CVE-2019-12261;
Race condition - CVE-2019-12263;
Argument injection or modification (4) - CVE-2019-12258, CVE-2019-12262, CVE-2019-12264 and CVE-2019-12265; and
Null pointer dereference - CVE-2019-12259;

Since the affected operating systems are used in a large number of IoT and ICS systems we can expect advisories from affected vendors implementing the Wind River mitigations measures. The NCCIC-ICS advisory already lists 2 vendor advisories and the Armis report adds a third. The three vendor advisories available to date include:

Rockwell,
Xerox, and

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow remote code execution.

Saturday, March 16, 2019

Public ICS Disclosures – Week of 03-09-19


This week we have five vendor notifications for products from Siemens, PEPPERL+FUCHS, and Schneider(3) and four vendor updates of previously published advisories for products from Siemens(3) and Medtronics.

Siemens Advisory


Siemens published an advisory describing a mirror port isolation vulnerability in their SCALANCE X switches. The vulnerability is being self-reported. Siemens has provided generic workarounds to mitigate the vulnerability.

PEPPERL+FUCHS Advisory


VDE CERT published an advisory describing two vulnerabilities in the PEPPERL+FUCHS ecom mobile devices. The vulnerabilities were reported by Ben Seri and Gregory Vishnepolsky of Armis; the armis 2017 Blueborne disclosure includes exploits. PEPPERL+FUCHS points to (no links provided) OEM vendors for updates for some of the affected products.

Schneider Advisories


Schneider published an advisory describing an uncontrolled search path element vulnerability in their Pelco VideoXpert OpsCenter. The vulnerability was reported by Osama Radwan. Schneider has a new version that mitigates the vulnerability. There is no indication that Radwan has been provided an opportunity to verify the efficacy of the fix.

Schneider published an advisory describing an SQL injection vulnerability in their U.motion Builder software product. The vulnerability was reported by Julien Ahrens (RCE Security). Schneider recommends that customers stop using the their U.motion Builder software product as it is no longer supported.

Schneider published an advisory describing an improper check for unusual or exceptional conditions vulnerability in their Triconex TriStation Emulator. The vulnerability was reported by Tom Westenberg – Applied Risk. Schneider plans to have an update available in July and has provided generic workarounds to mitigate the vulnerability in the mean time.

Siemens Updates


Siemens published an update for their advisory on Spectre and Meltdown Vulnerabilities in Industrial Products. They added an updated solution for their SINUMERIK PCU. NCCIC-ICS is not expected to publish and update for their Meltdown/Spectre alert (ICS-ALERT-18-011-01) since the link in that Alert to the Siemens Industrial Products already takes one to this latest update.

Siemens published an update for their advisory on Foreshadow / L1 Terminal Fault Vulnerabilities in Industrial Products. They added an updated solution for their SINUMERIK PCU. NCCIC-ICS has not published any advisories or alerts about the Foreshadow vulnerabilities.

Siemens published an update for their advisory on Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP. They added 14 new CVE’s to the already lengthy list of CVE’s covered in the advisory. NCCIC-ICS has not published an advisories or alerts on this family of Linux vulnerabilities.

Medtronic Update


Medtronic published an update for their advisory on MiniMed™ Paradigm™ Insulin Pumps. They added:

• Two new affected devices available in the US; and
A link to the field safety notification letter issued in August, 2018.

The NCCIC-ICS advisory (ICSMA-18-219-02) was originally published on August 8th, 2018. I suspect that this will be updated in the coming week.

NOTE: It is interesting that the letter (dated August 7th, 2018; the date of the original advisory) includes the two affected devices that are being added to the advisory via this update. The original Medtronic advisory made special note that none of the affected devices were available for sale in the United States.

 
/* Use this with templates/template-twocol.html */