Showing posts with label Biznet Bilisim. Show all posts
Showing posts with label Biznet Bilisim. Show all posts

Tuesday, May 5, 2020

2 Advisories Published – 5-5-20


Today the CISA NCCIC-ICS published two control system security advisories for products from SAE IT-systems and Fazecast.

SAE Advisory 


This advisory describes two vulnerabilities in the SAE FW-50 RTU modular telecontrol system. The vulnerabilities were reported by Murat Aydemir of Biznet Bilisim. SAE has a new CPU card that mitigates the vulnerability.

The two reported vulnerabilities are:

• Cross-site scripting - CVE-2020-10630; and
• Path traversal - CVE-2020-10634

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to execute remote code, disclose sensitive information, or cause a denial-of-service condition.

NOTE: Is it just me, or does replacing a CPU to fix a programming problem seem to be just a tiny bit of overkill?

Fazecast Advisory  


This advisory describes an uncontrolled search path element vulnerability in the Fazecast jSerialComm, a platform-independent serial port access library for Java. The advisory reports that this vulnerability (presumably as a third-party vuln) also affects the Schneider EcoStruxure IT Gateway (no Schneider advisory has been published yet). The vulnerability was reported by Ryan Wincey of Securifera via the Zero Day Initiative. Fazecast (and Schneider) has a new version that mitigates the vulnerability. There is no indication that Wincey has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an unauthenticated attacker to execute arbitrary code on a targeted system.

NOTE: It seems strange to see a library vulnerability advisory including the mention of an affected vendor on the day of the initial release. I suppose that Fazecast told either ZDI or NCCIC-ICS who their customers were so that NCCIC-ICS could contact them about the vulnerability. It will be interesting to see what (if) other vendors are using this Java library.

Thursday, March 19, 2020

2 Advisories Published – 3-19-20


Today the CISA NCCIC-ICS published one control system security advisory for products from Systech Corporation and one medical device security advisory for products from Insulet.

Systech Advisory


This advisory describes a cross-site scripting vulnerability in the Systech NDS-5000 Terminal Server. The vulnerability was reported by Murat Aydemir at Biznet Bilisim AS. Systech has a new firmware version that mitigates the vulnerability. There is no indication that Aydemir has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow information disclosure, limit system availability, and may allow remote code execution.

Insulet Advisory


This advisory describes an improper access control vulnerability int eh Insulet Omnipod Insulin Management System. The vulnerability was reported by Thirdwayv Inc. Insulet provides generic mitigation measures to address the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access (this is an RF intercept problem so – remote access?) could use a publicly available exploit to abuse (sorry, I did not want to repeat the word ‘exploit’; trying this on for size) the vulnerability.

NOTE: It looks like this ‘exploit’ is being developed by an unauthorized user group to expand the options for using the Insulet OmniPod insulin pump.



Wednesday, February 12, 2020

13 Advisories and 5 Updates Published – 2-11-20

Today the CISA NCCIC-ICS published 13 control system security advisories for products from Synergy Systems and Solutions, Digi International and Siemens (11). They also updated five control system security advisories for products from Siemens.

Synergy Systems Advisory


This advisory describes two vulnerabilities in the SSS HUSKY RTU. The vulnerabilities were reported by VAPT Team, C3i Center. SSS has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper authentication - CVE-2019-20046; and
• Improper input validation - CVE-2019-20045

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to read sensitive information, execute arbitrary code, or cause a denial-of-service condition.

Digi Advisory


This advisory describes two vulnerabilities in the Digi ConnectPort LTS 32 MEI. The vulnerabilities were reported by Murat Aydemir and Fatih Kayran of Biznet Bilisim. Digi has a new release that mitigates the vulnerabilities. There is no indication that the researchers have been provided with an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Unrestricted upload of file with dangerous type - CVE-2020-6975; and
• Cross-site scripting - CVE-2020-6973

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to limit system availability.

SIPROTEC Advisory


This advisory describes an improper input validation vulnerability in the Siemens SIPROTEC 4 and SIPROTEC Compact. The vulnerability was reported by Tal Keren from Claroty. Siemens has provided generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to conduct a denial-of-service attack over the network.

SIMATIC S7-1500 Advisory


This advisory describes a resource exhaustion vulnerability in the Siemens SIMATIC S7-1500 CPU family. The vulnerability is self-reported. Siemens has provided generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to conduct denial-of-service attacks.

SCALANCE S-600 Advisory


This advisory describes three vulnerabilities in the Siemens SCALANCE S-600 Firewall. One of the vulnerabilities was reported by Melih Berk Ekşioğlu. Siemens has provided generic workarounds to mitigate the vulnerability.

The three reported vulnerabilities are:

• Cross-site scripting - CVE-2019-6585; and
• Uncontrolled resource consumption (2) - CVE-2019-13925 and CVE-2019-13926

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to conduct denial-of-service or cross-site scripting attacks. User interaction is required for a successful exploitation of the cross-site-scripting attack.

OZW Web Server Advisory


This advisory describes and information disclosure vulnerability in the Siemens OZW web server. The vulnerability was reported by Maxim Rupp. Siemens has a new version that mitigates the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow unauthenticated users to access project files.

SIPORT Advisory


This advisory describes an insufficient logging vulnerability in the Siemens SIPORT MP. The vulnerability is self-reported. Siemens has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow the attacker to create special accounts with administrative privileges.

SCALANCE Advisory


This advisory describes a protection mechanism failure vulnerability in the Siemens SCALANCE X switches. The vulnerability is self-reported. Siemens has updates that mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to perform administrative actions.

SIMATIC PCS 7 Advisory


This advisory describes an incorrect calculation of buffer size vulnerability in the Siemens SIMATIC PCS 7, SIMATIC WinCC, SIMATIC NET PC products. The vulnerability was reported by Nicholas Miles from Tenable. Siemens has new versions that mitigate the vulnerability. There is no indication that Miles has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker with network access to cause a denial-of-service condition.

SIMATIC S7 Advisory


This advisory describes a resource exhaustion vulnerability in the Siemens SIMATIC S7 devices. The vulnerability was reported by China Industrial Control Systems Cyber Emergency Response Team. Siemens has a new version that mitigates the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow remote attackers to perform a denial-of-service attack by sending a specially crafted HTTP request to the web server of an affected device.

PROFINET Advisory


This advisory describes a resource exhaustion vulnerability in the Siemens PROFINET-IO Stack. The vulnerability was reported by Yuval Ardon and Matan Dobrushin of OTORIO. Siemens has updates that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to lead to a denial-of-service condition.

NOTE: OTORIO reports that this same vulnerability is found in multiple vendor products including the Moxa EDS Ethernet Switches.

SIMATIC CP Advisory


This advisory describes two vulnerabilities in the Siemens SIMATIC CP 1543-1. The vulnerabilities are self-reported. Siemens has a new version that mitigates the vulnerabilities.

The two reported vulnerabilities are:

• Improper access control - CVE-2019-12815; and
• Loop with unreachable exit condition - CVE-2019-18217

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow for remote code execution and information disclosure without authentication, or unauthenticated denial of service.

Industrial Products Advisory


This advisory describes two vulnerabilities in the Siemens SCALANCE, SIMATIC, SIPLUS products. The vulnerabilities were reported by Artem Zinenko of Kaspersky Lab. Siemens has new versions that mitigate the vulnerabilities. There is no indication that Zinenko has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Data processing errors - CVE-2015-5621; and
• Null pointer dereference - CVE-2018-18065

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow remote attackers to conduct a denial-of-service attack by sending specially crafted packets to Port 161/UDP (SNMP).

SIMOCODE Update


This update provides additional information on an advisory that was originally published on March 9th, 2019 and most recently updated on January 14th, 2020. The new information includes the addition of two affected products:

• SITOP PSU8600; and
• TIM 1531 IRC

Industrial Products w/OPC UA Update


This update provides additional information on an advisory that was originally published on April 9th, 2019 and most recently updated on January 14th, 2020. The new information includes updated affected version data and mitigation links for SIMATIC NET PC Software.

PROFINET Update


This update provides additional information on an advisory that was originally published on October 10th, 2019 and most recently updated on January 14th, 2020. The new information includes updated affected version data and mitigation links for SINAMICS DCP.

Industrial Real Time Devices Update


This update provides additional information on an advisory that was originally published on October 10th, 2019 and most recently updated on January 14th, 2020. The new information includes updated affected version data and mitigation links for SINAMICS DCP.

SIMATIC Update


This update provides additional information on an advisory that was originally published on December 10th, 2019. The new information includes updated affected version data and mitigation links for:

• TIM 1531 IRC;
• SIMATIC NET PC Software

Other Siemens Advisories and Updates


Siemens also published two additional advisories and 3 updates yesterday that have not yet been addressed by NCCIC-ICS.

Additionally, on Monday Siemens published updates of 58 previously published advisories. All of these updates were adding references to the SIPLUS device variants as affected products. Siemens has been adding references to this as they have been updating advisories for the last couple of months, so it looks like they are just doing the final house cleaning on the issue. I do not expect NCCIC-ICS to update all of their applicable advisories.

Tuesday, December 17, 2019

2 Advisories Published – 12-17-19


Today the CISA NCCIC-ICS published two control system security blogs for products from Siemens and GE.

Siemens Advisory


This advisory describes 54 vulnerabilities in the Siemens SPPA-T3000 servers. The vulnerabilities were reported by Gleb Gritsai, Eugenie Potseluevskaya, Sergey Andreev, and Radu Motspan from Kaspersky Lab; Vyacheslav Moskvin, and Ivan B from Positive Technologies; and Can Demirel from Biznet Bilisim Sistemleri ve Danışmanlık. Siemens has an update that mitigates three of the vulnerabilities on one of the affected products. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

Sorry, I am not going to list the 54 vulnerabilities.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to execute arbitrary code on the server, cause a denial-of-service condition, view and modify passwords, gain root privileges, access sensitive information, and read and write arbitrary files on the local system.

NOTE: This is the new vulnerability of the Siemens monthly drop from last week. I briefly discussed these vulnerabilities last Saturday.

GE Advisory


This advisory describes a cross-site scripting vulnerability in the GE S2020/S2020G Fast Switch 61850, a managed Ethernet switch. The vulnerability was reported by Murat Aydemir of Biznet Bilisim A.S.. GE has a new version that mitigates the vulnerability. There is no indication that Aydemir has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to inject arbitrary code and allow disclosure of sensitive data.

Saturday, December 14, 2019

Public ICS Disclosure – Week of 12-07-19


This week we have vendor disclosures from Siemens, Schneider (4) and Red Lion as well as advisory updates from Siemens (2) and Schneider. We also have security researcher reports for products from Advantech (2) and Schneider. And finally, we have an exploit published for products from Omron.

Siemens Advisory


Siemens published an advisory describing 53 vulnerabilities in their SPPA-T3000 servers. Vulnerabilities were reported by Gleb Gritsai, Eugenie Potseluevskaya, Sergey Andreev, and Radu Motspan from Kaspersky Lab; Vyacheslav Moskvin and Ivan B from Positive Technologies; and Can Demirel from Biznet Bilisim. Siemens has a new service pack for one of the affected servers that addresses a very limited number (3) of the applicable vulnerabilities. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

NOTE 1: This is the advisory discussed in the TWITTER® thread I mentioned earlier this week.

NOTE: The first vulnerability reported in the advisory (CVE-2018-4832) was previously reported in other Siemens products. Siemens has not yet provided updates for all of those affected products and this is not one of the vulnerabilities remediated in this advisory.

Siemens Updates


Siemens published an update for an advisory that was originally published on November 12th, 2019. The new information includes:

• Added SIMATIC S7-200 SMART to the list of affected devices; and
• SIPLUS devices now explicitly mentioned in the list of affected products

NOTE: NCCIC-ICS did publish an update for their advisory on this vulnerability on Tuesday, but somehow I overlooked it in my blog post.

Siemens published an update for an advisory that was originally published on July 9th, 2019. The new information includes:

• Updates for SIMATIC IPC2X7E, SIMATIC IPC327E, SIMATIC IPC377E; and
• SIPLUS devices now explicitly mentioned in the list of affected products

Schneider Advisories


Schneider published an advisory describing three improper check for unusual or exception condition vulnerabilities in their Modicon Controllers. The vulnerabilities were reported by Younes Dragoni (Nozomi Networks), Chansim Deng, Mengmeng Young and Gideon Guo. Schneider has new firmware versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Schneider published an advisory describing an improper authorization vulnerability in their EcoStruxure™ Control Expert. The vulnerability was reported by Rongkuan Ma, Xin Che and Peng Cheng (Zhejiang University). Schneider has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Schneider published an advisory describing a stack-based buffer overflow vulnerability in their Power SCADA Operation product. The vulnerability is self-reported. Schneider has a new version that mitigates the vulnerability.

Schneider published an advisory describing a permissions, privileges and access control vulnerability in their EcoStruxure Geo SCADA Expert (ClearSCADA). The vulnerability was reported by William Knowles (Lancaster University). Schneider has a new version that mitigates the vulnerability. There is no indication that Knowles has been provided an opportunity to verify the efficacy of the fix.

NOTE: Earlier this week there had been a fifth advisory listed on the Schneider security notifications site for their Saitel DP (866e) and Saitel DR (HUe) products, but that advisory has since been removed from the list.

Red Lion Advisory


Red Lion published an advisory describing the URGENT/11 vulnerabilities in their NT24k Switch Series. The vulnerability is self-reported. Red Lion has a firmware upgrade the implements the Wind River patch.

Advantech Researher Reports


Mat Powell from the Zero Day Initiative published a report of a zero-day stack-based buffer overflow vulnerability in the Advantech Web Access product. The vulnerability has been coordinated through NCCIC-ICS. Advantech apparently reported that the vulnerability is in a third-party component but has not shared with NCCIC-ICS whom that third-party is. I do not know why NCCIC-ICS has not yet released an advisory on this vulnerability.

Tenable published a report [corrected bad link - 22:10 EDT 3-26-20] describing a stack-based buffer overflow vulnerability in the Advantech Web Access product. Advantech has a new version that Tenable has confirmed mitigates the vulnerability. The Tenable report includes exploit code.

NOTE: The two reports both describe stack-based buffer overflows, but in different components of the product (BwOpcBs.exe in the ZDI report; BwPAlarm.dll in the Tenable report)

Schneider Researcher Report


Applied Risk published a report describing an insecure file permissions vulnerability in the Schneider ClearScada product. This is probably the same vulnerability as described in the Schneider ExoStruxure advisory above as William Knowles is associated with both reports.

Omron Exploit


NOBODY published an exploit for an unrestricted externally accessible lock vulnerability in the Omron CJ2M PLC. This appears to be the same vulnerability that was reported this week.


Thursday, December 13, 2018

5 Advisories and 2 Updates Published – 12-13-18

Today the DHS NCCIC-ICS published four control system security advisories for products from GE, Geutebruck, Siemens and Schneider and one medical device security advisory for products from Medtronic. They also published an update for a previously published control system security advisory for products from Siemens and a medical device security advisory for products from Philips.

GE Advisory


This advisory describes a path traversal vulnerability in the GE Mark VIe, EX2100e, EX2100e_Reg, and LS2100e distributed control systems. The vulnerability was reported by Can Demirel of Biznet Bilisim. GE has a new version that mitigates the vulnerability. There is no indication that Demirel has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to access system data, which could result in escalation of privilege and unauthorized access to the controller.

Geutebruck Advisory


This advisory describes an OS command injection vulnerability in the Geutebruck E2 Camera Series. The vulnerability was reported by Davy Douhine of RandoriSec. Geutebruck has a new version that mitigates the vulnerability. There is no indication that Douhine has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a remote attacker to inject OS commands as root.

Siemens Advisory


This advisory describes two improper input validation vulnerabilities in the Siemens EN100 Ethernet Communication Module and SIPROTEC 5 relays. These vulnerabilities were reported by Victor Nikitin, Vladislav Suchkov, and Ilya Karpov from ScadaX. Siemens has updates for some of the affected products and continues to work on updates for the remaining products.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to cause a denial-of-service condition of the network functionality of the device, compromising the availability of the system.

NOTE: This advisory was published when Siemens published an update last Tuesday. The original Siemens advisory was reported here back in July, 2018.

Schneider Advisory


This advisory describes three vulnerabilities in the Schneider Electric GUIcon. The vulnerabilities were reported by mdm and rgod of 9SG Security Team. Schneider has a new version that mitigates the vulnerabilities. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Type confusion (2) - CVE-2018-7813 and CVE-2018-7815; and
• Stack-based buffer overflow - CVE-2018-7814

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to execute code with privileges within the context of the application.

NOTE: I briefly reported the Schneider advisory last Saturday.

Medtronic Advisory


This advisory describes a missing encryption of sensitive data vulnerability in the Medtronic 9790 CareLink Programmer, 2090 CareLink Programmer, 29901 Encore Programmer; programmers for Medtronic cardiac devices. The vulnerabilities were reported by Researchers Billy Rios and Jonathan Butts of Whitescope LLC. Medtronic has provided generic workarounds for two of the devices and reports that the 9970 is out of support and all use should be discontinued. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an relatively low-skilled attacker with physical access to the devices could exploit the vulnerability to access PHI or PII stored on the device.

Siemens Update

This update provides additional information for an advisory that was originally published on March 29th, 2018 and updated on April 24th, 2018, June 12th, 2018 and again on November 14th, 2018. The update provides updated affected version information and mitigation links for SIMATIC NET PC-Software.

NOTE: Siemens updated their advisory on Tuesday and then again today. This NCCIC-ICS update reflects the corrected information published by Siemens today.

Philips Update


This update provides additional information for an advisory that was originally published on March 27th, 2018 and subsequently updated on December 11th, 2018. The updated information includes revised affected version data.

More Missing Siemens Updates


Siemens published four more updates today; only one of those was addressed by NCCIC-ICS today. It will be a long blog post here on Saturday. 

Wednesday, October 3, 2018

Three Advisories and Three Updates Published


Yesterday the DHS NCCIC-ICS published three control system security advisories for products from Entes, GE and Delta Electronics. They also updated previously published advisories for products from Phillips, WECOM and ABB.

Entes Advisory


This advisory describes two vulnerabilities in the Entes EMG 12, an Ethernet Modbus Gateway. The vulnerability was reported by Can Demirel of Biznet Bilisim. Entes has a new firmware version that mitigates the vulnerabilities. There is no indication that Demirel has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper authentication - CVE-2018-14826; and
Information exposure in query strings in get request - CVE-2018-14822

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to gain unauthorized access and could allow the ability to change device configuration and settings.

GE Advisory


This advisory describes a heap based buffer overflow in the GE Communicator application. The vulnerability was reported by kimiya, working with iDefense Labs. Newer versions of the application mitigate the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to execute arbitrary code or create a denial-of-service condition.

Delta Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Delta ISPSoft, a PLC program development tool. The vulnerability was reported by Ariele Caltabiano (kimiya) via ZDI. Newer versions of the tool mitigate the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to execute code under the context of the application.

Phillips Update


This update provides additional information on an advisory that was originally published on March 29th, 2018. The update adds the phrase “and/or system information” to the description provided for ‘information exposure’ vulnerabilities.

WECON Update


This update provides additional information on an advisory that was originally published on July 31st, 2018. The updated information includes:

• Two new vulnerabilities added, and
• Added a third reporting security researcher.

I would have normally expected this to be a separate advisory, but since the original advisory was based upon information provided via the Zero Day Initiative, I suspect that there was an issue on that end of the process that is being corrected here.

ABB Update


This update provides additional information on an advisory that was originally published on August 28th, 2018. The update provides new mitigation information.

Saturday, March 3, 2018

Public ICS Disclosures – Week of 2-24-18


We have two new vendor security advisories this week from Schneider and Siemens. Siemens also published an update to their ultrasound products notice for the WannaCry vulnerability. I mentioned the Siemens advisory and update in passing earlier this week.

Schneider Advisory


This advisory describes 11 vulnerabilities in the Pelco Sarix Professional fixed IP video surveillance cameras. The vulnerabilities were variously reported by Deng Yongkai of NSFOCUS Security Team, Melih Berk Eksioglu of Biznet Bilisim A.S., and Gjoko Krstic of Zero Science Labs. Schneider has a new firmware version that mitigates the vulnerabilities. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The reported vulnerabilities include:

• Information disclosure - CVE-2018-7227;
• Authentication bypass (3) - CVE-2018-7228, CVE-2018-7229, and CVE-2018-7236;
• XML external entity vulnerability - CVE-2018-7230;
• Command execution vulnerability (4) - CVE-2018-7231, CVE-2018-7232, CVE-2018-7233, and CVE-2018-7235;
• Arbitrary file download - CVE-2018-7234; and
Arbitrary file delete - CVE-2018-7237

ICS-CERT has published some surveillance camera security advisories, but it has been hit and miss. My coverage here has also been hit and miss since I lost (paid) access to the IPVM web site; they are certainly the best information source for vulnerability information (and lots of other information) on video systems. Since Schneider owns Pelco, there will be specific coverage in these weekly posts as appropriate since Schneider publishes a list of advisories as they are issued. That does not mean that other video systems are vulnerability free, just that I have not seen their reports.

Siemens Advisory


This advisory describes 8 vulnerabilities in the Siemens SIMATIC industrial PCs. The vulnerabilities are due to the presence of one or more of three Intel products in the PCs; Intel reported on these vulnerabilities back in November, 2017. Siemens has identified a generic work around for the vulnerabilities and there is no indication that further mitigations are in the works.

The reported vulnerabilities include:

• Buffer overflow (5) - CVE-2017-5705, CVE-2017-5706, CVE-2017-5707, CVE-2017-5711, and CVE-2017-5712; and
• Privilege escalation (3) - CVE-2017-5708, y CVE-2017-5709, and CVE-2017-5710;

The underlying Intel problems are wide spread and relatively serious. The Siemens advisory does not comment on the Intel mitigation measures (required dual firmware and software updates) nor the Intel detection tool. I wonder if they are still checking to see if those mitigations are compatible with their products or whether they are working on updates that will work with the Intel mitigation measures. It is not like Siemens not to provide this type of information.

Siemens Update


This update describes new mitigation information for the WannaCry vulnerability in the Siemens Healthineers ultrasound products. Technically, this update was included (but certainly not mentioned) in the latest ICS-CERT update of their WannaCry Alert (dated June 13th, 2017) since the link for this product line automatically takes one to the latest version.

Thursday, January 25, 2018

ICS-CERT Publishes 3 Advisories and 5 Siemens Updates

Today the DHS ICS-CERT published two control system security advisories for products from Siemens and Nari as well as a medical control system security advisory for products from Philips. They also updated five control system security advisories from Siemens.

Philips Advisory


This advisory describes an insufficient session expiration advisory for the Philips IntelliSpace Cardiovascular cardiac image and information management systems. According to the Philips product security page this vulnerability was identified based upon a customer submitted complaint. Philips plans on releasing an updated version to mitigate the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker with local access could exploit the vulnerability  to gain unauthorized access to sensitive information stored on the system and modify this information.

NOTE: This vulnerability was not reported on the FDA medical device safety communications page, probably because an exploit would only reveal personally identifiable information making this more of a HIPAA problem. Unfortunately, I cannot find (after an admittedly brief search) a software vulnerability reporting page on the HHS HIPAA site.

Siemens Advisory


This advisory describes an improper authentication vulnerability in the Siemens Desigo PXC. The vulnerability was reported by Can Demirel and Melih Berk Eksioglu from Biznet Bilisim. Siemens has provided an updated version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability to  allow unauthenticated remote attackers to upload malicious firmware without prior authentication.

BTW: Siemens tweeted this morning about another new advisory that they have just published. That will probably show up next week on the ICS-CERT site.

Nari Advisory


This advisory describes an improper input validation vulnerability in the Nari PCS-9611 relay, a control and monitoring unit. The vulnerability was reported by Kirill Nesterov and Alexey Osipov from Kaspersky Labs. Nari has not responded to ICS-CERT about this reported vulnerability.

ICS-CERT reports that a relatively low-skilled attacker could use a publicly available exploit to remotely exploit the vulnerability to gain arbitrary read/write abilities on the system.

Industrial Products (older advisory) Update



• SINEMA Remote Connect Client: All versions prior to V1.0 SP3;

NOTE: The revised Siemens security notice also changed the temporary mitigation measures for SIMATIC PCS 7 V8.1, but that was not mentioned in the ICS-CERT update.

S7-300 Update


This update provides new information for an advisory that was originally published on December 13th, 2016 and then updated on May 9th, 2017, July 25th, 2017, and again on November 28th, 2017. The new information includes the addition of two new affected products along with mitigation links:

• SIMATIC S7-400 V7 CPU family; and
• SIMATIC S7-410 V8 CPU family
NOTE: The revised Siemens security notice reports that the S7-410 V8 CPU family is only affected by the inadequate encryption strength vulnerability.

PROFINET Update


This update provides new information for an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th,  November 28th, 2017, and most recently January 18th, 2018. The new information includes new affected version data and mitigation links for:

• S7-400 PN/DP V7 Incl. F: All versions prior to V7.0.2
• SINAMICS DCP w. PN: All versions prior to V1.2 HF 1

SCALANCE Update


This update provides new information for an advisory that was originally published on November 14th, 2017 and updated on December 5th, 2017, and again on December 19th, 2017. The new information includes new affected version data and mitigation links for:


• SCALANCE WLC711: All versions prior to V9.21.19.003; and
• SCALANCE WLC712: All versions prior to V9.21.19.003


Industrial Products (newer advisory) Update


This update provides new information for an advisory that was originally published on December 5th, 2017 and updated on December 19th, 2017 and again on January 23rd, 2018. The new information includes new affected version data and mitigation links for:


• SIMATIC S7-400 PN/DP V7: All versions prior to V7.0.2; and
• SIMATIC ET 200MP: All versions prior to V4.0.2

Commentary


Even if Siemens does not issue any more multiple product advisories in the near future (not likely, they have obviously shared a bunch of code across product lines over the years) we will continue to see large numbers of these advisory updates over the next year or so. Unfortunately, while vulnerable code is relatively easy to share, fixes cannot be cut and pasted so easily; too many dependencies, loops, etc. to check and modify as necessary. These time and resource-consuming exercises being undertaken by Siemens are a good example of why secure coding practices are so important; it really is easier over the life of the product to do it right the first time.


It would really be a good cybersecurity grad-student project to look at the costs that Siemens is expending to go back and correct mistakes that should have been caught before they ever made it to market.

Wednesday, May 17, 2017

ICS-CERT Updates WannaCry Alert and Publishes 4 Advisories

Yesterday the DHS ICS-CERT updated their earlier alert on the WannaCry ransomware. They also published four control system security advisories for products from Schneider Electric (2), Hanwha Techwin, and Detcon.

WannaCry Update


This update provides additional information on the alert that was issued yesterday. The new information includes:

• Links to two new vendor advisories from ABB and Siemens; and
• Links to some generic information (here and here) from the FDA on medical device security.

Siemens makes an important point about medical device cybersecurity:

“We would like to point out that neither the use of an email client nor browsing the internet is part of the intended use of most of the product types covered by this Siemens Security Bulletin.”

The ABB document does mention restricting SMB protocol use but stops short of recommending disabling the protocol as suggested by Microsoft. They do note:

“This will help to prevent spreading of the WannaCry malware from individual compromised computers. For specific guidance please see additional communication for specific ABB solutions and contact your local ABB service organization.”

NOTE: The US-CERT also updated their alert for this malware.

Schneider VAMPSET Advisory


This advisory describes an improper input validation vulnerability in the Schneider VAMPSET tool. The vulnerability was reported by Kushal Arvind Shah from Fortinet's Fortiguard Labs. Schneider has produced a new firmware version to mitigate the vulnerability. There is no indication that Shah has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker with local access could exploit the vulnerability to cause the software to enter a denial-of-service condition. The Schneider Security Notification reports that vulnerability has no effect on the operation of the protection relay to
which VAMPSET is connected.

Techwin Advisory


This advisory describes an improper access control vulnerability in the Hanwha Techwin SRN-4000 network video management platform. The vulnerability was reported by Can Demirel and Faruk Unal of Biznet Bilisim. Techwin reports that a newer version mitigates the vulnerability. ICS-CERT reports that the researchers have verified the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to allow the attacker remote access to the web management portal with admin privileges without authentication.

Schneider SoMachine Advisory

This advisory describes two vulnerabilities in the Schneider SoMachine HVAC software. The vulnerabilities were separately reported by Zhou YU and Himanshu Mehta. Schneider reports that a newer version mitigates the vulnerability. There is no indication that either researcher has been provided the opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2017-7965; and
• Uncontrolled search path element - CVE-2017-7966

ICS-CERT reports that a relatively unskilled attacker (no access characterization) could exploit the vulnerability to allow arbitrary code execution and could cause the device that the attacker is accessing to crash due to a buffer overflow condition.

NOTE: The Schneider Security Notification only addresses the buffer overflow vulnerability.

Detcon Advisory


This advisory describes two vulnerabilities in the Detcon SiteWatch Gateway. The vulnerabilities were reported by Maxim Rupp. ICS-CERT reports that Detcon no longer owns or services the SiteWatch Gateway product, but it attempting to notify customers of the vulnerabilities.

The two reported vulnerabilities are:

• Improper authentication - CVE-2017-6049; and
• Plaintext storage of passwords - CVE-2017-6047


ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to allow remote code execution. An attacker who exploits these vulnerabilities may be able to change settings on the affected product or obtain user passwords.
 
/* Use this with templates/template-twocol.html */