Showing posts with label BlueKeep. Show all posts
Showing posts with label BlueKeep. Show all posts

Saturday, July 18, 2020

Public ICS Disclosures – Week of 7-11-20


This week we have four Ripple20 vendor disclosures from Siemens, ABB, Rockwell, Carestream and Schneider Electric; two SigRed vendor disclosures from Philips and GE Healthcare; and three other vendor disclosures from HMS and Schneider (2). Four vendor updates from Schneider (2) and Siemens (2) and  two researcher disclosures for products from Siemens and Advantech round out the weeks’ offerings.

Ripple20 Disclosures and Updates


Siemens published a Ripple20 advisory for their SPPA-T3000 Solutions distributed control system. Siemens provides generic mitigation measures for these vulnerabilities.

NOTE: Siemens published a note at the top of their Security Publications page noting that:

“No Siemens product is known to use Treck Inc.'s TCP/IP stack, or otherwise be affected by the reported vulnerabilities.
“Note that Siemens products and systems might interact with products from other manufacturers which are affected by the reported vulnerabilities. In such cases Siemens recommends that owners of operational infrastructures verify if these products are affected and evaluate the potential impact of the Ripple20 vulnerabilities.”

Since the SPPA-T3000 advisory also contains two Intel Server Platform Services vulnerabilities, I suspect that the Ripple20 vulnerabilities come with the Intel server upon which the T-3000 is built.

ABB published a Ripple20 advisory. The advisory contains a list of affected products and generic mitigation measures pending further work to address the vulnerabilities.

Rockwell updated their Ripple20 advisory. The new information includes an updated table of affected products.

Carestream updated their Ripple20 advisory (.PDF download link). The new information includes adding 20 products that were on the ‘still evaluating list’ to the not affected list. The list of affected products has not changed.

Schneider updated their Ripple20 advisory. The new information includes removing the “Smartlink ELEC” from the list of affected products.

SigRed Disclosures


SigRed is the ‘cute’ name given to the Microsoft ‘wormable’ remote code execution DNS vulnerability (CVE-2020-1350).

Phillips published a SigRed advisory noting that: “Philips is currently in the process of evaluating the Microsoft patch and vendor recommended mitigation options.”


GE Healthcare published a SigRed advisory noting that: “GE Healthcare is actively assessing products that utilize impacted Microsoft Operating Systems.”

Neither of these advisories provide much in the way of information beyond noting that a vague ‘some’ of their products may be affected.

Vendor Disclosures


HMS published an advisory describing a remote code execution vulnerability in their eCatcher product. The vulnerability was reported by Claroty. HMS has an update that mitigates the vulnerability. There is no indication that Claroty was provided an opportunity to verify the efficacy of the fix.

Schneider published an advisory describing an open redirect vulnerability in their Schneider Electric Software Update (SESU). The vulnerability was reported by Amir Preminger of Claroty. Schneider has a new version that mitigates the vulnerability. There is no indication that Preminger has been provided an opportunity to verify the efficacy of the fix.

Schneider published an advisory describing two denial of service vulnerabilities in their Floating License
Manager. These are third-party vulnerabilities in the Flexera FlexNet Publisher (reported here and here). Schneider has a new version that mitigates these vulnerabilities.

NOTE: Flexera is also reporting three other vulnerabilities (CVE-2019-8963, CVE-2020-12080, and CVE-2020-12081) that could potentially affect the Schneider Floating License Manager and a variety of other vendor ‘license manager’ products based upon the Flexera product.

Vendor Updates


Schneider updated their ZombieLoad advisory. The new information includes updated mitigation measures for the HMI products.

Schneider updated their BlueKeep advisory. The new information includes updated mitigation measures for the HMI products.

Siemens updated their Vulnerabilities in Intel CPUs advisory. The new information includes:

• Updated mitigation and affected version information for SIMATIC ITP1000, and
• Removed SIMATIC IPC827E from list of affected devices

Siemens updated heir GNU/Linux advisory. The new information includes adding:

CVE-2020-12114,
• CVE-2020-12659,
• CVE-2020-13630,
• CVE-2020-13631, and
• CVE-2020-13632

Researcher Disclosures


Talos published a report on the Siemens LOGO web server vulnerability that was reported earlier this week. The Talos report includes proof-of-concept code for the vulnerability.

The Zero Day Initiative published 43 reports, all based upon research by rgod, about the Advantech iView vulnerabilities that were reported earlier this week. Most of the reports provided more details on the three CVE’s listed in the NCCIC-ICS advisory. One of the reports, however, described an input validation vulnerability that was not reported by NCCIC-ICS.

Tuesday, February 18, 2020

4 Advisories and 1 Update Published – 2-18-20


Today the CISA NCCIC-ICS published two control system security advisories for products from Emerson and Honeywell, two medical device security advisories for products from GE and Spacelabs, and 1 update for products from Interpeak.

Emerson Advisory


This advisory describes a heap-based buffer overflow vulnerability in the Emerson OpenEnterprise SCADA Server. The vulnerability was reported by Roman Lozko of Kaspersky ICS CERT. Emerson has an upgrade that mitigates the vulnerability. There is no indication that Lozko has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit this vulnerability to allow an attacker to execute code on an OpenEnterprise SCADA Server.

Honeywell Advisory


This advisory describes a clear-text storage of sensitive information vulnerability in the Honeywell INNCOM INNControl 3 energy management platform. The vulnerability is self-reported. Honeywell has an upgrade available to mitigate the vulnerability.

NCCIC reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to escalate user privileges within the INNControl application.

GE Advisory


This advisory describes a protection measure failure vulnerability in the GE Ultrasound Products. The vulnerability was reported by Marc Ruef and Rocco Gagliardi of scip AG. GE has provided generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with local access could exploit the vulnerability to allow an attacker to gain access to the operating system of affected devices.

Spacelabs Advisory


This advisory describes the BlueKeep vulnerability in the Spacelabs Xhibit Telemetry Receiver. Spacelabs has an updated version that mitigates the vulnerability.

NOTE: A number of other vendors in both the control system and medical device realms issued advisories on this vulnerability (see my blog post here for example) beginning in May of last year. This is the first acknowledgement of vendor actions on this vulnerability from NCCIC-ICS though there was an obscure advisory on the vulnerability published by NCCIC-ICS.

Interpeak Update


This update provides additional information on the Urgent/11 advisory that was originally published on October 1st, 2019 and most recently updated on December 10th, 2019. The new information includes a link to a vendor advisory from Mitsubishi.

Saturday, November 23, 2019

Public ICS Disclosures – Week of 11-16-19


This week we have four vendor disclosures for products from 3S, Moxa (2) and Johnson Controls. There are also three exploit reports for products from Emerson, FlowChief, and GE.


3S Advisory


3S published an advisory describing a heap-based buffer overflow vulnerability in their CODESYS V3 web server. The vulnerability was reported by an OEM customer and Tenable, Inc. 3S has a new version that mitigates the vulnerability. There is no indication that Tenable was provided an opportunity to verify the efficacy of the fix.

NOTE 1: The Tenable report provides proof-of-concept exploit code.

NOTE 2: A reminder that 3S (Codesys) software is included in product from a large number of vendors (including the unnamed ‘OEM vendor’ who reported the vulnerability to 3S). Other vendors will have to fix the problem in their systems.

Moxa Advisories


Moxa published an advisory describing a denial of service vulnerability in the PROFINET implementation in their Moxa’s EDS-G508E, EDS-512E, and EDS-516E Series Ethernet Switches. The vulnerability was reported by Yuval Ardon and Matan Dobrushin of Otorio. Moxa has a patch available that mitigates the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

Moxa published an advisory describing an improper sanitization of special elements used in Web GUI in their EDR-810 Series Secure Routers. The vulnerability was reported by Neil Pope and Rhys Cable of Motherwell Advanced Technologies Cyber Review Team. Moxa has a new firmware version that mitigates the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

Johnson Controls Advisory


Johnson Controls has published an advisory on the BlueKeep vulnerability in their  4190 PC Annunciator product running on Windows 7® systems. The 4190 PC Annunciator is out-of-support and Johnson Controls has no replacement product.

Emerson Exploit


Luiz Martinez published an exploit for an unquoted service path vulnerability in the Emerson PAC Machine. There is no CVE number associated with this report and no information about coordination with Emerson. This may be a 0-day exploit.

FlowChief Exploit


Luiz Martinez published an exploit for a denial-of-service vulnerability in the FlowChief scadaApp for iOS. There is no CVE number associated with this report and no information about coordination with FlowChief. This may be a 0-day exploit.

GE Exploit


Luiz Martinez published an exploit for a denial-of-service vulnerability in the GE Open Proficy HMI-SCADA app. There is no CVE number associated with this report and no information about coordination with GE. This may be a 0-day exploit.

Commentary


With all three of the above exploits being potential 0-days, the question will certainly arise; why did I publish these notices? Am I not giving publicity to researchers who cannot be bothered coordinating their disclosures? My intention is to ensure that the users of the affected systems know that public exploits are available. This would be valuable information for risk assessment purposes and lacking the information that is widely available to the ‘bad guys’ is not a good way to stay safe and secure.

Now I would much rather see researchers like Martinez coordinate their disclosure with the vendor or one of any of a wide variety of disclosure coordinators (NCCIC-ICS or ZDI for instance). Lacking that, I would rather see them publishing on public forums like FullDisclosure or exploit-DB than selling the exploits on the DarkWeb.

Saturday, September 28, 2019

Public ICS Disclosures – Week of 09-21-19


This week we have four vendor disclosures for products from ABB, Schneider, Sick, and Yokogawa  and one vendor update for products from Schneider.

ABB Advisory


ABB published an advisory reporting that two of the Wind River URGENT/11 vulnerabilities affected their AC 800M controllers. ABB provides generic work arounds while it is working on new versions to mitigate the vulnerabilities.

Schneider Advisory


Schneider published an advisory describing the Microsoft Windows® DejaBlue vulnerabilities in a list of Schneider products. Schneider recommends applying the appropriate Windows updates for some products and provides generic workarounds for others.

Schneider Update


Schneider published an update for their advisory on the effect of the BlueKeep {Microsoft® RDP vulnerability (CVE-2019-0708)} on a list of their products. They added “Conext Control” to list of affected products.

Sick Advisory


Sick published an advisory describing a buffer overflow vulnerability in the Sick FX0-GENT00000 and FX0-GPNT00000 safety controllers. The vulnerability was reported by the security-testlab team of Fraunhofer IOSB. Sick has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Yokogawa Advisory


Yokogawa published an advisory describing an unquoted service path vulnerability in a list of their products. This vulnerability is self-reported. Yokogawa has new versions and patches to mitigate the vulnerability.

 
/* Use this with templates/template-twocol.html */