Showing posts with label Bolshev. Show all posts
Showing posts with label Bolshev. Show all posts

Monday, January 12, 2015

ICS-CERT Extends Emerson Advisory

Today the DHS ICS-CERT published a new advisory for the vulnerability they reported in the Emerson HART DTM last week. The difference is that instead of just limiting the advisory to Emerson HART DTM they are extending it to all versions of the DTM that use the same DTM libraries produced by CodeWrights. Specifically they include HART systems from:

● ABB,
● Berthold Technologies,
● Emerson,
● Endress+Hauser,
● Magnetrol, and
● Pepperl+Fuchs.

As with the revised advisory published on Friday, ICS-CERT claims that there are no publicly available exploits of these vulnerabilities. CodeWrights has developed a new version of the library and Emerson has tested the library to validate its efficacy. No one has apparently asked the original researcher, Alexander Bolshev, to validate the new library efficacy.


At this point it seems that only Emerson has fixed the vulnerability in their use of the libraries. ICS-CERT states that it will update this advisory when additional reports of fixes have been provided. They also note that CodeWrights is only providing the updated libraries to ‘customers with current support agreements’. This would seem to suggest that other vendors with HART applications may be using the same affected libraries.

Thursday, January 8, 2015

ICS-CERT Publishes First Advisories of New Year

This afternoon the DHS ICS-CERT published two new advisories for industrial control system vulnerabilities in specific equipment from Scheneider and Emmerson.

Schneider Advisory

This advisory describes a stack-based buffer overflow vulnerability in the Wonderware InTouch Access Anywhere Server product that was apparently self-identified. Schneider has a product security update that mitigates the vulnerability.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to execute arbitrary code. If Schneider has any additional information about this vulnerability they are restricting access to that information to just customer. Okay, I don’t really blame them, but it sure makes writing about the vulnerability difficult.

Emerson Advisory

This advisory describes an improper input vulnerability in the CodeWrights HART Device Type Manager (DTM) library utilized in Emerson’s HART DTM reported by Alexander Bolshev in a coordinated disclosure.  CodeWrights has produced a new library that Emmerson has verified mitigates the vulnerability. ICS-CERT and Emerson both claim that this vulnerability does not affect field devices or WirelessHART devices.

ICS-CERT reports that physical access to the Hart loop is required to exploit this vulnerability, but they also report that exploits are publicly available (See 2014 BlackHat presentation by Bolshev). This leads to the Emerson mitigation recommendation that, in addition to updating the HART DTM, Emerson recommends having physical protection of the end users’ entire infrastructure.


Emerson has a neat little side comment in their discussion about updating the HART DTM that apparently ICS-CERT overlooked. Emmerson reported that: “Note: This updated DTM will NOT fix other vendors DTMs affected by this issue.” One assumes that Emerson expects that other vendors are also using similar DTM libraries. That might have been something good for ICS-CERT to mention.
 
/* Use this with templates/template-twocol.html */