Showing posts with label Borja Merino. Show all posts
Showing posts with label Borja Merino. Show all posts

Saturday, October 12, 2019

Public ICS Disclosures – Week of 09-05-19


This week we have URGENT/11 updates from three ICS vendors; seven new vendor disclosures from Siemens, Schneider (4), Beckhoff (2) and Drager; six updates of previously issued advisories from Siemens (2), Schneider (3) and Yokogawa, and one exploit of a previously reported vulnerability for products from SMA Solar Technology.

URGENT/11 Updates



Siemens Advisory


Siemens published an advisory describing twelve vulnerabilities in the Siemens SIMATIC WinAC
RTX (F) 2010. These vulnerabilities are known as Spectre, Meltdown, Spectre-NG, Foreshadow, L1 Terminal Fault (L1TF), ZombieLoad, and Microarchitectural Data Sampling (MDS). These vulnerabilities were reported by various researchers. Siemens has an update that mitigates the vulnerabilities.

Schneider Advisories


Modicon Controllers Advisory #1

Schneider published an advisory describing a file and directory information disclosure vulnerability in the Schneider Modicon brand of programmable logic controllers. The vulnerability was reported by Jared Rittle (Cisco Talos); the report includes proof-of-concept (POC) code. Schneider provides generic workarounds to mitigate the vulnerability.

Modicon Controllers Advisory #2

Schneider published an advisory describing six vulnerabilities in the Schneider Modicon brand of programmable logic controllers. The vulnerabilities were reported by Jared Rittle and Patrick DeSantis (Cisco Talos) (the CVE links below are to the individual reports which contain POC code). Schneider provides generic workarounds to mitigate the vulnerability.

The six reported vulnerabilities are:

Uncaught exception (5) - CVE-2019-6841, CVE-2019-6842, CVE-2019-6843, CVE-2019-6844 and CVE-2019-6847; and
Clear-text transmission of sensitive information - CVE-2019-6846;

Modicon Controllers Advisory #3

Schneider published an advisory describing a clear-text transmission of sensitive information vulnerability in the Schneider Modicon brand of programmable logic controllers. The vulnerability was reported by Jared Rittle (Cisco Talos). Schneider provides generic workarounds to mitigate the vulnerability.

Modicon Controllers Advisory #4

Schneider published an advisory describing three vulnerabilities in the Schneider Modicon brand of programmable logic controllers. The vulnerabilities were reported by Jared Rittle (Cisco Talos) (the CVE links below are to the individual reports which contain POC code). Schneider provides generic workarounds to mitigate the vulnerability.

The three reported vulnerabilities are:

Uncaught exception vulnerability - CVE-2019-6848; and
Information exposure (2) - CVE-2019-6849 and CVE-2019-6850

Beckhoff Advisories


TwinCat Advisory

VDE-CERT published an advisory describing a divide by zero vulnerability in the Beckhoff TwinCAT real-time controller. The vulnerability was reported by Andreas Galauner from Rapid7. The Beckhoff advisory on this vulnerability reports that they are working on an update to mitigate the vulnerability.

CE Remote Display Advisory

Beckhoff published an advisory describing an incorrect login response vulnerability in the Beckhoff CE Remote Display. The vulnerability was reported by Chen Jie from NSFOCUS and Tijl Deneut from University Howest. Beckhoff has updates that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Drager Advisory


Drager has published an advisory describing three vulnerabilities in the Drager Infinity® M300 patient monitor. Drager is self-reporting the vulnerabilities. Drager will be releasing a new version to mitigate the vulnerabilities in March 2020.

The three reported vulnerabilities are:

Network DDOS attack;
Repeated DDOS attacks; and
Information exposure

Siemens Updates


Industrial Products Update

Siemens published an update for an advisory that was originally published in May of 2017 and most recently updated on February 14th, 2019. The new information includes:

• Merged WinAC RTX 2010 SP2 and WinAC RTX F 2010 SP2 to SIMATIC WinAC RTX (F) 2010; and
• Added mitigation information for SIMATIC WinAC RTX (F) 2010

NOTE: I expect NCCIC-ICS to update their advisory this week.

SIMATIC S7 Update

Siemens published an update for an advisory that was originally reported in November 2018 and most recently updated on August 13th, 2019. The new information includes:

• Added CVE-2019-1125, CVE-2019-15666 and CVE-2019-15903; and
• Removed CVE2018-19591 from the list of fixed vulnerabilities

NOTE: NCCIC-ICS has not addressed these Linux vulnerabilities.

Schneider Updates


Floating License Manager Update

Schneider published an update for an advisory that was originally published in May 2019 and most recently updated on September 10th, 2019. The new information is updated remediations for EcoStruxure Power
Monitoring Expert.

NOTE: NCCIC-ICS may update their advisory, but they did not update for the last Schneider update.

SoMachine Update

Schneider published an update for an advisory that was originally published on August 13th, 2019. The new information is adding SoMove FDT to the list of affected products.

NOTE: NCCIC-ICS did not address this vulnerability.

Embedded Web Server Update

Schneider published an update for an advisory that was originally published in November 2018 and most recently updated on June 11th, 2019. The new information includes mitigation information for the M340 controller.

 NOTE: NCCIC-ICS did not address these vulnerabilities.

Yokogawa Update


Yokogawa published an update for an advisory that was originally published on September 27th, 2019. The new information includes updated affected version data and mitigation measures for Exaquantum.

NOTE: NCCIC-ICS will probably update their advisory this week.

SMA Exploit


Borja Merino published an exploit for a cross-site forgery vulnerability in the SMA Sunny WebBox. An advisory for the vulnerability was published on October 8th, 2019.

Wednesday, October 9, 2019

4 Advisories and 6 Updates Published – 10-08-19


Yesterday the DHS NCCIC-ICS published four control system security advisories for products from Siemens (2), GE and SMA Solar Technology. They also updated a medical device advisory for products from BD and five control system advisories for products from Siemens.

SIMATIC Advisory #1


This advisory describes a use of hard-coded cryptographic key vulnerability in the Siemens SIMATIC IT Unified Architecture Discrete Manufacturing (UADM). This vulnerability is self-reported. Siemens has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to gain read and write access to the related TeamCenter station. The Siemens advisory notes that the remote attacker would have to be authenticated and have network access to network access to port 1434/tcp of SIMATIC IT UADM to exploit the vulnerability.

SIMATIC Advisory #2

This advisory describes an uncontrolled resource consumption vulnerability in the Siemens SIMATIC WinAC RTX (F) 2010. The vulnerability was reported by Tal Keren from Claroty. Siemens has provided generic workarounds to mitigate the vulnerability. There is no indication that Keren was provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to perform a denial-of-service attack that could compromise the availability of the service provided by the software.

GE Advisory

This advisory describes two vulnerabilities in the GE Mark VIe Controller. The vulnerabilities were reported by Sharon Brizinov of Claroty. GE provides generic workarounds to mitigate the vulnerability. There is no indication that Brizinov has been proved an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Improper authorization - CVE-2019-13554; and
Use of hard-coded credentials - CVE-2019-13918

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to create read/write/execute commands within the Mark VIe control system.

SMA Advisory


This advisory describes a cross-site request forgery vulnerability in the SMA Sunny WebBox. The vulnerability was reported by Borja Merino and Eduardo Villaverde of the Technical Inspection Laboratory of the Mining School (University of León). SMA provides generic workarounds for this end-of-life product. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to generate a denial-of-service condition, modify passwords, enable services, achieve man-in-the-middle, and modify input parameters associated with devices such as sensors.

BD Update


This update provides additional information on an advisory that was originally published on September 5th, 2019. The updated information includes:

Revised affected versions for Pyxis ES Versions; and
New mitigation measures for all products

Industrial Product Update #1

This update provides additional information on an advisory that was originally published on September 10th, 2019. The new information includes revised affected versions and mitigation measures for:

SINUMERIK 840D sl;
SINUMERIK 828D; and
SINUMERIK 808D

NOTE: This advisory describes the Siemens response to the Linux TCP SACK PANIC vulnerabilities.

SIMATIC Update #1


This update provides additional information on an advisory that was originally published on March 9th, 2019 and last updated on July 9th, 2019. The new information includes:

Renaming SIMATIC WinAC RTX 2010 to SIMATIC WinAC RTX (F) 2010;
Updating affected version numbers for SIMATIC WinAC RTX (F) 2010; and
Providing mitigation information for SIMATIC WinAC RTX (F) 2010

SIMATIC Update #2


This update provides additional information on an advisory that was originally published on May 20th, 2018 and most recently updated on May 14th, 2019. The new information includes:

Renaming SIMATIC WinAC RTX 2010 to SIMATIC WinAC RTX (F) 2010;
Updating affected version numbers for SIMATIC WinAC RTX (F) 2010; and
Providing mitigation information for SIMATIC WinAC RTX (F) 2010

Industrial Products Update #2


This update provides additional information on an advisory that was originally published on December 5th, 2017 and most recently updated on March 12th, 2019. The new information includes:

Renaming SIMATIC WinAC RTX 2010 to SIMATIC WinAC RTX (F) 2010;
Updating affected version numbers for SIMATIC WinAC RTX (F) 2010; and
Providing mitigation information for SIMATIC WinAC RTX (F) 2010

PROFINET Update


This update provides additional information on an advisory that was originally published on May 9th, 2017 and most recently updated on February 5th, 2019. The new information includes:

Renaming SIMATIC WinAC RTX 2010 to SIMATIC WinAC RTX (F) 2010;
Updating affected version numbers for SIMATIC WinAC RTX (F) 2010; and
Providing mitigation information for SIMATIC WinAC RTX (F) 2010

Other Siemens Announcements


Yesterday Siemens announced a total of five new security advisories and ten advisory updates. Some will be covered (hopefully) later this week by NCCIC-ICS and the remainder I will discuss Saturday.

 
/* Use this with templates/template-twocol.html */