Showing posts with label COMOS. Show all posts
Showing posts with label COMOS. Show all posts

Friday, December 13, 2013

ICS-CERT Publishes Late Siemens Advisory

This morning the DHS ICS-CERT published an advisory for an escalation of privilege vulnerability in the Siemens COMOS database application. The vulnerability was self-reported last week by Siemens and an update has been made available for the latest versions of the product.

ICS-CERT reports that a relatively low skilled attacker with authenticated local access to the database could exploit this vulnerability to compromise of the confidentiality, integrity, and availability of the database.


Siemens has revised their advisory that I mentioned last week with additional contact information. I notice that this is the second privilege escalation vulnerability that Siemens has reported in their COMOS product; the earlier advisory was published in August (ICS-CERT Advisory - ICSA-12-227-01; that was also late reported by ICS-CERT).

Friday, December 6, 2013

ICS-CERT Publishes RuggedCom Advisory

This afternoon the DHS ICS-CERT published an advisory for a pair of self-reported vulnerabilities in the RuggedCom devices with ROS firmware. Siemens reported the vulnerabilities today as well as announcing the availability of a firmware update that mitigates the vulnerabilities.

ICS-CERT describes the vulnerabilities as:

• Use of insufficiently random values, CVE-2013-6925; and
• Authentication bypass issues, CVE-2013-6926
NOTE: The CVE links are not yet active.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to be able to perform limited administrative operations over the network. Siemens notes that an attacker must have network access (port 443/tcp) to the affected devices for both vulnerabilities.


BTW: Siemens ProductCERT also published another industrial control system advisory today for a privilege escalation vulnerability in the COMOS engineering solution. Siemens has patches available for the affected versions of COMOS. There is no indication of why ICS-CERT does not have a similar advisory published.

Wednesday, August 21, 2013

ICS-CERT Publishes Another Self-Reported Siemens Advisory

This afternoon the DHS ICS-CERT published an advisory for a self-reported privilege escalation vulnerability in the Siemens COMOS database application. I assume that it is self-reported from the wording of the ICS-CERT advisory. The Siemens Product-CERT advisory says that “Siemens was notified of a vulnerability”, but no information was provided about a researcher responsible for the notification, so it appears that it was an internal notification.

ICS-CERT reports that a relatively low-skilled attacker with authenticated system access could use this vulnerability to escalate their access to system engineering files. This is not strictly speaking a control system vulnerability, but information available from the system could be used to make an attack on a control system more effective.

Siemens has developed a patch for this vulnerability. Since this is a self-reported vulnerability there is no expectation that there will be an independent verification of the efficacy of the patch.


NOTE: Siemens reports the publication date of their advisory as August 9th, 2013. There seems to be an increasing delay in ICS-CERT publishing advisories about self-reported disclosures and coordinated disclosures that are not coordinated through ICS-CERT. I am not sure if this is a funding issue or just a failure of ICS-CERT to routinely check vendor disclosure sites. I suppose that whether or not that is a problem depends on how many organizations are actually depending on ICS-CERT for vulnerability notification.

Wednesday, June 19, 2013

ICS-CERT Publishes 3 Siemens Advisories

Today the DHS ICS-CERT published advisories for multiple vulnerabilities in three separate products from Siemens; Scalance, WinCC and COMOS. While the vulnerabilities in WinCC were reported by Alexander Tlyapov of Positive Technologies, the remaining vulnerabilities were identified internally.

Multiple Vulnerabilities

The vulnerabilities include (Note: links on product names are to the respective Siemens ProductCERT report):

Scalance

• Permissions, privileges, and access controls: CVE-2013-3633 and CVE-2013-3634;

WinCC

• SQL injection:  CVE-2013-3957;
• Hard-coded credentials: CVE-2013-3958;
• Forced browsing: CVE-2013-3959; and

COMOS

• Permissions, privileges, and access controls: CVE-2013-3927

Exploitability

ICS-CERT reports that a relatively low skilled attacker could exploit these vulnerabilities. The Scalance and WinCC vulnerabilities could be exploited remotely, but the COMOS vulnerability requires local access by an authenticated user. The Scalance vulnerabilities would allow an attacker to execute arbitrary commands. The WinCC vulnerabilities could allow an attacker to gain full system access. The COMOS vulnerability would allow an attacker to gain full access to information stored in the COMOS library.

Mitigation

Software updates have been developed by Siemens for all three products. Siemens ProductCERT has verified that the modifications mitigate the vulnerabilities (Note: I would have been happier to hear that Alexander Tlyapov had been asked to validate the WinCC update) . The updates can be found at the below listed links:

Scalance;
WinCC; and
COMOS

Delayed Notification


The Siemens’ ProductCERT web page provides data on when these vulnerabilities were published by that organization (Scalance 5-24-13; Win CC 6-14-13; and COMOS 6-18-13). The same day publication of the COMOS vulnerability by ICS-CERT is pretty impressive; the three week delay for the Scalance program is not so much.
 
/* Use this with templates/template-twocol.html */