Showing posts with label CRITIFENCE. Show all posts
Showing posts with label CRITIFENCE. Show all posts

Tuesday, November 20, 2018

Two Advisories and One Update Published – 11-20-18


Today the DHS NCCIC-ICS published two control system security advisories for products from Schneider Electric and Teledyne DALSA. They also published an update for a previously published advisory for products from NUOO.

Schneider Advisory


This advisory describes an insufficient verification of data authenticity vulnerability in the Schneider Modicon M221 PLC. The vulnerability was reported by Eran Goldstein of CRITIFENCE. Schneider has provided workarounds to mitigate the vulnerability. There is no indication that Goldstein has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a change of IPv4 configuration (IP address, mask, and gateway) when remotely connected to the device.

Teledyne Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Teledyne Sherlock machine vision software interface. The vulnerability was reported by Robert Hawes. Teledyne reports that newer versions mitigate the vulnerability. There is no indication that Hawes has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to crash the device being accessed; a buffer overflow condition may allow remote code execution.

NUOO Update


This update provides additional information on an advisory that was originally reported on October 11th, 2018. The update adds additional affected version information and three new vulnerabilities:

• Path traversal - CVE-2018-17934;
• Unrestricted upload of file of dangerous type - CVE-2018-17936; and
SQL injection - CVE-2018-18982

Saturday, October 6, 2018

Public ICS Disclosures – Week of 09-29-18


This week we have two new vendor notifications for products from Schneider Electric and PTC. We also have a vendor update from BD.

Schneider Advisory


This advisory describes an insufficient verification of data authenticity vulnerability in the Schneider Modicon M221. The vulnerability was reported by Eran Goldstein of CRITIFENCE. Schneider reports on workarounds to mitigate the vulnerability. There is no indication that Goldstein has been provided an opportunity to verify the efficacy of the fix.

PTC Advisory


This advisory describes three vulnerabilities in the PTC ThingWorx Platform. The vulnerability was reported by Matteo Tomaselli from the SEC Consult Vulnerability Lab. PTC has new versions that mitigate the vulnerabilities. There is no indication that Tomaselli has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Disclosure of User Password Hashes to Privileged Users - CVE-2018-17216;
• Disclosure of Encrypted Credentials and Use of Hard-Coded Passwords - CVE-2018-17217; and
Reflected Cross-Site Scripting - CVE-2018-17218

BD Update


This update provides additional information on an advisory that was originally published on May 22, 2018. The update provides previously promised mitigation measures.

Tuesday, April 11, 2017

ICS-CERT Publishes Schneider Advisory

Today the DHS ICS-CERT published a control system security advisory for Schneider Modicon PLCs. The advisory describes two vulnerabilities that were reported by Eran Goldstein of CRITIFENCE. These are not the vulnerabilities that I briefly described on Saturday. Schneider has developed compensating controls to mitigate the vulnerability. There is no indication that Goldstein was provided the opportunity to verify the efficacy of the fix. There are no indications that Schneider intends to produce a more permanent fix to these vulnerabilities.

The two reported vulnerabilities are:

• Authentication Bypass by Capture-Replay - CVE-2017-6034; and
• Violation of Secure Design Principles - CVE-2017-6032

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to capture and replay sensitive commands to PLCs on a network using the Modicon Modbus protocol.


The Schneider security notification also mentions that SCADA/ICS Cyber Threats Research Group contributed to the identification of these vulnerabilities.

Thursday, November 3, 2016

ICS-CERT Publishes Two Advisories

Today the DHS ICS-CERT published two control system security advisories for products from Schneider and Moxa.

Schneider Advisory


This advisory describes twin uncontrolled resource consumption vulnerabilities in the Schneider Electric Magelis human-machine interface (HMI) products. The vulnerabilities were reported in a coordinated disclosure by Eran Goldstein, in collaboration with Check Point Software Technologies and CRITIFENCE and publicly reported earlier this week. Schneider plans on having a new release available next spring, but is providing work arounds listed in this advisory.

While ICS-CERT calls both vulnerabilities ‘uncontrolled resource consumption vulnerabilities. CRITIFENCE uses more descriptive names:

• Improper implementation of HTTP get request – CVI-2016-8367; and
• Improper implementation of HTTP chunked Transfer-Encoding request - CVI-2016-8374.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to cause a denial of service for the affected devices. The Schneider security notification notes that the vulnerabilities can only be exploited when the Web Gate Server is activated; the function is disabled by default.

BTW: These are the Schneider vulnerabilities that I retweeted about earlier this week.

Moxa Advisory


This advisory describes two vulnerabilities in the Moxa OnCell Security Software. The vulnerabilities were reported by Maxim Rupp (who at this point should be listed as a member of the Moxa cybersecurity team; just saying). Moxa has produced a new version (for two of the ten affected systems) that mitigates the vulnerability. There is no indication that Rupp was provided an opportunity to verify the efficacy of the fix.

The vulnerabilities include:

• Improper authentication - CVE-2016-8362; and
• Permissions, privileges and access control - CVE-2016-8363


ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to download files or execute arbitrary command by web console.
 
/* Use this with templates/template-twocol.html */