Showing posts with label Carlo Gavazzi. Show all posts
Showing posts with label Carlo Gavazzi. Show all posts

Thursday, May 18, 2023

Review – 4 Advisories and 1 Update Published – 5-18-23

Today, CISA’s NCCIC-ICS published four control system security advisories for Johnson Controls, Hitachi Energy, Mitsubishi and Carlo Gavazzi. They also updated an advisory for products from Rockwell.

Advisories

Johnson Controls Advisory - This advisory describes two vulnerabilities in the Johnson Controls OpenBlue Enterprise Manager Data Collector.

Hitachi Energy Advisory - This advisory discusses a permissions, privileges and access controls vulnerability in the Hitachi Energy MicroSCADA Pro/X SYS600 products.

Mitsubishi Advisory - This advisory describes an authentication bypass vulnerability in the Mitsubishi Electric MELSEC WS Series ethernet interface module.

Carlo Gavazzi Advisory - This advisory describes a path traversal vulnerability in the Carlo Gavazzi Powersoft energy management software.

Rockwell Update - This update provides new information on an advisory that was originally published on February 20th, 2020.

Updates

Rockwell Update - This update provides new information on an advisory that was originally published on February 20th, 2020.

 

For more details on these advisories, including links to third-party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/4-advisories-and-1-update-published-51a - subscription required.

Thursday, January 12, 2017

ICS-CERT Publishes Three Advisories

Today the DHS ICS-CERT published three control system security advisories for products from Carlo Gavazzi, VideoInsight, and Advantech. ICS-CERT also published their latest ICS-CERT Monitor for November and December 2016. I am not going to review this publication any longer.

Carlo Gavazzi Advisory


This advisory describes three vulnerabilities in the Carlo Gavazzi VMU-C EM, VMU-C PV web servers. The vulnerabilities were reported by Karn Ganeshen. Carlo Gavazzi has produced a new firmware version that mitigates the vulnerability. ICS-CERT reports that Ganeshen has verified the efficacy of the fix.

The reported vulnerabilities are:

• Access control flaws - CVE-2017-5144;
• Cross-site request forgery - CVE-2017-5145; and
• Sensitive information stored in clear text - CVE-2017-5146

ICS-CERT is confused on the exploitability of these vulnerabilities. At the start of the advisory they report that the vulnerabilities are: “Remotely exploitable/low skill level to exploit.” But later in the body of the advisory it reports: “Not remotely exploitable. High skill level is needed to exploit.” I suspect that the first is correct and the second may be an artifact of the new format ICS-CERT is using to report advisories; more on that later.

VideoInsight Advisory


This advisory describes an SQL injection vulnerability in the VideoInsight Web Client. The vulnerability was reported by Juan Pablo Lopez Yacubian. VideoInsight has produced a new version to mitigate the vulnerability. ICS-CERT reports that Yacubian has verified the efficacy of the fix.
ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to execute arbitrary commands on the target system.

Advantech Advisory


This advisory describes two vulnerabilities in the Advantech WebAccess application. The vulnerabilities were reported by Tenable Network Security via the Zero Day Initiative. Advantech has produced a new version to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Authentication bypass - CVE-2017-5152; and
• SQL injection - CVE-2017-5154

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerabilities to access pages unrestricted; the SQL injection condition may allow remote code execution.

New Advisory Format


ICS-CERT has started 2017 with a new format for their advisories. Any change is going to have plusses and minuses and it is easy to pick out the problems with the new format. Fortunately, there are more good things in this change, so I would like to highlight those.

First, ICS-CERT has obviously taken a hard look at what they think is the important information in the advisory and has moved that information to the top of the advisory. The first five items on the advisory are short listings of:

• CVSS v3 Score;
• Exploitability;
• Vendor;
• Affected equipment; and
• Vulnerability listing

These are certainly very important pieces of information. Their placement at the top of the format makes it easier to do a quick review of the advisory.

This is followed by essentially the same affected versions, impact, and mitigation measures. There are no significant changes to these sections. At the end of the advisory we now some major revisions to the vulnerability overview. Those changes include actual links to the CVE instead of a footnote to the URL; and more detailed background information on the types of vulnerabilities. That takes the form of links to the Common Weakness Enumeration (CWE) dictionary documenting the vulnerability.

The last section before the contact information of the advisory is the researcher section; listing the researcher's name and affiliation. It will be interesting to see how ICS-CERT handles self-identified vulnerabilities in this section.

The major downside of the new format is that the title of the advisory is taken from the first item on the advisory, the CVSS score. This will provide all sorts of misunderstandings and difficulties in finding specific advisories as the year goes on. This could be easily remedied by changing the order of the initial listing to show the vendor name first.

The second problem that I see is that ICS-CERT has taken out any information about what industries are affected by the advisory or the regions of the world in which the affected equipment is deployed. With the major players like Siemens and even mid-level players like Advantech this is not a real problem, but two of today’s advisories are for vulnerabilities in equipment from less well known vendors.


The last problem is more a matter of appearances than an actual problem; the moving of the researcher’s name to the end of the advisory. This certainly does nothing to tell the public (or the researcher) of the importance on the security researcher in the vulnerability reporting process. In my opinion the researchers name and affiliation should be included in the summary information at the top of the advisory.

Thursday, December 20, 2012

ICS-CERT Closes-out Two Alerts


Today the folks at DHS ICS-CERT published two advisories for different systems that were based upon uncoordinated disclosures reported earlier by ICS-CERT. Actually ICS-CERT only notes that one is based upon an earlier alert, but records show that both were. The affected systems are from RuggecCom and Carlo Gavazzi Automation.

RuggedCom Advisory


This advisory is based upon Key Management Errors originally reported by Justin W. Clarke of Cylance Inc and the ICS-CERT Alert was published in August and updated later that month. According to this Advisory a moderately skilled attacker could use the publicly available exploit “to establish a secure communication link with RuggedCom network devices and manipulate settings that would result in a denial of service condition”. Why that would only allow a ‘DOS condition’ is not made clear.

RuggedCom has developed a number of device specific mitigations for this vulnerability, ranging from an update for ROS devices, to a recommendation to update SSL and SSH keys for ROX devices. The situation for RUGGEDMAX devices appears to be more complicated because there is one solution for SSH service and a temporary solution for HTTPS access; the last doesn’t sound encouraging.

Carlo Gavazzi Automation Advisory


This advisory seems to me to be clearly based upon an alert issued in October for the Sinapsi eSolar Light Photovoltaic System Monitor. That alert clearly notes that the Gavazzi EOS box is one of the names under which the Sinapsi product was sold. This advisory does not mention the earlier alert and it only addresses two of the vulnerabilities (hard-coded credentials and SQL injection) addressed in that earlier alert. If the earlier alert does not in fact apply to the EOS box, ICS-CERT should revise the earlier alert to reflect that fact.

The advisory notes that a relatively unskilled attacker could use the publicly available exploit code (another reason to believe the alert should have been referenced) to remotely gain administrative access and control of the system (credential vuln) or gain access to information about the system (SQL vuln). Carlo Gazazzi has developed an updated firmware version to mitigate these vulnerabilities and has released the new firmware ‘directly to the devices’. Interestingly that is just what Sinapsi did almost a month earlier to their devices affected by the same vulnerabilities. As I have mentioned in the past, I thing that the ability of the manufacturer to release the firmware updates directly to the devices is a vulnerability in and of itself, even if it is not misused.

Two questions remain unanswered; what happened to the other two vulnerabilities mentioned in the original alert (and the Sinapsi advisory) and when will we see the advisories for the other manufacturers listed in the original alert?
 
/* Use this with templates/template-twocol.html */