Showing posts with label Carsten Eiram. Show all posts
Showing posts with label Carsten Eiram. Show all posts

Friday, March 28, 2014

Follow-up on Schneider Advisory

There has been an interesting Twittversation about these vulnerabilities since I did my earlier post.
Carsten Eiram (@carsteneiram) provided a link to the original vulnerability report that Risk Based Security published after Schneider apparently published their original (though no longer available) advisory back in March of last year. While that report is not exactly ‘exploit code’ it certainly contains enough information that a reasonably competent hacker should be able to write their own.

Adam Crain (@jadamcrain; of DNP3 Fuzzing Fame) asked: “Any idea what took @ICS-CERT so long on this one?” This is certainly a good question since it has now been over a year since Schneider first publicly reported the vulnerability.

The delay is almost certainly related to the fact that Schneider is fixing the problem system by system. While the problem is reportedly in the common ModbusDriverSuite, the implementation of that suite in each of the eleven products is likely slightly different. According to the most recent Schneider advisory (dated September 13th, 2013) they don’t intend to issue product updates just for this vulnerability; the fix will be included in the next product update.

I suspect that either ICS-CERT finally got fed up with the slow pace of updates or they received some recent communication from Schneider that indicated that Schneider had effectively decided not to fix the other eight products. Either would certainly explain the following comment in yesterday’s ICS-CERT Advisory:

“Schneider Electric has no immediate plan [emphasis added] for updating the other identified software products.”

In any case, Schneider has left customers owning the below listed software in an unenviable position. Their control system has a publicly identified security vulnerability that there is only a network limitation fix available; a fix that individual customers may or may not be in a situation to be able to put into place.

• TwidoSuite Versions 2.31.04 and earlier (available next month?);
• PowerSuite Versions 2.6 and earlier;
• SoMove Versions 1.7 and earlier;
• SoMachine Versions 2.0, 3.0, 3.1, and 3.0 XS;
• UnityLoader Versions 2.3 and earlier;
• Concept Versions 2.6 SR7 and earlier;
• ModbusCommDTM sl Versions 2.1.2 and earlier;
• PL7 Versions 4.5 SP5 and earlier and
• SFT2841 Versions 14, 13.1 and earlier.


Maybe this push by ICS-CERT will speed up the process. Or maybe enough complaints from customers will provide the necessary impetus. Finally regulators that have cyber security controls available may want to ensure that folks with these systems are taking special precautions.

Thursday, March 27, 2014

ICS-CERT Publishes New Schneider Advisory

Today the DHS ICS-CERT published a new advisory affecting 11 separate Schneider Electric products that use the serial MODBUS driver. This advisory is based upon a stack-based buffer overflow vulnerability reported by Carsten Eiram of Risk-Based Security in a coordinated disclosure. An updated ModbusDriverSuite has been produced, but there is no indication whether or not Carsten has had a chance to verify the efficacy of that mitigation.

ICS-CERT reports that a highly skilled attacker could remotely exploit this vulnerability to execute arbitrary code.

The ICS-CERT advisory gives conflicting information about the mitigation efforts undertaken by Schneider. In one paragraph it states that the latest versions of OFS and UnityPro have been released with an updated ModbusDriverSuite and other affected systems will have that suite in their next update. The next paragraph then states that: “Schneider Electric has no immediate plan for updating the other identified software products.”

The advisory from Schneider (originally released September 13th, 2013) states:

“The ModbusDriverSuite for TwidoSuite will be available in April of 2014. Until the ModbusDriverSuite becomes available for TwidoSuite, Schneider Electric recommends using a firewall to allow only authorized systems to access TwidoSuite. OFS V3.5 and Unity Pro V8 have been released including the updated ModbusDriverSuite. For other products listed, the updated ModbusDriverSuite will be implemented with each new version of those Software Products.”

The Schneider produced advisory has some changes recorded in it. It appears that initially at least that they believed that the vulnerability could only be exploited via local access. They also apparently initially underestimated the degree of risk associated with this vulnerability; they updated the CVSS Base Score from 6.9 to 9.3 (the same value that ICS-CERT is reporting). There is no indication when these two visible changes were made to their advisory.

Monday, October 7, 2013

ICS-CERT Updates Rockwell Advisory with New Vulnerabilities

Today the DHS ICS-CERT published an update for the control system advisor they published back on April 5th, 2013. The update adds three additional vulnerabilities in the Rockwell Automation FactoryTalk and RSLinx applications. These new vulnerabilities were also discovered by Carsten Eiram of Risk Based Security after the earlier vulnerability updates were made to the Rockwell software. It is not clear why ICS-CERT issued an update instead of publishing a new advisory.

The update adds the following vulnerabilities:

• Out of bounds read, CVE-2013-2805;
• Integer overflow, CVE-2013-2807; and
• Integer overflow, CVE-2013-2806.

NOTE: Links may not work for a couple of days; not shutdown related.

The advisory reports that all three new vulnerabilities can be remotely exploited via Port 4444/UDP to conduct a denial of service attack. Rockwell has produced a new set of patches for these vulnerabilities. There is no indication that Carsten or any other outside agency has validated the efficacy of the most recent patch.
 
/* Use this with templates/template-twocol.html */