Showing posts with label Chris Lyne. Show all posts
Showing posts with label Chris Lyne. Show all posts

Saturday, March 31, 2018

Public ICS Disclosures – Week of 03-24-18


This week we have one vendor notification from Siemens and two exploits for previously disclosed vulnerabilities in products from Hikvision and Advantech.

Siemens Advisory


This advisory describes 8 vulnerabilities in Siemens Building Technologies Products. The vulnerabilities were reported by Sergey Temnikov and Vladimir Dashchenko from Kaspersky Lab. The newest version of the license management systems for the affected products mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

These reported vulnerabilities are the Gemalto Sentinel LDK RTE vulnerabilities that have been previously reported by Siemens in other products.

Hikvision Exploit


This exploit provides proof-of-concept code for an attack on IP cameras from Hikvision. The backdoor vulnerability was previously disclosed on May 4th, 2017. The exploit was published by Matamorphosis on Exploit-DB.com.


Advantech Exploit


This exploit provides proof-of-concept code for an attack on the WebAccess products from Advantech. The stack-based buffer overflow vulnerability was previously disclosed on January 14th, 2016. The exploit was published by Chris Lyne on Expoit-DB.com.

Commentary


I noted in an earlier post that this set of Gemalto vulnerabilities probably effects a wide range of ICS products (including products from at least three other major ICS vendors) and suggested that ICS-CERT should have done an alert on these vulnerabilities. It is not too late to do so.

While both of the exploited vulnerabilities describe above were previously reported by ICS-CERT as not having publicly available exploits, ICS-CERT does not make a practice of removing that language from their advisories when exploits do become publicly available. It would probably be valuable to the ICS security community if that practice were changed.

Saturday, March 17, 2018

Public ICS Disclosure – Week of 03-10-18


We have two exploit code releases this week for industrial control systems, the vulnerability for one was previously reported by ICS-CERT. The vulnerable products come from Prisma Industriale and Advantech.

Prisma Exploit


Gjoko 'LiquidWorm' Krstic published exploit code for a hard-coded credential vulnerability in the Prisma Industriale Checkweigher, an in-line weighment device. The vulnerability had been previously published by Zero Science Labs; who had attempted to coordinate the disclosure with the vendor.

The vulnerability reportedly allows a successful attacker administrator level access to the device.

Advantech Exploit


Chris Lyne published exploit code for a directory traversal vulnerability in the Advantech WebAccess products. The vulnerability was previously reported by ICS-CERT and ZDI. According to ZDI, the vulnerability allows a successful attacker administrative-level remote-code execution ability.

Saturday, February 3, 2018

Public ICS Disclosures – Week of 1-25-18


This week we have a new coordinated disclosure for a Sprecher Automation remote terminal unit (RTU), exploit code for an Advantech WebAccess vulnerability and a late discussion of new information on the TRISIS attack.

Sprecher


SEC Consult Vulnerability Lab published a vulnerability report on the FullDisclosure.com web site this week for multiple vulnerabilities in the Sprecher SPRECON-E-C RTU. It reports five vulnerabilities (with proof of concept code), including:

• Authenticated path traversal;
• Client-side password hashing;
• Missing authentication;
• Permanent denial of service via port scan; and
Outdated Linux kernel.

Three of the five vulnerabilities have reportedly been fixed and work arounds have been provided for the other two.

Advantech Exploit


Chris Lyne published exploit code on the ExploitDataBase.com web site this week for an SQL injection vulnerability in the Advantech WebAccess application. The vulnerability was included in a recent ICS-CERT Advisory that was most recently updated on January 11th. For obvious reasons, ICS-CERT did not mention the publicly available exploit code and they have not made it a practice to further update their advisories to report the presence of exploits.

TRISIS Update


Most readers will probably be familiar with the Schneider presentation at S4X18 about new information on the recent attack on a Triconex safety system. The Schneider reported that they discovered a zero-day vulnerability used by the attacker and have provided a firmware update that mitigates the vulnerability. Schneider updated their security notification to reflect the new information.

ICS-CERT published a malware report not a control system advisory for the situation. It did provide a link to the original Schneider notification. I do not expect ICS-CERT to update their malware report, but I have been hoping to see an advisory for the newly reported vulnerability.

I cannot wait for DigitalBond to make the Schneider presentation available on their site.

 
/* Use this with templates/template-twocol.html */