Showing posts with label Cisco Talos. Show all posts
Showing posts with label Cisco Talos. Show all posts

Thursday, December 17, 2020

3 Advisories Published – 12-17-20

Today the CISA NCCIC-ICS published three control system security advisories for products from PTC (2) and Emerson.

LinkMaster Advisory

This advisory describes an incorrect default permissions vulnerability in the PTC Kepware LinkMaster application. The vulnerability was reported by Yuri Kramarz of Cisco Talos. PTC has a new version that mitigates the vulnerability. There is no indication that Kramarz has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow a local attacker to globally overwrite the service configuration to execute arbitrary code with NT SYSTEM privileges.

NOTE: The Talos report include proof-of-concept code.

KEPServerEX Advisory

This advisory describes three vulnerabilities in the PTC Kepware KEPServerEX connectivity platform. The vulnerability was reported by Uri Katz of Claroty. PTC has updates that mitigate the vulnerability. There is no indication that Katz has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2020-27265,

• Heap-based buffer overflow - CVE-2020-27263, and

• Use after free - CVE-2020-27267

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to lead to a server crashing, a denial-of-service condition, data leakage, or remote code execution.

NOTE 1: NCCIC-ICS reports that these vulnerabilities could serve as a third-party vulnerability in the following products:

Rockwell Automation KEPServer Enterprise,

GE Digital Industrial Gateway Server, and

Software Toolbox TOP Server

NOTE 2: NCCIC-ICS only provided links to the GE advisory.

Emerson Advisory

This advisory describes an improper authentication vulnerability in the Emerson Rosemount X-STREAM gas analysis software. The vulnerability was reported by Maxim Rupp. Emerson has firmware updates that mitigate the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker through a specially crafted URL to download files and obtain sensitive information.

Sunday, December 13, 2020

Public ICS Disclosures – Week of 12-5-20, Part II

This week we have nine disclosures for products from Schneider. We also have eight vendor updates for products from Siemens (5) and Schneider (3). Finally, we have two researcher reports about vulnerabilities in products from Schneider.

Schneider Advisories

Schneider published an advisory describing a write-what-where condition vulnerability in their EcoStruxure™ Control Expert. The vulnerability was reported by Jared Rittle of Cisco Talos; the report contains proof-of-concept code. Schneider provides generic workarounds pending development of remediation measures.

 

Schneider published an advisory describing an insufficiently protected credentials vulnerability in their EcoStruxure Geo SCADA Expert. The vulnerability is being self-reported. Schneider has updates available that mitigate the vulnerability.

 

Schneider published an advisory describing two vulnerabilities in their Web Server on Modicon M340 communication modules. The vulnerabilities were reported by DongJian Security Lab and the Russian BDU FSTEC (report here). Schneider has new firmware versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Forced browsing - CVE-2020-7541, and

• Improper check for unusual or exceptional conditions - CVE-2020-7539

 

Schneider published an advisory describing a missing authentication for critical function vulnerability in their Web Server on Modicon M340 communications modules. The vulnerability was reported by DongJian Security Lab. Schneider has new firmware versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

 

Schneider published an advisory describing a path traversal vulnerability on the Web Server on Modicon M340 communications modules. The vulnerability was reported by Zheng Qiang. Schneider has new firmware versions that mitigate the vulnerability. There is no indication that the researcher have been provided an opportunity to verify the efficacy of the fix.

 

Schneider published an advisory describing an improper check for unusual or exceptional conditions vulnerability in their Web Server on Modicon M340 communications modules. The vulnerability is being self-reported.

 

Schneider published an advisory describing an improper check for unusual or exceptional conditions vulnerability in their Modicon M340 CPU’s. The vulnerability was reported by the VAPT Team from C3i IITK, India. Schneider has new firmware versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

 

Schneider published an advisory describing three separate improper check for unusual or exceptional conditions vulnerabilities in their Modicon M580 controllers. The vulnerabilities were reported by Gao Jian of NSFOCUS, Daniel Lubel of OTORIO, Armis Security, Victor Fidalgo Villar of INCIBE-CERT, and Gideon Guo. Schneider has firmware updates that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

 

Schneider published an advisory describing an improper restriction of operations within the bounds of a memory buffer vulnerability in their M258 Logic Controllers and SoMachine/SoMachine Motion software. The vulnerability was reported by Kai Feng. Schneider has new versions that mitigate the vulnerability. There is no indication that Kai has been provided an opportunity to verify the efficacy of the fix.

Siemens Updates

Siemens published an update for their SegmentSmack advisory that was originally published on April 14th, 2020 and most recently updated on September 8th, 2020. The new information include updating information regarding successor products for SIMATIC RF180C and RF182C.

NOTE: NCCIC-ICS updated their advisory for this vulnerability back in September but has not updated for this Siemens update.

 

Siemens published an update for their GNU/Linux subsystem advisory that was originally published in 2018 and most recently updated on November 10th, 2020. The new information includes adding the following new vulnerabilities:

• CVE-2020-25284,

• CVE-2020-25668,

• CVE-2020-25705,

• CVE-2020-27618, and

• CVE-2020-27777

 

Siemens published an update for their Industrial Products advisory that was originally published on December 10th, 2019 and most recently updated on September 8th, 2020. The new information includes updating d information regarding successor products for SIMATIC RF182C and RFID 181EIP.

NOTE: NCCIC-ICS last updated their advisory for this product back in August.

 

Siemens published an update for their advisory that was originally published on September 9th, 2020 and most recently updated on October 13th, 2020. The new information includes adding patch links for:

• SIMATIC HMI Basic (2nd generation),

• Comfort (including SIPLUS variants), and

• Mobile Panels

NOTE: NCCIC-ICS published their advisory for these vulnerabilities back in September but has not updated it since.

 

Siemens published an update for their ZombieLoad advisory that was originally published on July 9th, 2019 and most recently updated on March 10th, 2020. The new information includes:

• Correcting mitigations for SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP and

• Providing updates for SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP

Schneider Updates

Schneider published an update for their Ripple20 advisory that was originally published on June 23, 2020 and most recently updated on November 10th, 2020. The new information includes adding remediation for:

• SCADAPack 32 RTU,

• XUPH001 OsSense communication module,

• XGCS850C201 OsiSense RFID compact smart antenna,

• ATV340E Altivar Machine Drives,

• ATV630/650/660/680/6A0/6B0 Altivar Process Drives,

• ATV930/950/960/980/9A0/9B0 Altivar Process Drives,

• VW3A3720, VW3A3721 Altivar Process Communication Modules,

• ACE850 Sepam communication interface,

• PowerLogic EGX300 Ethernet Gateway,

• PowerLogic EGX100 Ethernet Gateway, and

• Acti9 Smartlink IP

 

Schneider published an update for their CodeMeter advisory that was originally published on October 13th, 2020. The new information includes reporting that the CodeMeter V7.10a fix qualification is confirmed for EcoStruxure Machine SCADA Expert.

 

Schneider published an update for their Modicon controllers advisory that was originally published on May 14th, 2019 and most recently updated on October 18th, 2020. The new information includes adding a fix for additional attack scenario is available on M340 V3.30 for CVE-2018-7857.

Schneider Reports

Claroty published a report discussing the Modicon M221 PLC vulnerabilities reported Tuesday by Schneider.

Trustwave published a report discussing one of the Modicon M221 PLC vulnerabilities reported Tuesday by Schneider. This report contains proof-of-concept code for the one-way hash vulnerability.

Saturday, November 7, 2020

Public ICS Disclosures – Week of 10-31-20

This week we have seven vendor disclosures from BD, Johnson and Johnson, Moxa (2), Philips, Rockwell, and Sick. We also have two researcher reports about in the wild exploits for a vulnerability in products from Oracle that apparently affects a product from Siemens.

BD Advisory

BD published an advisory discussing the Netlogon vulnerability affect on products from BD. The advisory contains a list of potentially affected products. BD provides generic guidance on mitigation measures for this vulnerability.

Johnson and Johnson Advisory

Johnson and Johnson published an advisory discussing the Ryuk ransomware advisory from the Federal Government. The advisory notes that there are no Johnson and Johnson medical device products directly affected.

Moxa Advisories

Moxa published an advisory describing an incorrect default permissions vulnerability in their MXview Series network management software. The vulnerability was reported by Yuri Kramarz of Cisco Talos. Moxa has a new firmware version that mitigates the vulnerability. There is no indication that Kramarz has been provided an opportunity to verify the efficacy of the fix.

NOTE: The Talos report includes proof of concept code.

Moxa published an advisory describing six vulnerabilities in their EDR-810 series security router. The vulnerabilities were reported by BDU FSTEC. Moxa has new firmware that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities include:

• Execute Arbitrary Commands - BDU:2020-01269,

• Denial of Service - BDU:2020-04912, and

• No response from system (4) - BDU:2020-04913, BDU:2020-04914, BDU:2020-04915, and BDU:2020-04916.

NOTE 1: BDU FSTEC reports (see here for example) that these vulnerabilities were discovered in July 2018. This may be of concern since FSTEC is the Russian Federal Service for Technical and Export Control. I do not know what sort of links FSTEC may have to Russian intelligence or security services.

NOTE 2: The ‘BDU’ numbers are the FSTEC reporting numbers (similar to CVE’s?). They can be found here.

Philips Advisory

Phillips published an advisory discussing the Oracle WebLogic RCE vulnerability. Philips currently lists just one product (Tasy EMR v12.2.1.3) as being affected by this vulnerability.

Rockwell Advisory

Rockwell published an advisory discussing an HTTP session management vulnerability in their Stratix 5700 switch. This is a third-party (classic Cisco IOS) vulnerability. The vulnerability was reported by Amazon. Rockwell has a new version that mitigates the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

Sick Advisory

Sick published an advisory [.PDF download link] discussing a Windows® TCP/IP remote code execution vulnerability (CVE-2020-16898) in their Package Analytics product. Sick recommends applying the applicable Windows update.

Oracle Reports

FireEye published two reports (here and here) about on-going exploits of a classic buffer overflow vulnerability the Oracle Solaris enterprise operating system. Normally I would not cover vulnerabilities in this product, but Ralph Langner published a Tweet indicating that this vulnerability affected the Siemens SPPA-T2000.

Commentary

We are seeing an increasing number of reports of third-party vulnerabilities. I suspect that these reports are just sightings of the tips of the various control system icebergs out there. We will not know really how wide-spread and dangerous these vulnerabilities are until vendors are forced to look at reported vulnerabilities in their component systems provided by third parties.

Tuesday, October 20, 2020

2 Advisories and 2 Updates Published – 10-20-20

Today the CISA NCCIC-ICS published two control system security advisories for product from Hitachi ABB Power Grids, and Rockwell Automation, and updated an advisory for products from WECON. They also updated a medical device security advisory for products from Capsule Technologies.

Hitachi ABB Advisory

This advisory describes an improper authentication vulnerability in the Hitachi ABB XMC20 Multiservice-Multiplexer. The vulnerability is self-reported. Hitachi ABB has new firmware versions that mitigate the vulnerability.

NOTE: The Hitachi ABB advisory describes this as a third-party vulnerability in Libssh. They also report that exploit code is publicly available for the vulnerability. This vulnerability was reported by Peter Winter-Smith of NCC Group. An article on ZDNet.com notes that this is not the most commonly used ssh library, but we must assume that other vendor products may be affected by this vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to remotely take control of the product.

Rockwell Advisory

This advisory describes three classic buffer overflow vulnerabilities in the Rockwell 1794-AENT Flex I/O Series B ethernet/IP adapters. The vulnerabilities were reported (herehere and here) by Jared Rittle of Cisco Talos. Rockwell provides generic workarounds for these vulnerabilities.

NOTE: The Cisco Talos reports contain proof-of-concept exploit code for the vulnerabilities.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to crash the device being accessed, resulting in a buffer overflow condition that may allow remote code execution.

NOTE: I briefly reported on these vulnerabilities last Saturday.

WECON Update

This update provides additional information on an advisory that was originally published on August 25, 2020. The new information includes:

• Adding ‘improper restriction of xml external entity reference’ as a new vulnerability,

• Adding ‘and obtain sensitive information’ to the risk evaluation, and

• Adding ‘Mehmet D. INCE @mdisec from T0.Group’ as a reporting researcher.

Capsule Technologies Update

This update provides additional information on an advisory that was originally published on July 14th, 2020. The new information includes updated affected version information and links to mitigation measures.

Saturday, October 17, 2020

Public ICS Disclosures – Week of 10-10-20 – Part 1

This week we have seven vendor disclosures from Eaton, HMS, Bender, Sprecher, Bosch, Rockwell, and Carestream. There are also three vendor updates from ABB and Eaton (2). We also have an exploit that was published for products from BACnet Interoperability Test Services, Inc.

Eaton Advisory

Eaton published an advisory for the CodeMeter vulnerabilities in their Xsoft-CODESYS programming software.

NOTE: This is the first CodeMeter advisory that is specifically tied to the 4th party CODESYS implmenetation of the Wibu-Systems code that I have seen.

HMS Advisory

HMS published an advisory for the Ripple20 [corrected link, 10-18-20 0846 EDT] vulnerabilities, reporting that none of their products are affected.

NOTE: The advisory indicates that HMS employed a third-party research firm to help them assess the potential exposure to these vulnerabilities.

Bender Advisory

Bender published an advisory describing an improper authentication vulnerability in their COMTRAXX products. The vulnerability was reported by Maxim Rupp. Bender has a new software version that mitigates the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

Sprecher Advisory

Sprecher published an advisory describing an input validation vulnerability in their SPRECON-E engineering tools. The vulnerability was reported by Gregor Bonney of CyberRange-e at Innogy. Sprecher has a firmware update that mitigates the vulnerability. There is no indication that Bonney has been provided an opportunity to verify the efficacy of the fix.

Bosch Advisory

Bosch published an advisory describing the Microsoft® remote desktop services vulnerability in their Rexroth industrial PCs.

Rockwell Advisory

Rockwell published an advisory describing five buffer overflow vulnerabilities in their 1794-AENT Flex I/O products. The vulnerabilities were reported (here, here and here) by Jared Rittle of Cisco Talos. Rockwell provides generic workarounds to mitigate these vulnerabilities.

NOTE: The Cisco Talos reports provide proof-of-concept code for the vulnerabilities.

Carestream Advisory

Carestream published an advisory [.PDF download link] describing the Microsoft Bad Neighbor vulnerability. Carestream is looking into the potential effects of this vulnerability on their products.

ABB Update

ABB published an update of their CodeMeter advisory for their Automation Builder products that was originally published on September 17th, 2020. ABB reports that CVE-2020-14517 has not been closed in the latest version of the Wibu-Systems CodeMeter (v.7.10a). That version has been integrated into the latest version of Automation Builder.

Eaton Updates

Eaton published an update for their Ripple20 [Corrected link, 10-18-20, 0851 EDT] advisory that was originally published on June 23rd, 2020 and most recently updated on July 24th, 2020. The new information includes updated mitigation information for Form 4D.

Eaton published an update for their Triangle MicroWorks DNP3 Outstation Libraries vulnerability advisory that was originally published on April 22nd, 2020 and most recently updated on August 6th, 2020. Eaton has updated their affected product list and mitigation measures.

NOTE: The NCCIC-ICS advisory was never updated to provide links to vendors reporting these library vulnerabilities in their products.

BACnet Exploit

Zero Science Lab published an exploit for a remote denial of service vulnerability in the BACnet Test Server from BACnet Interoperability Test Services, Inc. There is no report of a coordinated disclosure or CVE # for this vulnerability so it looks like it may be a 0-day exploit.

More to Come

Part II of this post will include Schneider and Siemens advisories and updates.

Thursday, September 10, 2020

4 Advisories Published – 9-10-20


Today the CISA NCCIC-ICS published three control system and one medical device security advisories for products from HMS Network, FATEK Automation, AVEVA, and Philips.

HMS Advisory


This advisory describes a permissive cross-domain policy with untrusted domains vulnerability in the HMS Ewon Flexy and Cosy products. The vulnerability was reported by Parth Srivastava of Protiviti India Member Private Limited. HMS has updated firmware that mitigates the vulnerability. There is no indication that Srivastava has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow attackers to retrieve limited confidential information.

FATEK Advisory


This advisory describes a stack-based buffer overflow vulnerability in the FATEK PLC WinProladder. The vulnerability was reported by Natnael Samson via the Zero Day Initiative. FATEK has not responded to NCCIC-ICS about this vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to crash the device being accessed; a buffer overflow condition may cause a denial-of-service event and remote code execution.

AVEVA Advisory


This advisory describes an SQL injection vulnerability in the AVEVA Enterprise Data Management Web. The vulnerability was reported by Yuri Kramarz of Cisco Talos. AVEVA has an upgrade that mitigates the vulnerability. The AVEVA advisory notes that Kramzrz has verified the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow a remote attacker to execute arbitrary SQL commands on the affected device.

Philips Advisory


This advisory describes eight vulnerabilities in the Philips  Patient Information Center iX (PICiX); PerformanceBridge Focal Point; IntelliVue Patient Monitor products. The vulnerabilities were reported by Julian Suleder, Nils Emmerich, Birk Kauer of ERNW Research GmbH, Dr. Oliver Matula of ERNW Enno, and Rey Netzwerke GmbH via BSI. Philips plans on releasing updates over the next year.

The eight reported vulnerabilities are:

• Improper neutralization of formula elements in a CSV file - CVE-2020-16214,
• Cross-site scripting - CVE-2020-16218,
• Improper authentication - CVE-2020-16222,
• Improper check for certificate revocation - CVE-2020-16228,
• Improper handling of length parameter inconsistency - CVE-2020-16224,
• Improper validation of syntactic correctness of input - CVE-2020-16220,
• Improper input validation - CVE-2020-16216, and
• Exposure of resource to wrong sphere - CVE-2020-16212

NCCIC-ICS reports that a relatively low-skilled attacker with either physical access to surveillance stations and patient monitors or access to the medical device network could exploit the vulnerabilities to allow unauthorized access, interrupted monitoring, and collection of access information and/or patient data.

Saturday, June 13, 2020

Public ICS Disclosures – Week of 6-6-12


This week we have seven vendor disclosures from Schneider (3), WAGO (2), Moxa and Medtronic as well as four vendor updates for advisories from Schneider (3) and Siemens. There were three researcher reports about vulnerabilities from Siemens.

Schneider Advisories


Schneider published an advisory describing an out-of-bounds write vulnerability in their Modicon M218 Logic Controller. The vulnerability was reported by CNCERT. Schneider provides generic workarounds to mitigate the vulnerability.


Schneider published an advisory describing a use of hard-coded credentials vulnerability in their Unity Loader and OS Loader Software. The vulnerability was reported by Yang Dong of DingXiang Dongjian Security Lab. Schneider provides workarounds to mitigate the vulnerability, noting that: “Hardcoded credentials are kept for compatibility with legacy products.”


Schneider published an advisory describing a null pointer dereference vulnerability in their Modicon LMC078 Logic Controller. This vulnerability is self-reported. Schneider provides generic workarounds to mitigate the vulnerability.

NOTE: This vulnerability is in a third-party (Wind River) component (IGMP) and was introduced in a patch applied to mitigate the Urgent/11 vulnerabilities. This vulnerability should be able to be found in a large number of products. I expect that we will be seeing more of this one.

WAGO Advisories


CERT-VDE published an advisory describing an improper privilege management vulnerability in the WAGO Web Based Management products. This vulnerability was reported by CISCO Talos; the report includes proof-of-concept code. WAGO provides generic workarounds to mitigate this ‘feature’.


CERT-VDE published an advisory describing a classic buffer overflow vulnerability in the WAGO Series PFC100 and Series PFC200 PLC’s. This vulnerability was reported by BSI. WAGO has new firmware that mitigates the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

NOTE: This is the third-party (LINUX) PPP daemon vulnerability that has been previously reported in other products.

MOXA Advisory


Moxa has published an advisory describing a command injection vulnerability in their VPort 461 Series Industrial Video Servers. The vulnerability was reported by Xinjie Ma from Beijing Chaitin Future Technology Co. Moxa has a patch for this phased-out product. There is no indication that Xinjie has been provided an opportunity to verify the efficacy of the fix.

Medtronic Advisory


Medtronic has published an advisory describing the Bluetooth Impersonation Attacks (BIAS) vulnerabilities in their FA Controller and  Patient Telemetry Module products. Medtronic has not yet determined what mitigation measures it will take.

NOTE: These vulnerabilities may (probably?) affect any medical device or control system component that uses Bluetooth connectivity.

Schneider Updates


Schneider published an update for their Urgent/11 advisory that was originally published on August 2nd, 2020 and most recently updated on May 12th, 2020. The new information includes updated mitigation measures for:

 • Easergy T300 and
• Magelis HMI - HMIGTO Series, HMISCU Series,  HMIGTUX Series, and HMIGTU Series (Except Open BOX) products


Schneider published an update for their EcoStruxure™ Operator Terminal Expert advisory that was originally published on May 12th, 2020. The new information includes an update of CVE-2020-7495.


Schneider published an update for their GoAhead Web Server Vulnerability that was originally published on December 10th, 2015. The new information includes:

• A note that proof-of-concept code is publicly available,
• Updated remediation informtation.

NOTE: ICS-CERT (now NCCIC-ICS) published an advisory for this vulnerability, it will be interesting to see if they get around to updating it.

Siemens Update


Siemens published an update for their Urgent/11 advisory that was originally published on May 12th, 2020. The new information includes updated version data and mitigation measures for Siemens Power Meters Series 9810.

Researcher Reports – Siemens


CISCO Talos published three research reports (here, here and here) describing vulnerabilities in the Seiemens LOGO! Products. The reports each claim CVE# CVE-2020-7589 which was reported by Siemens (and NCCIC-ICS) earlier this week as a single missing authentication for critical function vulnerability. Each Talos report includes separate proof-of-concept code.

Saturday, March 28, 2020

Public ICS Disclosures – Week of 03-21-20


This week we have five vendor disclosures for products from Phoenix Contact (2), 3S (2) and Philips along with an update of a previous vendor disclosure from Belden. There is also an exploit publication for products from GE. Finally, an interesting look at control system security and COVID-19 ‘industrial distancing’.

Phoenix Contact Advisories


Phoenix Contact published an advisory [.PDF download link] describing a privilege escalation vulnerability in their Portico Remote desktop control software. The vulnerability was reported by an unnamed researcher. Phoenix Contact has a new version that mitigates the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.


Phoenix Contact published an advisory [.PDF download link] describing an insecure permissions vulnerability in their PC WORX SRT. The vulnerability was reported by  Sharon Brizinov of
Claroty. Phoenix Contact provides generic workarounds to mitigate the vulnerability.

3S Advisories


3S published an advisory [.PDF download link] describing an out-of-bounds memory buffer access vulnerability in their  CODESYS communication protocol. The vulnerability was reported by Carl Hurd of Cisco Talos and an OEM customer. 3S has a new version that mitigates the vulnerability. There is no indication that Hurd has been provided an opportunity to verify the efficacy of the fix.

NOTE: The Talos report includes proof-of-concept exploit code.


3S published an advisory [.PDF download link] describing a heap-based buffer overflow vulnerability in their Web Service application. The vulnerability was reported by Tenable. 3S has a new version that mitigates the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

NOTE: The Tenable report includes proof-of-concept exploit code.

Philips Advisory


Philips published an advisory describing two vulnerabilities in their AC 2719 Air Purifier when using the Air Matters Android application. Philips reports that this is a chip-level problem, but reportedly a newer version of the application mitigates the vulnerabilities (?). The vulnerabilities were reported by an unnamed researcher.

The two (3 or 4 depending on where you read in the advisory) reported vulnerabilities are:

• Cleartext transmission of information;
• Insufficient Diffie Helman strength; and
• Decompiling Android app

NOTE: Okay, I will admit that I am confused by this advisory. I cannot find a researcher report of these vulnerabilities. If someone wants to step forward and explain this to me, I would appreciate it.

GE Exploit


Ivan Marmolejo has published an exploit for a password denial of service vulnerability in the GE ProficySCADA for iOS. There is no CVE number associated with the exploit report nor any vendor contact reports and I cannot find a report of a similar vulnerability on the GE security advisory page so this looks like a 0-day exploit.

COVID-19


Otorio.com has an interesting blog post about the increase in remote access to industrial systems due to COVID-19. They introduce a fun new term ‘industrial distancing’. It is a quick read, but worth it.

Thursday, March 5, 2020

1 Advisory Published – 3-5-20


Today the CISA NCCIC-ICS published a control system security advisory for products from WAGO.

WAGO Advisory


This advisory describes nine vulnerabilities in the WAGO I/O-CHECK Series PFC100 and Series PFC200. The vulnerabilities were reported by Kelly Leuschner of Cisco Talos. WAGO has new firmware that mitigates the vulnerability. There is no indication that Leuschner has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to change settings, delete the application, run remote code, cause a system crash, cause a denial-of-service condition, revert to factory settings, and overwrite MAC addresses.

NOTE: I briefly discussed these vulnerabilities back in December. In that post I provided links to the individual vulnerability reports from Talos; many of those reports included proof-of-concept exploit code.

ICSJWG 2020 Spring Meeting


Yesterday @ICSCERT announced that the 2020 Spring Meeting would be held in Salt Lake City, UT on April 14th thru 15th. Unfortunately, the link provided in the TWEET is incomplete and returns a 404 message. There is no message about this on the ‘ICS-CERT Announcements’ page.

Saturday, December 21, 2019

Public ICS Disclosures – Week of 12-14-19


This week we have five vendor disclosures for products from WAGO, ABB, 3S, BD and Symantech. There is also an updated advisory from 3S.

WAGO Advisory


CERT-VDE published an advisory describing 9 vulnerabilities in the WAGO Series PFC100 and Series PFC200 devices. The vulnerabilities were reported (CVE links to individual reports) by Kelly Leuschner of Cisco Talos. WAGO has a specific workaround and firmware updates to mitigate the vulnerabilities. There is no indication that Leuschner has been provided an opportunity to verify the efficacy of the fix.

The nine reported vulnerabilities are:

• Information exposure through sent data - CVE-2019-5073;
• Buffer access with incorrect length value (2) - CVE-2019-5074 and CVE-2019-5075;
• Missing authentication for critical function (3) - CVE-2019-5077, CVE-2019-5078 and CVE-2019-5080; and
Classic buffer overflow (3) - CVE-2019-5079, CVE-2019-5081 and CVE-2019-5082

NOTE1: The following Talos reports include exploit code: CVE-2019-5073; CVE-2019-5074; CVE-2019-5075; CVE-2019-5079; CVE-2019-5081; CVE-2019-5082

NOTE2: Talos reports that some of these vulnerabilities are in third-party components from 3S.

ABB Advisory


ABB published an advisory that describes four vulnerabilities in their PB610 Panel Builder 600. The vulnerabilities were reported by NSFOCUS. ABB has a new version that mitigates the vulnerabilities. There is no indication that NSFOCUS was provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• PB610 HMIStudio crashes after launching an empty *.JPR application file;
• PB610 HMISimulator does not check content-length of the HTTP request;
• PB610 HMIStudio accepts malicious DLL file in an application; and
• PB610 HMISimulator provides interface with access to arbitrary files

3S Advisory


3S published an advisory [.PDF download link] describing a null pointer dereference vulnerability in their CODESYS V2 runtime systems. The vulnerability was reported by Chen Jie from NSFOCUS. 3S has new versions that mitigate the vulnerability. There is no indication that Chen has been provided an opportunity to verify the efficacy of the fix.

3S Update


3S published an update [.PDF download link] of an advisory that was originally published on November 20th, 2019. The new data includes updated exploit information.

BD Advisory


BD has published an advisory describing the impact of the Internet Explorer® Scripting Engine Memory Corruption Vulnerability in their products. The vulnerability is self-reported. BD is working to test and validate the Microsoft patch for BD products that use the affected third-party components.

Symantec Advisory


Symantec has published an advisory describing an improper authentication vulnerability in their Industrial Control System Protection product. The vulnerability was reported by Tyler Holland at Horne Cyber Solutions. Symantec has an update that mitigates the vulnerability. There is no indication that Holland has been provided an opportunity to verify the efficacy of the fix.

Saturday, October 12, 2019

Public ICS Disclosures – Week of 09-05-19


This week we have URGENT/11 updates from three ICS vendors; seven new vendor disclosures from Siemens, Schneider (4), Beckhoff (2) and Drager; six updates of previously issued advisories from Siemens (2), Schneider (3) and Yokogawa, and one exploit of a previously reported vulnerability for products from SMA Solar Technology.

URGENT/11 Updates



Siemens Advisory


Siemens published an advisory describing twelve vulnerabilities in the Siemens SIMATIC WinAC
RTX (F) 2010. These vulnerabilities are known as Spectre, Meltdown, Spectre-NG, Foreshadow, L1 Terminal Fault (L1TF), ZombieLoad, and Microarchitectural Data Sampling (MDS). These vulnerabilities were reported by various researchers. Siemens has an update that mitigates the vulnerabilities.

Schneider Advisories


Modicon Controllers Advisory #1

Schneider published an advisory describing a file and directory information disclosure vulnerability in the Schneider Modicon brand of programmable logic controllers. The vulnerability was reported by Jared Rittle (Cisco Talos); the report includes proof-of-concept (POC) code. Schneider provides generic workarounds to mitigate the vulnerability.

Modicon Controllers Advisory #2

Schneider published an advisory describing six vulnerabilities in the Schneider Modicon brand of programmable logic controllers. The vulnerabilities were reported by Jared Rittle and Patrick DeSantis (Cisco Talos) (the CVE links below are to the individual reports which contain POC code). Schneider provides generic workarounds to mitigate the vulnerability.

The six reported vulnerabilities are:

Uncaught exception (5) - CVE-2019-6841, CVE-2019-6842, CVE-2019-6843, CVE-2019-6844 and CVE-2019-6847; and
Clear-text transmission of sensitive information - CVE-2019-6846;

Modicon Controllers Advisory #3

Schneider published an advisory describing a clear-text transmission of sensitive information vulnerability in the Schneider Modicon brand of programmable logic controllers. The vulnerability was reported by Jared Rittle (Cisco Talos). Schneider provides generic workarounds to mitigate the vulnerability.

Modicon Controllers Advisory #4

Schneider published an advisory describing three vulnerabilities in the Schneider Modicon brand of programmable logic controllers. The vulnerabilities were reported by Jared Rittle (Cisco Talos) (the CVE links below are to the individual reports which contain POC code). Schneider provides generic workarounds to mitigate the vulnerability.

The three reported vulnerabilities are:

Uncaught exception vulnerability - CVE-2019-6848; and
Information exposure (2) - CVE-2019-6849 and CVE-2019-6850

Beckhoff Advisories


TwinCat Advisory

VDE-CERT published an advisory describing a divide by zero vulnerability in the Beckhoff TwinCAT real-time controller. The vulnerability was reported by Andreas Galauner from Rapid7. The Beckhoff advisory on this vulnerability reports that they are working on an update to mitigate the vulnerability.

CE Remote Display Advisory

Beckhoff published an advisory describing an incorrect login response vulnerability in the Beckhoff CE Remote Display. The vulnerability was reported by Chen Jie from NSFOCUS and Tijl Deneut from University Howest. Beckhoff has updates that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Drager Advisory


Drager has published an advisory describing three vulnerabilities in the Drager Infinity® M300 patient monitor. Drager is self-reporting the vulnerabilities. Drager will be releasing a new version to mitigate the vulnerabilities in March 2020.

The three reported vulnerabilities are:

Network DDOS attack;
Repeated DDOS attacks; and
Information exposure

Siemens Updates


Industrial Products Update

Siemens published an update for an advisory that was originally published in May of 2017 and most recently updated on February 14th, 2019. The new information includes:

• Merged WinAC RTX 2010 SP2 and WinAC RTX F 2010 SP2 to SIMATIC WinAC RTX (F) 2010; and
• Added mitigation information for SIMATIC WinAC RTX (F) 2010

NOTE: I expect NCCIC-ICS to update their advisory this week.

SIMATIC S7 Update

Siemens published an update for an advisory that was originally reported in November 2018 and most recently updated on August 13th, 2019. The new information includes:

• Added CVE-2019-1125, CVE-2019-15666 and CVE-2019-15903; and
• Removed CVE2018-19591 from the list of fixed vulnerabilities

NOTE: NCCIC-ICS has not addressed these Linux vulnerabilities.

Schneider Updates


Floating License Manager Update

Schneider published an update for an advisory that was originally published in May 2019 and most recently updated on September 10th, 2019. The new information is updated remediations for EcoStruxure Power
Monitoring Expert.

NOTE: NCCIC-ICS may update their advisory, but they did not update for the last Schneider update.

SoMachine Update

Schneider published an update for an advisory that was originally published on August 13th, 2019. The new information is adding SoMove FDT to the list of affected products.

NOTE: NCCIC-ICS did not address this vulnerability.

Embedded Web Server Update

Schneider published an update for an advisory that was originally published in November 2018 and most recently updated on June 11th, 2019. The new information includes mitigation information for the M340 controller.

 NOTE: NCCIC-ICS did not address these vulnerabilities.

Yokogawa Update


Yokogawa published an update for an advisory that was originally published on September 27th, 2019. The new information includes updated affected version data and mitigation measures for Exaquantum.

NOTE: NCCIC-ICS will probably update their advisory this week.

SMA Exploit


Borja Merino published an exploit for a cross-site forgery vulnerability in the SMA Sunny WebBox. An advisory for the vulnerability was published on October 8th, 2019.

Friday, May 3, 2019

Three Advisories Published – 05-02-19


Yesterday the DHS NCCIC-ICS published three control system security advisories for products from Sierra Wireless, GE, and Orpak

Sierra Wireless Advisory


This advisory describes seven vulnerabilities in the Sierra Wireless AirLink ALEOS. The vulnerabilities were reported by Carl Hurd and Jared Rittle of Cisco Talos. Sierra Wireless reports that the latest version of ALEOS (not all yet available) mitigates the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The seven reported vulnerabilities are:

OS command injection - CVE-2018-4061;
Use of hard-coded credentials - CVE-2018-4062;
Unrestricted upload of file with dangerous type - CVE-2018-4063
Cross-site scripting - CVE-2018-4065;
Cross-site request forgery - CVE-2018-4066;
Information exposure - CVE-2018-4067; and
Missing encryption of sensitive data - CVE-2018-4069

The Talos web site lists six additional vulnerabilities (with exploits) {NOTE: the Sierra Wireless advisory (.PDF Download) explains these ‘vulnerabilities’}:

Information exposure -  CVE-2018-4068;
Unverified password change - CVE-2018-4064;
Information disclosure (2) - CVE-2018-4070, CVE-2018-4071; and
Permission assignment (2) - CVE-2018-4072, CVE-2018-4073

NCCIC-ICS reports that a relatively low-skilled attacker could use publicly available exploits to remotely exploit these vulnerabilities to remotely execute code, discover user credentials, upload files, or discover file paths.

GE Advisory


This advisory describes five vulnerabilities in the General Electric Communicator. Reid Wightman of Dragos. GE has a new version that mitigates the vulnerability. There is no indication that Reid has been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

Uncontrolled search path (2) - CVE-2019-6564 and CVE-2019-6546;
Hard-coded credentials - CVE-2019-6548; and
Improper access controls (2) - CVE-2019-6544 and CVE-2019-6566

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to gain administrative privileges, manipulate widgets and UI elements, gain control over the database, or execute administrative commands.

Orpak Advisory


This advisory describes six vulnerabilities in the Orpak SiteOmat fuel management software. The vulnerabilities were reported by Ido Naor of Kaspersky Lab. Orpak has an update available that mitigates the vulnerability. This is no indication that Naor has been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

Use of hard-coded credentials - CVE-2017-14728;
Cross-site scripting - CVE-2017-14850;
SQL injection - CVE-2017-14851;
Missing encryption of sensitive data - CVE-2017-14852;
Code injection - CVE-2017-14853; and
Stack-based buffer overflow - CVE-2017-14854

NCCIC-ICS reports that a relatively low-skilled attacker could use publicly available exploits (NOTE: The exploits have been available for over one year) to remotely exploit these vulnerabilities to effect arbitrary remote code execution resulting in possible denial-of-service conditions and unauthorized access to view and edit monitoring, configuration, and payment information.

Thursday, June 14, 2018

ICS-CERT Publishes Two Advisories and an Update


Today the DHS ICS-CERT published a control system security advisory for products from Siemens and a medical device security advisory for products from Naus Xltek. They also updated a control system security advisory for products from Siemens.

NOTE: There are still three Siemens advisories and two Siemens updates that were announced by Siemens on Tuesday that have not been covered by ICS-CERT. I will address those in my Saturday post.

Siemens Advisory


This advisory describes a permissions, privileges and access controls vulnerability in the Siemens SCALANCE X switches, RUGGEDCOM WiMAX, RFID 181-EIP, and SIMATIC RF182C. The vulnerability was reported by Dr. Ang Cui and Joseph Pantoga from Red Balloon Security. Siemens has provided updates for some of the affected products. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that an uncharacterized attacker on the same local network segment could exploit the vulnerability to execute arbitrary code.

Natus Xltek Advisory


This advisory describes 8 vulnerabilities in the Natus Xltek NeuroWorks software. The vulnerabilities were reported by Cory Duplantis from Cisco Talos. Natus Xltek has produced an update to mitigate the vulnerabilities. There is no indication that Duplantix has been provided an opportunity to verify the efficacy of the fix.

The eight reported vulnerabilities are:

• Out-of-bounds read (4) - CVE-2017-2852, CVE-2017-2858, CVE-2017-2860, and CVE-2017-2861; and
Stack-based buffer overflow (4) - CVE-2017-2853, CVE-2017-2867, CVE-2017-2868, and CVE-2017-2869.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to crash the device being accessed; a buffer overflow condition may allow remote code execution.

Siemens Update


This update provides additional information on an advisory that was originally issued on November 8, 2016 and then updated November 22nd, 2016; December 23rd, 2016; February 14th, 2017; March 2nd, 2017,  May 9th, 2017, June 20th, 2017, and again on January 25th, 2018. The update provided corrected affected version numbers and a link to a mitigation measure for PCS 7 V8.2.

 
/* Use this with templates/template-twocol.html */