Showing posts with label Claroty. Show all posts
Showing posts with label Claroty. Show all posts

Saturday, June 10, 2023

Review – Public ICS Disclosures – Week of 6-3-23

This week we have 10 vendor disclosures from Broadcom, Fuji Electric, GE Gas Power, Johnson Controls, Moxa, Philips, VMware, WolfSSL, and Zyxel (2). We also have a vendor update from HPE. There are 17 researcher reports for products from Suprema (4), Control ID (5), and Connected IO (8). Finally, we have 2 exploits for products from Zyxel and Delta Electronics.

Advisories

Broadcom Advisory - Broadcom published an advisory that discusses an SQL injection vulnerability in multiple products.

Fuji Advisory - JP-CERT published an advisory that describes the eight vulnerabilities in multiple Fuji server products.

GE Advisory - GE published an advisory that discusses four vulnerabilities in their Control Server Virtual HMIs and ThickClient HMIs.

Moxa Advisory - Moxa published an advisory that describes a weak cryptographic algorithm vulnerability in the CN2600 Series terminal servers

Philips Advisory - Philips published an advisory that discusses the MoveIT SQL injection vulnerability.

VMware Advisory - VMware published an advisory that describes three vulnerabilities in their VMware Aria Operations for Networks product.

WolfSSL Advisory - WolfSSL published a change log for a new version of their SSL product that reports two vulnerabilities in the previous version that are being fixed in the new release.

Zyxel Advisory #1 - Zyxel published an advisory that describes a buffer overflow vulnerability in their 4G LTE and 5G NR outdoor routers.

Zyxel Advisory #2 - Zyxel published an advisory that describes a privilege escalation vulnerability in their GS1900 series switches.

Updates

HPE Update - HPE published an update for their Aruba OpenSSL advisory that was originally published on February 15th, 2023 and most recently updated on May 22nd, 2023.

Researcher Reports

Suprmema Reports - Claroty published four reports about individual vulnerabilities in the Suprema BioStar security platform.

Control ID Reports - Claroty published five reports about individual vulnerabilities in the Control ID iDSecure product.

Connected IO Reports #1-4 - Claroty published four reports about individual vulnerabilities in the Control IO ER2000 edge router.

Connected IO Reports #5-8 - Claroty published four reports about individual vulnerabilities in the Control IO IDSecure product.

Exploits

Zyxel Exploit - Sf published a Metasploit module for a command injection vulnerability in the Zyxel firewalls.

Delta Exploit - Shelby Pace published a Metasploit module for a deserialization of untrusted data vulnerability in the Delta InfraSuite Device Master.

 

For more details about these disclosures, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-f21 - subscription required.

Saturday, June 3, 2023

Review – Public ICS Disclosure – Week of 5-27-23

This week we have 31 vendor disclosures from BD, Bosch, B&R, Contec, Eaton, Fuji Electric, Hitachi Energy (2), HPE (3), Mitsubishi, Splunk (15), VMware, and Zyxel (3). There are also four vendor updates from HPE (2) and Moxa (2). We also have 40 researcher reports for vulnerabilities for products from Delta Electronics (22), Fatek Automation (11), Mitsubishi, and Unified Automation (6). Finally, we have an exploit for products from Seagate.

Advisories

BD Advisory - BD published an advisory that discusses a buffer underflow vulnerability in some of their Kiestra products.

Bosch Advisory - Bosch published an advisory that describes a chip damaging vulnerability in their CPP13 and CPP14 cameras.

B&R Advisory - B&R published an advisory that discusses an abuse of service location protocol vulnerability in their ARPOL product.

Contec Advisory - Contec published an advisory that describes seven vulnerabilities in their CONPROSYS HMI System.

Eaton Advisory - Eaton published an advisory that describes a group access authorization logic vulnerability in their SecureConnect portal.

Fuji Electric - JP CERT published an advisory that describes three vulnerabilities in the Fuji Electric FRENIC RHC Loader.

Hitachi Energy Advisory #1 - Hitachi published an advisory that describes an improper output neutralization for logs vulnerability in their UNEM product.

Hitachi Energy Advisory #2 - Hitachi published an advisory that that describes an improper output neutralization for logs vulnerability in their FOXMAN-UN product.

HPE Advisory #1 - HPE published an advisory that describes an arbitrary code execution vulnerability in their Smart Storage Administrator (SSA) Offline product.

HPE Advisory #2 - HPE published an advisory that discusses four vulnerabilities in their HP-UX BIND product.

HPE Advisory #3 - HPE published an advisory that describes a denial of service vulnerability in their HP-UX IPv6 Stack.

Mitsubishi Advisory - Mitsubishi published an advisory that describes four vulnerabilities in their MELSEC iQ-R Series/iQ-F Series EtherNet/IP modules and EtherNet/IP configuration tools.

Splunk Advisories 1-3 - Splunk published three advisories for product updates for third party vulnerabilities.

Splunk Advisories 4-15 - Splunk published 12 advisories for individual vulnerabilities in multiple products.

VMware Advisory - VMware published an advisory that describes an insecure redirect vulnerability in their Workspace ONE Access and Identity Manager products.

Zyxel Advisory #1 - Zyxel published an advisory that describes two classic buffer overflow vulnerabilities in their firewalls.

Zyxel Adviosry #2 - Zyxel published an advisory that describes an OS command injection vulnerability in some of their NAS versions.

Zyxel Advisory #3 - Zyxel published an advisory that discusses recent attacks on their ZyWALL devices.

Updates

HPE Update #1 - HPE published an update for their StoreEasy Servers advisory that was originally published on February 14th, 2023 and most recently updated on March 23rd, 2023.

HPE Update #2 - HPE published an update for their OneView advisory that was originally published on February 6th, 2023.

Moxa Update #1 - Moxa published an update for their MXsecurity advisory that was originally published on March 8th, 2023 and most recently updated on May 23rd, 2023.

Moxa Update #2 - Moxa published an update for their Arm-based Computer advisory that was originally published on November 22nd, 2022.

Researcher Reports

Delta Electronics Reports - ZDI published 22 reports about individual vulnerabilities in the Delta CNCSoft-B product.

Fatek Reports - ZDI published eleven reports about individual vulnerabilities in the Fatek FvDesigner.

Mitsubishi Report - Talos Intelligence published a report describing a memory corruption vulnerability in the Mitsubishi MELSEC iQ-F FX5U MELSOFT.

Unified Automation Report #1 - Claroty published a report that describes an object validation vulnerability in the Unified Automation UaGateway.

Unified Automation Reports #2-6 - ZDI published five reports describing vulnerabilities in the Unified Automation UaGateway.

Exploits

Seagate Exploit - Ege Balci published an metsploit module for an OS command injection vulnerability in the Seagate Central External NAS Storage device.


For more details about these disclosures, including links to researcher reports and exploits, as well as a brief description of new information in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-5-27 - subscription required.


Saturday, January 21, 2023

Review – Public ICS Disclosures – Week of 1-14-23

This week we have twelve vendor disclosures from Campbell Scientific, Contec, HIMA, HP, Medtronic, and Wireshark (7). We also have two researcher disclosures for products from Mitsubishi and GE,

Vendor Disclosures

Campbell Advisory - INCIBE-CERT published an advisory that describes an exposure of sensitive information to unauthorized actor vulnerability in the Campbell dataloggers.

Contec Advisory - Contec published an advisory that describes SQL injection vulnerabilities in their CONPROSYS HMI System.

HIMA Advisory - CERT-VDE published an advisory that describes an unquoted Windows search path vulnerability in multiple HIMA X-OPC and X-OTS products.

HP Advisory - HP published an advisory that discusses eight vulnerabilities in multiple HP products.

Medtronic Advisory - Medtronic published an end-of-life notice for their superDimension™ navigation system.

Wireshark Advisory #1 - Wireshark published an advisory that describes a packet injection vulnerability in their EAP dissector.

Wireshark Advisory #2 - Wireshark published an advisory that describes a memory leak vulnerability in their NFS dissector.

Wireshark Advisory #3 - Wireshark published an advisory that describes a denial of service vulnerability in their Dissection engine.

Wireshark Advisory #4 - Wireshark published an advisory that describes a denial of service vulnerability in their GNW dissector.

Wireshark Advisory #5 - Wireshark published an advisory that describes a denial of service vulnerability in their iSCSI dissector.

Wireshark Advisory #6 - Wireshark published an advisory that describes an excessive loop vulnerability in multiple dissectors.

Wireshark Advisory #7 - Wireshark published an advisory that describes a denial of service vulnerability in their TIPC dissector.

Researcher Reports

Mitsubishi Report - CISCO Talos published a report that describes an authentication bypass vulnerability in the Mitsubishi MELSEC iQ-FX5U webserver.

GE Report - Claroty published a report that describes five vulnerabilities in the GE Proficy Historian. The report contains proof-of-concept code.

 

For more details about these disclosures, including links to third-party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-6c3 - subscription required.

Tuesday, August 16, 2022

Review – 7 Advisories and 1 Update Published – 8-16-22

Today, CISA’s NCCIC-ICS published seven control system security advisories for products from Sequi, Emerson, B&R, Delta Industrial, Softing, LS Industrial Systems, and Yokogawa. They also updated an advisory for products from Siemens.

Sequi Advisory - This advisory describes two vulnerabilities in the Sequi PortBloque S serial Modbus firewall.

Emerson Advisory - This advisory describes six vulnerabilities in the Emerson Proficy Machine Edition.

B&R Advisory - This advisory describes an improper input validation vulnerability in the B&R Automation Studio PLC programming software.

NOTE: While this vulnerability was discussed in the Evil PLC Attack paper, it was originally reported by B&R on January 20th, 2022 which I reported earlier. B&R updated their advisory this week, adding a reference to the Evil PLC Attack paper.

Delta Advisory - This advisory describes an improper restriction of XML external entity reference vulnerability in the Delta DRAS controller software suite.

Softing Advisory - This advisory describes nine vulnerabilities in the Softing Secure Integration Server.

LS Industrial Advisory - This advisory describes an inadequate encryption strength vulnerability in the LS Industrial LS ELEC PLC and XG5000.

Yokogawa Advisory - This advisory describes a resource management errors vulnerability in the Yokogawa CENTUM VP/CS 3000 Controller FCS products.

NOTE: I briefly reported this vulnerability on July 30th, 2022.

Siemens Update - This update provides additional information on an advisory that originally published on May 12th, 2022 and most recently updated on July 12th, 2022.

NOTE: I briefly reported this update on Sunday.

 

For more details about these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-and-1-update-published-589 - subscription required.

Sunday, May 15, 2022

Review – Public ICS Disclosures – Week of 5-7-22 – Part 2

For Part 2 we have nine additional vendor disclosures from Philips, Phoenix Contact, ProsysOPC, Rockwell Automation, Schneider (3), and Tanzu (2). We also have eleven updates from QNAP, Rockwell (2), Schneider (3), and Siemens (5). There are also researcher two reports for products from XINJE and Rockwell. Finally, we have two exploits for products from USR IOT and Spring.

Philips Advisory - Philips published an advisory that discusses the F5 BIG IP vulnerability.

Phoenix Contact Advisory - Phoenix Contact published an advisory that discusses two vulnerabilities in their RAD-ISM-900-EN-BD devices.

ProsysOPC Advisory - ProsysOPC published an advisory that describes a resource exhaustion vulnerability in their OPC UA SDK for Java that was discovered during the PWN2OWN MIAMI 2022 competition.

Rockwell Advisory - Rockwell published an advisory that discusses an infinite loop vulnerability in their ThinMan and FactoryTalk products.

Schneider Advisory #1 - Schneider published an advisory that describes six vulnerabilities in their Wiser Smart products.

Schneider Advisory #2 - Schneider published an advisory that discusses an out-of-bounds write vulnerability in their Saitel DP RTU.

Schneider Advisory #3 - Schneider published an advisory that describes an improper input validation vulnerability in their PowerLogic ION Setup product.

Tanzu Advisory #1 - Tanzu published an advisory that describes a denial-of-service vulnerability in their Spring Framework.

Tanzu Advisory #2 - Tanzu published an advisory that describes a file download vulnerability in their Spring MVC or Spring WebFlux applications.

QNAP Update - QNAP published an update for their VS Series NVR advisory that was originally published on May 6th, 2022.

Rockwell Update #1 - Rockwell published an update for their Logix Controllers advisory that was originally published on March 31st, 2022.

NOTE: NCCIC-ICS has not updated their advisory (ICSA-22-090-05) for this new information.

Rockwell Update #2 - Rockwell published an update for their Logix Designer Application advisory originally published on March 31st, 2022.

NOTE: NCCIC-ICS has not updated their advisory (ICSA-22-090-07) for this new information.

Schneider Update #1 - Schneider published an update for their APC Smart-UPS advisory that was originally published on March 8th, 2022 and most recently updated on March 24th, 2022.

NOTE: NCCIC-ICS has not updated their advisory (ICSA-21-313-01) for this new information.

Schneider Update #2 - Schneider published an update for their Network Management Card advisory that was originally published on November 9th, 2022.

Siemens Update #1 - Siemens published an update for their OpenSSL advisory that was originally reported on July 13th, 2021 and most recently updated on April 12th, 2022.

Siemens Update #2 - Siemens published an update for their GNU/Linux advisory that was  originally published in 2018 and most recently updated on April 14th, 2022.

NOTE: NCCIC-ICS did not update their advisory (icsa-22-104-13) for this information.

Siemens Update #3 - Siemens published an update for their Log4Shell advisory that was was originally published on December 13th, 2021 and most recently updated on April 12th, 2022.

Siemens Update #4 - Siemens published an update for their Mbed TLS of LOGO! advisory that was originally published on September 14th, 2021.

NOTE: NCCIC-ICS did not update their advisory (ICSA-21-257-20) for this new information.

Siemens published an update for their SIMATIC WinCC advisory that was originally published on November 11th, 2021 and most recently updated on April 14th, 2022.

NOTE: NCCIC-ICS did not update their advisory (ICSA-21-315-03) for this new information.

XINJE Report - Claroty published a report about two vulnerabilities in the XINJE PLC programming tool.

Rockwell Report - ZDI published a report about a sensitive information disclosure vulnerability in the Rockwell ISaGRAF.

USR IOT Exploit - LiquidWorm published an exploit for a hard-coded credentials vulnerability in the USR IOT 4G LTE Industrial Cellular VPN Router.

Spring4Shell Exploit - Vleminator published a Metasploit module for the SpringShell vulnerabilities.

 

For more details about these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-5-34b - subscription required.

Saturday, November 27, 2021

Review – Public ICS Disclosures – Week of 11-20-21

This week we have ten vendor disclosures from Advantech, Hitachi, Hitachi Energy (2), Moxa (2), QNAP (2), and VMware. There is also an update from Mitsubishi. Additionally, we have two researcher reports for vulnerabilities for products from PerFact and Philips. Finally, we have an exploit for a product from ModbusTools.

Advantech Advisory - Advantech published an advisory describing five sets of vulnerabilities (each set corresponding to a separate Talos report containing multiple vulnerabilities) in their R-SeeNet application.

Hitachi Advisory - Hitachi published an advisory discussing 24 vulnerabilities in their Disk Array Systems.

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory describing two vulnerabilities in their XMC20 product.

Hitachi Energy Advisory #2 - Hitachi Energy published an advisory describing two vulnerabilities in their FOX61x product.

Moxa Advisory #1 - Moxa published an advisory describing eleven vulnerabilities in their ioLogik E2200 Series Controllers and I/Os.

Moxa Advisory #2 - Moxa published an advisory describing three vulnerabilities in their NPort IAW5000A-I/O Series Servers.

QNAP Advisory #1 - QNAP published an advisory describing an improper authentication vulnerability in their VS Series NVR.

QNAP Advisory #2 - QNAP published an advisory describing a command injection vulnerability in their VS Series NVR.

VMware Advisory - VMware published an advisory describing two vulnerabilities in their vCenter Server.

Mitsubishi Update - Mitsubishi published an update for their GENESIS64 and MC Works64 advisory that was originally published on October 21st, 2021.

PerFact Report - Claroty published a report describing vulnerabilities in VPN products in use in industrial applications including a previously unpublished server-side request forgery vulnerability in products from PerFact.

Philips Report - Nozomi Networks published a report describing five vulnerabilities in patient monitoring products from Philips.

ModbusTools Exploit - Yehia Elghaly published an exploit for an improper restriction of operations within the bounds of a memory buffer vulnerabilty in the Modbus Slave tool from ModbusTools.

For more details on these advisories, updates, reports and exploits, including links to supporting third-party vulnerabilities, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11-857 - subscription required.

Tuesday, June 29, 2021

Review - 6 Advisories Published - 6-29-21

 

Today CISA’s NCCIC-ICS published six control system security advisories for products from Claroty, Aveva, JTEKT, Panasonic and Johnson Controls (2).

 

Claroty Advisory - This advisory describes an authentication bypass using an alternative path or channel vulnerability in the Claroty Secure Remote Access Site.

Aveva Advisory - This advisory describes two vulnerabilities in the Aveva System Platform. The vulnerability was reported by Sharon Brizinov of Claroty.

JTEKT Advisory - This advisory describes an improper restriction of operations withing the bounds of a memory buffer vulnerability in the JTEKT TOYOPUC PLCs.

Panasonic Advisory - This advisory describes an improper restriction of XML external entity reference vulnerability in the Panasonic FPWIN Pro programming control software.

exacqVision Advisory #1 - This advisory describes a cross-site scripting vulnerability in the Johnson Controls exacqVision Enterprise Manager.

exacqVision Advisory #2 - This advisory describes a cross-site scripting vulnerability in the Johnson Controls exacqVision Web Service.

For more detailed information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-published - subscription required.

Saturday, June 26, 2021

Review - Public ICS Disclosures – Week of 6-19-21

This week we have 16 vendor disclosures from ABB, Aveva, Weidmueller, Draeger, Phoenix Contact (7), QNAP, Sick, SonicWall, and VMware (2). There are exploit reports for products from VMWare and HPE.

Miscellaneous Advisories

ABB Advisory - ABB published an advisory discussing CodeMeter vulnerabilities in their Automation Builder, Drive Application Builder and Virtual Drive products.

Aveva Advisory - Aveva published an advisory describing five vulnerabilities in the AutoBuild service of their System Platform.

Weidmueller Advisory - CERT-VDE published an advisory describing twelve vulnerabilities in the Weidmueller Industrial WLAN devices.

Draeger Advisory - Draeger published an advisory describing an integer overflow or wraparound vulnerability in their Clinical Assistance Package.

QNAP Advisory - QNAP published an advisory describing a command injection vulnerability in their NAS running legacy versions of QTS.

Sick Advisory - Sick published an advisory describing an inadequate SSH configuration vulnerability in their Visionary-S CX product.

SonicWall Advisory - SonicWall published an advisory describing a buffer overflow vulnerability in their SonicOS.

Phoenix Contact Advisories

Phoenix Contact published an advisory describing an undocumented access vulnerability in their AXL F BK and IL BK products.

Phoenix Contact published an advisory describing a denial of service vulnerability in their ILC1x1 Industrial controllers.

Phoenix Contact published an advisory describing a file parsing memory corruption vulnerability in their Automation Worx Software Suite.

Phoenix Contact published an advisory describing a race condition vulnerability in their r PLCNext, SMARTRTU AXC, CHARX control modular and EEM-SB37x products.

Phoenix Contact published an advisory describing two vulnerabilities in their PLCNext, ILC 2050 BI, FL MGUARD DM UNLIMITED, TC ROUTER und CLOUD CLIENT products.

Phoenix Contact published an advisory describing three vulnerabilities in their FL SWITCH SMCS series.

VMware Advisories

VMware published an advisory describing a local privilege escalation vulnerability in their VMware Tools, VMRC and VMware App Volumes products.

VMware published an advisory describing an authentication bypass vulnerability in their Carbon Black App Control product.

Exploits

CHackA0101 published an exploit for an improper privilege management vulnerability in the VMware vCenter Server.

Jeremy Brown published an exploit for a denial of service vulnerability in the HPE Remote Device Access product.

For more detailed information on the advisories see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-73d  (subscription required)


Tuesday, June 1, 2021

2 Advisories Published – 6-1-21

Today CISA’s NCCIC-ICS published a control system security advisory for products from Siemens and a medical device security advisory for products from Hillrom.

Siemens Advisory

This advisory describes an improper restriction of operations within the bounds of a memory buffer. . The vulnerability was reported by Tal Keren from Claroty. Siemens has new versions that mitigate the vulnerability. There is no indication that Keren has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow an attacker to write arbitrary data and code to protected memory areas or read sensitive data to launch further attacks.

NOTE: I briefly discussed this vulnerability last Saturday on CFSN Detailed Analysis (subscription required).

Hillrom Advisory

This advisory describes two vulnerabilities in Hillrom’s Welch Allyn medical device management tools. The vulnerabilities were reported by Uriel Malin, Jamison Utter, and Itay Kirshenbaum of Medigate. Hillrom has updates the mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Out-of-bounds write - CVE-2021-27410, and

• Out-of-bounds read - CVE-2021-27408

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerabilities to allow an attacker to cause memory corruption and remotely execute arbitrary code.

Saturday, May 22, 2021

Public ICS Disclosures – Week of 5-15-21

This week we have seven vendor disclosures from Bosch, CODESYS (2), WAGO, ENDRESS+HAUSER, Siemens, and VMware. We have two vendor updates from Siemens. Finally, we have a researcher report for products from Advantech.

Bosch Advisory

Bosch published an advisory discussing an input validation vulnerability in their IndraMotion MTX, MLC and MLD and the ctrlX CORE PLC application products. This is a third-party (CODESYS) vulnerability. An update for the ctrlX CORE PLC APP is pending. Generic mitigation measures are provided.

CODESYS Advisories

CODESYS published an advisory describing an improper input validation vulnerability in their CODESYS V3 products. The vulnerability was reported by  Alexander Nochvay from Kaspersky Lab ICS CERT. CODESYS has software updates available to mitigate the vulnerability. There is no indication that Nochvay has been provided an opportunity to verify the efficacy of the fix.

CODESYS published an advisory describing a NULL pointer dereference vulnerability in their CODESYS V3 products. The vulnerability was reported by Uri Katz of Claroty. CODESYS has new versions available that mitigate the vulnerability. There is no indication that Katz has been provided an opportunity to verify the efficacy of the fix.

WAGO Advisory

CERT-VDE published an advisory discussing twelve vulnerabilities in the WAGO PLCs. These are third-party (CODESYS) vulnerabilities that were reported by JSC Positive Technologies. WAGO has new firmware versions available that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The twelve reported vulnerabilities are:

• Allocation of resources without limit or throttling - CVE-2021-21000,

• Path traversal - CVE-2021-21001,

• Heap-based buffer overflow - CVE-2021-30186,

• Stack-based buffer overflow (2) - CVE-2021-30188, CVE-2021-30189,

• Improper input validation - CVE-2021-30195,

• Improper access control - CVE-2021-30190,

• Buffer copy without checking size of input - CVE-2021-30191,

• Improperly implemented security check - CVE-2021-30192,

• Out-of-bounds write - CVE-2021-30193,

• Out-of-bounds read - CVE-2021-30194,

• Improper neutralization of special elements used in an OS command - CVE-2021-30187

NOTE: The first two vulnerabilities have apparently not yet been addressed by CODESYS and have been given CERT-VDE CPE numbers.

ENDRESS+HAUSER Advisory

CERT-VDE published an advisory discussing the KRACK attacks vulnerabilities in the ENDRESS+HAUSER Proline portfolio flow meter products. ENDRESS+HAUSER has firmware updates that mitigate the vulnerabilities.

Siemens Advisory

Siemens published an advisory describing five vulnerabilities in their n JT2Go and Teamcenter Visualization products. The vulnerabilities were reported by the Zero Day Initiative and Carsten Eiram from Risk Based Security. Siemens has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Untrusted pointer dereference - CVE-2020-26991,

• Out-of-bounds read (3) - CVE-2020-26998, CVE-2020-26999, and CVE-2020-27002, and

• Stack-buffer overflow - CVE-2020-27001

NOTE: Apparently, none of the above vulnerabilities are the 0-day vulnerability that ZDI published for this product on April 28th.

VMWare Advisory

VMWare published an advisory describing three out-of-bounds read vulnerabilities in their VMware Workstation and Horizon Client for Windows. This is a third-party (Cortado ThinPrint) vulnerability. The vulnerabilities were published by Anonymous at ZDI and Hou JingYi of Qihoo 360. VMware has new versions that mitigate the vulnerabilities. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

NOTE: The Cortado web site make the following claim about ThinPrint, so these vulnerabilities may exist in other ICS products.

“Thanks to numerous OEM partnerships, ThinPrint technology components are integrated in a variety of terminals, print boxes and thin client of leading hardware manufacturers.”

Siemens Updates

Siemens published an update for their JT2Go and Teamcenter Visualization advisory that was originally published on January 12th, 2021 and most recently updated on February 9th, 2021. The new information includes:

• Moving vulnerabilities CVE-2020-26989, CVE-2020-26990, and CVE-2020-28383

to advisory SSA-663999 (see below), and

• Moving vulnerabilities d CVE-2020-26991 to SSA-695540 (see new advisory above).

NOTE: NCCIC-ICS should be updating their advisory, ICSA-21-012-03, this coming week.

Siemens published an update for their JT2Go and Teamcenter Visualization advisory that was originally published on February 9th, 2021. The new information includes:

• Removing vulnerabilities CVE-2020-26991, CVE-2020-26998, CVE-2020-26999, CVE-2020-27001, and CVE-2020-27002, and

• Adding vulnerabilities CVE-2020-28383, CVE2021-31784 (from update above).

NOTE: NCCIC-ICS should be updating their advisory, ICSA-21-040-06, this coming week.

Advantech Report

ZDI published a report describing a use of hard-coded credentials vulnerability in the Advantech BB-ESWGP506-2SFP-T industrial switches. ZDI coordinated the disclosure with NCCIC-ICS.

Sunday, May 16, 2021

Public ICS Disclosures – Week of 5-8-21, Part 3

Finally. We have seven vendor notifications from Schneider Electric. We also have six vendor updates for products from Schneider.

Schneider Advisories

Schneider published an advisory describing a weak password recovery mechanism for forgotten password vulnerability in their Modicon Managed Switch. Schneider has a new version that mitigates the vulnerability.

Schneider published an advisory describing an improper restriction of operations within the bounds of a memory buffer vulnerability in their Harmony HMI Products. The vulnerability was reported by Jie Chen of NSFOCUS. Schneider has a new version that mitigates the vulnerability. There is no indication that Jie has been provided an opportunity to verify the efficacy of the fix.

Schneider published an advisory describing six improper check for unusual or exceptional conditions vulnerabilities in their Triconex Model 3009 Main Processor (MP) and Tricon™ Communication Module (TCM) Models. The vulnerabilities were reported by CNCERT/CC and Kunlun Digital Technology Co. Schneider reports that their engineers will have to fix the affected systems. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Schneider published an advisory describing nine vulnerabilities in their homeLYnk and spaceLYnk products. The vulnerabilities were reported by Sharon Brizinov of Claroty. Schneider has new version that mitigates the vulnerability. There is no indication that Brizinov has been provided an opportunity to verify the efficacy of the fix.

The nine reported vulnerabilities are:

• Improper privilege management (2) - CVE-2021-22732 and CVE-2021-22733,

• Improper verification of cryptographic signature (2) - CVE-2021-22734 and CVE-2021-22735,

• Path traversal - CVE-2021-22736,

• Insufficiently protected credentials - CVE-2021-22737,

• Use of broken or risky cryptographic program - CVE-2021-22738, and

• Information exposure (2) - CVE-2021-22739 and CVE-2021-22740

Schneider published an advisory describing an improper input validation vulnerability in their Modicon M241 & M251 Logic Controllers. The vulnerability was reported by Marcin Dudek, Kinga Staszkiewicz, Jakub Suchorab, Joanna Walkiewicz from National Centre for Nuclear Research Poland. Schneider has new versions that mitigate the vulnerability. There is no indications that the researchers have been provided an opportunity to verify the efficacy of the fix.

Schneider published an advisory discussing six vulnerabilities in a variety of their products. These are third-party (CODESYS) vulnerabilities. Schneider has new versions that mitigate the vulnerabilities.

The six vulnerabilities reported are:

• Buffer overflow - CVE-2020-10245,

• Insufficient verification of data authenticity – CVE-2020-6081

• Cross-site scripting - CVE-2019-13538,

• Incorrect permission assignment for critical resource - CVE-2019-9008,

• Improper input validation - CVE-2019-9009, and

• Uncontrolled resource consumption - CVE-2020-7052,

NOTE: Links to CODESYS advisories. There is no CODESYS advisory listed for CVE-2020-6081 in the NIST database.

Schneider published an advisory describing a use of password hash with insufficient computational effort in their EcoStruxure Geo SCADA Expert products. The vulnerability was reported by Nicholas Hobbs. Schneider has a new version that mitigates the vulnerability. There is no indication that Hobbs has been given an opportunity to verify the efficacy of the fix.

Schneider Updates

Schneider published an update for their Ripple20 advisory that was originally published on June 23, 2020 and most recently updated on April 12th, 2021. The new information includes adding remediation for ZBRCETH Modbus TCP communication module for ZBRN1 Harmony Hub.

Schneider published an update for their Urgent/11 advisory that was  originally published on August 2nd, 2019 and most recently updated on October 13th, 2020. The new information includes updating remediations for Modicon M241 Micro PLC and Modicon M251 Micro PLC.

Schneider published an update for their Modicon Controllers advisory was originally published on March 20th, 2020 and most recently updated on November 10th, 2020. The new information includes adding a recommendation for Customers on EcoStruxure™ Control Expert versions prior to V15.0 to upgrade to remediate CVE-2020-7475.

Schneider published an update for their Web Server on Modicon M340 advisory that was originally published on December 8th, 2020. The new information includes adding all versions of BMXNOC0401 to the affected products table.

Schneider published an update for their Web Server on Modicon M580 Controllers that was originally published on October 8th, 2019 and most recently updated on April 15th, 2021. The new information includes announcing that mitigation measures are now available for CVE-2019-6849 on the BMENOC0311.

Schneider published an update for their Embedded FTP Servers advisory that was originally published on March 22nd, 2018. The new information includes:

• Updating CVSS scores, and

• Adding Modicon M580 and clarification on Modicon M340 affected products 

Thursday, May 13, 2021

4 Advisories Published – 5-13-21

Today CISA’s NCCIC-ICS published four control system security advisories for products from Unified Automation, OPC Foundation, Johnson Controls, and Rockwell.

Unified Automation Advisory

This advisory describes an exposure of sensitive information to an unauthorized actor vulnerability in the Unified Automation .NET based OPC UA Client/Server SDK Bundle. The vulnerability was reported by Eran Jacob with the Otorio Research Team. UA has new software to mitigate the vulnerability. There is no indication that Jacob has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an unauthenticated attacker to read any file on the file system.

 

NOTE: NCCIC-ICS reports that the vulnerability was originally documented by Microsoft in CVE-2015-6096.

OPC Foundation Advisory

This advisory describes an uncontrolled recursion vulnerability in the OPC Foundation OPC UA Servers. The vulnerability was reported by Eran Jacob with the Otorio Research Team. OPC has an update that mitigates the vulnerability. There is no indication that Jacob has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to trigger a stack overflow.

Johnson Controls Advisory

This advisory describes an off-by-one error vulnerability in the Sensormatic Electronics Tyco AI. This is a third-party (SUDO) vulnerability with multiple published exploits (see here, here, and here for instance). Johnson Controls has a new version that mitigates the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerability to obtain super-user access to the underlying openSUSE Linux operating system.

NOTE: The Johnson Control advisory says the product is the American Dynamics Tyco AI.

Rockwell Advisory

This advisory describes three vulnerabilities in the Rockwell Connected Components Workbench. The vulnerability was reported by Mashav Sapir of Claroty. Rockwell has a new version that mitigates the vulnerability. There is no indication that Sapir has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Deserialization of untrusted data - CVE-2021-27475,

• Path traversal - CVE-2021-27471, and

• Improper input validation - CVE-2021-27473

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow remote code execution, authentication bypass, or privilege escalation.

Saturday, May 8, 2021

Public ICS Disclosures – Week of 5-1-21

This week we have four vendor disclosures from ABB (2), WAGO, and WEIDMUELLER. There are vendor updates from Dell and Rockwell Automation. We have ten researcher reports for vulnerabilities in products from Delta Industrial Automation.

ABB Advisories

ABB published an advisory discussing the NAME:WRECK vulnerabilities in their AC 800PEC controller based products. ABB provides generic workarounds for the vulnerablity.

NOTE: The NAME:WRECK vulnerability associated with the ABB products is CVE-2016-20009 (WindRiver VxWorks). A report with exploit code was published for this vulnerability in August 2016. See page 9 of the NAME:WRECK report for commentary on this situation.

ABB published an advisory describing a path traversal vulnerability in the Cassia Access Controller for their Ability™ Smart Sensor. The vulnerability was reported by Claroty. ABB reports that the vulnerability has been patched an no action is needed.

WAGO Advisory

CERT-VDE published an advisory describing six vulnerabilities in the Web-Based Management (WBM) of WAGOs industrial managed switches. The vulnerabilities were reported by Dr. Tobias Augustin and Stephan Tigges of IKS, and Kai Gaul and Jan Rubenach of ABO Wind. WAGO has new firmware versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Exposure of sensitive information to an unauthorized actor - CVE-2021-20993,

• Cross-site scripting - CVE-2021-20994,

• Storage of user credentials in a cookie - CVE-2021-20995,

• Incorrect permission assignment for critical resource - CVE-2021-20996, and

• Insufficiently protected credentials - CVE-2021-20997

WEIDMUELLER Advisory

CERT-VDE published an advisory describing an exposure of resource to wrong sphere vulnerability in the WEIDMUELLER u-controls and IoT-Gateways. The vulnerability is self-reported. WEIDMUELLER has a new version that mitigates the vulnerability.

Dell Update

Dell published an update for their Wyse ThinOS advisory that was originally published on March 31st, 2021. There is no indication of what has changed in the advisory.

Rockwell Update

Rockwell published an update for their Logix Controllers advisory that was originally published on February 25th, 2021. The new information includes updating mitigation measures for 1783-CSP CIP Security Proxy.

NOTE: I suspect that NCCIC-ICS will update their advisory in the coming week.

Delta Reports

The Zero Day Initiative published 10 reports (ZDI-21-510 thru ZDI-21-519) for out-of-bounds read vulnerabilities in the Delta DOPSoft products. The vulnerabilities were reported by Natnael Samson. The vulnerabilities have been coordinated with NCCIC-ICS.

Saturday, May 1, 2021

Public ICS Disclosures – Week of 4-24-21

This week we three vendor NAME:WRECK disclosures from Boston Scientific, Braun, and Rockwell. We also have 14 vendor disclosures from Beckhoff, Bosch (2), B&R Industrial Automation, MB connect, CODESYS (5), Moxa, ODA, and Texas Instruments (2). We have five researcher reports for products from Advantech (4) and Siemens. Finally, we have exploits for products from OpenPLC and VMWare.

NAME:WRECK Advisories

Boston Scientific published an advisory discussing the NAME:WRECK vulnerabilities, announcing that they are investigating to see if any of their products are affected.

Braun published an advisory discussing the NAME:WRECK vulnerabilities, announcing that none of their ‘connected devices’ are affected.

Rockwell published an advisory discussing the NAME:WRECK vulnerabilities, providing a list of affected products and fixed versions.

Beckhoff Advisory

Beckhoff published an advisory describing an improper input validation vulnerability in their TwinCAT OPC UA Server and IPC Diagnostics UA Server. The vulnerability was reported by Industrial Control Security Laboratory of QI-ANXIN Technology Group. Beckhoff has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Bosch Advisories

Bosch published an advisory describing seven vulnerabilities in their ctrlX CORE - IDE App. These are third-party (OpenSSL and Python) vulnerabilities. The next version of the product will mitigate the vulnerabilities.

The seven reported vulnerabilities are:

• Improper encoding or escaping of output - CVE-2020-26116 (exploit),

• Inadequate information (NIST ?) - CVE-2020-27619,

• HTTP request smuggling - CVE-2021-23336 (exploit),

• Integer overflow or wraparound - CVE-2021-23840, CVE-2021-23841,

• Classic buffer overflow - CVE-2021-3177 (exploit), and

• NULL pointer dereference - CVE-2021-3449

Bosch published an advisory describing an FTP backdoor in their Rexroth Fieldbus Couplers. Bosch provides generic workarounds.

B&R Advisory

B&R published an advisory describing an uncontrolled resource consumption vulnerability in their  I/O system and HMI components. This is a third-party (Siemens) vulnerability. B&R provides generic workarounds.

MB Advisory

CERT-VDE published an advisory discussing the DNSpooq vulnerabilities in the MB connect mbNET products. MB connect has new versions that mitigate the vulnerabilities.

CODESYS Advisories

CODESYS published an advisory [.PDF download link] describing a cross-site request forgery vulnerability in their CODESYS Automation Server. The vulnerability was reported by Uri Katz of Claroty. CODESYS has a new version that mitigates this vulnerability. There is no indication that Katz has been provided an opportunity to verify the efficacy of the fix.

CODESYS published an advisory [.PDF download link] describing a NULL pointer dereference vulnerability in their CODESYS V3 products containing the CmpGateway. The vulnerability was reported by Uri Katz of Claroty. CODESYS has a new version that mitigates this vulnerability. There is no indication that Katz has been provided an opportunity to verify the efficacy of the fix.

CODESYS published an advisory [.PDF download link] describing an insufficient verification of data authenticity vulnerability in their Development System V3. The vulnerability was reported by an OEM customer. CODESYS has a new version that mitigates the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

CODESYS published an advisory [.PDF download link] describing describing an insufficient verification of data authenticity vulnerability in their Development System V3. The vulnerability was reported by Uri Katz of Claroty. CODESYS has a new version that mitigates this vulnerability. There is no indication that Katz has been provided an opportunity to verify the efficacy of the fix.

CODESYS published an advisory [.PDF download link] describing an improper input validation vulnerability in their V3 products and Control V3 Runtime System Toolkit. The vulnerability was reported by Alexander Nochvay from Kaspersky Lab ICS CERT. CODESYS has a new version that mitigates the vulnerability. There is no indication that Nochvay has been provided an opportunity to verify the efficacy of the fix.

Moxa Advisory

Moxa published an advisory describing four vulnerabilities in their NPort IA5000A Series Serial Device Servers. The vulnerability was reported by Alexander Nochvay from Kaspersky Lab ICS CERT. Moxa has a new version to mitigate one of the vulnerabilities and workarounds for the others. There is no indication that Nochvay has been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities:

• Improper access control - CVE-2020-27149,

• Unprotected storage of credentials - CVE-2020-27150,

• Cleartext transmission of sensitive information (2) - CVE-2020-27184 and CVE-2020-27185

ODA Advisory

ODA published an advisory describing an out-of-bounds write vulnerability in their Open Design Alliance Drawings SDK. ODA has a new version that mitigates the vulnerability.

NOTE: This is a very minimalist advisory.

TI Advisories

TI published an advisory discussing the BadAlloc vulnerabilities in their SimpleLink™ CC13XX, CC26XX, CC32XX and MSP432E4 products. TI provides generic work arounds for these vulnerabilities.

TI published an advisory describing an integer overflow vulnerability in their Networks Developers Kit. The vulnerability was reported by Omri Ben Bassat and David Atch of Microsoft. The product is no longer supported.

Advantech Report

The Zero Day Initiative published four reports for vulnerabilities in the Advantech WebAccess/HMI Designer products. The vulnerabilities were reported by kimiya and have been coordinated with NCCIC-ICS and an advisory from them is pending.

The four reported vulnerabilities are:

• Heap-based buffer overflow - ZDI-21-490 and ZDI-21-487,

• File parsing memory corruption- ZDI-21-489, and

• Out-of-bounds write - ZDI-21-488,

Siemens Report

ZDI published a report describing an information validation vulnerability in the Siemens JT2Go product. The vulnerability was reported by Michael DePlante. ZDI has been coordinating with NCCIC-ICS since last September.

OpenPLC Exploit

Fellipe Oliveira published an exploit for a remote code execution vulnerability in the OpenPLC product. There is no CVE provided and no indications of coordination with the vendor. This may be a 0-day vulnerability.

VMware Exploit

Egor Dimitrenko published a Metasploit module for two vulnerabilities in the VMware vRealize Operations Manager. The vulnerabilities were reported by VMware on March 31st, 2021.

The two exploited vulnerabilities are:

• Server-side request forgery - CVE-2021-21975, and

• Arbitrary file write - CVE-2021-21983


Thursday, April 29, 2021

4 Advisories Published – 4-29-21

Today, CISA’s NCCIC-ICS published control system security advisories for products from multiple RTOS vendors, Johnson Controls, Cassia Networks, and Texas Instruments.

RTOS Advisory

This advisory describes 23 [corrected typo '13' to '23', 4-30-21 0853 EDT] different integer overflow or wraparound vulnerabilities in multiple real-time operating systems (RTOS). The vulnerabilities were discovered by Microsoft’s Section 52, the Azure Defender for IoT security research group and are collectively named BadAlloc. The advisory provides links to updated versions for most of the affected products.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to result in unexpected behavior such as a crash or a remote code injection/execution.

NOTE: NCCIC-ICS has updated their remote access – VPN guidance:

“When remote access is required, use secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as its connected devices.”

Johnson Controls Advisory

This advisory describes an off-by-one error vulnerability in Johnson Controls exacqVision Network Video Recorder running on unpatched versions of the Ubuntu operating system. This is a third-party (Sudo) vulnerability and there are exploits reported (here, here, and here for example). Johnson Controls recommends updating the Ubuntu operating systems to mitigate the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker with local access could exploit the vulnerability to  obtain “Super User” access to the underlying Ubuntu Linux operating system.

Cassia Advisory

This advisory describes a path traversal vulnerability for the Cassia Networks Access Controller. The vulnerability was reported by Amir Preminger and Sharon Brizinov of Claroty. Cassia has a patch that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit this vulnerability to allow an attacker to read any file from the Access Controller server.

TI Advisory

This advisory describes five vulnerabilities in the Texas Instruments SimpleLink Wi-Fi products. The vulnerabilities were reported by David Atch and Omri Ben Bassat from Microsoft. TI has software versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Integer overflow or wraparound (4) - CVE-2021-22677, CVE-2021-22675, CVE-2021-22679, and CVE-2021-22671, and

• Stack-based buffer overflow - CVE-2021-22673

Thursday, April 22, 2021

2 Advisories Published – 4-22-21

Today CISA’s NCCIC-ICS published two control system security advisories for products from Mitsubishi Electric and Horner Automation.

Mitsubishi Advisory

This advisory describes an improper authentication vulnerability in the Mitsubishi GOT products. The vulnerability is self-reported. Mitsubishi provides generic mitigation measures pending development of an updated version.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow an attacker to gain unauthorized access.

Horner Advisory

This advisory describes two vulnerabilities in the Horner Automation Cscape control system application programming software. The vulnerabilities were reported by Sharon Brizinov of Claroty. Horner has a new version that mitigates the vulnerability. There is no indication that Brizinov has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper input validation - CVE-2021-22678, and

• Improper access control - CVE-2021-22682

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerability to allow code execution in the context of the current process or locally escalate privileges.

Thursday, April 15, 2021

2 Advisories Published – 4-15-21

Today CISA’s NCCIC-ICS published two control system security advisories for products from EIPStackGroup and Schneider Electric.

EIPStackGroup Advisory

This advisory describes four vulnerabilities in the EIPStackGroup OpENer EtherNet/IP stack. The vulnerabilities were reported by Tal Keren and Sharon Brizinov of Claroty. The Claroty report includes proof-of-concept code. EIPStackGroup has new commits that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Incorrect conversion between numeric types - CVE-2021-27478,

• Out-of-bounds read - CVE-2021-27482, and

• Reachable assertion (2) - CVE-2021-27500 and CVE-2021-27498

NOTE: The Claroty report includes a fifth vulnerability: out-of-bounds write - CVE-2020-13556.

The NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to cause a denial-of-service condition and data exposure.

Schneider Advisory

This advisory describes five vulnerabilities in the Schneider C-Bus Toolkit. The vulnerabilities were reported by rgod, and Simon Zuckerbraun via the Zero Day Initiative. Schneider has newer versions that mitigates the vulnerabilities. There was no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Improper privilege management - CVE-2021-22716,

• Path traversal (4) - CVE-2021-22717, CVE-2021-22718, CVE-2021-22719, and CVE-2021-22720.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow remote code execution.

NOTE 1: This looks like a third-party product from Clipsal, so the stand-alone Clipsal product may have the same vulnerabilities and other vendors may be using the same software.

Commentary

We are seeing more and more of these ‘stack’ advisories. Claroty followed the same tack that Forescout took earlier this week by releasing the fuzzing tool that they used to find these reported vulnerabilities. This is going to ensure that more researchers will be doing research on these stacks and finding new vulnerabilities. Researchers will also be able to identify end-products that use the currently reported vulnerable stacks.

I was surprised on Tuesday when NCCIC-ICS did not publish a single advisory for the NAME:WRECK vulnerabilities and simply list the individual Siemens advisories that reflected those vulnerabilities. They could then have added additional products to the ‘affected list’ once other vendors start reporting their vulnerable products. That is almost certainly what they intend to do with today’s EIPStackGroup advisory.

Tuesday, April 13, 2021

15 Advisories Published – 4-13-21

Today CISA’s NCCIC-ICS published 15 control systems security advisories for products Siemens (12), JTEKT, Advantech, and Schneider Electric. One of the Siemens advisories also affects products from Milestone and another also affects products from PKE.

Milestone Advisory

This advisory describes a use of hard-coded cryptographic key in the Siemens Siveillance (Milestone) Video Open Network Bridge (ONVIF). The vulnerability was reported by Milestone PSIRT. Siemens has a hot fix and Milestone has an update to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an authenticated remote attacker to retrieve and decrypt all user credentials stored on the ONVIF server.

Nucleus Advisory #1

This advisory describes a use of insufficiently random variables vulnerability in the Siemens Nucleus DNS module. This is one of the NAME:WRECK DNS vulnerabilities reported by Forescout and JSOF. Siemens has generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to poison the DNS cache or spoof DNS resolving.

SIMOTICS Advisory

This advisory describes four vulnerabilities in the Siemens SIMOTICS CONNECT 400. The vulnerabilities were self-reported. These are NAME:WRECK vulnerabilities in the third-party Mentor DNS Module. Siemens has a new version that mitigates the vulnerabilities.

The four reported vulnerabilities are:

• Improper null termination - CVE-2020-27736,

• Out-of-bounds read - CVE-2020-27737, and

• Access of memory location after end of buffer - CVE-2020-27738 and CVE-2021-25677

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to poison the DNS cache or spoof DNS resolving.

Tecnomatix Advisory

This advisory describes an out-of-bounds write in the Siemens Tecnomatix RobotExpert. The vulnerability was reported by Francis Provencher via the Zero Day Initiative. Siemens has a new version that mitigates the vulnerability. There is no indication that Provencher has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow remote code execution.

TIM Advisory

This advisory describes 14 vulnerabilities in the Siemens TIM 4R-IE. This is a third-party vulnerability (ntp.d in SNTP). The vulnerabilities are self-reported.

The 14 reported vulnerabilities are:

• Incorrect type conversion or cast - CVE-2015-5219,

• Improper input validation (4) - CVE-2015-7855 (exploit), CVE-2015-7705, CVE-2015-8138, and CVE-2016-1547,

• Improper authentication (2) - CVE-2015-7871 and CVE-2016-4953

• Security features - CVE-2015-7973,

• Null pointer dereference - CVE-2015-7977,

• Data processing errors (2) - CVE-2015-7979 and CVE-2016-1548,

• Exposure of sensitive information to an unauthorized actor - CVE-2016-1550, and

• Race condition - CVE-2016-4954

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to compromise the confidentiality, integrity, and availability of the device.

PKE Advisory

This advisory describes twelve vulnerabilities in the Siemens (and PKE) Control Center Server (CCS). The vulnerabilities were reported by Raphaël Rigo of Airbus Security Lab. Siemens (and PKE) has new versions that mitigate the vulnerabilities. There is no indication that Rigo has been provided an opportunity to verify the efficacy of the fix.

The 12 reported vulnerabilities are:

• Cleartext storage of sensitive information in GUI - CVE-2019-13947,

• Improper authentication (2) - CVE-2019-18337 and CVE-2019-18341

• Relative path traversal - CVE-2019-18338,

• Use of a broken or risky cryptographic algorithm - CVE-2019-18340,

• Exposed dangerous method or function - CVE-2019-18342,

• Path traversal - CVE-2019-19290,

• Cleartext storage in a file or on a disk - CVE-2019-19291,

• SQL Injection - CVE-2019-19292,

• Cross-site scripting (2) - CVE-2019-19293 and CVE-2019-19294, and

• Insufficient logging - CVE-2019-19295

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to read and write arbitrary files and sensitive data and execute commands and arbitrary code.

NOTE: These vulnerabilities were removed from earlier Siemens Advisories, SSA-761617 and SSA-844761.

LOGO! Advisory

This advisory describes two vulnerabilities in the Siemens LOGO! engineering software products. The vulnerabilities were reported by Mashav Sapir from Claroty. Siemens provides generic workarounds to mitigate the vulnerabilities.

The two reported vulnerabilities are:

• Path traversal - CVE-2020-25243, and

• Uncontrolled search path element - CVE-2020-25244

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a local attacker to take over the system where the software is installed.

NOTE: Someone slipped up on the listing of ‘Equipment’ and ‘Vulnerability’ in the ‘Executive Summary’ section of the advisory.

SINEMA Advisory

This advisory describes two vulnerabilities in the Siemens SINEMA Remote Connect Server. These are third-party vulnerabilities (libxml2). Siemens has a new version that mitigates the vulnerabilities.

The two reported vulnerabilities are:

• Missing release of resource after effective lifetime - CVE-2019-19956, and

• Infinite loop - CVE-2020-7595

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to cause a memory leak or an infinite loop situation resulting in a denial-of-service condition.

SCALANCE Advisory

This advisory describes two vulnerabilities in the Siemens Web Server of SCALANCE X200. The vulnerabilities are self-reported. Siemens has a new version that mitigates the vulnerabilities.

The two reported vulnerabilities are:

• Heap-based buffer overflow - CVE-2021-25668, and

• Stack-based buffer overflow - CVE-2021-25669

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to cause a buffer overflow condition resulting in remote code execution.

Solid Edge Advisory

This advisory describes five vulnerabilities in the Siemens Solid Edge software tools. The vulnerabilities were reported by Francis Provencher and rgod via ZDI. Siemens has updates that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Out-of-bounds write - CVE-2020-28385, CVE-2021-25678, CVE-2021-27380,

• Untrusted pointer dereference - CVE-2020-26997, and

• Stack-based buffer overflow - CVE-2021-27382

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerabilities to lead to a crash, arbitrary code execution, or data extraction on the target host system.

Nucleus Advisory #2

This advisory describes two infinite loop vulnerabilities in the Siemens Nucleus products. The vulnerabilities were self-reported. Siemens has a new version for one of the affected products that mitigates the vulnerabilities.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to cause a denial-of-service condition.

Nucleus Advisory #3

This advisory describes two vulnerabilities in the Siemens Nucleus DNS module. These are two of the NAME:WRECK DNS vulnerabilities reported by Forescout and JSOF. Siemens provides generic work arounds to mitigate the vulnerabilities.

The two reported vulnerabilities are:

• Out-of-bounds write - CVE-2020-15795, and

• Use of out-of-range pointer offset - CVE-2020-27009

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow a denial-of-service condition or for the execution of code remotely.

NOTE: There were two additional Siemens’ advisories published today that were not covered by NCCIC-ICS. If they are not covered on Thursday, I will address them on Saturday.

JTEKT Advisory

This advisory describes an improper resource shutdown or release vulnerability in the JTEKT TOYOPUC products. The vulnerability was reported by Younes Dragoni from Nozomi Networks. JTEKT has provided generic mitigation measures.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an unauthorized user to stop Ethernet communications between devices from being established.

Advantech Advisory

This advisory describes an incorrect permission assignment for critical resources in the Advantech WebAccess/SCADA. The vulnerability was reported by Chizuru Toyama of TXOne IoT/ICS Security Research Labs of Trend Micro. Advantech has a new version that mitigates the vulnerability. There is no indication that Toyama has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to login as an ‘admin’ to fully control the system.

Schneider Advisory

This advisory describes an improper restriction of XML external entity reference vulnerability in the Schneider SoMachine Basic products. The vulnerability was reported by Gjoko Krstikj of Applied Risk. Schneider has a new product that replaces the affected product and has updated the mitigation measures.

NOTE 1: This is actually based upon an update to a Schneider advisory that was published on May 22nd, 2018.

NOTE 2: Schneider also published two advisories and two other updates today. If they are not covered by NCCIC-ICS on Thursday, I will address them here on Saturday.

 
/* Use this with templates/template-twocol.html */