Showing posts with label ClearSCADA. Show all posts
Showing posts with label ClearSCADA. Show all posts

Thursday, March 13, 2014

ICS-CERT Publishes Another Schneider Advisory

This afternoon the DHS ICS-CERT published an advisory for input project-file validation vulnerability in the Schneider ClearSCADA application. The vulnerability was discovered by Andrew Brooks and coordinated through the Zero Day Initiative (ZDI; it is not yet listed on the ZDI web site). The vulnerability is located in the optional PLC Driver in the KepServerEX V4 component; this is a third-party component of the ClearSCADA application.

ICS-CERT reports that a moderately skilled attacker with local system access could exploit this vulnerability to cause the system to crash. Schneider recommends that customers uninstall the Kepware driver in the vulnerable product versions and migrate to an external installation of KepServerEX V5. That version does not contain this vulnerability.

According to the advisory published by Schneider, they had recommended a year and a half-ago that customers should take the action being recommended in the ICS-CERT Advisory because of other stability issues with the driver.


Since this is a third-party component of the system, the obvious question that must be asked is does this same PLC Driver show up in other controls systems? If it does, are they also vulnerable? And, finally, how would a control system owner be able to tell?

Sunday, June 24, 2012

ICS-CERT Updates ICS Internet Accessibility Alert


On Friday afternoon the DHS ICS-CERT updated their alert on internet accessibility of ICS systems that was originally issued in January. The original report outlined a large number of reports of ICS systems being found on the Internet through the use of SHODAN, Googel, ERIPP and other search engines. This update provides information about Internet facing ICS systems with default passwords or weak authentication.

The update starts off (pg 2) by explaining that: “ICS-CERT has recently become aware of multiple systems with default usernames and passwords that are accessible via the Internet.”

This generic claim is not much help to the general ICS community, but the Alert does note that ICS-CERT has directly contacted the owner/operators of the affected systems to let them know of their vulnerability.

There is a new vendor name included in this initial paragraph, Echelon and their i.LON series of communications devices. ICS-CERT notes that the new reports that they have received include information on “the Echelon i.LON product that is commonly deployed within ICS devices such as motors, pumps, valves, sensors, etc., which contain a default username and password”. They do note that this is not an ‘inherent vulnerability’ (read; the user should have corrected the situation during the installation process).

The alert revision goes on to remind their audience that there have been a number of ICS-CERT advisories (including: ClearSCADA, Siemens Simatic, and RuggedCom) about systems with weak authentication mechanisms. They do not specifically mention that any of these systems that have been reported to be Internet facing, but given the current state of ICS security it would seem inevitable that there would be a number of these systems that are relying solely on their weak authentication systems for Internet protection.

Nothing has changed in the sections of this Alert that deal with mitigation efforts. Neither ICS-CERT nor any other ICS security player has come up with a magic bullet to protect Internet facing ICS equipment. The revised alert simply serves as an updated reminder that every ICS owner/operator needs to take a hard look at their control systems to ensure that they are appropriately protected. As such this updated alert deserves the widest possible dissemination.

NOTE: There is an interesting follow-up to this post written by Reid Wightman over on DigitalBond. Well worth reading and makes some additional points that bear attention. Plus he was nice enough to mention this post. [6-25-12 20:20 EDST]

Thursday, August 25, 2011

ICS-CERT ClearSCADA Advisory


Today the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) publicly published an advisory for Control Mircrosystems’ ClearSCADA platform. The advisory was originally published in limited distribution on the US-CERT portal in June. The vulnerability identified by Jeremy Brown would allow an unauthorized remote user access to system diagnostic information.

Control Microsystems has corrected the problem in ClearSCADA server 2010 R1.1 and newer versions. Patches will not be made available for older versions. They also recommend disabling logons on non-secure ports in the server configuration window. That would make it seem that the default settings specifically allow for logging onto the system via unsecure ports; that doesn’t seem right.

Thursday, February 17, 2011

ICS-CERT Updated ClearSCADA Advisory

This morning the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) updated their vulnerability advisory on ClearSCADA Software. I described the earlier advisory in an earlier blog. There are no new vulnerabilities disclosed in this update. Interestingly ICS-CERT has expanded the systems affected to include SCX (from Serck UK or Serck Aus) software because Serck bundles ClearSCADA in their product.

Owners of SCX Version 67 R4.5 or SCX Version 68 R3.9 (or older versions) need to update their software. No web site for the needed download exists. Owners need to directly contact the nearest Serck office to obtain the appropriate downloads. The nearest office can be found via: http://www.serck-controls.com/global.html.

Wednesday, February 2, 2011

ICS-CERT Advisory for ClearSCADA

Yesterday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published an advisory concerning multiple vulnerabilities in the Control Microsystems’ ClearSCADA software. The three vulnerabilities in multiple versions of the software have been addressed by the vendor.

The three vulnerabilities identified are:

• Heap Overflow Vulnerability
• Cross-site Scripting Vulnerabilities
• Insecure Web Authentication.
There are no known publicly available exploits for the first vulnerability, but there are tools available that could allow for an exploit of the other two vulnerabilities.

ICS-CERT and Control Microsystems recommend the following mitigation measures (after appropriate system vulnerability review):

• Upgrade older versions or install service packs (http://www.clearscada.com/services-support/software-updates/) for newer versions of this software.

• Disable logons on ClearSCADA non-secure ports. Locate this setting under System Configuration => WebX in the server configuration window.

• Install a WebX security certificate from a trusted authority.

• Limit access to the server and server network to only trusted networks and users.
NOTE: See this post at DigitalBond.com for some interesting background on this advisory.
 
/* Use this with templates/template-twocol.html */