Showing posts with label Clorius Controls. Show all posts
Showing posts with label Clorius Controls. Show all posts

Tuesday, January 13, 2015

ICS-CERT Publishes 5 Advisories and 1 Update

It was a busy day for ICS-CERT today with four new advisories, an almost three month old advisory being publicly published and one update of an advisory that was published yesterday. Did anyone mention that S4x15 started today?

GE DNP3 Advisory

Let’s get the old advisory out of the way first. This advisory was originally published back on October 14th on the US-CERT Secure Portal. It describes a Crain-Sistrunk improper input validation vulnerability in the DNP3 implementation used by GE iFix and Cimplicity products. The implementation was produced by Catapult Software who developed a patch that mitigates the vulnerability and GE has verified the efficacy of the patch. It does not appear that Crain-Sistrunk have verified the efficacy.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to effect a DOS attack.

According to the Project Robus web site it now looks like 29 of the 30 DNP3 vulnerabilities reported by Crain-Sistrunk have now been publicly disclosed by ICS-CERT.

NOTE: There is no reason given for the unusually long delay between the US-CERT publication and the ICS-CERT public notification.

GE Multilink Advisory

This advisory describes two vulnerabilities that effect the GE Multilink line of switches. The vulnerabilities were found by Eireann Leverett of IOActive in one of the Multilink switch lines and GE notified ICS-CERT that other lines were affected as well. A firmware upgrade is available.

The two reported vulnerabilities are:

● Resource consumption vulnerability - CVE-2014-5418; and
● Hard-coded key - CVE-2014-5419

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to conduct a DOS attack or decrypt traffic. ICS-CERT reports that there is no public exploits for these specific vulnerabilities while GE restricts that claim specifically only to the ML800 switches.

Phoenix Contact Software Advisory

This advisory describes an authentication vulnerability in applications developed by Phoenix Contact Software. These applications are used by undisclosed vendors to run process control and manage IEC 61131 logic. The vulnerabilities were originally reported by Reid Wightman of Digital Bond. Phoenix Contact Software is considering developing a fix for these vulnerabilities.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to inject arbitrary commands into the protocol.

The end use product may or may not contain mitigation measures to protect against this vulnerability.

GOOD LUCK. Caveat emptor.

Clorius Controls Advisory

This advisory describes an insecure Java client web authentication vulnerability in the Clorius Controls A/S ISC SCADA server. The vulnerability was originally reported by  Aditya Sood  who has validated the efficacy of the update that has been made available.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to gain complete access to the server.

Siemens Advisory

I noted the Siemens release of their advisory about this vulnerability this morning on Twitter and am now happy to report the ICS-CERT prompt release of their advisory. It describes three separate authentication vulnerabilities in the WinCC Sm@rtClient iOS Application. The vulnerabilities were originally reported by Kim Schlyter, Seyton Bradford, and Richard Warren from FortConsult. Siemens has produced an update to mitigate the vulnerability, but there is no report that the researchers have validated its efficacy.

The vulnerabilities include:

● Insufficiently protected credentials - CVE-2014-5231 and CVE-2014-5233; and
● Improper authentication - CVE-2014-5232

ICS-CERT reports that a relatively low skilled attacker with local access to the mobile device could exploit these vulnerabilities to gain access to the application and then presumably (my guess, not mentioned in the advisory) remotely access the control system with the full rights of the mobile device owner.

CodeWrights Advisory Update

Yesterday’s advisory was updated today to clarify that while ABB is a customer of CodeWrights HART DTM  library that they have not yet verified that any of their systems are affected by the identified vulnerability. The update provides a link to the ABB security advisory page where ABB will make the notification if any systems are found to be vulnerable.

I think that it is probably safe to assume that ICS-CERT has not yet verified that any other of the potentially affected vendors listed actually have products with the vulnerabilities. They apparently made the somewhat reasonable assumption that if these vendors (including ABB) had bought the rights to use the vulnerable libraries that there products using those libraries would be affected.


I guess we will just have to wait and see. I know which way I would bet.

Tuesday, April 2, 2013

ICS-CERT Publishes Two Alerts and an Advisory


Yesterday ICS-CERT published alerts for systems from Clorius Controls and Mitsubishi and an advisory for a Wind River product.

Wind River Advisory

This advisory is for multiple vulnerabilities in the Wind River VxWorks Remote Terminal Operating System (RTOS) reported by Hisashi Kojima and Masahiro Nakada of Fujitsu Laboratories in  a coordinated disclosure. VxWorks is an operating system that is used in a variety of industrial control systems. The vulnerabilities include:

• Improper input validation, CVE-2013-0711, CVE-2013-0712, CVE-2013-0713, CVE-2013-0714, CVE-2013-0716; and
• Command injection, CVE-2013-0715.

ICS-CERT notes that a relatively low skilled attacker could remotely exploit these vulnerabilities though a couple require a user ID and password to exploit. Successful exploitation could lead to a DoS attack in most cases but exploitation of one of the improper validation vulnerabilities could lead to arbitrary code execution.

The advisory notes that “[a]ccording to Wind River, software patches” (pg 5) are available from Wind River technical support for all VxWork versions. This wording probably indicates that neither ICS-CERT nor the original researchers have validated the efficacy of the patches.

It would be helpful in situations like this where a vulnerability may affect products from multiple vendors if the advisory would note that either the reported mitigation would work on multiple vendor products or which vendor’s products were or were not protected by the mitigation measure. ICS-CERT would be the only organization that could possibly address this multiple vendor issue. As it is we must just assume that every product that uses VxWorks has these vulnerabilities and must be separately addressed by the using vendor.

Mitsubishi Alert

This alert addresses a heap-based buffer overflow vulnerability in an ActiveX control in the Mitsubishi MX SCADA/HMI product. The vulnerability disclosure (with exploit code) was reported by Dr IDE (not identified on the ICS-CERT alert) on the OSVDB.org web site on 3-26-13. The remotely exploitable vulnerability could result in arbitrary code execution.

Clorius Controls Alert

This alert addresses an information disclosure vulnerability in the Clorius Controls ICS SCADA product. This remotely exploitable vulnerability with publicly available exploit code could result in ‘loss of confidentiality’. The alert notes that ICS-CERT is still trying to contact the researcher and Clorius Controls about this vulnerability.

Researcher Identification

Standard verbiage in both alerts clearly state that ICS-CERT will provide attribution of the researcher who discovered the vulnerability unless “unless the reporter notifies ICS-CERT that they wish to remain anonymous”. That does not appear to be the case in either of these alerts; Dr IDE is clearly identified in the OSVDG report so he has no anonymity beyond his handle and ICS-CERT apparently hasn’t been able to contact the Clorius Controls researcher. Thus it appears that ICS-CERT is slipping back into its adversarial mode in dealing with authors of uncoordinated disclosures.

The bad news here is that the black hat community may have access to details about the Clorius Controls vulnerability that the vendor and owners may not be aware of. At least in the Mitsubishi alert ICS-CERT provided a link to the OSVDB web site discussing the vulnerability so that we all have a general picture of the vulnerability and a level playing field (though it was seven days late).
 
/* Use this with templates/template-twocol.html */