Showing posts with label Controls System Security. Show all posts
Showing posts with label Controls System Security. Show all posts

Friday, December 1, 2017

ICS-CERT Publishes 2 Advisories and 3 Updates

Yesterday the DHS ICS-CERT published two control system security updates for products from Geovap and Siemens. They also updated three previously published control system security advisories, all for products from Siemens.

Geovap Advisory


This advisory describes a cross-site scripting vulnerability in the Geovap Reliance SCADA software management platform. The vulnerability was reported by Can Demirel. Geovap has released a new version that mitigates the vulnerability. There is no indication that Demirel has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability to inject arbitrary JavaScript in a specially crafted URL request that may allow for read/write access.

NOTE: The Geovap update notes for this new version would seem to indicate that they also fixed one or more vulnerabilities in the Reliance Smart Client.

Siemens Advisory


This advisory describes multiple vulnerabilities in the Siemens SWT 3000 Teleprotection system. The vulnerabilities are self-reported. Siemens has produced updated firmware that mitigates the vulnerability.

The reported vulnerabilities are:

• Improper authentication (2) - CVE-2016-4784, CVE-2016-4785;
• Authentication bypass using an alternate path or channel (2) - CVE-2016-4785, CVE-2016-7114; and
• Improper input validation - CVE-2016-7113

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to perform a denial-of-service attack. The Siemens security advisory notes that network access to the devices is required for exploitation.

OPC/UA Update


This update provides new information on an advisory that was originally published on 8-31-17 and updated on October 3rd, 2017. The update provides new version information and mitigation measures for:

• SIMATIC IT Production Suite: Versions between V6.5 and V7.1

SIPROTEC Update


This update provides new information on an advisory that was originally published on July 6th, 2017, and updated on July 18th, on July 28th, and then again on October 10th. The update provides new version information and mitigation measures for:

• SIPROTEC 7SD686: All versions prior V4.05

The Siemens updated security advisory explains why there are two separate affected versions for SIPROTEC 7SD686. Versions before 4.05 are affected by vulnerability #6 and versions before 4.03 are also affected by vulnerability #2.

SIMATIC Update


This update provides new information on an advisory that was originally published on February 14th, 2017 and updated on June 15th,  and again on July 6th. The update provides new version information and mitigation measures for:


• SIMATIC IT: All versions prior to V7.1

Thursday, September 14, 2017

ICS-CERT Updates an Advisory and Publishes Another

Today the DHS ICS-CERT updated a previously published advisory for a product from Siemens. They also published a new advisory for a product from LOYTEC.

Siemens Update


This update provides additional information on an advisory that was originally published on originally published on May 9th, 2017 and updated on June 15, 2017, on July 25th, 2017, and then again on August 18th, 2017. The update provides new affected version information and mitigation links for:

• SCALANCE M-800,S615: All versions prior to V04.03,

LOYTEC Advisory


The advisory describes four vulnerabilities in the LOYTEC LVIS-3ME HMI touch panel. The vulnerabilities were reported by Davy Douhine of RandoriSec. LOYTEC has released a firmware update to mitigate the vulnerabilities. There is no indication that Douhine was provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Relative path traversal - CVE-2017-13996;
• Insufficient entropy - CVE-2017-13992;
• Improper neutralization of input during web page generation - CVE-2017-13994; and
• Insufficiently protected credentials - CVE-2017-13998


ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to cause information exposure or allow arbitrary code execution.

Wednesday, January 13, 2016

Cyber Weapon Testing

As the use of cyber tools to attack infrastructure is apparently starting to be used as a means of effecting nation state political goals it is necessary to examine how those tools can be honed, improved and tested without risking conventional warfare. While in the early days of cyber weapon development (ala Stuxnet) subterfuge or obfuscation was adequate to prevent retaliation, strides in the technologies for isolation, identification and attribution of cyber weapons are making real world testing of these weapons more difficult.

Artificial testbeds and weapons ranges will certainly have their place in cyber weapon development and evaluation, but a cautious adversary would be wary of relying on new strategic weapons in a full scale attack without having tested both their capability and their target’s potential responses to such an assault.

Proxy Targets

A time honored tradition in conventional weapon development has been the use of new weapon systems against proxy targets. Lesser third party nations that had limited retaliatory capability were attacked with new weapons to see how well the weapons actually fared in combat conditions. If the proxy target had some of the defensive armament used by the primary opponent, the test would provide important data to the developers of weapons and tactics as to how best employ the new weapons in future conflicts.

There have been people that have suggested that the recent cyber-attacks on the electric grid in the Ukraine was just this type of attack. While the Russians certainly have local interests vis a vis the Ukraine that might cause them to execute this type of attack, the use of a new cyber-attack methodology in actual field conditions could certainly be used to refine and improve such methods.

Mini Attacks

Limited attacks with conventional kinetic weapons against one’s primary adversary are very hard to hide. That may not be the case with cyber weapons. If one were to employ portions of the attack tools against an adversary during events when the target was already being stressed, the target might not notice the small cyber effects.

For example, if during a winter storm when a certain amount of electric distribution and transmission failures are to be expected, an adversary were to us new cyber weapons in very limited application the failures related to those attacks might not be investigated in sufficient detail to identify them as a cyber-attack.

An adversary that had already gained access to an electrical distribution network, for instance, could cause an automated breaker to open and carefully watch how that opening affected the remainder of the network. If the breaker controller had been doctored to not show that particular directed opening it is unlikely that the utility would take particular note of that breaker opening in the grand scheme of responding to the weather related problems.

Camouflaged Attacks

In a posting on the SANS ICS Blog last summer I described how isolated changes could be made to the controls of chemical reactions in a chemical manufacturing plant and make them seem like operator errors. Such attacks could be used to map control system responses at such a facility. Lacking detailed process knowledge, an attacker could use such response mapping over time as a method for developing an effective attack that could shut down or even damage the facility.

Preparedness

The last two weapon testing methodologies should be of increasing concern to control system owners as it becomes more obvious that there are nation states (and possibly non-state organizations) that are actively developing technology to attack industrial control systems as a tool of cyber warfare.


While few organizations are going to have the internal resources to complete prevent the possibility of such an attack, the ability to identify unauthorized intrusions into control system networks is a key to limiting the effectiveness of such attacks if they do occur. Such identification should allow for the emergency isolation/shutdown of the affected systems in a way that minimizes the potential damage. 
 
/* Use this with templates/template-twocol.html */