Showing posts with label DNSpooq. Show all posts
Showing posts with label DNSpooq. Show all posts

Wednesday, March 10, 2021

11 Updates Published – 3-9-21

Yesterday the CISA NCCIC-ICS updated eleven control system security advisories for products from Siemens (9), dnsmasq by Simon Kelley, and Luxion.

PROFINET DCP Update

This update provides additional information on an advisory that was originally published on May 9th, 2017 and most recently updated on August 11th, 2020. The new information includes:

• Adding ecoPN model (6ES7148-6JG00-0BB0) as not affected

• Adding MV400 to the affected product list and providing mitigation measures, and

• Updating CWE classification for CVE-2017-2680 and CVE-2017-2681

Industrial Products Update

This update provides additional information on an advisory that was originally published on December 5th, 2017 and most recently updated on August 11th, 2020. The new information includes adding ecoPN model (6ES7148-6JG00-0BB0) as not affected.

SINEMA Update

This update provides additional information on an advisory that was originally published on April 9th, 2019. The new information includes adding CVE-2019-3823, the third-party (libcurl) heap out-of-bounds read vulnerability.

SIMATIC Update #1

This update provides additional information on an advisory that was originally published on June 11th, 2019. The new information includes adding mitigation measures for or MV400.

PROFINET-IO Stack Update

This update provides additional information on an advisory that was originally published on February 11th, 2020 and most recently updated on December 8th, 2020. The new information includes:

• Adding ecoPN model (6ES7148-6JG00-0BB0) as not affected, and

• Adding mitigation information for MV400

NOTE: NCCIC-ICS provided the original publication date not the date of the last update in the Update Information.

KTK Update

This update provides additional information on an advisory that was originally published on April 14th, 2020 and most recently updated on May 12th, 2020. The new information includes adding Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200 (P) to the list of affected products.

SIMATIC Update #2

This update provides additional information on an advisory that was originally published on July 9th, 2020 and most recently updated on January 12th, 2021. The new information includes adding mitigation measures for:

• SINUMERIK ONE Virtual, and

• SINUMERIK Operate

NOTE: NCCIC-ICS missed the date of the previous update in the Update Information of this advisory, providing the one before instead.

UMC Stack Update

This update provides additional information on an advisory that was originally published on July 14th, 2020 and most recently updated on February 9th, 2021. The new information includes adding mitigation measures for SIMATIC IT Production Suite.

Embedded TCP/IP Stack Update

This update provides additional information on an advisory that was originally published on December 12th, 2020 and most recently updated on February 9th, 2021. The new information includes:

• Adding mitigation measures for SIRIUS 3RW5 communication module Modbus TCP, and

• Adding reference to additional AMNESIA:33 advisory (SSA-541018)

DNSMASQ Update

This update provides additional information on an advisory that was originally published on January 19th, 2021. The new information includes publishing a link to the Siemens advisory that was originally published on January 19th, 2021 and updated yesterday.

Luxion Update

This update provides additional information on an advisory that was originally published on February 4th, 2021. The new information includes adding a link to a Siemens advisory for products affected by this vulnerability.

NOTE: Note the Siemens advisory is one of the two unlisted advisories that I mentioned in the close of last night’s blog post.

Other Siemens Updates

Yesterday Siemens published three other updates that were not covered by NCCIC-ICS yesterday. I will discuss them this weekend.

Saturday, February 27, 2021

Public ICS Disclosures – Week of 2-20-21

This week we have six vendor disclosures from Advantech, Aruba Networks (2), Bosch, Carestream, and VMware. We have researcher a report for products from Secomea (and B&R automation). Finally, there are two remote access exploits for products from ASUS and

Advantech Advisory

Advantech published an advisory discussing the DNSpooq vulnerabilities in their industrial cellular routers. Advantech notes that their routers are only vulnerable to the three ‘cache poisoning’ vulnerabilities. Advantech has new firmware that mitigates the vulnerabilities.

Aruba Advisories

Aruba published an advisory discussing the DNSpooq vulnerabilities in their products. Aruba reports that their products are only vulnerable to the three ‘cache poisoning’ vulnerabilities. Aruba will update the dnsmasq in “future routine maintenance patches”.

 

Aruba published an advisory describing twelve vulnerabilities in their AirWave Management Platform. The vulnerabilities were reported by multiple researchers via the BugCrowd platform. Aruba has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The twelve reported vulnerabilities are:

• Cross-site request forgery (2) - CVE-2021-29960 and CVE-2021-29961,

• Command injection (2) - CVE-2021-29962 and CVE-2021-29963,

• Improper access control - CVE-2021-29964,

• SQL injection (2) - CVE-2021-29965 and CVE-2021-29966,

• Reflected cross-site scripting - CVE-2021-29967,

• Authenticated stored cross-site scripting - CVE-2021-29968,

• Authenticated XML external entity - CVE-2021-29969, and

• Authenticated remote command injection (2) - (CVE-2021-29970 and CVE-2021-29971

Bosch Advisory

Bosch published an advisory describing three vulnerabilities in their ctrlX CORE and the IoT Gateway. These are third-party (Linux kernel and sudo) vulnerabilities. Bosch reports that the next updates for the affected products would include updates for both the kernel and sudo.

The three reported vulnerabilities are:

• Improper locking and use after free - CVE-2020-29661,

• Out-of-bounds write - CVE-2021-3156 (multiple exploits publicly available), and

• Use after free - CVE-2021-3347 (exploit publicly available)

Carestream Advisory

Carestream published an advisory [.PDF download link] describing a heap-based buffer overflow vulnerability in a number of their products. This is a third-party (Chrome) vulnerability. Carestream reports that Chrome will be updated with the next software release for most of the affected products. This vulnerability has been exploited in the wild, but not yet in Carestream products.

VMware Advisory

VMware published an advisory describing three vulnerabilities in their VMware ESXi and vCenter Server. The vulnerabilities were reported by Mikhail Klyuchnikov of Positive Technologies, and Lucas Leong via the Zero Day Initiative. VMware has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Remote code execution - CVE-2021-21972,

• Heap-based buffer overflow - CVE-2021-21974,

• Server-side request forgery - CVE-2021-21973

Tenable has published a report on the vulnerabilities noting that these vulnerabilities have been exploited in the wild. NebulabdSec has published proof-of-concept code for the RCE vulnerability.

Secomea Report

Tenable published a report (including proof-of-concept code) describing three vulnerabilities in the Secomea GateManager (also applies to B&R GateManager). The report was coordinated with both Secomea and B&R; Secomea has a new version that mitigates the vulnerability. B&R’s response is pending.

The three reported vulnerabilities include:

• Reflected cross-site scripting - CVE-2020-29028,

• Authentication token exposed in URL path - CVE-2020-29030, and

• Authenticated malicious firmware upload - CVE-2020-29029

NOTE: This is likely to be a third-party vulnerability in products from vendors other than B&R.

Remote Access Exploits

H4rk3nz0 published an exploit for a remote code execution vulnerability in the ASUS Remote Link. There is no CVE# listed and no indication that ASUS had been contacted. This may be a 0-day exploit.

MATTHEW DUNN published a Metasploit module for an authentication timing vulnerability for Remote Desktop Web Access. The is no CVE# and no indication that Microsoft has been contacted. This may be a 0-day exploit.

Tuesday, January 19, 2021

3 Advisories Published – 1-19-21

Today CISA’s NCCIC-ICS published two control system security advisories for products from Reolink and Simon Kelley, and one medical device security advisory for products from Philips.

Reolink Advisory

This advisory describes two vulnerabilities in the Reolink P2P protocol. The vulnerabilities were reported by Nozomi Networks. Reolink has a firmware upgrade that mitigates some of the risk.

The two reported vulnerabilities are:

• Use of hard-coded cryptographic key - CVE-2020-25173, and

• Ceartext transmission of sensitive information - CVE-2020-25169

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to  permit unauthorized access to sensitive information.

Dnsmasq Advisory

This advisory describes seven vulnerabilities in the Dnsmasq maintained by Simon Kelley. The vulnerabilities were reported by JSOF Tech (named DNSpooq by JSOF). Kelley has a new version that mitigates the vulnerabilities. The JSOF report confirms that the new version adequately mitigates the vulnerabilities.

The seven reported vulnerabilities are:

• Heap-based buffer overflow (4) - CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, and CVE-2020-25687,

• Insufficient verification of data authenticity (2) - CVE-2020-25684 and CVE-2020-25686, and

• Use of a broken or risky cryptographic algorithm - CVE-2020-25685,

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to result in cache poisoning, remote code execution, and a denial-of-service condition.

NOTE: The JSOF report makes it clear that there will almost certainly a number of ICS vendors that will be affected by this set of DNS vulnerabilities. At least one vendor has already reported this vulnerability in some of their products, more will be coming.

Philips Advisory

This advisory describes an OS command injection vulnerability in the Philips Haswell workstations. The vulnerability was self-reported. Philips has a patch that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to remotely shut down or restart the workstation.

 
/* Use this with templates/template-twocol.html */