Showing posts with label David Atch. Show all posts
Showing posts with label David Atch. Show all posts

Friday, October 6, 2017

ICS-CERT Publishes Two Advisories

Yesterday the DHS ICS-CERT published two control system security advisories for products from Siemens and GE.

Siemens Advisory


This advisory describes an authentication bypass vulnerability in the Siemens 7KT PAC1200 data manager. The vulnerability was reported by Maxim Rupp. Siemens has produced new firmware that mitigates the vulnerability. There are not indications that Rupp has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to bypass authentication mechanisms and perform administrative functions. The Siemens security bulletin reports that the attacker must have network access to the device to exploit the vulnerability.

GE Advisory


This advisory describes a stack-based buffer overflow vulnerability in the GE CIMPLICITY software. The vulnerability was reported by David Atch of CyberX.  GE has released a new version that mitigates the vulnerability. There is no indication that Atch has been provided an opportunity to verify the efficacy of the fix.


ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause the device that the attacker is accessing to crash; a buffer overflow condition may allow arbitrary remote code execution.

Tuesday, March 28, 2017

ICS-CERT Publishes Two Advisories

Today the DHS ICS-CERT published two control system security advisories for products from 3S – Smart Software Solutions and Siemens.

3S Advisory


This advisory describes two vulnerabilities in the 3S CODESYS Web Server which is used by an undisclosed variety of equipment manufacturers. The vulnerability was reported by David Atch of CyberX. 3S has provided a patch that mitigates the vulnerability. ICS-CERT reports that Atch has tested the patch and apparently verifies the efficacy of the fix.

The two vulnerabilities are:

• Unrestricted upload of file with dangerous type - CVE-2017-6027; and
• Stack-based buffer overflow - CVE-2017-6025

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerabilities to allow arbitrary files to be uploaded to the CODESYS Web Server without authorization. Additionally, an attacker may be able to crash the application or execute arbitrary code.

Siemens Advisory


This advisory describes multiple vulnerabilities in the Siemens RUGGEDCOM VPN endpoints and firewall devices. Maxim Rupp reported four of the five vulnerabilities. Siemens has developed a mitigation tool [.PDF download] for these vulnerabilities. There is no indication that Rupp was provided an opportunity to verify the efficacy of the fix.

The vulnerabilities are:

• Improper authorization - CVE-2017-2686 and CVE-2017-2689;
• Cross-site request forgery - CVE-2017-2688
• Cross-site scripting - CVE-2017-2687 and CVE-2017-6864;


ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to perform actions with administrative privileges. The Siemens Security Advisory notes that network access is required to exploit three of the vulnerabilities while the other two require a social engineering attack.

Tuesday, January 26, 2016

ICS-CERT Publishes Two Advisories

This morning the DHS ICS-CERT published two control system advisories. They were for systems from Rockwell Automation and MICROSYS.

Rockwell Advisory

This advisory describes a stack-based buffer overflow vulnerability in the Allen-Bradley MicroLogix 1100 PLCs. The vulnerability was reported by David Atch of CyberX. Rockwell has produced a firmware update that mitigates the vulnerability, but there is no indication that Atch has been provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to run arbitrary code on the device.

MICROSYS Advisory

This advisory describes a memory corruption vulnerability in the MICROSYS PROMOTIC application. The vulnerability was reported by Praveen Darshanam of Versa Networks. MICROSYS has produced a new version which mitigates the vulnerability and Darshanam has verified the efficacy of the fix.

ICS-CERT reports that it would be relatively easy to craft a social engineering exploit of this vulnerability. This is the first time that I have seen ICS-CERT that crafting a specific social engineering exploit “would be simple”.


The PROMOTIC update note indicate that the vulnerability exists in the TrendsView ActiveX component.
 
/* Use this with templates/template-twocol.html */