Showing posts with label Davy Douhine. Show all posts
Showing posts with label Davy Douhine. Show all posts

Saturday, August 22, 2020

Public ICS Disclosures – Week of 8-15-20


This week we have three vendor disclosures for products from Phoenix Contact, Moxa, and Eaton and one update from Rockwell. There are researcher reports for products from WECON. There were two control system exploits published for products from PNPSCADA and Geutebruck.

Phoenix Contact Advisory


Phoenix Contact published an advisory [.PDF download link] describing a synchronous access of remote resource without timeout vulnerability in their Emalytics, ILC 2050 BI and ILC 2050 BI-L products. This is a third-party vulnerability in the Tridium Niagara product that was reported earlier this month by NCCIC-ICS. Phoenix Contact reports that they expect to fix this vulnerability in the next firmware update in October 2020.

Moxa Advisory


Moxa published an advisory describing six vulnerabilities in their NPort IAW5000A-I/O Series Serial Device Servers. The vulnerabilities were reported by Evgeniy Druzhinin and Ilya Karpov of Rostelecom-Solar. Moxa has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Session fixation,
• Improper privilege management,
• Weak password requirements,
• Cleartext transmission of sensitive information,
• Improper restriction of excessive authentication attempts, and
• Information exposure

Eaton Advisory


Eaton published an advisory describing two vulnerabilities in their Secure Connect Android Mobile app. The vulnerability was reported by Vishal Bharad. Eaton has a new version that mitigates the vulnerabilities. There is no indication that Bharad has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Information exposure, and
• Information exposure through log files

Rockwell Update


Rockwell published an update for an advisory that was originally published on July 8th, 2020 and most recently updated on July 23rd, 2020. The new information includes links to additional detections.

WECON Reports


The Zero Day Initiative has published (ZDI-20-1055 thru ZDI-20-1076) 22 reports of 0-day vulnerabilities in the WECON LeviStudioU. The vulnerabilities have been reported to ‘ICS-CERT’ (presumably CISA NCCIC-ICS) which reportedly received no response from WECON. The vulnerabilities were reported by Natnael Samson. The vulnerabilities are all stack-based buffer overflows in various components of the LeviStudioU product. NO CVEs have been reported.

PNPSCADA Exploit


İsmail ERKEK published an exploit for an SQL injection vulnerability in the PNPSCADA. There is no CVE for this vulnerability and there is no indication that ERKEK has contacted the vendor, so this looks like it is a 0-day vulnerability.

Geutebruck Exploit


Davy Douhine published a Metasploit module for an authenticated arbitrary command execution vulnerability in Geutebruck G-Cam and G-Code cameras. This vulnerability was previously reported by NCCIC-ICS.

Thursday, December 13, 2018

5 Advisories and 2 Updates Published – 12-13-18

Today the DHS NCCIC-ICS published four control system security advisories for products from GE, Geutebruck, Siemens and Schneider and one medical device security advisory for products from Medtronic. They also published an update for a previously published control system security advisory for products from Siemens and a medical device security advisory for products from Philips.

GE Advisory


This advisory describes a path traversal vulnerability in the GE Mark VIe, EX2100e, EX2100e_Reg, and LS2100e distributed control systems. The vulnerability was reported by Can Demirel of Biznet Bilisim. GE has a new version that mitigates the vulnerability. There is no indication that Demirel has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to access system data, which could result in escalation of privilege and unauthorized access to the controller.

Geutebruck Advisory


This advisory describes an OS command injection vulnerability in the Geutebruck E2 Camera Series. The vulnerability was reported by Davy Douhine of RandoriSec. Geutebruck has a new version that mitigates the vulnerability. There is no indication that Douhine has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a remote attacker to inject OS commands as root.

Siemens Advisory


This advisory describes two improper input validation vulnerabilities in the Siemens EN100 Ethernet Communication Module and SIPROTEC 5 relays. These vulnerabilities were reported by Victor Nikitin, Vladislav Suchkov, and Ilya Karpov from ScadaX. Siemens has updates for some of the affected products and continues to work on updates for the remaining products.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to cause a denial-of-service condition of the network functionality of the device, compromising the availability of the system.

NOTE: This advisory was published when Siemens published an update last Tuesday. The original Siemens advisory was reported here back in July, 2018.

Schneider Advisory


This advisory describes three vulnerabilities in the Schneider Electric GUIcon. The vulnerabilities were reported by mdm and rgod of 9SG Security Team. Schneider has a new version that mitigates the vulnerabilities. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Type confusion (2) - CVE-2018-7813 and CVE-2018-7815; and
• Stack-based buffer overflow - CVE-2018-7814

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to execute code with privileges within the context of the application.

NOTE: I briefly reported the Schneider advisory last Saturday.

Medtronic Advisory


This advisory describes a missing encryption of sensitive data vulnerability in the Medtronic 9790 CareLink Programmer, 2090 CareLink Programmer, 29901 Encore Programmer; programmers for Medtronic cardiac devices. The vulnerabilities were reported by Researchers Billy Rios and Jonathan Butts of Whitescope LLC. Medtronic has provided generic workarounds for two of the devices and reports that the 9970 is out of support and all use should be discontinued. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an relatively low-skilled attacker with physical access to the devices could exploit the vulnerability to access PHI or PII stored on the device.

Siemens Update

This update provides additional information for an advisory that was originally published on March 29th, 2018 and updated on April 24th, 2018, June 12th, 2018 and again on November 14th, 2018. The update provides updated affected version information and mitigation links for SIMATIC NET PC-Software.

NOTE: Siemens updated their advisory on Tuesday and then again today. This NCCIC-ICS update reflects the corrected information published by Siemens today.

Philips Update


This update provides additional information for an advisory that was originally published on March 27th, 2018 and subsequently updated on December 11th, 2018. The updated information includes revised affected version data.

More Missing Siemens Updates


Siemens published four more updates today; only one of those was addressed by NCCIC-ICS today. It will be a long blog post here on Saturday. 

Wednesday, March 21, 2018

ICS-CERT Publishes 2 Advisories and 3 Updates

Yesterday the DHS ICS-CERT published two new control system advisories for products from Siemens and Geutebruck. It also updated three previously published control system advisories for products from Siemens (2) and AutomationDirect. ICS-CERT has missed some recent Siemens updates and an advisory.

Siemens Advisory


This advisory describes an improper input validation vulnerability in the Siemens SIMATIC, SINUMERIK, and PROFINET IO products. The vulnerability is being self-reported by Siemens. Siemens has provided updates that mitigate the vulnerability is some products and has provided generic workarounds for the remaining products while updates are developed for them.

ICS-CERT reports that an uncharacterized attacker on an adjacent network could exploit this vulnerability to execute a denial-of-service condition requiring a manual restart to recover the system. The Siemens security advisory notes that OSI Layer 2 access is required to exploit the vulnerability.

Geutebruck Advisory


This advisory describes six vulnerabilities in the Geutebruck IP cameras. The vulnerabilities were reported by Davy Douhine of RandoriSec and Nicolas Mattiocco of Greenlock. Geutebruck has a new firmware version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Improper authentication - CVE-2018-7532;
• SQL injection - CVE-2018-7528;
• Cross-site request forgery - CVE-2018-7524;
• Improper access control - CVE-2018-7520;
• Server-side request forgery - CVE-2018-7516; and
• Cross-site scripting - CVE-2018-7512

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to lead to proxy network scans, access to a database, adding an unauthorized user to the system, full configuration download including passwords, and remote code execution.

SIMATIC Update


This update provides additional information on an advisory that was originally published on February 27th, 2018. It provides updated version information and mitigation measures for:

• SIMATIC IPC547G: Update BIOS to R1.21.0

SIPROTEC Update


This update provides additional information on an advisory that was originally published on July 6th, 2017, and updated on July 18th, on July 28th, on October 10th, on November 30th, and then again on January 4th, 2018. It provides updated version information and mitigation measures for:

• SIPROTEC 7SJ66: All versions prior to V4.30


AutomationDirect Update


This update provides additional information on an advisory that was originally published on November 9th, 2017. It adds a new product (Do-more Designer) to the list of vulnerable products and provided mitigation links for that product.

Missing Siemens Updates


Siemens has published updates and advisories that have not been covered in this latest series of ICS-CERT publications. Normally, I would not mention the ones from yesterday (two updates here and here, and a new advisory here), but today’s new Siemens advisory was also released yesterday. There is also an update from last week (here) that was not mentioned.

Two of the updates (here and here) are for the Spectre and Meltdown vulnerabilities in the Siemens Industrial products. ICS-CERT is unlikely to update their alert to reflect these new mitigation measures since the existing link to the Siemens advisory will take someone to the new information. This is a potential problem for anyone that is relying on ICS-CERT for information, but because of the way that ICS-CERT does their updates (and does not provide detailed change information) this appears to be unavoidable.

Thursday, September 14, 2017

ICS-CERT Updates an Advisory and Publishes Another

Today the DHS ICS-CERT updated a previously published advisory for a product from Siemens. They also published a new advisory for a product from LOYTEC.

Siemens Update


This update provides additional information on an advisory that was originally published on originally published on May 9th, 2017 and updated on June 15, 2017, on July 25th, 2017, and then again on August 18th, 2017. The update provides new affected version information and mitigation links for:

• SCALANCE M-800,S615: All versions prior to V04.03,

LOYTEC Advisory


The advisory describes four vulnerabilities in the LOYTEC LVIS-3ME HMI touch panel. The vulnerabilities were reported by Davy Douhine of RandoriSec. LOYTEC has released a firmware update to mitigate the vulnerabilities. There is no indication that Douhine was provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Relative path traversal - CVE-2017-13996;
• Insufficient entropy - CVE-2017-13992;
• Improper neutralization of input during web page generation - CVE-2017-13994; and
• Insufficiently protected credentials - CVE-2017-13998


ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to cause information exposure or allow arbitrary code execution.

Tuesday, February 14, 2017

ICS-CERT Publishes 3 Advisories and 3 Updates

Today the DHS ICS-CERT published three control system security advisories for products from Siemens, Geutebrück and Advantech. They also updated three control system security advisories for products from Siemens and Rockwell.

Siemens Advisory


This advisory describes an authentication bypass vulnerability in the Siemens SIMATIC Logon application. This vulnerability is being self-reported by Siemens. Siemens has produced an updated version of the application to mitigate the vulnerability.

ICS-CERT reports that an relatively low skilled attacker could remotely exploit this vulnerability to circumvent user authentication under certain conditions.

Geutebrück Advisory


This advisory describes two vulnerabilities in the Geutebrück G-Cam IP camera. The vulnerabilities were reported by Davy Douhine of RandoriSec, Florent Montel and Frédéric Cikala. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Authentication bypass using an alternative path or channel - CVE-2017-5174;
• Improper neutralization of special elements used in an OS command - CVE-2017-5173

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to bypass authentication and obtain remote anonymous access to the device; these vulnerabilities may allow remote code execution.

Advantech Advisory


This advisory describes a DLL hijacking vulnerability in the Advantech WebAccess application. The vulnerability was reported by Li MingZheng Kuangn. Advantech has produced a new version to mitigate the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could exploit the vulnerability o execute arbitrary code within the system. ICS-CERT does not mention what type access is required or comment on the need for an social engineering attack.

Siemens APOGEE Update


This update provides additional information about an advisory originally published on March 22nd, 2016. The update includes:

• A correction of the name of one of the reporting institutions;
• Additional information about the affected versions; and
• Reports a new version that mitigates the vulnerability.

Siemens Industrial Produces Update


This update provides additional information about an advisory originally published on November 8th, 2016 and then updated on November 22nd, 2016 and updated again on December 22nd. The update includes:

• Updated ‘version affected’ information on SIMATIC IT Production Suite;
• Provided mitigation information for SIMATIC IT Production Suite; and
• Removed SIMATIC IT Production Suite from the temporary fix list.

Rockwell Update


This update provides additional information about an advisory originally published on January 5th, 2017. The update includes:

• Adds PowerFlex 700S drives to the list of affected devices;
• Adds DriveLogix 5730 controller option explanation; and

• Explains that the PowerFlex 700S is not covered by the new firmware version mitigation.

Thursday, January 26, 2017

ICS-CERT Publishes Two Advisories

Today the DHS ICS-CERT published two control system security advisories for products from Belden and Eaton.

Belden Advisory


This advisory describes a path traversal vulnerability in the Belden Hirschmann GECKO. The vulnerability was reported by Davy Douhine of RandoriSec. Belden produced a new version to mitigate the vulnerability. There is no indication that Douhine was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a highly skilled attacker could remotely exploit this vulnerability to access a copy of the configuration file of an affected device without authenticating, exposing sensitive information. The Belden Security Bulletin notes that only administrators that are using the configuration download feature are affected.

Eaton Advisory


This advisory describes path traversal vulnerability in legacy Eaton ePDUs. The vulnerability was reported by Maxim Rupp. The affected products are no longer supported; Eaton suggests using defense in depth mitigation measures if the devices are not replaced.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to access configuration files.


NOTE: For some reason this vulnerability was presented in last year’s format. I’ve already gotten so used to the new format that this reversion feels odd. Oh well….
 
/* Use this with templates/template-twocol.html */