Showing posts with label Delta Electronics. Show all posts
Showing posts with label Delta Electronics. Show all posts

Tuesday, March 22, 2022

Review – 1 Advisory and 1 Update Published – 3-22-22

Today, CISA’s NCCIC-ICS published both a control system security advisory and an update for a previously published advisory for products from Delta Electronics.

Delta Advisory - This advisory describes 17 vulnerabilities in the Delta DIAEnergie.

NOTE: Heinzl’s advisories (see here for example) provide a description of an extremely long coordination exercise with NCCIC-ICS to get Delta to complete work on the fix for these vulnerabilities.

Delta Update - This update provides additional information on an advisory that was originally published on August 26th, 2021 and most recently updated on December 16th, 2021.

For more details on these advisories, including links to researcher reports and reports on 12 additional SQL injection vulnerabilities in the products covered by today’s new advisory, see my article at CFSN Detailed Analysis - - subscription required.

Thursday, January 21, 2021

5 Advisories Published – 1-21-21

Today CISA’s NCCIC-ICS published five control system security advisories for products from WAGO, Mitsubishi Electric, Honeywell, and Delta Electronics (2).

WAGO Advisory

This advisory describes a deserialization of untrusted data vulnerability in the M&M Software fdtCONTAINER (M&M is subsidiary of WAGO). The vulnerability was reported by Emerson. M&M has a new version that mitigates the vulnerability (but would not be compatible with existing projects). There is no indication that Emerson has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low skilled attacker could exploit the vulnerability via a social engineering attack to allow malicious code to be executed without notice.

NCCIC-ICS reports that this vulnerability affects products from Emerson and PEPPERL+FUCHS.

NOTE: I briefly discussed this vulnerability last Saturday, but I was not aware that M&M was a subsidiary of WAGO.

Mitsubishi Advisory

This advisory describes an uncontrolled resource consumption vulnerability in the Mitsubishi MELFA product line. The vulnerability was reported by Qi An Xin Group, Inc. Mitsubishi has provided generic mitigation measures for the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to cause a denial-of-service condition.

NOTE: NCCIC-ICS provided an incorrect link for the Mitsubishi advisory (listed as ‘Mitsubishi Electric website’ in this advisory). The link should have been https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-019_en.pdf.

Honeywell Advisory

This advisory describes four vulnerabilities in the Matrikon (a subsidiary of Honeywell) OPC UA Tunneller. The vulnerability was reported by Uri Katz of Claroty. Matrikon has a new version that mitigates the vulnerability. There is no indication that Katz has been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Heap-based buffer overflow - CVE-2020-27297,

• Out-of-bounds read - CVE-2020-27299,

• Improper check for unusual or exceptional conditions - CVE-2020-27274, and

• Uncontrolled resource3 consumption - CVE-2020-27295

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to disclose sensitive information, remotely execute arbitrary code, or crash the device.

TPEditor Advisory

This advisory describes two vulnerabilities in the Delta TPEditor. The vulnerabilities were reported by kimiya via the Zero Day Initiative. Delta has a new version that mitigates the vulnerabilities. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Untrusted pointer dereference - CVE-2020-27288, and

• Out-of-bounds write - CVE-2020-27284

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to allow an attacker to execute code under the privileges of the application.

ISPSoft Advisory

This advisory describes a use after free vulnerability in the Delta ISPSoft PLC program development tool. The vulnerability was reported by Francis Provencher via ZDI. Delta has a new version that mitigates the vulnerability. There is no indication that Provencher has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to allow an attacker to execute code under the privileges of the application.

Tuesday, January 5, 2021

6 Advisories Published – 1-5-21

Today the CISA NCCIC-ICS published six control system security advisories for products from Delta Electronics (2), Red Lion, GE, Panasonic and Schneider.

CNCSoft Advisory

This advisory describes a stack-based buffer overflow vulnerability in the Delta CNCSoft ScreenEditor. The vulnerability was reported by Kimiya via the Zero Day Initiative. Delta has an update that mitigates the vulnerability. There is no indication that Kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow arbitrary code execution.

DOPSoft Advisory

This advisory describes two vulnerabilities in the Delta DOPSoft software. The vulnerability was reported by Kimiya via the Zero Day Initiative. Delta has an update that mitigates the vulnerability. There is no indication that Kimiya has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Out-of-bounds write - CVE-2020-27275, and

• Untrusted pointer dereference - CVE-2020-27277

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow arbitrary code execution.

Red Lion Advisory

This advisory describes three vulnerabilities in the Red Lion Crimson 3.1 programming software. The vulnerabilities were reported by Marco Balduzzi, Ryan Flores, Philippe Lin, Charles Perine, Ryan Flores, Rainer Vosseler via ZDI. Red Lion has a new version that mitigates the vulnerabilities. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Null pointer dereference - CVE-2020-27279,

• Missing authentication for critical function - CVE-2020-27285, and

• Improper resource shutdown - CVE-2020-27283

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to create a denial-of-service condition, read and modify the database, and leak memory data.

GE Advisory

This advisory describes two vulnerabilities in the GE Reason RT43X Clocks. The vulnerabilities were reported by Tom Westenberg of Thales UK. GE has a new firmware version that mitigates the vulnerabilities. There is no indication that Westenberg has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Code injection - CVE-2020-25197, and

• Use of hard-coded cryptographic key - CVE-2020-25193

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an authenticated remote attacker to execute arbitrary code on the system or intercept and decrypt encrypted traffic.

NOTE: I (very) briefly mentioned the GE advisory for these vulnerabilities back in November.

Panasonic Advisory

This advisory describes an out-of-bounds read vulnerability in the Panasonic FPWIN Pro programming software. The vulnerability was reported by Francis Provencher via ZDI. Panasonic has a new version that mitigates the vulnerability. The is no indication that Provencher has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to  allow remote code execution.

Schneider Advisory

This advisory describes three vulnerabilities in the Schneider Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy products. The vulnerabilities were reported (here and here) by Kai Wang of Fortinet's FortiGuard Labs. Schneider continues to work on mitigation measures for supported versions of the affected products.

The three reported vulnerabilities were:

• Out-of-bounds read - CVE-2020-7562,

• Out-of-bounds write - CVE-2020-7563, and

• Classic buffer overflow - CVE-2020-7564

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow write access and the execution of commands, which could result in data corruption or a web server crash.

NOTE: I briefly described these vulnerabilities back in November.

NCCIC-ICS Updates

NCCIC-ICS also published five updates today. I will cover them in a separate blog post.

Tuesday, March 17, 2020

1 Advisory Published – 3-17-20


Today the CISA NCCIC-ICS published one control system security advisory for products from Delta Electronics.

Delta Advisory


The advisory describes two vulnerabilities in the Delta Industrial Automation CNCSoft ScreenEditor. The vulnerability was reported by Natnael Samson (@NattiSamson) and kimiya, working with the Zero Day Initiative. Delta has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2020-7002; and
• Out-of-bounds read - CVE-2020-6976

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to cause buffer overflow conditions that may allow information disclosure, remote code execution, or crash the application. According to the ZDI advisories (here, here and here) the vulnerabilities are remotely exploitable.

Commentary


The two different ZDI advisories for the buffer overflow vulnerability show slightly different descriptions of the vulnerability. Both describe parsing problems in DBP files. The kimiya advisory appears to be slightly more generic where the Samson advisory specifies that the problem lies in parsing the GifName information in DPB files. There is a possibility that there are two separate vulnerabilities here. This is where it would be helpful to have the researchers verify the efficacy of the fix. We could have a situation here where the more specific vulnerability was fixed, but the more generic problem remains.

Tuesday, September 10, 2019

6 Advisories and 3 Updates Published – 09-10-19


The DHS NCCIC-ICS published six control system security advisories for products from OSIsoft, Siemens (4), and Delta Electronics. They also updated two previously published advisories for products from Siemens and an alert from Mitsubishi Electric Europe.

OSIsoft Advisory


This advisory describes an integer overflow or wraparound vulnerability in the OSIsoft PI SQL Client. The vulnerability is self-reported. OSIsoft has a new version that mitigates the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow remote code execution or cause a denial of service, resulting in disclosure, deletion, or modification of information.

SIMATIC Advisory


This advisory describes an improper input validation vulnerability in the Siemens SIMATIC TDC CP51M1 multiprocessor automation system. The vulnerability is self-reported. Siemens has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to create a denial-of-service condition within UDP communication.

WirelessHart Gateway Advisory


This advisory describes a cross-site scripting vulnerability in the Siemens IE/WSN-PA Link WirelessHART Gateway. The vulnerability is self-reported. Siemens has provided generic mitigation measures for the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow information disclosure, code execution, or denial-of-service.

Comment: Usually a vendor provides generic mitigation measures for a vulnerability when they are forced to disclose a vulnerability due to the disclosure process. With this being a self-disclosed vulnerability, Siemens was not forced to disclose this vulnerability with a generic mitigation. That takes a certain amount of integrity, but it does place some of their customers at an unusual level of risk. The generic mitigation measure is not unusual or even an unexpected requirement, but some customers will not have taken the standard precaution and are unlikely to implement it now.

Industrial Product Advisory


This advisory describes three vulnerabilities in the Siemens Industrial Products. The vulnerabilities were self-reported. Siemens has new versions that mitigate the vulnerabilities is some of the affected products.

The three reported vulnerabilities are:

Integer overflow or wraparound - CVE-2019-11477;
Uncontrolled resource consumption (2) - CVE-2019-11478, and CVE-2019-11479

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to cause denial-of-service condition.

SINETPLAN Advisory


This advisory describes an improper authorization vulnerability in the Siemens Network Planner (SINETPLAN). The vulnerability is self-reported. Siemens has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow information disclosure, code execution, and denial-of-service. The Siemens Advisory notes that the vulnerability can only be exploited “local users”.

Delta Electronics Advisory


This advisory describes three vulnerabilities in the Delta Electronics TPEditor. The vulnerabilities were reported by kimiya of 9sg Security Team vis the Zero Day Initiative. Delta has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

Stack-based buffer overflow - CVE-2019-13540;
Heap-based buffer overflow - CVE-2019-13536; and
Out-of-bounds write - CVE-2019-13544

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow information disclosure, remote code execution, or may crash the application.

PCS7 Update


This update provides new information on an advisory that was originally reported on July 9th, 2019 and last updated on August 13th, 2019. The new information includes updated version information and mitigation links for SIMATIC WinCC Runtime Professional V14 and V15.

WinCC Update


This update provides new information on an advisory that was originally reported on July 11th, 2019 and updated on August 13th, 2019.

Mitsubishi Update


This update provides new information on an alert that was originally published on August 13, 2019. The revised alert changes the name of the vendor to “Mitsubishi Electric Europe B.V.”.

Other Siemens Advisories


Today was disclosure Tuesday for Siemens. They published six advisories and three updates. Two of those advisories are for third-party vulnerabilities (DejaBlue and Urgent/11). The Urgent/11 advisory could be added to the NCCIC-ICS advisory on those vulnerabilities via an update on Thursday. To date, NCCIC-ICS has not addressed DejaBlue, so I suspect that this Siemens advisory will be ignored. The last advisory will probably be addressed by NCCIC-ICS on Thursday.

Friday, July 12, 2019

7 Advisories Published – 07-11-19


Yesterday the DHS NCCIC-ICS published six industrial control system advisories for products from Schneider Electric (2), AVEVA, Siemens (3) and Delta Industrial. They also published a medical device security advisory for products from Philips.

Interactive Graphical SCADA Advisory


This advisory describes an out-of-bounds write vulnerability in the Schneider Interactive Graphical SCADA System (IGSS). The vulnerability was reported by mdm and rgod of 9SG Security Team via the Zero Day Initiative. Schneider has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerability to  allow an attacker to achieve arbitrary code execution or crash the software.

Floating License Manager Advisory


This advisory describes four vulnerabilities in the Schneider Floating License Manager. The vulnerabilities are self-reported. According to the Schneider advisory, the vulnerabilities are in a third-party component (Flexera FlexNet Publisher) of their product. Schneider has a patch available that mitigates the vulnerability.

The four reported vulnerabilities are:

Improper input validation (3) - CVE-2018-20031, CVE-2018-20032, and CVE-2018-20034; and
Memory corruption - CVE-2018-20033

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to deny the acquisition of a valid license for legal use of the product.

NOTE: There are still three other advisories published by Schneider on Tuesday that have not been reported by NCCIC-ICS; all for Modicon controllers. I will address these on Saturday.;

AVEVA Advisory


This advisory describes the same four vulnerabilities reported above, this time in the AVEVA Vijeo Citect and Citect SCADA Floating License Manager. These vulnerabilities have not yet been reported by AVEVA. A new version is available from Schneider to mitigate the vulnerabilities.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to deny the acquisition of a valid license for legal use of the product.

SIMATIC Advisory


This advisory describes three vulnerabilities in the Siemens SIMATIC RF6XXR. The vulnerabilities are in older, third-party SSL and TLS applications still in use by these products. The vulnerabilities were reported by Wendy Parrington from United Utilities. Siemens reports that newer versions mitigate the vulnerabilities.

The three reported vulnerabilities are:

Improper input validation - CVE-2011-3389; and
Cryptographic issues (2) - CVE-2016-6329 and CVE-2013-0169

NCCIC-ICS reports that an uncharacterized attacker could use publicly available exploits (two of these are older, well recognized vulnerabilities) to remotely exploit the vulnerabilities to allow access to sensitive information.

TIA Portal Advisory


This advisory describes an improper access control vulnerability in the Siemens TIA Administrator (TIA Portal). The vulnerability was reported (with proof of concept code) by Joseph Bingham of Tenable. Siemens has an update that mitigates the vulnerability. There is no indication that Bingham has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an execution of some commands without proper authentication.

SIMATIC WinCC Advisory


This advisory describes an unrestricted upload of file with dangerous type vulnerability in the Siemens SIMATIC WinCC and SIMATIC PCS7 devices. The vulnerability was reported by Xuchen Zhu from ZheJiang Guoli Security Technology. Siemens has updates available that mitigates the vulnerability. There is no indication that Xuchen has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to cause a denial-of-service condition on the affected service or device. The Siemens advisory notes that the attacker has to be authenticated with a valid user account.

NOTE: There is still one new advisory that Siemens published on Tuesday that has not been reported by NCCIC-ICS. I will cover it tomorrow.

Delta Industrial Advisory


This advisory describes two vulnerabilities in the Delta Electronics CNCSoft ScreenEditor. The vulnerability was reported by Natnael Samson (@NattiSamson) via ZDI. Delta has a new version that mitigates the vulnerabilities. There is no indication that Samson was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Heap-based buffer overflow - CVE-2019-10982; and
Out-of-bounds read - CVE-2019-10992

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause buffer overflow conditions that may allow information disclosure, remote code execution, or crash the application.

Philips Advisory


This advisory describes a use of obsolete function vulnerability in the Philips Holter 2010 Plus, a 12-lead EKG analysis software program. The vulnerability is self-reported. Philips provides generic measures to mitigate the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit this vulnerability to lead to a product feature escalation.

Wednesday, October 3, 2018

Three Advisories and Three Updates Published


Yesterday the DHS NCCIC-ICS published three control system security advisories for products from Entes, GE and Delta Electronics. They also updated previously published advisories for products from Phillips, WECOM and ABB.

Entes Advisory


This advisory describes two vulnerabilities in the Entes EMG 12, an Ethernet Modbus Gateway. The vulnerability was reported by Can Demirel of Biznet Bilisim. Entes has a new firmware version that mitigates the vulnerabilities. There is no indication that Demirel has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper authentication - CVE-2018-14826; and
Information exposure in query strings in get request - CVE-2018-14822

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to gain unauthorized access and could allow the ability to change device configuration and settings.

GE Advisory


This advisory describes a heap based buffer overflow in the GE Communicator application. The vulnerability was reported by kimiya, working with iDefense Labs. Newer versions of the application mitigate the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to execute arbitrary code or create a denial-of-service condition.

Delta Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Delta ISPSoft, a PLC program development tool. The vulnerability was reported by Ariele Caltabiano (kimiya) via ZDI. Newer versions of the tool mitigate the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to execute code under the context of the application.

Phillips Update


This update provides additional information on an advisory that was originally published on March 29th, 2018. The update adds the phrase “and/or system information” to the description provided for ‘information exposure’ vulnerabilities.

WECON Update


This update provides additional information on an advisory that was originally published on July 31st, 2018. The updated information includes:

• Two new vulnerabilities added, and
• Added a third reporting security researcher.

I would have normally expected this to be a separate advisory, but since the original advisory was based upon information provided via the Zero Day Initiative, I suspect that there was an issue on that end of the process that is being corrected here.

ABB Update


This update provides additional information on an advisory that was originally published on August 28th, 2018. The update provides new mitigation information.

Friday, September 28, 2018

4 ICS Advisories


Yesterday the DHS NCCIC-ICS (okay, I finally gave in; ICS-CERT is gone; please clean up the web site) published four control system security advisories for products from Delta Electronics, Fuji Electric (2) and Emerson.

Delta Advisory

This advisory describes an out-of-bounds read vulnerability in the Delta Industrial Automation PMSoft software development tool. The vulnerability was reported by Mat Powell via ZDI. Delta has an update available that mitigates the vulnerability. There is no indication that Powell has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to read confidential information.

FRENIC Advisory


This advisory describes three vulnerabilities in the Fuji FRENIC HVAC drive devices. The vulnerability was reported by Michael Flanders and Ghirmay Desta via ZDI. Fuji is working on mitigation measures.

The three reported vulnerabilities are:

• Buffer over-read - CVE-2018-14790;
• Out-of-bounds read - CVE-2018-14798; and
Stack-based buffer overflow - CVE-2018-14802

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow for arbitrary remote code execution affecting the availability of the device.

Alpha5 Advisory


This advisory describes two buffer-overflow vulnerabilities in the Fuji Alpha5 Smart Loader servo drive. The vulnerability was reported by Michael Flanders via ZDI. Fuji is working on mitigation measures.

The two reported vulnerabilities are:

• Classic buffer overflow - CVE-2018-14788; and
• Heap-based buffer overflow - CVE-2018-14794

NCCIC-ICS reports that a relatively low-skilled attacker could remotely use publicly available exploits to allow for arbitrary remote code execution on the device.

NOTE: It is disappointing that Fuji was not even able to provide workaround security measures for these two product lines. Does anyone know if NCCIC-ICS is still giving the 45-day grace period before publishing their advisories?

Emerson Advisory


This advisory describes two vulnerabilities in the Emerson AMS Device Manager. The vulnerabilities were reported by Sergey Temnikov of Kaspersky Lab and Emerson. Emerson has patches available to mitigate the vulnerabilities. There is no indication that Temnikov has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper access control - CVE-2018-14804; and
• Improper privilege management - CVE-2018-14808

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to

Tuesday, August 7, 2018

ICS-CERT Publishes 3 Advisories


Today the DHS ICS-CERT published one control system security advisory for products from Delta Electronics and two medical device security advisories for products from Medtronic.

Delta Advisory


This advisory describes two vulnerabilities in the Delta CNCSoft and ScreenEditor products. The vulnerability was reported by Mat Powell via the Zero Day Initiative. Delta has an updated version of CNCSoft that mitigates the vulnerabilities. There is no indication that Powell was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-10636; and
Out-of-bounds read - CVE-2018-10598

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to gain remote code execution with administrator privileges.

MiniMed Advisory


This advisory describes two vulnerabilities in the Medtronic MiniMed 508 Insulin Pump. The vulnerabilities were reported by Billy Rios, Jesse Young, and Jonathan Butts of Whitescope LLC. Medtronic does not intend to develop a mitigation for these vulnerabilities (see note below).

The two reported vulnerabilities are:

• Cleartext transmission of sensitive information - CVE-2018-10634; and
• Authentication bypass by capture replay - CVE-2018-14781

ICS-CERT reports that an uncharacterized attacker could remotely exploit these vulnerabilities to allow an attacker to replay captured wireless communications and cause an insulin (bolus) delivery.

NOTE: The Medtronic security advisory reports that the following must occur for these vulnerabilities to be exploited:

1. The remote option for the pump would need to be enabled. This is not a factory-delivered default, and a user must choose this option.
2. The user’s remote controller ID needs to be registered to the pump.
3. The easy bolus option would need to be turned on and easy bolus step size programmed in the pump.
4. An unauthorized individual would need to be within close proximity to the user, with
necessary equipment to copy the RF signals activated, when the user is delivering a bolus
using the remote controller.
5. The unauthorized individual would need to be within the vicinity of the userto play back the RF signals to deliver a malicious remote bolus.
6. The user would need to ignore the pump alerts, which indicates that a remote bolus is being delivered.

MyCareLink Advisory


This advisory describes two vulnerabilities in the Medtronic MyCareLink Patient Monitor. The vulnerabilities were reported by Billy Rios, Jesse Young, and Jonathan Butts of Whitescope LLC. Medtronic is making (has made for one of the vulnerabilities) server side updates to mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Insufficient verification of data authenticity - CVE-2018-10626; and
• Storing passwords in a recoverable format - CVE-2018-10622

ICS-CERT reports that an uncharacterized attacker with physical access to the device could exploit the vulnerabilities to obtain per-product credentials that are utilized to authenticate data uploads and encrypt data at rest. Additionally, an attacker with access to a set of these credentials and additional identifiers can upload invalid data to the Medtronic CareLink network.

Wednesday, February 28, 2018

ICS-CERT Publishes 5 Advisories and 5 Siemens Updates


Yesterday the DHS ICS-CERT published two medical device security advisories for products from Philips and Medtronic. They published three industrial control system security advisories for products from Emerson, Delta Electronics and Siemens. They also updated five previously published control system security advisories for a variety of products from Siemens.

NOTE: The Siemens advisory and five updates were briefly mentioned here last week. There was another advisory and another update (both 3rd party vendor problems affecting Siemens products) that Siemens announced at the same time that ICS-CERT has apparently decided not to address.

ICS-CERT also recently announced a call for abstracts for the Spring 2018 meeting of the ICSJWG in Albuquerque, NM on April 10 - 12, 2018. Abstracts need to be submitted by March 13th, 2018.

Philips Advisory


This advisory describes a relatively large number of vulnerabilities in the Philips Intellispace Portal ISP visualization and image analysis system. The vulnerabilities are apparently being self-reported. There is no report about these vulnerabilities on the FDA medical device safety page. Philips will be issuing an updated version in the coming months to mitigate the vulnerabilities.

NOTE: Apparently at least some of these vulnerabilities are 3rd party vendor issues that have seen publicly available exploits in other products.

The 35 reported vulnerabilities include:

• Improper input validation (13) - CVE-2018-5474, CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, CVE-2017-0148, CVE-2017-0272, CVE-2017-0277, CVE-2017-0278, CVE-2017-0279, CVE-2017-0269, CVE-2017-0273, and CVE-2017-0280;
• Information exposure (8) - CVE-2017-0147, CVE-2017-0267, CVE-2017-0268, CVE-2017-0270, CVE-2017-0271, CVE-2017-0274, CVE-2017-0275, and CVE-2017-0276;
• Permissions, privileges and access controls (4) - CVE-2018-5472, CVE-2018-5468, CVE-2017-0199, and CVE-2005-1794;
• Unquoted search path element - CVE-2018-5470;
• Left over debug code - CVE-2018-5454; and
Cryptographic issues (8) - CVE-2018-5458, CVE-2018-5462, CVE-2018-5464, CVE-2018-5466, CVE-2011-3389, CVE-2004-2761, CVE-2014-3566, and CVE-2016-2183

ICS-CERT reports that an uncharacterized attacker could remotely exploit these vulnerabilities  to gain unauthorized access to sensitive information, perform man-in-the-middle attacks, create denial of service conditions, or execute arbitrary code.

Medtronic Advisory


This advisory describes two vulnerabilities in the Medtronic 2090 CareLink Programmers. The vulnerabilities were reported by Billy Rios and Jonathan Butts of Whitescope LLC. There is no report about these vulnerabilities on the FDA medical device safety page. Medtronics has identified compensating controls that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Strong password in a recoverable format - CVE-2018-5446; and
• Relative path traversal - CVE-2018-5448

ICS-CERT reports that an uncharacterized attacker with access to a CareLink Programmer could exploit the vulnerability to obtain per-product credentials to the software deployment network. These credentials grant access to the software deployment network, but access is limited to read-only versions of device software applications. No write capability exists with the credentials.

Emerson Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Emerson ControlWave Micro Process Automation Controller. The vulnerability was reported by Younes Dragoni of Nozomi Networks. Emerson has a new firmware version that mitigates the vulnerability. There is no indication that Dragoni has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to execute a denial of service attact.

Delta Advisory


This advisory describes three vulnerabilities in the Delta WPLSoft PLC programming software. The vulnerability was reported by Axt via the Zero Day Intitiative. The newest version of the software mitigates the vulnerability. There is no indication that Axt has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-7494;
• Heap-based buffer overflow - CVE-2018-7507; and
• Out-of-bounds write - CVE-2018-7509

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow remote code execution or cause the software the attacker is accessing to crash.

Siemens Advisory


This advisory describes a cryptographic vulnerability in the Siemens SIMATIC Industrial PCs. This is a 3rd party vulnerability in RSA key generation allowing for a potential ROCA attack. The vulnerability is being self-reported by Siemens. Siemens has produced firmware updates that mitigate the vulnerability.

ICS-CERT reports that an uncharacterized attacker [probably pretty skilled IMO] could remotely exploit the vulnerability to conduct cryptographic attacks against the key material.

NOTE: This is going to be a widespread vulnerability, potentially affecting any control system using Infineon’s Trusted Platform Module for the generation of RSA keys. It is also another vulnerability that it would have been helpful if ICS-CERT had published an alert on the topic last fall.

SIMATIC Update


This update provides additional information on an advisory that was was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14thNovember 28th, and most recently January 18, 2018. The update adds five new vulnerabilities to the advisory:

• Improper restrictions of operations within the bounds of a memory buffer (3) - CVE-2017-12818, CVE-2017-12820, and CVE-2017-12821;
• Security features - CVE-2017-12819; and
• Improper access control - CVE-2017-12822

Industrial Products Update


This update provides additional information on an advisory that was originally published on December 5th, 2017 and updated on December 19th, 2017 and again on January 23rd, 2018. The new information includes new affected version data and mitigation links for:

• SIMATIC ET 200MP IM155-5 PN ST: All versions prior to V4.1;
• SIMOTION P V4.4 and V4.5: All versions prior to V4.5 HF5;
• DK Standard Ethernet Controller: All versions prior to V4.1.1 Patch 05; and
• EK-ERTEC 200 PN IO: All versions prior to V4.5

PROFINET 1 Update


This update provides additional information on an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, 2017, November 14th, 2017, and most recently on January 23rd, 2018. The update provides updated affected version information and mitigation links for:

• SIMATIC WinCC flexible 2008: All versions prior to flexible 2008 SP5

PROFINET 2 Update


This update provides additional information on an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th,  November 28th, 2017, and most recently January 18th, 2018, and most recently on January 25th, 2018. The new information includes new affected version data and mitigation links for:

• SIMATIC ET 200MP-IMI55-5 PN ST: All versions prior to V4.1

Ruggedcom Update


This update provides additional information on an advisory that was was originally published on September 28th, 2017, and updated on October 17th, 2017. The new information adds corrected version information and mitigation links for:

• SCALANCE XR-500/XM-400: All versions between v6.1 and 6.1.1; and
• SCALANCE XB-200/XC-200/XP-200/XR300-WG: All versions between v3.0 and v3.0.2

Thursday, January 4, 2018

ICS-CERT Publishes 2 Advisories and Siemens Update

Today the DHS ICS-CERT published two control system security advisories for products from Advantech and Delta Electronics. It also updated a previously published advisory for products from Siemens

Advantech Advisory


This advisory describes multiple vulnerabilities in the Advantech WebAccess products. The vulnerabilities were reported by Steven Seeley of Offensive Security, Zhou Yu and Andrea Micalizzi working with the Zero Day Initiative, and Michael Deplante. Advantech has released a new version that mitigates the vulnerabilities. There is no indication that any of the researchers were provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Untrusted pointer deference - CVE-2017-16728;
• Stack-based buffer overflow - CVE-2017-16724;
• Path traversal - CVE-2017-1672;
• SQL injection - CVE-2017-16716; and
• Improper input validation - CVE-2017-16753

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to cause the device to crash, remotely execute arbitrary code or bypass authentication.

Delta Advisory


This advisory describes multiple vulnerabilities in the Delta Industrial Automation Screen Editor. The vulnerabilities were reported by Steven Seeley of Source Incite. The affected product has been discontinued and Delta recommends upgrading to DOPSoft, Version 2. There is no indication that Seeley has verified the efficacy of the fix.

The three reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2017-16751;
• Use after free - CVE-2017-16749; and
• Out-of-bounds write - CVE-2017-16747

ICS-CERT reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to remotely execute arbitrary code.

Siemens Update


This update provides new information on an advisory that was was originally published on July 6th, 2017, and updated on July 18th, on July 28th, on October 10th, and then again on November 30th. Siemens is providing updated version information and mitigation measures for their SIPROTEC 7UT686.


NOTE: This is the update that I mentioned last Saturday.

Wednesday, December 14, 2016

ICS-CERT Publishes 5 Advisories and Strategy Document

Yesterday the DHS ICS-CERT published five control system security advisories for products from Siemens (2), Delta Electronics, Moxa, and Visonic. Additionally is published information about a new US – Canada agreement on a strategy for protecting the electric grid from both man-made and natural events.

Siemens S7 Advisory


This advisory describes two advisories in the Siemens S7-300 and S7-400 programmable logic controllers. The vulnerabilities were reported by Zhu WenZhe from Beijing Acorn Network Technology. Siemens has published interim mitigation guidance pending the production of an actual fix for the vulnerabilities.

The reported vulnerabilities are:

• Inadequate encryption strength - CVE-2016-9159; and
• Protection mechanism failure - CVE-2016-9158

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to effect a denial-of-service condition or credential disclosure. Siemens notes that an attacker would have to have network access to the device.

NOTE: Siemens announced this vulnerability in a tweet last Friday.

Siemens SIMATIC Advisory


This advisory describes an ActiveX vulnerability in the Siemens SIMATIC WinCC and SIMATIC PCS 7. The vulnerability was reported by Mingzheng Li from Acorn Network Security Lab. Siemens has produced a new version to mitigate the vulnerability. There is no indication that Li has been provided an opportunity to verify the fix.

ICS-CERT reports that this vulnerability requires a social engineering attack and is thus not remotely exploitable. The Siemens security advisory simply notes that an attacker must have control of a web site “that is allowed to execute ActiveX components”. A successful attack could allow an attacker to crash the component or leak application memory content.

NOTE: Siemens announced this vulnerability in a tweet last Friday.

Delta Electronics Advisory


This advisory describes two vulnerabilities in the Delta Electronics WPLSoft, ISPSoft, and PMSoft software applications. The vulnerabilities were separately reported by axt and Ariele Caltabiano via the Zero Day Initiative. Delta Electronics has produced new software versions to mitigate these vulnerabilities. There is no indication that either researcher was provided an opportunity to verify the efficacy of the fix.

The reported vulnerabilities are:

• Heap-based buffer overflow - CVE-2016-5805; and
• Out-of-bounds write - CVE-2016-5802

ICS-CERT reports that a social engineering attack is required to exploit these vulnerabilities. A successful exploit could allow an attacker to execute arbitrary code.

Moxa Advisory


This advisory describes two vulnerabilities in the Moxa DACenter application. The vulnerabilities were reported by Zhou Yu. Moxa has produced a patch to mitigate the vulnerabilities. ICS-CERT reports that Yu has verified the efficacy of the fix.

The reported vulnerabilities are:

• Resource exhaustion - CVE-2016-9354; and
• Unquoted search path - CVE-2016-9356

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to effect a denial of service attack or allow an authorized but nonprivileged local user to execute arbitrary code with privileges on the system.

Visonic Advisory


This advisory describes two vulnerabilities in the Visonic PowerLink2 module. The vulnerabilities were reported by Aditya K. Sood. Visonic has produced an updated version to mitigate the vulnerabilities. There is no indication that Sood has been provided an opportunity to verify the efficacy of the fix.

The reported vulnerabilities are:

• Information exposure - CVE-2016-5813; and
• Cross-site scripting - CVE-2016-5811

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerabilities to download images from the server.

Electric Grid Security Strategy  

ICS-CERT published a fact sheet about and a link to a new US-Canada electric grid security strategy document. The strategy focuses on three goals:

• Protect today’s electric grid and enhance preparedness;
• Manage contingencies and enhance response and recovery efforts; and
• Build a more secure and resilient future electric grid.

As one would expect, the actual strategy document is a high-level political document with very little technical information. It is important, however, in that it reflects the reality of the fact that the electric grid of these two countries is interconnected and that adequate protection of that interconnected grid is going to take coordinated efforts from both parties.


As in any strategy, the tactics used to implement that strategy may be as important as the strategy itself.  It will be interesting to see if any similar tactical documents are publicly released.
 
/* Use this with templates/template-twocol.html */