Showing posts with label Dillon Beresford. Show all posts
Showing posts with label Dillon Beresford. Show all posts

Thursday, September 26, 2013

ICS-CERT Publishes Emerson RTU Advisory

Today the DHS ICS-CERT published a control system advisory for Emerson Process Management RTUs for multiple vulnerabilities. The vulnerabilities were reported by Dillon Beresford, Brian Meixell, Marc Ayala, and Eric Forner of Cimation in a coordinated disclosure. ICS-CERT reports that Emerson has developed a patch that has been validated by the Cimation researchers.

ICS-CERT reports that there are three separate hidden functionality vulnerabilities and a hard-coded credential vulnerability. The four vulnerabilities are:

• OSE debug broadcast, CVE-2013-0693;
• OSE debug service, CVE-2013-0692;
• TFTP server, CVE-2013-0689; and
• Use of hardcoded credentials, CVE-2013-0694.

NOTE: The CVE links will be functional in the near future.

The advisory notes that each of these vulnerabilities are remotely exploitable and would allow a relatively low skilled attacker to execute arbitrary code and gain full control of the device. These are all serious vulnerabilities; the lowest CVSS v2 base score is 9.0.


Organizations with a large number of these RTUs, particularly those in distribution systems, will have a large degree of difficulty in patching all of the affected devices in a timely manner and their systems will remain vulnerable until all RTUs are patched.

Sunday, April 28, 2013

ICS-CERT Publishes Two Friday Advisories


On Friday afternoon the DHS ICS-CERT published two advisories for multiple vulnerabilities on MatrikonOPC and a single vulnerability on Galil RIO-47100. Both advisories were based upon coordinated disclosures.

NOTE: Along with a recent change in the ICS-CERT web site format, ICS-CERT has changed their Advisories (and presumably Alerts) from .PDF pages to .HTML pages. They may still be saved as .PDF files, but this should remove some of the complaints heard about ICS-CERT using an ‘inherently vulnerable’ .PDF format for their reports. I’ve even heard some really paranoid individuals complain that ICS-CERT was using the .PDF reports to spread spyware.

MatrikonOPC Advisory

ICS-CERT reports that two vulnerabilities [Link added 4-28-13 07:05 CDT] were reported by Dillon Beresford of Cimation. The vulnerabilities are:

• Path traversal, CVE-2013-0673; and
• Error handling, CVE-2013-0666

(NOTE: CVE links will not be active for a couple of days) [4-28-13 07:05 CDT]

ICS-CERT notes that a relatively low skilled attacker could remotely exploit these vulnerabilities to gain access to system files or crash the configuration utility. They also note that the system must be accessible via the internet for the remote exploitation to be possible.

MatrikonOPC has produced patches that have been verified by Dillon to mitigate the vulnerabilities. The link to the patch page in the advisory does not work [NOTE: As of 04:00 CDT 4-29-13, this has been corrected]. Use this link (http://www.opcsupport.com/ics/support/default.asp?deptID=4590) to the product advisory page instead. Click on the appropriate product and use the instructions on the product page to download the patch.

Galil Advisory

ICS-CERT reports an input validation vulnerability [link added 4-28-13 07:05 CDT] in the Galil RIO-47100 PLC that was reported by Jon Christmas of Solera Networks.

ICS-CERT notes that a moderately skilled attacker could remotely exploit this vulnerability to execute a DoS attack.

A firmware update is available at http://www.galilmc.com/support/firmware-downloads.php and Christmas confirms that it resolves the identified vulnerability. The link in the advisory is good, but it takes you through a ‘You are leaving ICS-CERT’ page which I have always found to be annoying and more than a little mindless. Interestingly the Firmware Release Notes page also explains that the latest release fixes a buffer overflow issue not mentioned in the ICS-CERT advisory.

New Format

As I mentioned earlier, ICS-CERT has changed the format for their Advisories and Alerts. They have gone back and updated earlier alerts (at least through the Clorius Controls Alert from April 1st. Along with changing from a .PDF to .HTML file format, they have significantly modified the typography and slightly modified the lay out. In my opinion (FWIW) the changes have detracted from the readability of the documents. This is especially true when the document is saved in a .PDF format.

The change in format also removes two fixtures of the reports. The recently added ‘Traffic Light Protocol’ (TLP) markings have been removed from the documents; a good move in my opinion. The product warranty box at the bottom of the first page of the old format has also been removed. This was one of those legal disclaimer things that we are seeing in too many areas of our public lives and the world would be a better place without them.

Sunday, July 24, 2011

ICS-CERT Publishes Saturday Alert for Siemens PLCs

Yesterday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published an alert for the Siemens S7-300 and S7-400 PLC’s. There is not much information in the alert (which is not unusual, if more information was available and or ICS-CERT was able to confirm the details it would have been published as an ‘advisory’). The core information of the alert is found in two sentences:

“On July 23, 2011 an independent security researcher publicly announced a vulnerability affecting the Siemens S7-300 and S7-400 PLCs. The researcher claims that he was able to achieve a command shell using credentials he was able to acquire from the PLC.”
As of the publication of the alert yesterday, no body was officially confirming or denying the existence of the reported vulnerability. This isn’t surprising with the underlying information being made public on Saturday.

It looks like the disclosure was made in a TWEET® by Dillon Beresford on Saturday. He posted:

“All S7-300/400s contain a hard coded password as I suspected, I decrypted the firmware image and located the password. We have a shell! WEWT”
It’s not clear yet if this ‘hard coded’ credential (its hard to accept the concept of a hard wired ‘password’) is a substantial part of the security measures that Siemens recently claimed protected these two PLC series from Stuxing. If it is, Siemens severely underestimated the ability and determination of security researchers (of both hat colors).

It will be interesting to see how Siemens deals with this tomorrow.
 
/* Use this with templates/template-twocol.html */