Showing posts with label DingXiang Dongjian Security Lab. Show all posts
Showing posts with label DingXiang Dongjian Security Lab. Show all posts

Sunday, October 18, 2020

Public ICS Disclosures – Week of 10-10-20 – Part II

We have four new vendor notifications from Schneider. We also have nine vendor updates from Schneider (6) and Siemens (3).

Schneider Advisories

Schneider published an advisory describing a credentials management vulnerability in their Modicon Ethernet Programmable Automation products. The vulnerability was reported by Yang Dong  of DingXiang Dongjian Security Lab. Schneider has new firmware versions that mitigate the vulnerabilities. There is no indication that Yang has been provided an opportunity to verify the efficacy of the fix.

Schneider published an advisory describing an insufficiently random values vulnerability in their Smartlink, PowerTag, and Wiser series gateways. The vulnerability is self-reported. Schneider has new firmware versions that mitigate the vulnerability.

Schneider has published an advisory describing three vulnerabilities in their EcoStruxure™ and SmartStruxure™ Power Monitoring & SCADA Software. The vulnerabilities were reported by Michiel Evers and Niels Pirotte. Schneider has new products and upgrades that mitigate the vulnerabilities in some of the affected systems. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Improper access control (2) - CVE-2020-7545 and CVE-2020-7547, and

• Improper neutralization of input during web page generation - CVE-2020-7546

Schneider published an advisory for the Microsoft® Netlogon vulnerability. Schneider has not yet determined how the MS patch would affect their systems.

Schneider Updates

Schneider published an update for their Ripple20 advisory that was  originally published on June 23, 2020 and most recently updated on September 1st, 2020. The new information includes adding remediation guidance for:

• VW3A3310 Altivar 61/71 Modbus TCP,

• VW3A3310D Altivar 61/71 Ethernet daisy chain,

• VW3A3316 Altivar 61/71 Ethernet IP, and

• VW3A3320 Altivar 61/71 Ethernet IP RSTP

Schneider published an update for their Urgent/11 advisory that was  originally published on August 2nd, 2019 and most recently updated on June 9th, 2020. The new information includes providing updated remediations for:

• Modicon LMC078 Controller,

• Modicon M580 Ethernet communications Modules,

• Modicon M580 IEC 61850 - BMENOP0300 (C),

• Modicon MC80 Programmable Logic Controller,

• Modicon Quantum 140 NOP Communications Module,

• PacDrive 3 Eco/Pro/Pro2 Motion Controllers,

• Pro-face HMI -GP4000H/R/E Series, GP4100 Compact Series, LT4000M Modular Series

Schneider published an update for the advisory on their Modbus Serial Driver that was originally published on August 11th, 2020. The new information includes adding a remediation note for EcoStruxure Machine Expert Basic.

Schneider published an update for the advisory on their Modicon Controllers that was originally published on May 14th, 2019 and most recently updated on August 11th, 2020. The new information includes additional remediation steps for M580 and M340.

Schneider published an update for the advisory on their SCADAPack products that was originally published on September 8th, 2020. The new information includes correcting the fix version of RemoteConnect from V2.3.2 to V2.4.2 package.

Schneider published an update for the advisory on their Modicaon Controllers that was originally published on March 16th, 2017. The new information includes updates in the following sections (a fairly major rewrite):

• Products affected,

• Vulnerability details,

• Remediation, and

• Acknowledgement

NOTE: This advisory was one of three that were included in the ICS-CERT advisory, ICSA-17-089-02. NCCIC-ICS should probably update that advisory.

Siemens Updates

Siemens published an update for their Intel CPU advisory that was originally published on February 11th, 2020 and most recently updated on July 14th, 2020. The new information includes updated solutions for:

• SIMATIC IPC427E,

• SIMATIC IPC477E, and

• SIMATIC IPC477E Pro

Siemens published an update for their GNU/Linux advisory that was originally published in 2018 and most recently updated on September 8th, 2020. The new information includes adding:

• CVE-2019-19037,

• CVE-2020-10732,

• CVE-2020-14145,

• CVE-2020-14381,

• CVE-2020-1968,

• CVE-2020-24394,

• CVE-2020-25212, and

• CVE-2020-25220

Siemens published an update for their CodeMeter advisory that was originally published on September 8th, 2020. The new information includes:

• Adding PSS CAPE Protection Simulation Platform to the list of affected product,

• Adding solution by software update for SIMATIC WinCC OA,

• Adding solution by installation of latest CodeMeter Runtime version for SIMIT, SINEC INS, and PSS CAPE

NOTE: The original Siemens advisory was included in the initial list of covered vendors in ICSA-20-203-01. NCCIC-ICS would not be expected to specifically note this updated advisory since the link provide would go to the updated version on the Siemens web site.


Saturday, June 13, 2020

Public ICS Disclosures – Week of 6-6-12


This week we have seven vendor disclosures from Schneider (3), WAGO (2), Moxa and Medtronic as well as four vendor updates for advisories from Schneider (3) and Siemens. There were three researcher reports about vulnerabilities from Siemens.

Schneider Advisories


Schneider published an advisory describing an out-of-bounds write vulnerability in their Modicon M218 Logic Controller. The vulnerability was reported by CNCERT. Schneider provides generic workarounds to mitigate the vulnerability.


Schneider published an advisory describing a use of hard-coded credentials vulnerability in their Unity Loader and OS Loader Software. The vulnerability was reported by Yang Dong of DingXiang Dongjian Security Lab. Schneider provides workarounds to mitigate the vulnerability, noting that: “Hardcoded credentials are kept for compatibility with legacy products.”


Schneider published an advisory describing a null pointer dereference vulnerability in their Modicon LMC078 Logic Controller. This vulnerability is self-reported. Schneider provides generic workarounds to mitigate the vulnerability.

NOTE: This vulnerability is in a third-party (Wind River) component (IGMP) and was introduced in a patch applied to mitigate the Urgent/11 vulnerabilities. This vulnerability should be able to be found in a large number of products. I expect that we will be seeing more of this one.

WAGO Advisories


CERT-VDE published an advisory describing an improper privilege management vulnerability in the WAGO Web Based Management products. This vulnerability was reported by CISCO Talos; the report includes proof-of-concept code. WAGO provides generic workarounds to mitigate this ‘feature’.


CERT-VDE published an advisory describing a classic buffer overflow vulnerability in the WAGO Series PFC100 and Series PFC200 PLC’s. This vulnerability was reported by BSI. WAGO has new firmware that mitigates the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

NOTE: This is the third-party (LINUX) PPP daemon vulnerability that has been previously reported in other products.

MOXA Advisory


Moxa has published an advisory describing a command injection vulnerability in their VPort 461 Series Industrial Video Servers. The vulnerability was reported by Xinjie Ma from Beijing Chaitin Future Technology Co. Moxa has a patch for this phased-out product. There is no indication that Xinjie has been provided an opportunity to verify the efficacy of the fix.

Medtronic Advisory


Medtronic has published an advisory describing the Bluetooth Impersonation Attacks (BIAS) vulnerabilities in their FA Controller and  Patient Telemetry Module products. Medtronic has not yet determined what mitigation measures it will take.

NOTE: These vulnerabilities may (probably?) affect any medical device or control system component that uses Bluetooth connectivity.

Schneider Updates


Schneider published an update for their Urgent/11 advisory that was originally published on August 2nd, 2020 and most recently updated on May 12th, 2020. The new information includes updated mitigation measures for:

 • Easergy T300 and
• Magelis HMI - HMIGTO Series, HMISCU Series,  HMIGTUX Series, and HMIGTU Series (Except Open BOX) products


Schneider published an update for their EcoStruxure™ Operator Terminal Expert advisory that was originally published on May 12th, 2020. The new information includes an update of CVE-2020-7495.


Schneider published an update for their GoAhead Web Server Vulnerability that was originally published on December 10th, 2015. The new information includes:

• A note that proof-of-concept code is publicly available,
• Updated remediation informtation.

NOTE: ICS-CERT (now NCCIC-ICS) published an advisory for this vulnerability, it will be interesting to see if they get around to updating it.

Siemens Update


Siemens published an update for their Urgent/11 advisory that was originally published on May 12th, 2020. The new information includes updated version data and mitigation measures for Siemens Power Meters Series 9810.

Researcher Reports – Siemens


CISCO Talos published three research reports (here, here and here) describing vulnerabilities in the Seiemens LOGO! Products. The reports each claim CVE# CVE-2020-7589 which was reported by Siemens (and NCCIC-ICS) earlier this week as a single missing authentication for critical function vulnerability. Each Talos report includes separate proof-of-concept code.

 
/* Use this with templates/template-twocol.html */