Showing posts with label Dmitry Sklyarov. Show all posts
Showing posts with label Dmitry Sklyarov. Show all posts

Saturday, March 7, 2020

Public ICS Disclosure – Week of 2-29-20


This week we have lots of new ‘information’ on SweynTooth vulnerabilities and three vendor disclosures for products from Rockwell, Phoenix Contact and Moxa.

SweynTooth


In addition to the CISA alert for the SweynTooth  Bluetooth vulnerabilities published this week there was an advisory from the FDA and brief disclosures from the following medical device vendors:

Medtronic;
BD; and
Drager

Rockwell Advisory


Rockwell published an advisory describing four vulnerabilities in their MicroLogix Controllers and RSLogix 500 Software. The vulnerabilities were reported by Ilya Karpov, Evgeny Druzhinin from ScadaX Security and Dmitry Sklyarov from Positive Technologies. Rockwell has new versions for some products that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Use of hard-coded cryptographic key - CVE-2020-6990;
• Use of broken or risky algorithm for password protection - CVE-2020-6984;
• Use of client-side authentication - CVE-2020-6988; and
• Unsecured SMTP data storage - CVE-2020-6980

Phoenix Contact Advisory


Phoenix Contact published an advisory [.PDF download link] describing three vulnerabilities in their  TC ROUTER & TC CLOUD CLIENT devices. The vulnerabilities were reported by Thomas Weber, SEC Consult Vulnerability Lab. Phoenix Contact has new firmware that mitigates the vulnerability. There is no indication that Weber was provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Improper control of generation of code - CVE-2017-16544;
• Command injection - CVE-2020-9436; and
• Hard-coded certificate - CVE-2020-9435

NOTE: the first vulnerability is an old library problem that has lots of exploits available.

Moxa Advisory


Moxa published an advisory describing an improper authentication vulnerability in their MGate MB3180/MB3280/MB3480/MB3170/MB3270 Series Protocol Gateways. This is a self-reported vulnerability. Moxa has new firmware versions available that mitigate the vulnerability.

Saturday, January 12, 2019

ICS Public Disclosures – Week of 01-05-19


This week we have five new vendor disclosures and seven vendor updates, all for products from Siemens.

EN100 Ethernet Advisory


Siemens published an advisory for their EN100 Ethernet communication module for SWT 3000 describing two denial of service vulnerabilities. The vulnerabilities were reported by Victor Nikitin, Vladislav Suchkov, and Ilya Karpov from ScadaX. Siemens has identified a workaround that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

SICAM A8000 Advisory


Siemens published an advisory for their SICAM A8000 RTU series describing an denial of service vulnerability. The vulnerability was reported by Emanuel Duss and Nicolas Heiniger from Compass Security. Siemens has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

CP1604 and CP1616 Advisory


Siemens published an advisory for their CP1604 and CP1616 devices describing a denial of service vulnerability. The vulnerability is self-reported. Siemens has new versions that mitigate the vulnerability.

SIMATIC S7-300 Advisory


Siemens published an advisory for their SIMATIC S7-300 CPU describing a denial of service vulnerability. The vulnerability was reported by the Electronic Technology Information Research Institute. Siemens has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

S7-1500 Advisory


Siemens published an advisory for their S7-1500 CPU describing two denial of service vulnerabilities. The vulnerabilities were reported by Georgy Zaytsev, Dmitry Sklyarov, Druzhinin Evgeny, Ilya Karpov, and Maxim Goryachy from Positive Technologies. Siemens has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Siemens Updates


As part of the swath of 12 advisories and updates issued by Siemens this week there was one update that was not covered by NCCIC-ICS updates. This was for vulnerabilities addressed in ICS-CERT generic alerts; NCCIC-ICS does not update these alerts for new information from the existing vendor list on the alert, the links on those alerts already take interested parties to this latest information.

SSB-439005: v 1.2 - Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP - Added CVE-2018-19931 and CVE-2018-19932;

There were six additional updates that I suspect that NCCIC-ICS could still pick-up in the coming week.

SSA-592007: v 1.3 - Denial-of-Service Vulnerability in Industrial Products – NCCIC-ICS published their latest update (ICSA-18-079-02A) on October 9th, 2018 - Added update for SIMATIC S7-300 incl. F and T;
SSA-535640: v 1.3 - Vulnerability in Industrial Products – NCCIC-ICS published their latest update (ICSA-17-243-01B) on November 30th, 2017 - Added fix for SIMATIC NET PC Software;
SSA-348629: v 1.7 - Denial-of-Service Vulnerability in SIMATIC PCS 7, SIMATIC WinCC, SIMATIC WinCC Runtime Professional and SIMATIC NET PC Software - NCCIC-ICS published their latest update (ICSA-18-088-03E) on December 13th, 2018 - Updated patch links for WinCC 7.2 and 7.4;
SSA-346262: v 2.1 - Denial-of-Service in Industrial Products - NCCIC-ICS published their latest update (ICSA-17-339-01J) on December 12th, 2018 - Updated solution for SIMATIC S7-300;4
SSA-293562: v 2.6 - Vulnerabilities in Industrial Products - NCCIC-ICS published their latest update (ICSA-17-129-02N) on December 12th, 2018 - Updated information for CP 1243-1; and
SSA-181018: v 1.3 - Heap Overflow Vulnerability in SCALANCE X switches, RUGGEDCOM WiMAX, RFID 181-EIP, and SIMATIC RF182C - NCCIC-ICS published their original advisory (ICSA18-165-01) on June 13th, 2018 - Added solution for RUGGEDCOM WiMAX

Thursday, February 19, 2015

ICS-CERT Publishes Another Siemens Advisory

This morning the DHS ICS-CERT published another advisory for twin vulnerabilities in the Siemens SIMATIC STEP 7 TIA Portal. Each advisory was separately discovered by Quarkslab team and Dmitry Sklyarov with PT-Security. Siemens has produced a patch to mitigate the vulnerabilities, but there is no indication that either research team has been given the opportunity to verify the efficacy of the patch.


The two vulnerabilities are:

● Man-in-the Middle vulnerability - CVE-2015-1601; and
● Use of password with insufficient computational effort - CVE-2015-1602

ICS-CERT reports that it would be moderately difficult to construct a workable exploit for these two vulnerabilities. Siemens reports that access to the network path between client and server would be required for the first vulnerability and access to TIA project files would be required for the second.

Why Siemens

At some point we have to wonder why we are seeing so many Siemens advisories. In many cases (but certainly not even most) the answer is self-reporting and that is a mark of a current commitment to security. But sooooo many vulnerabilities, surely that is the sign of a basic problem?

Yes, there were certainly problems with the way that most of these programs were originally written. The mistakes we are seeing seem so basic now, but that is because we have been seeing them throughout the industry for the last few years. Siemens is not paying for the mistakes that they and most of the rest of the industry made back when security was a ‘non-issue’ because control systems were air gapped and so hard to understand.

Siemens is now facing much the same problem that Micrsoft faced twenty years ago. Because of their size, familiarity and availability, researchers around the world are taking a hard look at Siemens products, knowing that they are going to find vulnerabilities. It many not be quite shooting fish in a barrel, but it is certainly fishing in a freshly stocked pond.

Many of these researchers are going to start to move on to the other suppliers in the field using the skills they honed on working on Siemens gear. There will be more advisories for other vendors and people will laugh at how easy they were to find; unless the other vendors internalize the searches and fix them before the researchers find them.


And the Siemens advisories will continue. Siemens makes ever more complex products; with more and more capabilities. Mistakes will be made. More importantly researchers (of whatever hat color) are also getting more and more sophisticated. They will find new types of vulnerabilities that we have not even thought about yet. Security designers and researchers will continue to be locked in a war of improving capabilities. And we users; we will be better for it.
 
/* Use this with templates/template-twocol.html */