Showing posts with label Ecava. Show all posts
Showing posts with label Ecava. Show all posts

Saturday, March 12, 2022

Review – Public ICS Disclosures – Week of 3-5-22 – Part 1

It has been a busy week, even without the 2nd Tuesday disclosures. This will be a three-part report. This week we have thirteen vendor disclosures from Boston Scientific, Broadcom, Carestream, WAGO, Draeger, Eaton (4), GE Gas Power, Genetec, Hitachi Energy, and Johnson Controls.

Boston Scientific Advisory - Boston Scientific published an advisory discussing the Access:7 vulnerabilities.

Broadcom Advisory - Broadcom published an advisory discussing the DirtyPipe vulnerability.

Carestream Advisory - Carestream published an advisory discussing the Access:7 vulnerabilities.

Ecava Advisory - Incibe CERT published an advisory discussing eight vulnerabilities in the Ecava IntegraXor.

WAGO Advisory - VDE CERT published an advisory describing a cross-site scripting vulnerability in various WAGO PLCs.

Draeger Advisory - Draeger published an advisory discussing the PwnKit vulnerability.

Eaton Advisory #1 - Eaton published an advisory describing a cross-site scripting vulnerability in their Intelligent Power Manager.

Eaton Advisory #2 - Eaton published an advisory describing a cross-site scripting vulnerability in their Intelligent Power Manager.

Eaton Advisory #3 - Eaton published an advisory describing a cross-site scripting vulnerability int heir Intelligent Power Manager.

Eaton Advisory #4 - Eaton published an advisory describing a cross-site scripting vulnerability int heir Intelligent Power Manager.

GE Gas Power Advisory - GE Gas Power published an advisory discussing the Russia-Ukraine situation.

Genetec Advisory - Genetec published an advisory describing a privilege escalation vulnerability in the Authentication Service role in their Security Center product.

Hitachi Energy Advisory - Hitachi Energy published an advisory describing seven vulnerabilities (two with published exploits) in their RelCare product.

Johnsons Controls Advisory - Johnson Controls published an advisory discussing a deserialization of untrusted data vulnerability in their DSC PowerManage product.

 

For more details on these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3 - subscription required.

Tuesday, December 19, 2017

ICS-CERT Publishes 5 Advisories and 2 Updates

Today the DHS ICS-CERT published control system security advisories for products from WECON, Siemens, Ecava, PEPPERL+FUCHS and ABB. They also published updates for two previous published advisories for products from Siemens.

WECON Advisory


This advisory describes a heap-based buffer overflow in the WECON LeviStudio HMI. The vulnerability was reported by Michael DePlante working with the Zero Day Initiative (ZDI). WECON notes that the current version mitigates the vulnerability. There is no indication that DePlante was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to crash the device and a buffer overflow condition may allow remote code execution.

Siemens Advisory


This advisory describes a download of code without integrity check vulnerability in the Siemens LOGO! Soft Comfort engineering software product. The vulnerability was reported by Tobias Gebhardt. Siemens is providing SHA-256 checksums for all LOGO! Soft Comfort software packages via a secured HTTPS channel.

ICS-CERT reports that an uncharacterized attacker could remotely exploit the vulnerability to manipulate a software package during download. The Siemens security advisory reports that a successful exploitation would require that the attacker must be able to gain a privileged network position allowing him to capture and modify the affected system’s network communication.

Ecava Advisory


This advisory describes two SQL injection vulnerabilities in the Ecava IntegraXor. The vulnerabilities were independently reported by Steven Seeley of Source Incite, and Michael DePlante and Brad Taylor (working with ZDI). Ecava reports that a newer version mitigates the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to disclose sensitive information from the database or generate an error in the database log.

PEPPERL+FUCHS Advisory


This advisory describes the key reinstallation attacks (KRACK) vulnerabilities in various WLAN enabled products from PEPPERL+FUCHS. This report lists 9 of the 10 KRACK CVE’s. The vendor is still working on fixes for their Android® based products. For their Windows® based products they are recommending that users apply the security update provided by Microsoft. If users are using WPA-TKIP in their WLAN, users should switch to AES-CCMP immediately.

ABB Advisory


This advisory describes an unprotected transport of credentials vulnerability in the ABB Ellipse. ICS-CERT reports that this vulnerability was self-reported by ABB, but the ABB security advisory notes that ABB had received information about this vulnerability through responsible disclosure from an unnamed researcher. ABB has released product updates to mitigate the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to discover authentication credentials by sniffing the network traffic. ABB notes that local network access is required for the exploit.

NOTE: I reported on this vulnerability earlier this month.

Industrial Products Update


This update provides additional information on an advisory that was originally published on December 5th, 2017. It provides updated affected version information and mitigation information for:

• SIMATIC S7-400 H V6: All versions prior to V6.0.8,
• SIMATIC S7-1500: All versions prior to V2.0,
• SIMATIC S7-1500 Software Controller: All versions prior to V2.0,

SCALANCE Update


This update provides additional information on an advisory that was originally published on November 14th, 2017 and updated on December 5th, 2017. It provides updated affected version information and mitigation information for:

• RUGGEDCOM RX1400 with WLAN interface: All versions prior to V2.11.2
• SIMATIC RF350M: All versions with Summit Client Utility prior to V22.3.5.16
• SIMATIC RF650M: All versions with Summit Client Utility prior to V22.3.5.16.


Note: Siemens has issued a separate security advisory for the last two products listed above. That advisory only lists two of the 10 KRACK CVEs instead of the 10 listed in the original Siemens KRACK advisory. It is not clear why ICS-CERT merged these two advisories.

Wednesday, June 21, 2017

ICS-CERT Publishes New Advisory and Updates 2 Siemens Advisories

Yesterday the DHS ICS-CERT published a new control system security advisory for a product from Ecava. They also update two previously published advisories for products from Siemens.

Ecava Advisory


This advisory describes an SQL injection vulnerability in the Ecava IntegraXor. The vulnerability was reported by Tenable Security. Ecava has produced a new version that mitigates the vulnerability. ICS-CERT reports that Tenable has verified the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to effect unauthenticated remote code execution.

PROFINET Update


This update provides additional information on an advisory originally published on May 9th, 2017 and updated on June 15th, 2017. This update provides new affected version data and links to updates for Primary Setup Tool (PST): All versions prior to  V4.2 HF1.

Interestingly, this information on the PST was made available in the same updated version of the Siemens Advisory published on June 13th that was used for the previous ICS-CERT update. A close comparison of the original Siemens Advisory and the June 13th versions shows that there was an additional product that was updated, but also not mentioned in the earlier ICS-CERT update or in this update; the Security Configuration Tool (SCT): All versions < V5.0.

Industrial Products Update


This update provides additional information on an advisory originally issued on November 8, 2016 and then updated November 22nd, 2016; December 23rd, 2016; February 14th, 2017; March 2nd, 2017 and May 9th, 2017. This update provides the same new information as the ICS-CERT updated described above. Interestingly (and kudos to ICS-CERT for really prompt reporting), Siemens published their updated Security Advisory just yesterday morning (ICS-CERT time).


NOTE: Siemens also announced (via TWITTER®; @ProductCERT ) yesterday that they had published a new security advisory (SSA-126840) and updated another advisory (SSA-275839)with the same SCT information noted above. I expect that we will see those reflected on the ICS-CERT site today or tomorrow.

Tuesday, January 31, 2017

ICS-CERT Publishes Two Advisories and Updates Another

Today the DHS ICS-CERT published two control system security advisories for products from Ecava and BINOM3. They also updated a previously published advisory for products from Moxa; that advisory was originally published on October 13th, 2016.

Ecava Advisory


This advisory describes an SQL injection vulnerability in the Ecava IntegraXor. The vulnerability was reported by Brian Gorenc and Juan Pablo Lopez via the Zero Day Initiative. Ecava has produced a software update to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability. That exploit could lead to arbitrary data leakage, data manipulation, and remote code execution.

BINOM3 Advisory


This advisory describes multiple vulnerabilities in the BINOM3 Electric Power Quality Meter. The vulnerability was reported by Karn Ganeshen. ICS-CERT reports that BINOM3 has not provided any mitigation measures for these vulnerabilities.

The reported vulnerabilities are:

• Cross-site scripting - CVE-2017-5164;
• Improper access control - CVE-2017-5162;
• Cross-site request forgery - CVE-2017-5165;
• Information exposure - CVE-2017-516; and
• Hard-coded password - CVE-2017-5167.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities. Such an exploit could cause the device to inaccurately report a range of electrical quality measurements.

Format Update


Just a quick note that ICS-CERT has made another modification to their new advisory format. They have added a new section; Background. It provides information about the vulnerable device/application including affected sectors, where the device/application is used, and where the vendor is located.

Moxa Update


This update provides new information, including:

• Notification that the vulnerabilities also affect the ioLogik E2200 series devices;
• Provides affected version information for the ioLogik E2200 series devices; and
• Links for downloads of the firmware updates for the ioLogik E2200 series devices.


Thursday, April 14, 2016

ICS-CERT Publishes 3 Advisories

This morning the DHS ICS-CERT published three control system advisories for systems from Ecava, Accuenergy, and Sierra Wireless.

Ecava Advisory

This advisory describes multiple vulnerabilities in the Ecava IntegraXor application. The vulnerabilities were independently reported by Steven Seeley of Source Incite and Marcus Richerson. Ecava has produced a new version to mitigate the vulnerabilities. Richerson has tested the new version and verified that it fixed all but one (partially fixed) of the vulnerabilities; Ecava will address that in their next release.

The eight vulnerabilities include:

• Clear text transmission of sensitive information - CVE-2016-2306;
• Cross-site scripting - CVE-2016-2305;
• Improper neutralization of alternate XSS syntax - CVE-2016-2304;
• Improper authorization - CVE-2016-2300;
• SQL injection (2) - CVE-2016-2299 and CVE-2016-2301;
• Information exposure - CVE-2016-2302; and
• Improper neutralization of CLRF sequences in HTTP headers - CVE-2016-2303

ICS-CERT reports that a relatively unskilled attacker could remotely use publicly available exploits to gain complete control of the system.

The Ecava vulnerability note does not mention that one of the vulnerabilities is only partially corrected. Nor does it mention the role of Steven Seeley.

NOTE: There is a minor error in the ICS-CERT advisory. The print version of the link has an incorrect version number (5.0.4522.2 instead of 5.0.4525.2), but the actual link goes to the correct place.

Accuenergy Advisory

This advisory describes twin vulnerabilities in the Accuenergy Acuvim II Series AXM-NET module. The vulnerabilities were reported by Maxim Rupp. Accuenergy has developed suggested user mitigations and there is no indication that a fix is planned for the vulnerabilities.

The vulnerabilities are:

• Authentication bypass issues - CVE-2016-2293; and
• Plain text storage of passwords - CVE-2016-2294

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to execute a denial of service attack on the meter.

The Accuenergy suggested mitigations are very broadly painted instructions designed to deny unauthorized access to the meter. They include the use of firewalls, authentication, and VPN use. No specific information for the use of these techniques with this equipment is provided.

Sierra Wireless Advisory

This advisory describes a file and directory information exposure vulnerability in the Sierra Wireless ACEmanager application. The vulnerability was reported by Maxim Rupp. Sierra Wireless has produced a new version that mitigates the vulnerability, but there is no indication that Rupp has been provided the opportunity to verify the efficacy of the fix.


ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to  learn operational characteristics of the gateway.

Tuesday, March 31, 2015

ICS-CERT Publishes 3 Advisories and an Update

Today the DHS ICS-CERT published three new advisories for control systems from Hospira, Ecava and Inductive Automation and an update for a recently released advisory for Schneider Electric.

Schneider Update

This update is for the Schneider advisory released last week for the InduSoft WebStudio and InTouch Machine applications. The update provides a link to additional information about the vulnerabilities, but it is only available to registered Wonderware customers, external partners or distributors.

Hospira Advisory

This advisory describes multiple vulnerabilities in the Hospira MedNet server software. The vulnerabilities were reported by Billy Rios. Hospira has produced a new version of the software and provided additional mitigation measures, but there is no indication that Billy has been given the opportunity to verify the efficacy of the fix.

The four vulnerabilities are:

∙ Password in configuration file - CVE-2014-5400;
∙ Improper control of generation code - CVE-2014-5401;
∙ Hard-coded cryptographic key - CVE-2014-5403; and
∙ Hard-coded password - CVE-2014-5405

ICS-CERT reports that a relatively low skilled attacker could remotely exploit three of the vulnerabilities; the pass in configuration file vulnerability is locally exploitable.

ICS-CERT explains that the new version of the MedNet server software addresses three of the vulnerabilities. The fourth vulnerability (improper control of generation of code) is found in “the vulnerable version of JBoss Enterprise Application Platform [link added] software, used in the MedNet software”. There is no indication which version of the EAP software is involved. MedNet has issued two reports (Improving Security in Hospira MedNet 5.5 and 5.8) discussing mitigation methods for this vulnerability. They are reportedly available from MedNet technical support.

NOTE: It goes without saying that vendors that use JBoss EAP should contact RedHat for details about this vulnerability. It will be interesting to see how long it is before this shows up in other ICS application advisories.

Ecava Advisory

This advisory describes a DLL loading vulnerability on the Ecava  IntegraXor SCADA Server. The vulnerability was reported by Praveen Darshanam. Ecava has produced a patch that mitigates the vulnerability and Darshanam has verified the efficacy of the patch.

ICS-CERT reports that a social engineering attack is required to get an authorized user to load a compromised DLL. A successful attack could result in the ability to run malicious code at the authorization level of the DLL.

Inductive Automation Advisory

This advisory describes multiple vulnerabilities in the Inductive Automation Ignition software (HMI/SCADA). The vulnerabilities were reported by Evgeny Druzhinin, Alexey Osipov, Ilya Karpov, and Gleb Gritsai of Positive Technologies. Inductive Automation has produced a patch that mitigates the vulnerability but there is no indication that the researchers have been given an opportunity to verify the efficacy of the fix.

The six vulnerabilities are:

∙ Cross-site scripting - CVE-2015-0976;
∙ Information exposure through error message - CVE-2015-0991;
∙ Insecure storage of sensitive information - CVE-2015-0992;
∙ Insufficient session expiration - CVE-2015-0993;
∙ Credentials management - CVE-2015-0994; and
∙ Use of password hash with insufficient computational effort - CVE-2015-0995


ICS-CERT explains that a relatively low skilled attacker can only locally exploit these vulnerabilities, though they earlier report that the vulnerabilities are remotely exploitable (which sounds more reasonable). The advisory does not describe potential consequences, but it would seem that a successful exploit should allow running of arbitrary code.

Thursday, September 11, 2014

ICS-CERT Publishes Two Advisories; Ecava and Schneider

Today the DHS ICS-CERT published to control system security advisories for systems from Ecava and Schneider. Both advisories are based upon coordinated disclosures.

Ecava Advisory

This advisory addresses multiple vulnerabilities in the IntegraXor SCADA Server. An Improper Privilege Management vulnerability was reported by Andrea Micalizzi and three other vulnerabilities were identified by Alain Homewood. Alain has verified the efficacy of the patch produced by Ecava to resolve the vulnerabilities that he identified. No information was provided on the efficacy of the fix for resolving the vulnerability identified by Andrea.

The four vulnerabilities identified in this system are:

● External control of file name or path, CVE-2014-2375;
● SQL injection, CVE-2014-2376;
● Sensitive information disclosure, CVE-2014-2377; and
● Improper privilege management, CVE-2014-2386.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities.

NOTE: This advisory was originally released to the US-CERT secure portal on August 12th. This was the advisory that I had referred to earlier. Readers that had access to the secure portal would have already known about this vulnerability.

Schneider Advisory

This advisory address a buffer overflow vulnerability (been a while since we’ve seen one of those) in the VAMPSET software reported by Aivar Liimets of Martem AS. Schneider has produced an update that according to Aivar mitigates the vulnerability.


ICS-CERT reports that direct access to the relay is required for a successful attack. Schneider provides a more detailed description of the way the vulnerability works in their report on the vulnerability. That report also describes additional mitigation measures that can be taken by the system owner/operator.

Tuesday, April 29, 2014

ICS-CERT Publishes 2 HeartBleed Updates and an Advisory

This afternoon the DHS ICS-CERT published updates on a Siemens HeartBleed Advisory, an update of their SA Alert on HeartBleed and one new advisory for an Ecava information disclosure vulnerability.

HeartBleed Updates

My followers on TWITTER® already heard about the Siemens update last Friday morning when Siemens @ProductCert tweeted about the publication of their updated HeartBleed advisory that included notification that their WinCC product now has an update available to fix the HeartBleed bug in that system.

ICS-CERT published their late update of the HeartBleed advisory that they issued on April 15th. The ICS-CERT Situational Awareness Alert was updated to show the new Siemens status. It also adds two new affected industrial control system notifications, one for ABB (Relion 650 series Ver. 1.3.0) and one for Digi (ConnectPort LTS, ConnectPort X2e, Digi Embedded Linux, and Wireless Vehicle Bus Adapter). Separate advisories are in the works. The links above are for the vendor notices.

The ABB mitigation measures are still under development and the Digi updates may already be available (the document was published on 4-18-14 with an availability date for the fix of 4-21-14). Digi is making the remote update service for remote devices available free of charge for 30 days.

ICS-CERT also added a list of Digi devices to the list of unaffected ICS services. This was also found on the Digi web site link identified above.

Ecava Advisory

This advisory reports on an information disclosure vulnerability on the Ecava IntegraXOR product that was reported by Andrea Micalizzi, aka rgod, in a coordinated disclosure via the Zero Day Initiative. Ecava has produced a new version that mitigates the vulnerability, but there is no indication in the advisory that Micalizzi has verified the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to obtain clear text administrative credentials and own the system.


The Ecava vulnerability note provides additional mitigation measures that can be employed to mitigate the vulnerability until the patch is put into place. They note that since the complete project URL is need to exploit this vulnerability, owner/operators should avoid publication of the full URL. They also recommend avoiding the use of the default port number.

Thursday, January 16, 2014

ICS-CERT Publishes Advisory for Yesterday’s Ecava Alert

Today, in what is probably record time, ICS-CERT published an advisory for the Ecava IntegraXor buffer overflow vulnerability that was reported yesterday in an ICS-CERT alert. The vulnerability was reported yesterday by Luigi at the S4x14 security conference in Miami. Would that all vulnerabilities could be resolved this quickly

ICS-CERT notes that the vulnerability can be remotely exploited by a relatively unskilled attacker using publicly available exploit code. A successful exploit could result in a denial of service.

ICS-CERT reported that Ecava confirmed the existence of the vulnerability and developed a patch for the problem which is now available on-line. Additionally Ecava published a vulnerability notice describing the problem and proposing some additional mitigation measures that can be used to deal with the situation. There is no indication that Luigi has had a chance to verify the efficacy of the mitigation measures/ It is understandable that the Ecava management wants to get this problem addressed as quick as possible since the exploit code is publicly available.

Specifically Ecava notes that to successfully exploit this vulnerability one need the complete project URL. They suggest that users of this system take care not to publish the full URL of projects. They also suggest that system operators not use the default port with the system.


Ecava is to be commended on their quick response to this issue.

Wednesday, January 15, 2014

ICS-CERT Publishes First S4x14 Alert

Dale must be proud (grin); this evening DHS ICS-CERT published their first alert for a vulnerability disclosure from Digital Bond’s S4 conference in Miami. Appropriately enough the vulnerability was disclosed by Luigi, the first since Luigi and his partner Donato formed ReVuln.com.

According to the alert Luigi disclosed a buffer overflow vulnerability in the Ecava IntegraXor SCADA/HMI interface. As with past Luigi disclosures this was accompanied by proof-of-concept code.

I think that this is the same disclosure that Dale Tweeted about this afternoon:

@digitalbond - Luigi & Donato demoing ICS vuln and there fix to it, without any vendor involvement, #S4x14

A buffer overflow vulnerability is hardly worth mentioning at a conference like S4x14. The big news was apparently that Luigi and company had discovered a way to fix the vulnerability without getting the vendor involved. This would certainly be good news for Luigi’s system owner clients; they could get their systems fixed before anyone else, including the vendor, was made aware of the vulnerability.


While some vendors are working hard at establishing a reputation for quickly responding to vulnerability disclosures, most still have a long way to go (for example we are still waiting for a piss pot load of Crain-Sistrunk vulnerability disclosures by the vendors for vulnerabilities identified last summer).

Wednesday, January 8, 2014

ICS-CERT Publishes Ecava Advisory

This afternoon the DHS ICS-CERT issued an advisory for an unauthorized file access vulnerability in the Ecava Sdn Bhd IntegraXor application. The vulnerability was reported by an independent researcher “Alphazorx aka technically.screwed” (you gotta love these handles) as a coordinated disclosure through ZDI. Ecava has produced an update to resolve the issue but it has not been validated by the researcher (more on that later).

ICS-CERT reports that the vulnerability can be remotely exploited by a relatively low skilled attacker. Successful exploitation could result in the attack gaining access to project directory files for the SCADA system.

Normally we do not see any information why a patch or update efficacy has not been validated by the discovering researcher. In this case Ecava has provided a brief explanation with their report on this vulnerability. They were notified by ICS-CERT about the vulnerability on November 7th and had a published fix ready on November 11th. Apparently they waited until December 20th for an acknowledgement of the efficacy of their fix (after being advised to proceed without it by DHS on December 5th) then the publicly announced the vulnerability.

There is no word why ICS-CERT waited almost 20 days to publish this advisory. I would like to think that it was to allow the system owners who were (presumably) contacted on the 20th to get the fix installed. If that was the reason it would have been smart for ICS-CERT to make a comment to that effect in the advisory. It would have made them look more responsive. That probably wasn’t the reason though as ZDI published their advisory (ZDI-13-277) on December 15th so the vulnerability was in the public domain for almost a month before ICS-CERT published this advisory.


NOTE: I really should add ZDI and OVDB web sites to my daily crawl. In researching this post I noted that there are two ZDI reported vulnerabilities (ZDI-13-268 and ZDI-13-270) in the ABB MicroSCADA application that have not yet been reported by ICS-CERT; both reported in November by ZDI. Both have fixes in place.

Tuesday, February 5, 2013

ICS-CERT Publishes Ecava Advisory


Today the DHS ICS-CERT published an advisory for a buffer overflow vulnerability in the Ecava IntegraXor application. The vulnerability was reported by Andrew Brooks in a coordinated disclosure.

ICS-CERT reports that a moderately skilled attacker utilizing a social engineering attack could remotely exploit this vulnerability to run arbitrary code on the system. Ecava has produced an updated version of the affected application that has been verified by Brooks to correct the vulnerability.
 
/* Use this with templates/template-twocol.html */