Showing posts with label Ecava IntegraXor. Show all posts
Showing posts with label Ecava IntegraXor. Show all posts

Monday, June 6, 2011

ICS-CERT Updates Two Separate Advisories

Recently (last Friday and today) the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) updated two previously issued control system advisories. These updates covered the DLL Hijacking vulnerability in the Ecava IntegraXor system and the multiple denial of service (DOS) vulnerabilities in the 7-Tecnologies IGSS system.

Ecava IntegraXor

The original vulnerability advisory was published on May 27th. There was apparently an update published the same day with a revised link for the patch provided by Ecava, but I cannot find anywhere on the ICS-CERT site where it was actually published. This second revision (‘B’ Version) corrects the impression left by earlier versions that this vulnerability could only be accessed locally. It also provides yet another link for the patch that is available to correct this vulnerability

7 Technologies IGSS

The original advisory was published on May 12th. This update reports that both ICS-CERT and Joel Langill (the researcher that identified the vulnerabilities) have validated the patches provided by 7 Technologies. It also updates the list of affected versions of the software. It also provides updated patch information since it is now apparent that each of the affected versions requires a slightly different patch.

Monday, May 30, 2011

ICS-CERT Publishes 2 Advisories for Ecava IntegraXor

On Friday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published two separate advisories for vulnerabilities in the Ecava IntegraXor system. The vulnerabilities would allow DLL hijacking and cross site scripting. Both vulnerabilities would allow execution of arbitrary code by an attacker with moderate skill levels. The first would require the attacker to have access to the computer’s file system and the second would require the operator viewing an infected web site.

There are no known exploits publicly available for either vulnerability and Ecava has developed a single patch to mitigate both vulnerabilities.

Wednesday, December 29, 2010

DHS Addresses Two Ecava IntegraXor Vulnerabilities

Yesterday evening the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) took the unusual action of publishing two documents on vulnerabilities in the same SCADA system, the Ecava IntegraXor. The first is a follow-up to an earlier Alert and the second is a new alert about a newly reported vulnerability.

Directory Traversal Vulnerability

Last week ICS-CERT published an alert about a directory traversal vulnerability in the Ecava IntegraXor Human Machine Interface (HMI). At the time of the alert there were no specific mitigation measures available to respond to the vulnerability. Yesterday ICS-CERT published an Advisory on this vulnerability providing newly released information on a patch (along with a point of contact for additional support information) made available by Ecava Sdn Bhd, the Malaysia-based software development company that provides the IntegraXor product.

Additionally ICS-CERT makes their routine recommendation to “Minimize network exposure for all control system devices. Critical devices should not directly face the Internet. Control system networks and remote devices should be located behind firewalls and be isolated from the business network. If remote access is required, secure methods such as Virtual Private Networks (VPNs) should be used.” They also provided their standard risk assessment caveat for both this standard mitigation technique and the patch.

ICS-CERT notes that this vulnerability would allow an attacker with a low skill level to add an arbitrary path and files to the system and to read any file within the system. The vulnerability is exploitable using publicly available tools from a remote system.

DLL Hijacking Vulnerability

DHS published an Alert on a second vulnerability, this one dealing with a susceptibility to DLL hijacking attacks. The Alert reports that there are tools publicly available to exploit this vulnerability and that ICS-CERT is working with the Ecava on mitigation options. When more information becomes available, ICS-CERT will issue the appropriate advisories.

Thursday, December 16, 2010

DHS ICS-CERT Issues Ecava IntegraXor Advisory

Yesterday afternoon the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) issued an advisory about a buffer overflow vulnerability for the Ecava IntegraXor Human-Machine Interface (HMI). The vulnerability was discovered by Jeremy Brown, an independent security researcher and has been addressed by Ecava, who has released a patch to mitigate the vulnerability.

ICS-CERT notes that this stack based buffer overflow could allow an attacker with an intermediate skill level to remotely exploit the vulnerability, allowing the execution of arbitrary code. There is currently no known exploit published for this vulnerability.

ICS-CERT recommends the following mitigation measures after conducting a proper impact analysis and risk assessment:

• Update IntegraXor to the latest version and install the latest patch. For more information, customers can contact Ecava support at support@integraxor.com.
• Minimize network exposure for all control system devices. Critical devices should not directly face the Internet. Control system networks and remote devices should be located behind firewalls, and be isolated from the business network. If remote access is required, secure methods such as Virtual Private Networks (VPNs) should be utilized.
 
/* Use this with templates/template-twocol.html */