Showing posts with label Echelon. Show all posts
Showing posts with label Echelon. Show all posts

Saturday, July 21, 2018

Public ICS Disclosures – Week of 07-14-18


This week we have two vendor updates (Rockwell and Siemens), two coordinated disclosures with POC (Sony), and proof-of-concept code (POC) for a recently disclosed vulnerability in Echelon products. There is also an announcement about an update to a security tool from OSIsoft.

Rockwell Update


Rockwell updated their FactoryTalk® Activation Manager advisory (previous update). The new version notes that: “Cisco has released several Snort Rules [Snort Rule 38246Snort Rule 38247, Snort Rule 39910] to addressing the Flexera software vulnerability.”

NOTE 1: Since at least one other vendor (Schneider) apparently uses the same third-party software these Cisco snort rules may be more widely applicable in the control system community.

NOTE 2: This was published on Friday so there is a good chance that we will see the ICS-CERT version of this advisory updated in the coming week.

Siemens Update


Siemens published an update of their general advisory on the Spectre/Meltdown vulnerabilities. Siemens continues to expand their coverage of the newer versions of this problem; this time adding information on the Lazy FP State Restore and Spectre V1.1 vulnerabilities. While the latest version of the ICS-CERT Spectre/Meltdown alert does provide a link to this advisory, there is no mention of the newer versions of this continuing problem in that alert.

Sony Vulnerabilities


Talos Intelligence published two vulnerability reports (here and here) for coordinated disclosures of vulnerabilities in the Sony IPELA E Series Camera. According to the reports Sony has a patch available to mitigate the vulnerabilities, but there is no indication that they have had the opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Command injection - CVE-2018-3937; and
Stack-based buffer overflow - CVE-2018-3938

NOTE: This was reported Friday, so there is always a chance that ICS-CERT will report this in the coming week. They have reported on IP camera vulnerabilities before, but do not necessarily report on all such vulnerabilities.

Echelon Exploit


Maxim Rupp published proof-of-concept exploit code on TWITTER for one of the Echelon vulnerabilities reported this week by ICS-CERT. Maxim has reportedly known about this vulnerability for about a year now; no word on why he has not reported it.

OSIsoft Security Audit Tool


OSIsoft announced that they have a new version of their PI Security Audit Tools (v. 2.2.0.3) available. They note that: “This tool is a PowerShell module that performs validation checks for the machine, PI Data Archive, PI AF Server, SQL Server, and PI Vision, indicating areas where the security configuration is out of compliance with best practices, and providing actionable information to address the issue.”

Thursday, July 19, 2018

ICS-CERT Publishes 4 Advisories


Today the DHS ICS-CERT published four control system security advisories for products from Moxa, Echelon, and AVEVA(2).

Moxa Advisory


This advisory describes a resource exhaustion vulnerability in the Moxa NPort serial network interface. The vulnerability was reported by Mikael Vingaard. The latest firmware mitigates the vulnerability. There is no indication that Vingaard has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability  to send TCP SYN packages, causing a resource exhaustion condition that would cause the device to become unavailable.

Echelon Advisory


This advisory describes four vulnerabilities in the Ecelon Smart Server and i.LON products. The vulnerabilities were reported by Daniel Crowley and IBM’s X-Force Red team. Echelon has a new version that mitigates three of the vulnerabilities and provides a workaround for the fourth. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Information exposure - CVE-2018-10627;
• Authentication bypass using an alternate path or channel - CVE-2018-8859;
• Unprotected credentials - CVE-2018-8851; and
Clear text transmission of critical information - CVE-2018-885

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow for remote code execution on the device.

In Touch Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Aveva InTouch HMI. This vulnerability was reported by George Lashenko of CyberX. Aveva has updates available that mitigate the vulnerabilities. There is no indication that Lashenko has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability to remotely execute code with the same privileges as those of the InTouch View process which could lead to a compromise of the InTouch HMI.

InduSoft Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Aveva InduSoft Web Studio and InTouch Machine Edition HMIs. This vulnerability was reported by Tenable Research. Aveva has updates available that mitigate the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow remote code execution.

Sunday, June 24, 2012

ICS-CERT Updates ICS Internet Accessibility Alert


On Friday afternoon the DHS ICS-CERT updated their alert on internet accessibility of ICS systems that was originally issued in January. The original report outlined a large number of reports of ICS systems being found on the Internet through the use of SHODAN, Googel, ERIPP and other search engines. This update provides information about Internet facing ICS systems with default passwords or weak authentication.

The update starts off (pg 2) by explaining that: “ICS-CERT has recently become aware of multiple systems with default usernames and passwords that are accessible via the Internet.”

This generic claim is not much help to the general ICS community, but the Alert does note that ICS-CERT has directly contacted the owner/operators of the affected systems to let them know of their vulnerability.

There is a new vendor name included in this initial paragraph, Echelon and their i.LON series of communications devices. ICS-CERT notes that the new reports that they have received include information on “the Echelon i.LON product that is commonly deployed within ICS devices such as motors, pumps, valves, sensors, etc., which contain a default username and password”. They do note that this is not an ‘inherent vulnerability’ (read; the user should have corrected the situation during the installation process).

The alert revision goes on to remind their audience that there have been a number of ICS-CERT advisories (including: ClearSCADA, Siemens Simatic, and RuggedCom) about systems with weak authentication mechanisms. They do not specifically mention that any of these systems that have been reported to be Internet facing, but given the current state of ICS security it would seem inevitable that there would be a number of these systems that are relying solely on their weak authentication systems for Internet protection.

Nothing has changed in the sections of this Alert that deal with mitigation efforts. Neither ICS-CERT nor any other ICS security player has come up with a magic bullet to protect Internet facing ICS equipment. The revised alert simply serves as an updated reminder that every ICS owner/operator needs to take a hard look at their control systems to ensure that they are appropriately protected. As such this updated alert deserves the widest possible dissemination.

NOTE: There is an interesting follow-up to this post written by Reid Wightman over on DigitalBond. Well worth reading and makes some additional points that bear attention. Plus he was nice enough to mention this post. [6-25-12 20:20 EDST]
 
/* Use this with templates/template-twocol.html */