Showing posts with label Ehab Hussein. Show all posts
Showing posts with label Ehab Hussein. Show all posts

Tuesday, June 2, 2020

6 Advisories and 1 Update Published – 6-2-20


Today the CISA NCCIC-ICS published six control system security advisories for products from ABB (4), GE and SWARCO Traffic Systems. They also updated an advisory for products from Inductive Automation

System 800xA Advisory


This advisory describes two incorrect default permissions vulnerabilities in the ABB System 800xA. The vulnerabilities were reported by William Knowles of Applied Risk. ABB provides generic work arounds to mitigate the vulnerabilities.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to escalate privileges, cause system functions to stop, and corrupt user applications.

NOTE: I briefly described these vulnerabilities in early April.

System 800xA Base Advisory


This advisory describes an incorrect permission assignment for critical resource vulnerability in the ABB System 800xA Base. The vulnerabilities were reported by William Knowles of Applied Risk. ABB has a new version that mitigates the vulnerabilities. There is no indication that Knowles has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to escalate privileges and cause system functions to stop or malfunction.

NOTE: I briefly described these vulnerabilities in early April and then I discussed the ABB update later that month. The updated version is being reported by NCCIC-ICS.

System 800xA Products Advisory


This advisory describes seven incorrect default permission vulnerabilities in various ABB System 800xA products. The vulnerabilities were reported by William Knowles of Applied Risk. NCCIC-ICS reports that ABB plans to correct these vulnerabilities in a future version.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to make the system node inaccessible or tamper with runtime data in the system.

NOTE: I briefly described these vulnerabilities in early April and then I discussed the ABB update later that month. The updated version is being reported by NCCIC-ICS.

Central Licensing System Advisory


This advisory describes five vulnerabilities in the ABB Central Licensing System. The vulnerabilities were reported by William Knowles of Applied Risk. ABB has new versions that mitigate the vulnerabilities. There is no indication that Knowles has been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Information exposure - CVE-2020-8481,
• Improper restriction of XML external entity reference - CVE-2020-8479,
• Uncontrolled resource consumption - CVE-2020-8475,
• Permissions, privileges and access controls - CVE-2020-8476, and
• Improper access controls - CVE-2020-8471

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to take control of the affected system node remotely and cause an affected CLS Server node to stop or prevent legitimate access to the affected CLS Server.

I briefly reported these vulnerabilities in late April.

GE Advisory


This advisory describes a missing authentication for critical function vulnerability in the GE Grid Solutions Reason RT Clocks. The vulnerability was reported by Ehab Hussein of IOActive. GE has a new firmware version that mitigates the vulnerability. There is no indication that Hussein has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow access to sensitive information, execution of arbitrary code, and cause the device to become unresponsive.

SWARCO Advisory


This advisory describes an improper access control vulnerability in the SWARCO CPU LS4000. The vulnerability was reported by Martin Aman of ProtectEM. SWARCO has a patch that mitigates the vulnerability. There is no indication that Aman has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow access to the device and disturb operations with connected devices.

I briefly discussed this vulnerability last Saturday.

Inductive Automation Update


This update provides additional information on an advisory that was originally published on May 26th, 2020. The new information includes adding Ignition 7 Gateway to the list of affected products and providing mitigation measures for that product.

Wednesday, October 5, 2016

ICS-CERT Updates 2 Siemens Advisories and Publishes 2 New Advisories

The DHS ICS-CERT recently updated two control system security advisories for products from Siemens (the two I briefly discussed last week). Yesterday they also published two new control system security advisories for products from Indas and Beckhoff.

Siemens SIMATIC Update


This update adds new information for an advisory originally published in July and then updated in August. It provides updated affected version information for SIMATIC WinCC v7.0 SP3 and SIMATICS PCS 7 v8.0. It also provides update links for SIMATIC WinCC v7.0 and SIMATICS PCS 7 v7.2 and v8.0.

Siemens glibc Update


This update adds new information for an advisory that was reported in April and updated once in June and then again in July. It provides updated affected version information for SCALANCE M-800/S615. It also provides a link for a patche for those affected SCALANCE M-800/S615 products.

INDAS Advisory


This advisory describes a path traversal vulnerability in the INDAS Web SCADA application. The vulnerability was reported by Ehab Hussein of IOActive. INDAS has produced a new version of the software to mitigate the vulnerability, but there is no indication that Hussein has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to download arbitrary files from the target system.

Beckhoff Advisory


This advisory describes two vulnerabilities in the Beckhoff Embedded PC Images and TwinCAT Components. The vulnerabilities were publicly reported in February of 2015 at the 1st International Conference on Information Systems Security and Privacy by Marko Schuba from FH Aachen University of Applied Sciences (there may be an earlier report). In 2014 Beckhoff produced a new version of the software and published three security advisories (here, here, and here) to mitigate the vulnerabilities, but there is no indication that Schuba has been provided an opportunity to verify the efficacy of the fixes.

The vulnerabilities described in the advisory are:

• Improper restriction of excessive authentication attempts - CVE-2014-5414; and
• Exposed dangerous method of function - CVE-2014-5415


ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to gain unauthorized access to systems or read and manipulate transmitted information, especially passwords. Interestingly ICS-CERT does not apparently consider the formal academic paper on these vulnerabilities to be a public exploit that “specifically target these vulnerabilities”.
 
/* Use this with templates/template-twocol.html */