Showing posts with label Elad Luz. Show all posts
Showing posts with label Elad Luz. Show all posts

Wednesday, July 10, 2019

5 Advisories and 4 Updates Published – 07-09-19


Yesterday the DHS NCCIC-ICS published four control system security advisories {Siemens (2), Schneider Electric, Rockwell and Emerson}, one medical device security advisory for products from GE, and updated four previously published advisories for products from Siemens.

SIPROTEC Advisory


This advisory describes two improper input validation vulnerabilities in the Siemens SIPROTEC 5 and DIGISI 5 products. The vulnerability was reported by Pierre Capillon, Nicolas Iooss, and Jean-Baptiste Galet from Agence Nationale de la Sécurité des Systèmes d’Information (ANSSI). Siemens has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a denial-of-service condition and limited control of file upload, download, and delete functions.

Spectrum Power Advisory


This advisory describes a cross-site scripting vulnerability in the Siemens Spectrum Power product. The vulnerability was reported by Ismail Mert AY AK of Biznet Bilisim AS. Siemens has an update available that mitigates the vulnerability. There is no indication that Mert has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to inject arbitrary code in a specially crafted HTTP request and monitor information.

NOTE 1: The Siemens advisory uses new terminology for reporting NCCIC-ICS coordination efforts, it cites “CISA-Industrial Control System Vulnerability Disclosure team” as the coordinating agency. I am wondering if this is an official designation of a specific group of people operating at NCCIC or just another smoke and mirrors name change.

NOTE 2: Siemens published four other advisories yesterday in addition to these two. If they are not addressed by NCCIC-ICS later this week, I will be looking at them Saturday.

Schneider Advisory


This advisory describes a use after free vulnerability in the Schneider Zelio Soft programming platform. The vulnerability was reported by 9sg Security Team via the Zero Day Initiative. Schneider has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow remote code execution through the opening of a specially crafted project file.

NOTE 1: NCCIC-ICS does not provide a link to the Schneider Zelio Soft advisory.

NOTE 2: Schneider published five other advisories yesterday as well as the Zelio Soft advisory. It was a busy ICS security day.

Rockwell Advisory


This advisory describes an improper access control vulnerability in the Rockwell PanelView 5510 HMI. This vulnerability is self-reported. Rockwell has new versions that mitigate the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit this vulnerability to allow a remote unauthenticated user to gain root privileges on the device.

Emerson Advisory


This advisory describes a hard-coded credential vulnerability in the Emerson DeltaV Distributed Control System (DCS) software platform. The vulnerability was reported by Benjamin Crosasso of Sanofi. Emerson has a patch available to mitigate the vulnerability. There is no indication that Crosasso has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to gain administrative access to DeltaV Smart Switches.

GE Advisory


This advisory describes an improper authentication vulnerability in the GE Aestiva and Aespire Anesthesia Machines. The vulnerability was reported by Elad Luz of CyberMDX. GE has provided generic workarounds to mitigate the vulnerability. The FDA has not published a safety communication on this vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker the ability to remotely modify GE Healthcare anesthesia device parameters.

SIMATIC PCS Update


This update provides additional information on an advisory that was originally published on May 14th, 2019. The new information includes updated version data and links to mitigation measures for:

SIMATIC WinCC V7.4;
SIMATIC PCS 7 V8.2; and
SIMATIC PCS 7 V9.0

SIMATIC Update


This update provides additional information on an advisory that was originally published on April 9th, 2019 and updated on May 14th, 2019 and June 11th, 2019. The new information includes updated version data and links to mitigation measures for:

SIMATIC RF600R;
SIMATIC RF185C;
SIMATIC RF186C; and
SIMATIC RF188C

Industrial Products Update


This update provides additional information on an advisory that was originally published on April 9th, 2019 and updated on May 14th, 2019 and June 11th, 2019. The new information includes updated version data and links to mitigation measures for:

SIMATIC RF600R;
SIMATIC RF188C; and
SINEMA Server

CP 1604 Update


This update provides additional information on an advisory that was originally published on February 12th, 2019. The new information includes:

Update version information and mitigations; and
Add fixes for older product versions for CVE-2018-13808

NOTE: Siemens published four additional advisory updates yesterday. NCCIC-ICS is unlikely to address them so I will on Saturday.

Thursday, June 13, 2019

3 Advisories Published – 06-13-19


Today the DHS NCCIC-ICS published two control system security advisories for products from WAGO and Johnson Controls. They also published a medical device security advisory for products from BD.

WAGO Advisory


This advisory describes three vulnerabilities in the WAGO 852 Industrial Managed Switches. The vulnerability was reported by T. Weber of SEC Consult Vulnerability Lab. WAGO reports that the latest firmware for the affected products mitigate the vulnerabilities. There is no indication that Weber has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

Use of hard-coded credentials - CVE-2019-12550;
Use of hard-coded cryptographic key - CVE-2019-12549;
Use of components with known vulnerabilities

Note: The CERT VDE advisory lists the following component vulnerabilities:

BusyBox (v 1.12.0) - CVE-2013-1813, CVE-2016-2148, CVE-2016-6301, CVE-2011-2716, CVE-2011-5325, CVE-2015-9261, CVE-2016-2147, CVE-2017-16544 etc.; and
GNU glibc (v 2.8) - CVE-2010-0296, CVE-2010-3856, CVE-2012-4412, CVE-2014-4043, CVE-2014-9402, CVE-2014-9761, CVE-2014-9984, CVE-2015-14 etc.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow a compromise of the managed switch, resulting in disruption of communication, and root access to the operating system. The SEC Consult report includes proof of concept code for the first two vulnerabilities.

Johnson Controls Advisory


This advisory describes an improper authorization vulnerability in the Johnson Controls exacqVision Enterprise System Manager. The vulnerability was reported by @bzyo_. Johnson Controls reports that the latest version mitigates the vulnerability. There is no indication that @bzyo_ has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerability to allow malicious code execution.

BD Advisory


This advisory describes two vulnerabilities in the BD Alaris Gateway Workstation. The vulnerability was reported by Elad Luz of CyberMDX. BD reports that the latest firmware mitigates the first vulnerability and provides generic mitigations for the second. The is no indication that Luz has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Improper access control - CVE-2019-10962; and
Unrestricted upload of file with dangerous type - CVE-2019-10959

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to view and edit device status and configuration details as well as cause devices to become unavailable.

Wednesday, August 29, 2018

ICS-CERT Publishes 5 Advisories


Yesterday the DHS ICS-CERT published four control system security advisories for products from ABB and Schneider (3). They also published on medical device security advisory for products from Qualcomm Life.

The ABB vulnerability was previously discussed here two weeks ago. Two of the Schneider vulnerabilities were discussed here last weekend.

ABB Advisory


This advisory describes an improper authentication vulnerability in the ABB eSOMS electronic shift operations management system. The vulnerability is self-reported (the ABB security advisory notes that they “received information about this vulnerability through responsible disclosure” but did not name the researcher). ABB will publish a new version on September 28th that will mitigate the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability to gain access to the application without authentication.

Note: The ICS-CERT link to the ABB security advisory does not work, use the link above.

PowerLogic Advisory


This advisory describes a cross-site scripting vulnerability in the Schneider PowerLogic PM5560 power management system. The vulnerability was reported by Ezequiel Fernandez and Bertin Jose. Schneider has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow user input to be manipulated, allowing for remote code execution.
                                             

Modicon 221 Advisory (1)


This advisory describes an improper check for unusual or exceptional conditions vulnerability in the Schneider Modicon 221 PLCs. The vulnerability was reported by Yehonatan Kfir of Radiflow. A new firmware version mitigates the vulnerability. There is no indication that Kfir has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that an uncharacterized attacker could remotely exploit this vulnerability to remotely reboot the device.

Modicon 221 Advisory (2)


This advisory describes three vulnerabilities in the Schneider Modicon 221 PLCs. The vulnerabilities were reported by Irfan Ahmed, Hyunguk Yoo, Sushma Kalle, and Nehal Ameen of the University of New Orleans. A new firmware version mitigates the vulnerability. There is no indication that researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Information management errors - CVE-2018-7790; and
Permissions, privileges and access controls (2) - CVE-2018-7791 and CVE-2018-7792

ICS-CERT reports that an uncharacterized attacker could remotely exploit the vulnerabilities to replay authentication sequences, overwrite passwords, or decode passwords.

Qualcomm Advisory


This advisory describes a code weakness vulnerability in the Qualcomm Life Capsule Datacaptor Terminal Server (DTS). The vulnerability was reported by Elad Luz of CyberMDX. A new firmware update mitigates the vulnerability in one of the affected products and work arounds have been identified for the remaining products. There is no indication that Luz has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability  to execute unauthorized code to obtain administrator-level privileges on the device.

Thursday, August 23, 2018

ICS-CERT Publishes BD Advisory


Today the DHS ICS-CERT published a medical device security advisory for BD Alaris syringe pumps. The advisory describes an improper authentication vulnerability. The vulnerability was reported by Elad Luz of CyberMDX. BD has identified work arounds and there is no indication that BD intends to further mitigate this vulnerability.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability  to gain unauthorized access to various Alaris Syringe pumps and impact the intended operation of the pump when it is connected to a terminal server via the serial port.

 
/* Use this with templates/template-twocol.html */