Showing posts with label Evgeniy Druzhinin. Show all posts
Showing posts with label Evgeniy Druzhinin. Show all posts

Saturday, August 22, 2020

Public ICS Disclosures – Week of 8-15-20


This week we have three vendor disclosures for products from Phoenix Contact, Moxa, and Eaton and one update from Rockwell. There are researcher reports for products from WECON. There were two control system exploits published for products from PNPSCADA and Geutebruck.

Phoenix Contact Advisory


Phoenix Contact published an advisory [.PDF download link] describing a synchronous access of remote resource without timeout vulnerability in their Emalytics, ILC 2050 BI and ILC 2050 BI-L products. This is a third-party vulnerability in the Tridium Niagara product that was reported earlier this month by NCCIC-ICS. Phoenix Contact reports that they expect to fix this vulnerability in the next firmware update in October 2020.

Moxa Advisory


Moxa published an advisory describing six vulnerabilities in their NPort IAW5000A-I/O Series Serial Device Servers. The vulnerabilities were reported by Evgeniy Druzhinin and Ilya Karpov of Rostelecom-Solar. Moxa has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Session fixation,
• Improper privilege management,
• Weak password requirements,
• Cleartext transmission of sensitive information,
• Improper restriction of excessive authentication attempts, and
• Information exposure

Eaton Advisory


Eaton published an advisory describing two vulnerabilities in their Secure Connect Android Mobile app. The vulnerability was reported by Vishal Bharad. Eaton has a new version that mitigates the vulnerabilities. There is no indication that Bharad has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Information exposure, and
• Information exposure through log files

Rockwell Update


Rockwell published an update for an advisory that was originally published on July 8th, 2020 and most recently updated on July 23rd, 2020. The new information includes links to additional detections.

WECON Reports


The Zero Day Initiative has published (ZDI-20-1055 thru ZDI-20-1076) 22 reports of 0-day vulnerabilities in the WECON LeviStudioU. The vulnerabilities have been reported to ‘ICS-CERT’ (presumably CISA NCCIC-ICS) which reportedly received no response from WECON. The vulnerabilities were reported by Natnael Samson. The vulnerabilities are all stack-based buffer overflows in various components of the LeviStudioU product. NO CVEs have been reported.

PNPSCADA Exploit


İsmail ERKEK published an exploit for an SQL injection vulnerability in the PNPSCADA. There is no CVE for this vulnerability and there is no indication that ERKEK has contacted the vendor, so this looks like it is a 0-day vulnerability.

Geutebruck Exploit


Davy Douhine published a Metasploit module for an authenticated arbitrary command execution vulnerability in Geutebruck G-Cam and G-Code cameras. This vulnerability was previously reported by NCCIC-ICS.

Wednesday, February 26, 2020

5 Advisories Published – 2-25-20


Yesterday the CISA NCCIC-ICS published five control system security advisories for products from Honeywell and Moxa (4).

Honeywell Advisory


This advisory describes three vulnerabilities in the Honeywell WIN-PAK monitoring platform. The vulnerabilities are self-reported. Honeywell has an update available that mitigates the vulnerabilities.

The three reported vulnerabilities are:

• Cross-site scripting - CVE-2020-7005;
• Improper neutralization of HTTP headers for scripting syntax - CVE-2020-6982; and
• Use of obsolete function - CVE-2020-6978

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerabilities to allow an attacker to perform remote code execution.

EDS-G516E Advisory


This advisory describes seven vulnerabilities in the Moxa EDS-G516E series, and EDS-510E series ethernet switches. The vulnerabilities were reported by Ilya Karpov and Evgeniy Druzhinin from Rostelecom-Solar, and Georgy Zaytsev of Positive Technologies. Moxa has new firmware that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The seven reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2020-7007;
• Use of broken or risky encryption algorithm - CVE-2020-7001;
• Use of hard-coded cryptographic key - CVE-2020-6979;
• Use of hard-coded credentials - CVE-2020-6981;
• Classic buffer overflow - CVE-2020-6989;
• Cleartext transmission of sensitive information - CVE-2020-6997; and
• Weak password requirements - CVE-2020-6991

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to crash the device, execute arbitrary code, and allow access to sensitive information.

PT-7528 Advisory


This advisory describes six vulnerabilities in the Moxa PT-7528 Series and PT-7828 Series ethernet switches. The vulnerabilities were reported by Ilya Karpov and Evgeniy Druzhinin from Rostelecom-Solar, and Georgy Zaytsev of Positive Technologies. Moxa has a security patch that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2020-6989;
• Use of broken or risky cryptographic algorithm - CVE-2020-6987
• Use of a hard-coded cryptographic key - CVE-2020-6983;
• Use of hard-coded credentials - CVE-2020-6985;
• Weak password requirements - CVE-2020-6995; and
• Information exposure - CVE-2020-6993

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to crash the device or allow access to sensitive information.

ioLogik 2542-HSPA Advisory


This advisory describes three vulnerabilities in the Moxa ioLogik 2542-HSPA Series Controllers and IOs, and IOxpress Configuration Utility. The vulnerabilities were reported by Ilya Karpov and Evgeniy Druzhinin from Rostelecom-Solar. Moxa has a security patch that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Clear-text storage of sensitive information - CVE-2019-18238;
• Clear-text transmission of sensitive information - CVE-2020-7003; and
• Incorrectly specified destination in a communication channel - CVE-2019-18242

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to crash the device or allow access to sensitive information.

MB3xxx Advisory


This advisory describes nine vulnerabilities in the Moxa MB3170 series, MB3180 series, MB3270 series, MB3280 series, MB3480 series, and MB3660 series protocol gateways. The vulnerabilities were reported by Ilya Karpov and Evgeniy Druzhinin from Rostelecom-Solar, and Georgy Zaytsev of Positive Technologies. Moxa has new firmware that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The nine reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2019-9099;
• Integer overflow to buffer overflow - CVE-2019-9098;
• Cross-site request forgery - CVE-2019-9102;
• Use of broken or risky encryption algorithm - CVE-2019-9095;
• Information exposure - CVE-2019-9103;
• Clear-text transmission of sensitive information - CVE-2019-9101;
• Weak password requirements - CVE-2019-9096;
• Clear-text storage of sensitive information - CVE-2019-9104; and
• Incorrectly specified destination in a communication channel - CVE-2019-9097

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to crash the device, cause a buffer overflow, allow remote execution of arbitrary code, or allow access to sensitive information.

NOTE: All four of these Moxa advisories cover vulnerabilities that were originally reported by Moxa on September 25th, 2019.

Tuesday, November 26, 2019

2 Advisories Published – 11-26-19

Today the CISA NCCIC-ICS published two control system security advisories for products from ABB.

ABB Advisory #1


This advisory describes a path traversal vulnerability in the ABB Relion 670 series. The vulnerability was reported by Kirill Nesterov of Kaspersky Lab. ABB has new versions that mitigate the vulnerability. There is no indication that Nesterov has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to read and delete files on the device.

ABB Advisory #2


This advisory describes an improper input validation vulnerability in the ABB  Relion 650 and 670 Series. The vulnerability was reported by Ilya Karpov, Evgeniy Druzhinin, and Victor Nikitin of ScadaX. ABB has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to reboot the device, causing a denial of service.

NOTE: I briefly reported on both of these vulnerabilities and a third that was also reported by ABB on the same day back in October. The third advisory dealt with OpenSSL vulnerabilities.

Saturday, October 26, 2019

Public ICS Disclosures – Week of 10-19-19


This week we have three vendor disclosures from ABB and two vendor updates from 3S and Yokogawa. There is also an exploit report for previously reported vulnerabilities in products from Moxa.

ABB Advisories


Relion® 670 series

ABB published an advisory describing a path traversal vulnerability in the MMS server included in their Relion 670 series protection and control IEDs. The vulnerability was reported by Kirill Nesterov of Kaspersky Lab. ABB has new versions that mitigate the vulnerability. There is no indication that Nesterov has been provided an opportunity to verify the efficacy of the fix.

Relion® 650 series and Relion® 670 series
ABB published an advisory describing a terminal reboot vulnerability in the SPA protocol over TCP/IP included in their Relion 650 and 670 series protection and control IEDs. The vulnerability was reported by Ilya Karpov, Evgeniy Druzhinin, Damir Zainullin of Positive Technologies and Victor Nikitin of i-Grids. ABB has updates that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Relion® 650 series and Relion® 670 series

ABB published an advisory describing four known OpenSSL vulnerabilities (CVE-2017-3737, CVE-2018-0739, CVE-2018-0737, CVE-2018-0732) in their Relion 650 and 670 series protection and control IEDs. These vulnerabilities are self-reported. ABB has updates that mitigate the vulnerabilities.

3S Update


3S published an update an advisory that was originally published on September 12th, 2019. The new information includes:

Revised affected version numbers;
Added CVE number for vulnerability; and
Revised version number for mitigation

Yokogawa Update


Yokogawa published an update for an advisory that was originally published on September 27th, 2019 and most recently updated on October 11th, 2019. The new information includes a link to the patch for the Exaquantum product.

Moxa Exploit


RANDORISEC published exploit code for two vulnerabilities in the Moxa Moxa EDR-810 Series Secure Routers. One of these vulnerabilities was addressed in an NCCIC-ICS advisory published on October 1st, 2019. The second vulnerability was reported in a Moxa advisory published on October 2nd, 2019.

Thursday, January 24, 2019

Two Advisories Published – 01-24-19


Today the DHS NCCIC-ICS published two control system security advisories for products from Phoenix Contact and Advantech.

Phoenix Contact Advisory


This advisory describes six vulnerabilities in the Phoenix Contact FL SWITCH. The vulnerabilities were reported by Evgeniy Druzhinin, Ilya Karpov, and Georgy Zaytsev of Positive Technologies via CERT@VDE. Phoenix Contact reports that newer firmware versions mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Cross-site request forgery - CVE-2018-13993;
• Improper restriction of excessive authentication attempts - CVE-2018-13990;
• Cleartext transmission of sensitive information - CVE-2018-13992;
• Resource exhaustion - CVE-2018-13994;
• Insecure storage of sensitive information - CVE-2018-13991; and
Memory corruption - CVE-2017-3735

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow attackers to have user privileges, gain access to the switch, read user credentials, deny access to the switch, or perform man-in-the-middle attacks.

NOTE: The CERT@VDE advisory notes that CVE-2018-13992 has not been fixed in the newer firmware versions available. A generic fix for that vulnerability has been recommended.

Advantech Advisory


This advisory describes three vulnerabilities in the Advantech WebAccess/SCADA platform.
The vulnerabilities were reported by Devesh Logendran of Attila Cybertech. Advantech has a new version that mitigates the vulnerabilities. There is no indication that Logendran has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Improper authentication - CVE-2019-6519:
• Authentication bypass using an alternate path or channel - CVE-2019-6521; and
• SQL injection - CVE-2019-6523

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to access and manipulate sensitive data.

Thursday, May 17, 2018

ICS-CERT Publishes 4 Advisories and 2 Siemens Updates


Today the DHS ICS-CERT published three control system security advisories for products from Delta Electronics, Siemens, Phoenix Contact, and Medtronic. They published on medical device security advisory for products from Medtronic. They also updated two previously issued control system security advisories for products from Siemens.

The three Siemens advisories/updates are the ones I mentioned in passing earlier this week.

Delta Advisory


This advisory describes a heap-based buffer overflow vulnerability in the Delta Industrial Automation TPEditor. The vulnerability was reported by ThePotato working with ZDI. Delta has released a new version that mitigates the vulnerability. There is no indication that the researcher was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to crash the accessed device, resulting in a buffer overflow condition that may allow remote code execution.


Siemens Advisory


This advisory describes an improper input validation vulnerability in the Siemens S7-400 CPU. The vulnerability is being self-reported. Siemens has updates that mitigate the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial-of-service condition of the CPU. The CPU will remain in DEFECT mode until a manual restart is performed. The Siemens security advisory notes that:

“Successful exploitation requires an attacker to be able to send a specially crafted S7 communication packet to a communication interface of the CPU. This includes Ethernet, PROFIBUS, and Multi Point Interfaces (MPI). No user interaction or privileges are required to exploit the security vulnerability”

Phoenix Contact Advisory


This advisory describes four vulnerabilities in the Phoenix FL SWITCH 3xxx/4xxx/48xx Series. The vulnerabilities were reported by  Vyacheslav Moskvin, Semen Sokolov, Evgeniy Druzhinin, Georgy Zaytsev and Ilya Karpov of Positive Technologies working through CERT@VDE. Newer firmware mitigates the vulnerability. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Command injection - CVE-2018-10730;
• Information exposure - CVE-2018-10729; and
Stack-based buffer overflow (2) - CVE-2018-10728, and CVE-2018-10731

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow for remote code execution and information disclosure.

GE Advisory


This advisory describes an improper input validation vulnerability n the GE PACSystems, an industrial Internet controller. The vulnerability was reported by Younes Dragoni of Nozomi Networks. GE has released new firmware to mitigate the vulnerability. There is no indication that Dragoni was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause the device to reboot and change its state, causing the device to become unavailable.

Medtronic Advisory


This advisory describes a missing encryption of sensitive data vulnerability in the Medtronic N’Vision Clinician Programmer. The vulnerability was reported by Billy Rios of Whitescope LLC. Medtronic has mitigated the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker with physical access to the card could exploit the vulnerability to access personal health information (PHI) or personally identifiable information (PII).

NOTE: This vulnerability was not reported on the FDA Medical Device Safety Communications page.

SIPROTEC Update #1


This update provides additional information on an advisory that was originally reported by ICS-CERT on May 19th, 2016 and updated on July 5th, 2016. This update removes 7SD80 from list of affected products.

SIPROTEC Update #2


This update provides additional information on an advisory that was was originally published on March 8th, 2018 and updated on April 19th, 2018. This update provides updated effected version information and mitigation measures for 7SD80.

Friday, January 12, 2018

ICS-CERT Publishes Alert, 3 Advisories and 1 Update

Yesterday ICS-CERT published an alert for the Intel Meltdown and Spectre vulnerabilities. They published three control system security advisories for products from Phoenix Contact, Moxa, and WECON. They also updated a previously published advisory for products from Advantech.

Meltdown Alert


This alert describes the CPU hardware vulnerable to side-channel attacks vulnerabilities known as  Meltdown and Spectre. The alert provides links to the following vendor notifications about these vulnerabilities:

ABB;
Rockwell Automation (account required for login); and
Siemens

The alert also provides a generic link to the ICS-CERT recommended practices page. It is disappointing that, in light of the problems seen with the Windows Update for Meltdown seen on some systems (here and here for example), ICS-CERT has not specifically mentioned the need for checking any updates on a test platform before uploading to a live control system.

Phoenix Contact Advisory


This advisory describes two vulnerabilities in the Phoenix Contact FL Switch product line. The vulnerabilities were reported by Ilya Karpov and Evgeniy Druzhinin of Positive Technologies. Newer versions of the firmware mitigate these vulnerabilities. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper authorization - CVE-2017-16743; and
• Information exposure - CVE-2017-16741

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to gain administrative privileges and expose information to unauthenticated users.

Moxa Advisory


This advisory describes an unquoted search path vulnerability in the Moxa MXview network management software. The vulnerability was reported by Karn Ganeshen. Moxa has produced a firmware update that mitigates the vulnerability. There is no indication that Ganeshen was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker with locally authorized access could exploit the vulnerability to escalate privileges by inserting arbitrary code into the unquoted service path.

WECON Advisory


This advisory describes two vulnerabilities in the WECON LeviStudio HMI Editor. The vulnerabilities were reported by Sergey Zelenyuk of RVRT, HanM0u of CloverSec Labs, and Brian Gorenc via the Zero Day Initiative. The latest version of the software mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2017-16739; and
• Heap-based buffer overflow - CVE-2017-16737

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to effect arbitrary code execution.

Advantech Update


This update updates information on an advisory that was originally published on January 4th, 2018. This update adds two vulnerabilities to those previously reported:

• Unrestricted upload of file with dangerous type - CVE-2017-16736 and

• Use after free - CVE-2017-16732
 
/* Use this with templates/template-twocol.html */