Showing posts with label Exodus Intelligence. Show all posts
Showing posts with label Exodus Intelligence. Show all posts

Friday, November 10, 2017

ICS-CERT Publishes Two Advisories

Yesterday the DHS ICS-CERT published two control system security advisories for products from Schneider and AutomationDirect.

Schneider Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Schneider InduSoft Web Studio and InTouch Machine Edition. The vulnerabilities were reported by Aaron Portnoy, formerly of Exodus Intelligence. Schneider has produced new versions that mitigate the vulnerability. There is no indication that Portnoy has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could use a publicly available exploit to remotely exploit this vulnerability to remotely execute code with high privileges. The Schneider security bulletin notes that the vulnerability exists during tag subscription.

AutomationDirect Advisory


This advisory describes and uncontrolled search path element vulnerability in a number of AutomationDirect products. The vulnerability was reported by Mark Cross of RIoT Solutions. Newer software versions are available from AutomationDirect that mitigate the problem. There is no indication that Cross has been provided an opportunity to verify the efficacy of the fix.


ICS-CERT reports that an uncharacterized attacker with uncharacterized access to execute arbitrary code on the system.

Wednesday, March 27, 2013

ICS-CERT Publishes Two Metasploit Updated Advisories


Late this afternoon ICS-CERT published two updated advisories that were issued earlier this year; one for multiple vulnerabilities in CoDeSys Gateway-Web Servers and the other for a single vulnerability in the WellinTech KingView product. Both updates were necessary because the organization initially reporting the vulnerability had recently released a Metasploit module for exploiting the identified vulnerabilities.

Both Exodus Intelligence and Ioactive have produced Metasploit modules for the vulnerabilities that they reported in coordinated disclosures. EI explains on their web page that it is their intention to provide their customers with exploit tools for vulnerabilities that they discover. Apparently Ioactive has the same policy. This is becoming a more common approach as security researchers explore a variety of business models to make their security research worthwhile.

In both of these cases the exploit modules were published well after the ICS-CERT advisories were published. Thus the vendors had time to produce and distribute patches or updates to fix the vulnerabilities before the exploit tools became publicly available. Of course, no one really knows how many of the system owners actually knew about the vulnerabilities or if they did know actually had a chance to update their systems.

Tuesday, February 19, 2013

ICS-CERT Publishes CoDeSys Server Advisory


This afternoon the DHS ISC-CERT published an advisory for multiple vulnerabilities in the 3S CoDeSys Gateway-Server application. The vulnerabilities were reported by Aaron Portnoy of Exodus Intelligence in a coordinated disclosure.

The Advisory

The reported vulnerabilities include:

• Improper access of indexable resource, CVE-2012-4704;
• Directory or path traversal, CVE-2012-4705;
• Heap-based buffer overflow, CVE-2012-4706;
• Improper restriction of operations within the bounds of a memory buffer, CVE-2012-4707; and
• Stack-based buffer overflow, CVE-2012-4708.

NOTE: the CVE links may not be active for a couple of days; NIST uses this report to populate the CVE file.

ICS-CERT reports that a moderately skilled attacker could remotely exploit these vulnerabilities to crash the system or exploit arbitrary code. 3S has produced a patch that ICS-CERT reports mitigates these vulnerabilities.

Exploits Code Available?

The advisory states that there are no publicly available exploits for these vulnerabilities. Given that they were reported by Exodus Intelligence, I am not so sure that that is the case. Readers will remember my comment on the Exodus business model in an earlier blog post. EI provides their customers with exploit code for all of their ‘responsibly reported’ discoveries either just after the vulnerabilities are reported or when the vendor reports the vulnerabilities. Now this might not fit the ‘publicly available’ definition that ICS-CERT is using this week, but it looked like it did last week with the Schneider advisory.

Wednesday, February 13, 2013

ICS-CERT Publishes Two More Buffer Overflow Advisories


Yesterday (lost in the cybersecurity EO and State of the Union hoopla) the DHS ICS-CERT published two advisories addressing buffer overflow vulnerabilities in industrial control systems. The advisories addressed vulnerabilities in products from Schneider and WellinTech.

Schneider Advisory

This advisory addresses a heap-based buffer overflow in the Accutech Manager application from Schneider. The vulnerability was reported by Aaron Portnoy of Exodus Intelligence in a coordinated disclosure (more about this later) and according to the advisory Aaron has verified that the update provided by Schneider effectively mitigates the vulnerability.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability using publicly available code and it could allow the attacker to execute arbitrary code on the system.

The advisory also notes that Schneider recommends closing Accutech Manager when not actually using it. ICS-CERT (apparently) also recommends ensuring that the vulnerable port (2537/TCP) is not accessible from the internet

WellinTech Advisory

This advisory addresses a memory corruption buffer overflow in the kingMess application within the KingView product. The vulnerability was reported by Lucas Apa and Carlos Mario Penagos Hollman of IOActive in a coordinated disclosure. They have also verified that the patch produced by WellinTech fixes the vulnerability.

ICS-CERT reports that a highly skilled attacker could remotely exploit this vulnerability to execute arbitrary code on the system.

It’s interesting to note that WellinTech reportedly released the patch on November 15th of last year and ICS-CERT is just now publishing the advisory. This may be because WellinTech did not disclose the vulnerability to ICS-CERT until recently.

New Twist on Coordinated Disclosure

The Schneider advisory has something that I don’t recall seeing in a coordinated disclosure advisory before, a report that there is publicly available exploit code for the vulnerability. Typically the researcher keeps any exploit code they developed tightly held, only sharing it with the vendor. There is nothing specific about who has released the exploit, so I can’t tell from the advisory if it was Aaron who released the exploit code or some other researcher who independently discovered the vulnerability.

A look at the Exodus Intelligence (Aaron’s employer) web site sheds some light on the situation. Exodus Intelligence offers their customer two different types of ‘vulnerability intelligence data feeds’. A ‘Zero-day Feed’ offers to their customers information on vulnerabilities (including exploit code) just after Exodus notifies the vendor of the vulnerability. I’m assuming that there is some sort of non-disclosure agreement that goes along with this feed.

A separate (and presumably cheaper) ‘Day of Disclosure Feed’ provides the same information to Exodus customers the same day as the vendor publicly announces the availability of the mitigation for the vulnerability. Again this includes a copy of the exploit code for the vulnerability. I’m assuming that this is the exploit code for the Schneider vulnerability that is referenced in the advisory.

It is interesting to me to see how many different business models are beginning to grow out of the white hat side the cybersecurity universe. Researchers need to make money to support their nasty habits like eating and bathing and these varied business models will make it easier for these folks to keep plying their trade keeping software vendors on their toes.

Friday, January 18, 2013

ICS-CERT Publishes Another Schneider Vulnerability Report


It’s been a bad week for Schneider Electric and their customers. As of late this afternoon there have been two ICS-CERT advisories and one alert published for industrial control systems from Schneider. The latest is an advisory covering a buffer-stack overflow vulnerability in their Interactive Graphical SCADA System (IGSS) application reported by Aaron Portnoy of Exodus Intelligence in a coordinated disclosure.

According to the advisory a moderately skilled attacker could remotely exploit this vulnerability and potentially execute arbitrary code. Schneider has separate patches for the two latest versions of IGSS (V9 & V10) and Portnoy has validated these patches. For older versions of the application Schneider recommends either:

• Upgrade to a newer, mitigated version; or

• Filter communications over Port 12397/TCP to “only allow access from the specific IP addresses for the devices being controlled or monitored” (page 3).

Interestingly a tweet by Exodus Intelligence notes that “Schneider Electric has patched one of the [emphasis added] RCE vulnerabilities we reported in their IGSS SCADA product”. Do we wait for the other shoe to drop until the ICS-CERT 45-day limit expires? Oops, the 45-day ICS-CERT limit passed on November 15th of last year (See the Schneider Electric Vulnerabilities page).
 
/* Use this with templates/template-twocol.html */