Showing posts with label Forescout. Show all posts
Showing posts with label Forescout. Show all posts

Saturday, January 25, 2025

Review – Public ICS Disclosures – Week of 1-18-25

This week we have seven vendor disclosures from Bosch, CODESYS, Delta Electronics, HPE, Palo Alto Networks, QNAP, and SonicWall. We also have five updates from ABB, FortiGuard (3) and HPE. Finally, we have an exploit for a vulnerability in a product from Forescout.

Advisories

Bosch Advisory - Bosch published an advisory that describes an unquoted service path enumeration vulnerability in their DIVAR IP all-in-one 7000 product.

CODESYS Advisory - CODESYS published an advisory that discusses an observable discrepancy vulnerability with publicly available exploit in the CODESYS Key USB dongle.

Delta Advisory - Delta published an advisory that describes a heap-based buffer overflow vulnerability in their CNCSoft-G2.

HPE Advisory - HPE published an advisory that discusses an inefficient regular expression complexity vulnerability in their Telco Service Orchestrator.

Palo Alto Networks Advisory - Palo Alto Networks published an advisory that discusses 20 vulnerabilities (11 with publicly available exploits) in their PAN-OS product.

QNAP Advisory - QNAP published an advisory that discusses six vulnerabilities in their HBS 3 Hybrid Backup Sync product.

SonicWall Advisory - SonicWall published an advisory that describes a deserialization of untrusted data vulnerability that is listed in the CISA Known Exploited Vulnerabilities catalog.

Updates

FortiGuard Advisory #1 - FortiGuard published an update for their Node.js websocket module advisory that was originally published on January 14th, 2025.

FortiGuard Advisory #2 - FortiGuard published an update for their captive portal advisory that was originally published on February 27th, 2024.

FortiGuard Advisory #3 - FortiGuard published an update for their multiple logic flaws advisor that was originally published on January 14th, 2025.

HPE Update - HPE published an update for their RADIUS protocol advisory that was originally published on July 9th, 2024, and most recently updated on October 9th, 2024.

Exploits

Forescout Exploit - Nightsedge published an exploit for a creation of a temporary in directory with insecure permissions vulnerability in the Forescout SecureConnector.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-423 - subscription required.

Saturday, June 24, 2023

Review – Public ICS Disclosures – Week of 6-17-23

This week we have twelve vendor disclosures from FortiGuard (2), GE Gas Power, HP, HPE, Sick, Schweitzer Engineering Labs (2), Sierra Wireless, VMware, Western Digital, and Zyxel. There is also an update from GE Gas Power. We also have three researcher reports for products from Dell and an update of the OT:ICEFALL report. Finally, we have an exploit for the HiSECOS from Belden.

Advisories

FortiGuard Advisory #1 - FortiGuard published an advisory that describes a deserialization of untrusted data vulnerability in their FortiNAC.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes a command injection vulnerability in their FortiNAC product

GE Gas Power Advisory - GE published an advisory that discusses five vulnerabilities in their Proficy Historian product.

HP Advisory - HP published an advisory that discusses a Time-of-Check to Time-of-Use (TOCTOU) vulnerability in their PC products using AMI UEFI Firmware.

HPE Advisory - HPE published an advisory that discusses a remote code execution vulnerability in their IceWall product modules.

Sick Advisory - Sick published an advisory that describes vulnerabilities in their SICK EventCam App.

SEL Advisory #1 - SEL announced that a new version of their SEL-5037 SEL Grid Configurator is available that mitigates undescribed cybersecurity vulnerabilities.

SEL Advisory #2 - SEL announced that a new version of their SEL-5030 acSELerator QuickSet Software is available that mitigates undescribed cybersecurity vulnerabilities.

Sierra Wireless Advisory - Sierra Wireless published an advisory that provides additional guidance on a previously disclosed improper authentication vulnerability for their routers using the AirLink Management Service (ALMS).

VMware Advisory - VMware published an advisory that describes five vulnerabilities in their vCenter Server and Cloud Foundation products.

Western Digital Advisory - Western Digital published an advisory that describes two command injection vulnerabilities in their My Cloud OS 5 Firmware.

Zyxel Advisory - Zyxel published an advisory that describes a command injection vulnerability in the NAS products. This vulnerability is listed in the CISA Known Exploited Vulnerabilities Catalog.

Updates

GE Gas Power Update - GE published an update for their Proficy Historian that was originally published on February 3rd, 2023.

Researcher Reports

Dell Reports - Binarly published three reports describing individual vulnerabilities in the Dell Edge Gateway BIOS.

OT:ICEFALL Report - Forescout published an update of their OT:ICEFALL report.

Exploits

Belden Exploit - Dreizehnutters published an exploit for a privilege escalation vulnerability in Belden’s HiSecOS Web Server.

 

For more details on these disclosures, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-7c8 - subscription required.

Saturday, November 13, 2021

Review - Public ICS Disclosures – Week of 11-6-21 – Part 1

This week we have twelve vendor disclosures from Blackberry, Draeger, Open Design Alliance, HPE (4), Milestone, Phoenix Contact, QNAP, and VMware (2). There is also an update from CODESYS. Finally, we have a research report from Forescout on the plethora of TCP/IP vulnerability disclosures.

I will cover the remaining Siemens and Schneider advisories and updates that were published Tuesday, but not yet covered by NCCIC-ICS in Part 2.

Blackberry Advisory - Blackberry published an advisory describing three vulnerabilities in their Protect for Windows product.

Draeger Advisory - Draeger published an advisory discussing the NUCLEUS:13 vulnerabilities.

ODA Advisory - Incibe Cert published an advisory describing nine vulnerabilities in the ODAViewer.

HPE Advisory #1 - HPE published an advisory describing an arbitrary code execution vulnerability in their ProLiant Gen10 Plus Servers.

HPE Advisory #2 - HPE published an advisory describing 15 vulnerabilities in their ProLiant and Apollo Gen10 and Gen10 Plus servers.

HPE Advisory #3 - HPE published an advisory discussing  three vulnerabilities in their ProLiant, Apollo, Synergy Gen10 and Gen10 Plus Servers.

HPE Advisory #4 - HPE published an advisory discussing an escalation of privilege vulnerability in their ProLiant, Apollo, Edgeline, and Synergy Servers.

Milestone Advisory - Milestone published an advisory describing an arbitrary file access vulnerability in their XProtect DLNA server.

Phoenix Contact Advisory - Phoenix Contact published an advisory describing two vulnerabilities in their FL MGUARD 1102/1105 products.

QNAP Advisory - QNAP published an advisory describing a cross-site scripting vulnerability in their NAS running QmailAgent.

VMware Advisory #1 - VMware published an advisory describing a privilege escalation vulnerability in their vCenter Server.

VMware Advisory #2 - VMware published an advisory discussing a denial-of-service vulnerability in their Tanzu Application Service for VMs.

CODESYS Update - CODESYS published an update for their V2 web server advisory that was originally published on October 25, 2021.

TCP/IP Vulnerability Report - Forescout published an overview report on the recent spate of TCP/IP stack vulnerability reports.

For more details on these advisories and updates, including links to 3rd party reports, researcher reports and exploits, see my article at CSFN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11 - subscription required.

Tuesday, April 13, 2021

15 Advisories Published – 4-13-21

Today CISA’s NCCIC-ICS published 15 control systems security advisories for products Siemens (12), JTEKT, Advantech, and Schneider Electric. One of the Siemens advisories also affects products from Milestone and another also affects products from PKE.

Milestone Advisory

This advisory describes a use of hard-coded cryptographic key in the Siemens Siveillance (Milestone) Video Open Network Bridge (ONVIF). The vulnerability was reported by Milestone PSIRT. Siemens has a hot fix and Milestone has an update to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an authenticated remote attacker to retrieve and decrypt all user credentials stored on the ONVIF server.

Nucleus Advisory #1

This advisory describes a use of insufficiently random variables vulnerability in the Siemens Nucleus DNS module. This is one of the NAME:WRECK DNS vulnerabilities reported by Forescout and JSOF. Siemens has generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to poison the DNS cache or spoof DNS resolving.

SIMOTICS Advisory

This advisory describes four vulnerabilities in the Siemens SIMOTICS CONNECT 400. The vulnerabilities were self-reported. These are NAME:WRECK vulnerabilities in the third-party Mentor DNS Module. Siemens has a new version that mitigates the vulnerabilities.

The four reported vulnerabilities are:

• Improper null termination - CVE-2020-27736,

• Out-of-bounds read - CVE-2020-27737, and

• Access of memory location after end of buffer - CVE-2020-27738 and CVE-2021-25677

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to poison the DNS cache or spoof DNS resolving.

Tecnomatix Advisory

This advisory describes an out-of-bounds write in the Siemens Tecnomatix RobotExpert. The vulnerability was reported by Francis Provencher via the Zero Day Initiative. Siemens has a new version that mitigates the vulnerability. There is no indication that Provencher has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow remote code execution.

TIM Advisory

This advisory describes 14 vulnerabilities in the Siemens TIM 4R-IE. This is a third-party vulnerability (ntp.d in SNTP). The vulnerabilities are self-reported.

The 14 reported vulnerabilities are:

• Incorrect type conversion or cast - CVE-2015-5219,

• Improper input validation (4) - CVE-2015-7855 (exploit), CVE-2015-7705, CVE-2015-8138, and CVE-2016-1547,

• Improper authentication (2) - CVE-2015-7871 and CVE-2016-4953

• Security features - CVE-2015-7973,

• Null pointer dereference - CVE-2015-7977,

• Data processing errors (2) - CVE-2015-7979 and CVE-2016-1548,

• Exposure of sensitive information to an unauthorized actor - CVE-2016-1550, and

• Race condition - CVE-2016-4954

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to compromise the confidentiality, integrity, and availability of the device.

PKE Advisory

This advisory describes twelve vulnerabilities in the Siemens (and PKE) Control Center Server (CCS). The vulnerabilities were reported by Raphaƫl Rigo of Airbus Security Lab. Siemens (and PKE) has new versions that mitigate the vulnerabilities. There is no indication that Rigo has been provided an opportunity to verify the efficacy of the fix.

The 12 reported vulnerabilities are:

• Cleartext storage of sensitive information in GUI - CVE-2019-13947,

• Improper authentication (2) - CVE-2019-18337 and CVE-2019-18341

• Relative path traversal - CVE-2019-18338,

• Use of a broken or risky cryptographic algorithm - CVE-2019-18340,

• Exposed dangerous method or function - CVE-2019-18342,

• Path traversal - CVE-2019-19290,

• Cleartext storage in a file or on a disk - CVE-2019-19291,

• SQL Injection - CVE-2019-19292,

• Cross-site scripting (2) - CVE-2019-19293 and CVE-2019-19294, and

• Insufficient logging - CVE-2019-19295

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to read and write arbitrary files and sensitive data and execute commands and arbitrary code.

NOTE: These vulnerabilities were removed from earlier Siemens Advisories, SSA-761617 and SSA-844761.

LOGO! Advisory

This advisory describes two vulnerabilities in the Siemens LOGO! engineering software products. The vulnerabilities were reported by Mashav Sapir from Claroty. Siemens provides generic workarounds to mitigate the vulnerabilities.

The two reported vulnerabilities are:

• Path traversal - CVE-2020-25243, and

• Uncontrolled search path element - CVE-2020-25244

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a local attacker to take over the system where the software is installed.

NOTE: Someone slipped up on the listing of ‘Equipment’ and ‘Vulnerability’ in the ‘Executive Summary’ section of the advisory.

SINEMA Advisory

This advisory describes two vulnerabilities in the Siemens SINEMA Remote Connect Server. These are third-party vulnerabilities (libxml2). Siemens has a new version that mitigates the vulnerabilities.

The two reported vulnerabilities are:

• Missing release of resource after effective lifetime - CVE-2019-19956, and

• Infinite loop - CVE-2020-7595

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to cause a memory leak or an infinite loop situation resulting in a denial-of-service condition.

SCALANCE Advisory

This advisory describes two vulnerabilities in the Siemens Web Server of SCALANCE X200. The vulnerabilities are self-reported. Siemens has a new version that mitigates the vulnerabilities.

The two reported vulnerabilities are:

• Heap-based buffer overflow - CVE-2021-25668, and

• Stack-based buffer overflow - CVE-2021-25669

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to cause a buffer overflow condition resulting in remote code execution.

Solid Edge Advisory

This advisory describes five vulnerabilities in the Siemens Solid Edge software tools. The vulnerabilities were reported by Francis Provencher and rgod via ZDI. Siemens has updates that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Out-of-bounds write - CVE-2020-28385, CVE-2021-25678, CVE-2021-27380,

• Untrusted pointer dereference - CVE-2020-26997, and

• Stack-based buffer overflow - CVE-2021-27382

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerabilities to lead to a crash, arbitrary code execution, or data extraction on the target host system.

Nucleus Advisory #2

This advisory describes two infinite loop vulnerabilities in the Siemens Nucleus products. The vulnerabilities were self-reported. Siemens has a new version for one of the affected products that mitigates the vulnerabilities.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to cause a denial-of-service condition.

Nucleus Advisory #3

This advisory describes two vulnerabilities in the Siemens Nucleus DNS module. These are two of the NAME:WRECK DNS vulnerabilities reported by Forescout and JSOF. Siemens provides generic work arounds to mitigate the vulnerabilities.

The two reported vulnerabilities are:

• Out-of-bounds write - CVE-2020-15795, and

• Use of out-of-range pointer offset - CVE-2020-27009

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow a denial-of-service condition or for the execution of code remotely.

NOTE: There were two additional Siemens’ advisories published today that were not covered by NCCIC-ICS. If they are not covered on Thursday, I will address them on Saturday.

JTEKT Advisory

This advisory describes an improper resource shutdown or release vulnerability in the JTEKT TOYOPUC products. The vulnerability was reported by Younes Dragoni from Nozomi Networks. JTEKT has provided generic mitigation measures.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an unauthorized user to stop Ethernet communications between devices from being established.

Advantech Advisory

This advisory describes an incorrect permission assignment for critical resources in the Advantech WebAccess/SCADA. The vulnerability was reported by Chizuru Toyama of TXOne IoT/ICS Security Research Labs of Trend Micro. Advantech has a new version that mitigates the vulnerability. There is no indication that Toyama has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to login as an ‘admin’ to fully control the system.

Schneider Advisory

This advisory describes an improper restriction of XML external entity reference vulnerability in the Schneider SoMachine Basic products. The vulnerability was reported by Gjoko Krstikj of Applied Risk. Schneider has a new product that replaces the affected product and has updated the mitigation measures.

NOTE 1: This is actually based upon an update to a Schneider advisory that was published on May 22nd, 2018.

NOTE 2: Schneider also published two advisories and two other updates today. If they are not covered by NCCIC-ICS on Thursday, I will address them here on Saturday.

Sunday, February 14, 2021

Public ICS Disclosures – Week of 2-6-21 – Part 2

Now I will consider the advisories listed in the monthly tranche of disclosures (original and updates) from Siemens and Schneider that were not reported by NCCIC-ICS this week.

Siemens Advisory

Siemens published an advisory that describes a predictable exact value from previous values vulnerability in their Mentor Nucleus ReadyStart and Nucleus NET modules. The vulnerability was reported by Daniel dos Santos from Forescout Technologies. Siemens has an update for some of the affected products that mitigates the vulnerability. There is no indication that dos Santos has been provided an opportunity to verify the efficacy of the fix.

NOTE: This vulnerability is the apparently the same one that NCCIC-ICS reported in section 3.2.9 of ICSA-21-042-01, Multiple Embedded TCP/IP stacks. That is not, however, currently reflected in the NVC-NIST listing, which lists a different CWE than reported by CISA. And the NCCIC-ICS advisory does not list or link to this advisory.

Schneider Advisory

Schneider published an advisory that describes three vulnerabilities in its PowerLogic power metering products. These vulnerabilities are self-reported. Schneider has new versions for some of the affected products that mitigates the vulnerabilities.

The three reported vulnerabilities are:

• Cross-site request forgery - CVE-2021-22701, and

• Clear-text transmission of sensitive information (2) - CVE-2021-22702 and CVE-2021-22703.

Siemens Updates

Siemens published an update to their GNU/Linux subsystem advisory that was originally published in 2018 and most recently updated on December 8th, 2020. The new information includes adding the following new CVE’s:

• CVE-2020-1971,

• CVE-2020-8694,

• CVE-2020-15437,

• CVE-2020-25704,

• CVE-2020-29361,

• CVE-2020-29362,

• CVE-2020-29363,

• CVE-2020-29369,

• CVE2020-29660,

• CVE-2020-29661,

• CVE-2020-35448,

• CVE-2020-36221,

• CVE-2020-36222,

• CVE-2020-36223,

• CVE-2020-36224,

• CVE-2020-36225,

• CVE-2020-36226,

• CVE-2020-36227,

• CVE-2020-36228,

• CVE-2020-36229,

• CVE-2020-36230, and

• CVE2021-21120

NOTE: The last corrective action listed was the introduction of v 2.8.4 in December of 2020.

 

Siemens published an update to their CodeMeter advisory that was originally published on September 8th, 2020 and most recently updated on January 12th, 2020. The new information includes updating mitigation information for SPPA S3000 (with fixes for the open CVEs).

NOTE: NCCIC-ICS does not update their CodeMeter advisory for changes in vendor advisories since the NCCIC-ICS advisory links to the latest version of the vendor advisory.

 

Siemens published an update to their SCALANCE click-jacking advisory that was originally published on February 11th, 2020. The new information includes adding mitigation measures for the SCALANCE X-200IRT switch family.

Schneider Update

Schneider published an update for their SNMP Service on Modicon M340 advisory that was originally published on December 12th, 2020. The new information includes:

• Adding BMXNOC0401 as an affected product, and

• Adding mitigation measures for BMXNOR0200H


Thursday, February 11, 2021

2 Advisories and 1 Update Published – 2-11-21

Today CISA’s NCCIC-ICS published two control system security advisories for products from Rockwell and multiple embedded TCP/IP stacks.

Rockwell Advisory

This advisory describes an uncontrolled search path element vulnerability in the Rockwell DriveTools SP and Drives AOP. The vulnerability was reported by Claroty and Cognite, Rockwell has an update that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker with local access could exploit the vulnerability resulting in privilege escalation and complete control of the system.

TCP/IP Stacks Advisory

This advisory describes nine separate use of insufficiently random values vulnerabilities in multiple open-source and proprietary TCP/IP stacks. The vulnerabilities (nicknamed NUMBER:JACK) were reported by Daniel dos Santos, Stanislav Dashevskyi, Jos Wetzels, and Amine Amri of Forescout Research Labs. Some the affected vendors have new versions that mitigate the vulnerability in their TCP/IP stack.

The nine reported CVE’s (each generally associated with a separate TCP/IP stack vendor) are:

• CVE-2020-27213 - Nut/Net 5.1 - Patch in progress

• CVE-2020-27630 - uC/TCP-IP 3.6.0 - Patched in the latest version of Micrium OS (successor project),

• CVE-2020-27631 - CycloneTCP 1.9.6 - Patched in version 2.0.0,

• CVE-2020-27632 - NDKTCPIP 2.25 - Patched in version 7.02 of Processor SDK,

• CVE-2020-27633 - FNET 4.6.3 - Documentation updated to warn users and recommend implementing their own PRNG [pseudorandom number generator],

• CVE-2020-27634 - uIP 1.0 Contiki-OS 3.0 Contiki-NG 4.5 - No response from maintainers,

• CVE-2020-27635 - PicoTCP 1.7.0 PicoTCP-NG - Version 2.1 removes the default (vulnerable) implementation and recommends users implement their own PRNG,

• CVE-2020-27636 - MPLAB Net 3.6.- Patched in version 3.6.4.

• CVE-2020-28388 Nucleus NET 4.3 -Patched in Nucleus NET 5.2 and Nucleus ReadyStart v2012.12.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to hijack or spoof TCP connections, cause denial-of-service conditions, inject malicious data, or bypass authentication.

NOTE: The “NUMBER:JACK” report explains that “Forescout Research Labs has released an open source script that uses active fingerprinting to detect which stack a target device is running.” {pg 6}.

Commentary: Oh this is going to be a fun one. I foresee lots of equipment vendor advisories in the works as everyone scrambles to try to fix this mess. BTW, the Report notes that an attack on this type of vulnerability in the old IT world was known as a Mitnick Attack.

CodeMeter Update

This update provides new information on an advisory that was originally published on September 8th, 2020 and most recently updated on December 3rd, 2020. The new information includes adding links to the vendor alert from Drager.

 
/* Use this with templates/template-twocol.html */