Showing posts with label Fortiphyd Logic. Show all posts
Showing posts with label Fortiphyd Logic. Show all posts

Saturday, May 18, 2019

2 Advisories Published – 05-16-19


On Thursday the DHS NCCIC-ICS published two control system security advisories for products from Fuji Electric and Schneider Electric.

Fuji Advisory


This advisory describes an out-of-bounds read vulnerability in the Fuji Alpha7 PC Loader motor controller. The vulnerability was reported by kimiya of 9SG Security Team via the Zero Day Initiative. Fuji has a new version that mitigates the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to crash the device..

Schneider Advisory


This advisory describes a use of insufficiently random values vulnerability in the Schneider Modicon M580, Modicon M340, Modicon Premium, and Modicon Quantum products. The vulnerability was reported by David Formby and Raheem Beyah of Fortiphyd Logic and Georgia Tech. Schneider has a firmware update available for one of the products and has provided generic workarounds for the others. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to to hijack TCP connections or cause information leakage.

Tuesday, May 23, 2017

ICS-CERT Publishes 3 Advisories

Today the DHS ICS-CERT published two industrial control system advisories for products from Rockwell and Moxa. They also published a medical control system advisory for products from B Braun Medical. The Rockwell advisory was previously published on the NCCIC Portal on April 25th, 2017. The Braun Medical advisory was previously published on the NCCIC Portal on March 23rd, 2017l

B Braun Medical Advisory


This advisory describes an open redirect vulnerability on the B Braun Medical SpaceCom module. The vulnerability was reported by Marc Ruef and Rocco Gagliardi of scip AG. Braun has produced a software update that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to  allow URL redirection to untrusted web sites.

Rockwell Advisory


This advisory describes multiple vulnerabilities in the Allen-Bradley MicroLogix 1100 and 1400 PLCs. The three of the vulnerabilities were reported by David Formby and Raheem Beyah of Georgia Tech and Fortiphyd Logic, Inc with the last one being reported by Ilya Karpov of Positive Technologies. Rockwell has provided a firmware update for one of the affected products and recommends disabling the web server as an alternative and/or additional mitigation measure. There is no indication that the researchers have been provide an opportunity to verify the efficacy of the fix.

The reported vulnerabilities are:

• Predictable value range from previous values - CVE-2017-7901;
• Reusing a nonce, key pair in encryption - CVE-2017-7902;
• Information exposure - CVE-2017-7899;
• Improper restriction of excessive authentication attempts- CVE-2017-7898; and
• Weak password requirements - CVE-2017-7903

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerabilities  to gain unauthorized access to the affected programmable logic controllers and to spoof or disrupt TCP connections.

Moxa Advisory


This advisory describes three vulnerabilities in the Moxa OnCell IP gateways. The vulnerabilities were reported by Maxim Rupp. Moxa reports that the latest version of two of the products mitigate the vulnerabilities and provides a work around for the remainder. There is no indication that Rupp was provided an opportunity to verify the efficacy of the fix.

The reported vulnerabilities are:

• Improper restriction of excessive authentication attempts - CVE-2017-7915;
• Plain text storage of a password - CVE-2017-7913; and
• Cross-site request forgery - CVE-2017-7917


ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to allow an attacker to use brute force to determine parameters needed to access the application. An attacker may also obtain credentials by obtaining files that store passwords in clear text.

Thursday, March 30, 2017

ICS-CERT Publishes 2 Schneider Advisories and Medical IOT Alert

Today the DHS ICS-CERT published two control system advisories for products from Schneider Electric. They also published a medical control system alert for a medical lab device from Miele.

Modicon Advisory


This advisory describes multiple vulnerabilities in the Schneider Modicon PLCs. The vulnerabilities were reported by David Formby and Raheem Beyah of Georgia Tech and Fortiphyd Logic, Inc. Schneider has produced new firmware versions to mitigate two of the vulnerabilities and work arounds for the remaining vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Predictable value range from previous values - CVE-2017-6030;
• Use of insufficiently random values - CVE-2017-6026; and
• Insufficiently protected credentials - CVE-2017-6028

ICS-CER reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to spoof or disrupt Transmission Control Protocol (TCP) connections, sniff sensitive account information, and gain unauthorized access to a current web session.

Schneider has taken the unusual move of publishing separate Security Notification documents for each vulnerability (here, here, and here).

Wonderware Advisory


This advisory describes multiple vulnerabilities in the Schneider Wonderware InTouch Access Anywhere. The vulnerabilities were reported by Ruslan Habalov and Jan Bee of the Google ISA Assessments Team. Schneider has produced a new version to mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Cross-Site Request Forgery - CVE-2017-5156;
• Information Exposure - CVE-2017-5158; and
• Inadequate Encryption Strength - CVE-2017-5160

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability  to perform actions on behalf of a legitimate user, perform network reconnaissance, and gain access to resources beyond those intended with normal operation of the product.

The Schneider Security Bulletin reports a fourth vulnerability; Ability to escape out of remote InTouch applications and launch other processes. No CWE information is provided for the fourth vulnerability. Schneider also reports that the researchers have verified the efficacy of the fix.

Miele Alert


This alert describes a publicly reported path traversal vulnerability in the Miele Professional PG 8528, a large capacity cleaner and disinfector used in hospitals and laboratory settings. ICS-CERT does report that Jens Regel publicly disclosed this vulnerability without providing a link to the disclosure on the Full Disclosure web site.

The Miele press release on this vulnerability minimizes the criticality of the problem (perhaps legitimately so). What is more interesting is their comment on their failure to respond to Regel’s attempt at responsible disclosure:

“The technical aspects in this case are entirely separate from the fact that the Miele company failed to respond to several notifications regarding this issue. Executive Directors view this as a serious shortcoming, the details of which have already been investigated in depth with a view to preventing any repeat occurrence in future. They stress that they would like to thank Jens Regel, the source of this evidence, for his information – and for his perseverance.”


While the initial disclosure response was deficient, this certainly reflects a more helpful attitude of the upper management of the company.
 
/* Use this with templates/template-twocol.html */