Showing posts with label Full Disclosure. Show all posts
Showing posts with label Full Disclosure. Show all posts

Saturday, December 2, 2017

Public ICS Disclosure – Week of 11-25-17

This week there were two industrial control system vulnerability disclosures on the Full Disclosure web site. They addressed products from Hikvison and CODESYS.

Hikvision Vulnerability


This report by IOT Sec describes a Wi-Fi access vulnerability in Hikvision Wi-Fi IP Cameras installed in a wired configuration. A default wireless SSID exists in the products with a setting of no WiFi encryption or authentication.

This disclosure was coordinated with Hikvision. No fix has been reported but a work around was described.

The disclosure timeline reported by IOT Sec includes an unsuccessful attempt to coordinate the vulnerability with ICS-CERT {as recommended by (US-?)CERT}. While IP cameras are only industrial control systems in the broadest sense, ICS-CERT has posted advisories for these products in the recent past (including some of the specific devices included in this report). I am very surprised that ICS-CERT did not respond to IOT Sec; I would hope that this was due to miscommunications issues, not bureaucratic inaction.

CODESYS Vulnerability



This report by SEC Consult describes an improper authentication vulnerability in the CODESYS WAGO PFC 200 Series. This appears to be an extension of a previously reported vulnerability. ICS-CERT reported on that advisory that it would affect products from as many as 260 other vendors that used the affected code. This disclosure was a coordinated with CODESYS and SEC Consult reports that CODESYS will release a patch next month.

Saturday, September 10, 2016

Public ICS Vulnerability Disclosures – 9-10-16

There were two interesting public (uncoordinated?) disclosures of control system vulnerabilities this week over at the Full Disclosure mailing list. Both were from Karn Ganeshen.

The first describes multiple vulnerabilities in the Powerlogic/Schneider Electric IONXXXX series Smart Meters. The reported vulnerabilities include:

• No access control
• Vulnerable to Cross-Site Request Forgery; and
• Weak Credential Management

The second describes multiple vulnerabilities in the ELNet Energy & Electrical Power Meter. He reported vulnerabilities include:

• Unauthenticated Web Management access;
• Weak Credential Management; and
• Password Recovery Functionality

Thanks to ‏@infracritical for tweeting about these vulnerabilities (here and here).


Both disclosures were late in the week. We may see (hopefully) ICS-CERT alerts on these next week.
 
/* Use this with templates/template-twocol.html */