Showing posts with label GE Proficy. Show all posts
Showing posts with label GE Proficy. Show all posts

Tuesday, July 12, 2016

ICS-CERT Publishes Two Advisories

Today the DHS ICS-CERT published two control system security advisories for products from GE and Tollgrade.

GE Proficy Advisory


This advisory describes an improper privilege management vulnerability in earlier versions of the GE Proficy HMI/SCADA CIMPLICITY application. The vulnerability was reported by Zhou Yu of Acorn Network Security. GE notes that subsequent versions of the application do not contain the vulnerability, having been corrected by August 2014.

ICS-CERT reports that local access is required or that a remote exploit would require a social engineering attack. Exploit code is publicly available (link not provided in ICS-CERT Advisory).

The GE Product Security Advisory for this vulnerability recommends upgrading to a newer version of the application, but it also provides commands that serve to mitigate the vulnerability in the affected versions.

Tollgrade Advisory


This advisory describes three vulnerabilities in the Tollgrade Communications, Inc. Smart Grid LightHouse Sensor Management System (SMS) Software EMS. The vulnerabilities were reported by Ashish Kamble of Qualys, Inc. Tollgrade has produced a new version that mitigates the vulnerabilities. ICS-CERT reports that Kamble has tested the new version to verify the efficacy of the fix.

The vulnerabilities are:

• Missing authentication for critical application - CVE-2016-5790;
• Information exposure through an error message - CVE-2016-5797; and
• Forced browsing - CVE-2016-5807

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerabilities to restart the system, brute force a login, or change privileged parameters.

Friday, January 24, 2014

ICS-CERT Publishes GE Proficy Advisory

Yesterday the DHS ICS-CERT published an advisory for twin path traversal vulnerabilities reported in the GE Proficy CIMPLICITY application by amisto0x07 and Z0mb1E. The disclosure was coordinated through the Zero Day Initiative (ZDI). A patch has been developed by GE for one of the vulnerabilities and a configuration change has been suggested for the other. There is no indication that the researchers have validated the efficacy of these mitigation measures.

ICS-CERT notes that a moderately skilled attacker could remotely exploit either of these vulnerabilities to execute arbitrary code on the system.

GE has published two advisories (GEIP13-05 and GEIP13-06) that discuss the vulnerabilities in more detail and explain the mitigation measures.

GEIP13-05 – No Patch

This GE Advisory notes that the vulnerability is due to a single component (gefebt.exe) and recommends that ‘all copies’ of the file be deleted. The advisory provides information about where copies of the file should be found in the server directories and on the server web pages.

The advisory notes that making these changes will disable links on the default home page on the CIMPLICITY system that allow users to “to browse CIMPLICITY projects and view alarms, points, screens and objects”. To regain this functionality, the default home pages will have to be re-created using the “Create Webpage” option.

This could be a very complex remediation.

GEIP13-06 – Patch Available

The second advisory provides a link for a patch to CIMPLICITY version 8.2. It notes that users of versions earlier than 8.2 should upgrade to version 8.2. Interestingly, versions 4.0 and earlier are not affected by either of these vulnerabilities.

GE provides two other mitigation options as alternatives to updating or applying the patch to version 8.2. If web –based HMI functionality is not need, they provide the option of disabling that functionality. If that functionality is required there is the option of using an alternative web server, IIS web server instead of the vulnerable CimWebServer.exe.

Delayed ICS-CERT Notification

Joel Langill notes that OSVDB has been reporting this vulnerability since the middle of December. The GE advisories are also dated from the same point in time and both note that public disclosure of the vulnerabilities was expected by December 31st.


There is no explanation in the ICS-CERT advisory as to why it has taken them so long to report this vulnerability. These delays are becoming increasingly common with ICS-CERT advisories. More importantly it is becoming more common for ICS-CERT to ignore or miss reports of ICS vulnerabilities all together. Perhaps it is time for Congress to exercise their oversight responsibility and look into the operations of ICS-CERT.

Tuesday, November 19, 2013

Identical Twin ICS-CERT DNP3 Advisories Published

Today the DSH ICS-CERT published two virtually identical DNP3 advisories for twin improper input validation vulnerabilities in Catapult Software DNP3 Drivers and GE Proficy platform. The reason that they are nearly identical is because the Proficy vulnerability is due to the use of the Catapult Software drivers. Since these are familiar DNP3 vulnerabilities, it should come as no surprise that they were first reported by the team of Crain and Sistrunk. Technically, GE self-reported their vulnerability when notified of the problem by Catapult Software.

These are the same IP-based and serial-based validation vulnerabilities that we have seen before in similar Crain-Sistrunk based advisories. ICS-CERT reports that the IP-based vulnerability has a higher CVSS v2 base score (7.1 vs 4.7) but that reflects the fact that the IP-based vulnerability can be more easily exploited remotely. Many cybersecurity commentators (though certainly not all) note that physically accessing the serial connection may actually be easier at remote, low-security sites.

Catapult Software has produced updated software that mitigates both their system vulnerabilities and the Proficy vulnerabilities. The Catapult advisory does report that Crain and Sistrunk have validated the efficacy of the new software version. While that is not specifically mentioned in the GE advisory, I would assume that the same validation applies to the Proficy issues.

The Automatak web site reports these vulnerabilities as numbers 10 and 11 of the 25 vulnerable systems that they have discovered. I wonder how many of the remaining 14 are also based upon either the Catapult system or the earlier Triangle Microworks library. Both have obviously been made available (sold) to other vendors. Of course, it is also possible that Crain and Sistrunk have not yet found all of the system vulnerabilities since they have apparently stopped looking for these vulnerabilities; no challenge left I suppose.

Hopefully, any unidentified DNP3 vendors will take the leads posted by these two and self-correct and self-report their problems without being identified by Project Robus.

NOTE: A quick update from an Adam Crain Tweet® - None of the remaining vulns are catapult related. Should probably read 11/26 now, but we've kinda stopped counting.

Wednesday, January 23, 2013

ICS-CERT Publishes 2 GE Proficy Advisories and Updates ICS TIP


Yesterday the DHS ICS-CERT published two advisories for GE Proficy products and updated for a second time their TIP sheet about “Targeted Cyber Intrusion Detection and Mitigation Strategies”. I know that the Control System Security Program web page shows three GE advisories issued today, but a closer look shows that two of them are for the same advisory. [NOTE: As of 13:00 EST on 1-23-13 this has been corrected.]

ICS TIP


Back in May of last year, ICS-CERT issued the first of their technical information papers (TIP) concerning actions to be taken when corporate networks are thought to have been attacked. ICS-CERT updated the TIP in July by adding a section on Credential Management. This latest update makes revisions to the same section; based largely in differences in new versions of Windows® software. Some of the specific changes include:

• Added a link to recent Microsoft guidance on protecting user credentials;

• Expanded the discussion about privileged accounts; and

• Removed the discussion about cached credentials;

GE Information Portal Advisory


In this advisory GE has self-reported two information disclosure vulnerabilities in its Proficy Information Portal application. ICS-CERT reports that a relatively low skilled attacker could remotely exploit either of these vulnerabilities and acquire configuration information about the system including potentially user names and passwords via calls to Port80/TCP.

GE has published two security advisories (GEIP12-14 and GEIP12-15) that explain how to make the necessary configuration changes to address these vulnerabilities.

GE Cimplicity Advisory


In this advisory GE has self-reported two vulnerabilities in its Cimplicity products. The two remotely exploitable vulnerabilities are:

• A directory traversal vulnerability; and

• An improper input validation vulnerability.

ICS-CERT reports that either vulnerability could be remotely executed by a relatively low skilled attacker. The directory traversal vulnerability could allow the attacker to view or download files from the server. The input validation vulnerability could allow the attacker to execute arbitrary commands.

GE has created patches and developed configuration changes to address these vulnerabilities. Information is available in security advisories GEIP12-13 and GEIP12-19.

Additional Information


As is usual in producing these advisories, ICS-CERT provides additional generic information about the protection of control systems. Among the standard items listed is a reference to their TIP “Targeted Cyber Intrusion Detection and Mitigation Strategies” that I mentioned earlier in this post. Interestingly, both of these GE advisories reference the July 2012 version of the TIP, not the version released yesterday. To be fair they were both issued earlier in the day than was the newest version of the TIP, but a little bit better internal coordination could have provided more up-to-date information.

Tuesday, October 16, 2012

GE Proficy Advisory from ICS-CERT


Yesterday afternoon the DHS ICS-CERT published an advisory for multiple vulnerabilities in the GE Intelligent Platforms Proficy Real-Time Information Portal. The vulnerabilities were reported by Kuang-Chun Hung of Information and Communication Security Technology Center (ICST) in a coordinated disclosure and had previously been published on the US-CERT secure Portal library.

The Vulnerabilities


Three separate improper input validation vulnerabilities could allow a skilled attacker to remotely execute a denial of service (DoS) attack. GE has provided patches for three of the affected versions (3.0 SP1 SIM 44, 3.5 SIM 17, and 3.5 SP1 SIM 1). Owners of earlier versions are encouraged by GE to upgrade to newer, patched versions of the system.

Upgrading Industrial Control Systems


We are seeing an increasing number of notices about having to upgrade older versions of ICS products to get security fixes put into place. In many ways this is to be expected. A vendor has to make a business decision as to where they are going to expend valuable programming assets, fixing old products or producing new products. In IT systems, this is not nearly the problem that it is in ICS products since we have come to expect having to buy new systems on a frequent basis to deal with new versions of operating systems.

ICS owners, on the other hand, have invested money in their control systems that they expected to see remain in operation for a long time; an eternity in IT-system years. In addition, they have to consider the compatibility of the new control system version with a large number of existing peripheral devices. Even where compatibility may have been assured, modifications made on-site to control devices may render them incompatible with the new system.

Even when the new systems are ‘completely compatible’ with existing equipment, control-systems are not operating in a plug-and-play environment like we see in modern IT systems. Extensive tuning may be required before the control system operates effectively, and multiple iterations of that tuning may be required because of process interactions with other devices.

Making the decision to upgrade to a new version of a control system is not a decision to be made lightly. Vendors should also realize that many organizations, when forced to make such a decision, may decide that it makes for an opportune time to change vendors. I have been in an organization that made just such a decision; the time and effort that would have been required to upgrade was not that much different than that for going to a new system. The other vendor had capabilities that we had wanted to add to our system, but was not worth the hassle of a change on their own. We figured that since we were changing anyway we might as go all the way.

Thursday, June 28, 2012

ICS-CERT Publishes Two Advisories and a new Luigi Alert


Yesterday the DHS ICS-CERT published a new advisory (GE Intelligent Platforms Proficy products), an advisory updating an earlier Luigi alert (Pro-Face Pro-Server) and an alert for new uncoordinated Luigi reported vulnerabilities (Sielco Sistemi Winlog).

GE Proficy Advisory


This advisory is based upon a command injection vulnerability reported by Andrea Micalizzi and the subsequent discovery (by GE Intelligent Platforms) of a stack-based buffer overflow in a third-party HTML help application used by some GE Intelligent Platforms Proficy products. Both vulnerabilities are remotely exploitable by a moderately skilled attacker utilizing a social engineering attack. The folks at GE are to be commended for going the extra step in discovering and identifying the additional vulnerability.

GE recommends unregistering and deleting the KeyHelp.ocx ActiveX control and has provided product specific instructions for doing so.

As with any vulnerability in a third-party provided component of an ICS system, one has to wonder what other vendors have used the same component in their product. One would suspect that any such system would have the same vulnerabilities as those identified here.

Pro-Face Advisory


This advisory is a close-out of an alert issued in May for an uncoordinated vulnerability-disclosure made by Luigi. That alert identified five separate remotely-exploitable vulnerabilities:

• Memory Corruption (2);

• Integer Overflow;

• Unhandled Exception; and

• Invalid Memory Read Access.

The Advisory reports that Digital Electronics, the developer/manufacturer of the Pro-Face line, has released patch modules for the affected systems. The Advisory describes the patch this way:

“The patch module prevents the Pro-Server EX and WinGP from an attack using inaccurate packets.”

This wording is odd because only one of the vulnerability descriptions mentions the use of packets in the exploitation of the vulnerability. This combined with the lack of a report that the mitigation has been verified by Luigi or ICS-CERT makes one wonder about the efficacy of the mitigation. Digital Electronics has apparently addressed this issue by recommending:

• A review of all network configurations for control system devices;

• The removal of unnecessary PCs from control system networks; and

• The removal of unnecessary applications from control system networks.

All of these are appropriate recommendations for any control system, but are hardly effective mitigation measures for these identified vulnerabilities. Especially since Luigi always publishes proof of concept exploit codes. This is very poor security support.

Sielco Sistemi Alert


This ICS-CERT alert addresses the latest report of ICS vulnerabilities by Luigi. Luigi identified multiple vulnerabilities when the software is configured to allow the system to act as a TCP/IP server. Those vulnerabilities include:

• Multiple buffer overflows;

• Directory traversal;

• Improper access of indexable resource; and

• Write-what-where condition.

As always Luigi provides proof-of-concept exploit code on his web site.

Tuesday, November 29, 2011

ICS-CERT Publishes Two Luigi Vulns – Old and New

Today the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published two reports on two Luigi reported vulnerabilities. The first is an alert for a new vulnerability MICROSYS, spol. sr.o. PROMOTIC, a Czech SCADA HMI. The second is an update on an older advisory on the GE Proficy system.

PROMOTIC Alert


The PROMOTIC alert is a bit unusual in that it does not involve a remotely exploitable vulnerability. It is a use-after-free vulnerability that requires the loading of a ‘specially crafted’ project file. That file causes the program to terminate allowing an opportunity to execute code after the allocated resources are freed up.

Luigi provides detailed information on his web page about this vulnerability.

BTW: Luigi was kind enough to post a comment to yesterday’s ICS-CERT related post providing a link to the Optima vulnerability information on his web page.

GE Proficy Update


ICS-CERT updated their GE Proficy Historian advisory simply to provide notice that Luigi was the researcher who initially discovered this vulnerability. Since this was technically a coordinated disclosure that Luigi worked through the Zero Day Intiative (ZDI), it is appropriate that he be given appropriate credit.

Looking at the ZDI web site for this vulnerability, it looks like they gave Luigi credit all along, so it seems odd that the folks at ICS-CERT overlooked giving him credit for this long. Oh well, better late than never…

Wednesday, November 2, 2011

ICS-CERT Updates Duqu – Issues 3 GE Proficy Advisories

Yesterday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) issued an updated alert for Duqu and three separate advisories for the GE Proficy system.

W.32 Duqu Alert Update


The fourth update (third public update) of the Alert ICS-CERT originally published on October 21st and is based upon new information provided by Symantec and the Laboratory of Cryptography and Systems Security (CrySyS) of the Budapest University of Technology and Economics (the original discoverer and namer of Duqu in the wild). Symantec’s ver 1.3 of their Duqu White Paper provides more detailed information. The ICS-CERT update does note that they are in the process of drafting an Duqu Advisory.

The good news is that a dropper for the malware has been identified. Unfortunately it is a zero-day kernel vulnerability in MS Word that allows the malware to be sent as a Word document (.doc) so we now have malware delivery systems using .PDF and .DOC files. Social engineering attacks just became that much more effective.

Another piece of good news is that another C&C server has been identified and removed from the Internet, this time in Belgium. The bad news is that researchers have identified a Stuxnet-like peer-to-peer network communications protocol that allows a machine to contact the C&C server remotely. This makes it more difficult to identify an infected machine by its communications with the C&C server.

The real bad news in all of this is that W32.Duqu is apparently continuing to evolve. The good news is that there is still no indication of any actual attacks on control systems or positive identification of control system information being targeted. Keep your fingers crossed, your AV signatures up to date, and actively monitor your networks.

GE Intelligent Platform Proficy Advisories


ICS-CERT issued separate advisories on three different components of the GE Proficy platform. The components are:


Historian Web Administrator – Multiple cross-site scripting vulnerabilities, CVE-2011-3320; and

Historian Data Archiver – Buffer overflow vulnerability, CVE-2011-1918

All three advisories were previously issued on the US-CERT secure portal on August 31, 2011 to “allow users time to download and install the update” (from ‘Overview’ section on all three Advisories). Does it seem odd to anyone else that GE customers needed 2 months to download and install updates?

All three sets of vulnerabilities would allow remote exploitation by a moderately skilled attacker, but there are no known exploits available. Software improvement modules (updates) are available for all three sets of vulnerabilities.

Interestingly all three of these advisories were based upon disclosures to ICS-CERT from GE Intelligent Platforms. No word if they discovered these internally or if an outside researcher coordinated the disclosures directly with GE instead of directly contacting ICS-CERT.
 
/* Use this with templates/template-twocol.html */