Showing posts with label Gemalto. Show all posts
Showing posts with label Gemalto. Show all posts

Saturday, April 25, 2020

Public ICS Disclosure – Week of 4-18-20


This week we have 8 vendor advisories for products from ABB (4), Johnson Controls, Rockwell, BD and Eaton; as well as 3 updated advisories for products from ABB. There are also 3 researcher disclosures for products from P5, Rockwell and Siemens.

ABB Advisories


ABB published an advisory describing a path traversal vulnerability in their UPS Adapter CS141. The vulnerability was reported by Eduardo Cataño Conde. ABB has a new version that mitigates the vulnerability. There is no indication that Conde has been provided an opportunity to verify the efficacy of the fix.


ABB published an advisory describing five vulnerabilities in their ABB Central Licensing System. The vulnerabilities were reported by William Knowles at Applied Risk. ABB will be preparing product specific advisories for these vulnerabilities.

The five reported vulnerabilities are:

• Information disclosure - CVE-2020-8481;
• XML external entity injection - CVE-2020-8479;
• Denial of service - CVE-2020-8475;
• Privilege elevation - CVE-2020-8476; and
• Weak file permissions - CVE-2020-8471


ABB published an advisory describing the impact of their Central Licensing System Vulnerabilities (see above) on their System 800xA, Compact HMI and Control Builder Safe products. A new version of the Central Licensing System is available that mitigates some of the vulnerabilities. There is no indication that Knowles has been provided an opportunity to verify the efficacy of the fix.


ABB published an advisory describing Inter process communication vulnerability in System 800xA. The vulnerabilities were reported by William Knowles at Applied Risk. ABB has provided generic workarounds to mitigate the vulnerability while working on product updates. NOTE: ABB has requested separate CVE numbers for each affected product based upon varying levels of risk in the products.


NOTE: The ABB Alerts and Notifications page also lists two advisories for products from B&R. I have not covered them here because they were covered when they were released by B&R.

Johnson Controls Advisory


Johnson Controls published an advisory describing an XML external entity injection vulnerability in their BCPro Workstation and Building Configuration Tool (BCT) software. The vulnerability is self-reported. Johnson Controls has a patch that mitigates the vulnerability.

Rockwell Advisory


Rockwell published an advisory describing eight third-party vulnerabilities in their FactoryTalk product. The vulnerabilities are in the Gemalto Sentinal LDK Runtime Environment. The Sentinal LDK vulnerabilities were reported by Kaspersky in January of 2018. Rockwell has a new version that mitigates the vulnerabilities.

BD Advisory


BD published an advisory describing a third-party vendor outdated certificate vulnerability in a large number of their products. The problem was identified by ESET in some of their legacy products. BD is working on validating the ESET update.

Eaton Advisory


Eaton published an advisory describing a third-party vendor stack-based buffer overflow vulnerability in their products  supporting DNP3 Protocol. The Triangle MicroWorks vulnerability was reported by NCCIC-ICS (ICSA-20-105-02) last week. Eaton provided generic workarounds while it is evaluating the vulnerability and its effects on their products.

ABB Updates


ABB published an update for their System 800xA Weak File Permissions advisory that was originally published on April 2nd, 2020. The new information includes an added FAQ question on functional safety.


ABB published an update for their System 800xA Information Manager advisory that was originally published on April 2nd, 2020. The new information includes an added FAQ question on functional safety. (NOTE: includes statement that: “Under certain conditions exploits of this vulnerability may affect the integrity of safety functions in System 800xA.”)


ABB published an update for their System 800xA Weak Registry Permissions advisory that was originally published on April 2nd, 2020. NOTE: The ABB Alerts and Notifications page says that this advisory was updated on “2020-04-21” like the previous 2, but the link takes one to the original advisory with no changes. I suspect that the update should include the same added FAQ question seen in the two updates described above. The difference would be in the answer to that FAQ.


Researcher Disclosures


Zero Science published a report describing a stored cross-site scripting vulnerability in the P5 FNIP-8x16A eight channel relay module. The report includes links to an exploit published by LiquidWorm. Zero Science has attempted to contact P5 but has received no response.

Applied Risk published a report describing an insecure registry permissions vulnerability in the Rockwell RSLinx Classic. This vulnerability was reported by NCCIC-ICS on April 9th, 2020.

Applied Risk published a report describing an insecure file permissions vulnerability in the Siemens TIA Portal. This vulnerability was reported by NCCIC-ICS on January 14th, 2020 and subsequently updated on April 14th.

Saturday, December 28, 2019

Public ICS Disclosures – Week of 12-21-19


This holiday week we had two vendor disclosures from HMS and Thales Group.

HMS Advisory


HMS published an advisory describing a cross-site scripting vulnerability in their Flexy and Cosy industrial routers. The vulnerability was reported by Ander Martínez from Titanium Industrial Security. HMS has a new firmware version that mitigates the vulnerability. There is no indication that Martinez has been provided an opportunity to verify the efficacy of the fix.

Thales Advisory


Gemalto published an advisory describing a vulnerability in their Sentinel LDK License Manager. Details about the vulnerability are restricted to registered customers only.

Happy Holidays


Saturday, October 19, 2019

Public ICS Disclosures – Week of 10-12-19


This week we have four vendor disclosures for products from Phoenix Contact, ABB, Gemalto and Eaton. We also have an updated disclosure from Schneider and a report of a cyberattack from Pilz.

Phoenix Contact Advisory


Phoenix Contact published an advisory [.PDF download link] for an out-of-bounds read vulnerability in their Automationworx Suite. The vulnerability was reported by the 9sg Security Team via the Zero Day Initiative. Phoenix Contact has provided generic workarounds pending publication of a new version.

NOTE: The vulnerability was reportedly coordinate through NCCIC-ICS so an advisory from them should be forthcoming.

ABB Advisory


ABB published an advisory describing an improper authentication vulnerability in their UnoDM. The vulnerability was reported by Maxim Rupp. ABB has updates that mitigate the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

Gemalto Advisory


Gemalto announced that they have published an advisory (customer registration required for access) for a vulnerability in their Sentinel LDK License Manager when installed as a service.

NOTE: I suspect that owners of systems from other vendors that use the LDK License Manager will have to wait for notification from those vendors before they will be able to learn about this vulnerability and fixes available for it.

Eaton Advisory


Eaton published an advisory describing an undisclosed vulnerability in their CGLine+ when connected to CGVision. The vulnerability is self-reported. Eaton has a new version that mitigates the vulnerability.

Schneider Update


Schneider published an update of their URGENT/11 advisory. The new information includes updated version information and mitigation links for:

SCADAPack 57x RTUs; and
SAGE RTU

Pilz Cyberattack


Pilz is currently reporting that: “Since Sunday, October 13, 2019, all server and PC workstations including the communication network of the automation company have been affected worldwide. The website is currently only partially functional.”

They also note that: “Data sent to us by partners and customers have not been lost or misappropriated by third parties. At the current time, however, we cannot completely exclude this.”

NOTE: Both quotes are Google Translations from German.

Saturday, June 8, 2019

Public ICS Disclosures – Week of 06-01-19


This week we have five vendor disclosures for products from Gemalto, ABB (3), and TECSON/GOK. There is also one new Windows® RDP advisory from a vendor.

RDP Vulnerability Disclosures



Gemalto Advisory


Gemalto published an advisory describing a DLL vulnerability in the Gemalto Sentinel SuperPro, Sentinel Hardware Keys and Sentinel UltraPro Products. Details are only available to registered customers.

ABB Advisories


1. ABB has published an advisory describing multiple vulnerabilities in the ABB CP635
HMI. The vulnerabilities were reported by Xen1thLabs. ABB has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

Outdated software components;
Hard-coded credentials; and
Absence of signature verification

2. ABB has published an advisory describing multiple vulnerabilities in the ABB PB610. The vulnerabilities were reported by Xen1thLabs. ABB has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

Hidden administrative accounts;
HTTP server authentication bypass;
FTP server path traversal;
HTTP server uncontrolled format string;
FTP server uncontrolled format string; and
HTTP server stack-based buffer overflow

3. ABB has published an advisory for multiple vulnerabilities in the ABB CP651 HMI. The vulnerabilities were reported by Xen1thLabs. ABB has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

Outdated software components;
Hard-coded credentials; and
Absence of signature verification.

TESCON/GOK Advisory


CERT VDE published an advisory describing an improper access control vulnerability in the TESCON/GOK type LX-Net, LX-Q-Net, e-litro net, SmartBox4 LAN and SmartBox4 pro LAN devices. The vulnerabilities were reported by Maxim Rupp. TESCON/GOK has a new firmware version that mitigates the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

Saturday, May 4, 2019

Public ICS Disclosures – Week of 04-25-19


This week we have two vendor disclosures on security products from Cisco and Gemalto.

Cisco Advisory


Cisco published an advisory describes a denial of service vulnerability in the Cisco Adaptive Security Appliance (ASA) Software. (NOTE: Cisco ASA software is used as third-party software in at least one control system security product.) The vulnerability is self-reported. Cisco has updates available that mitigate the vulnerability.

Gemalto Advisory


Gemalto has announced that it has an advisory available for vulnerabilities in the Gemalto Sentinel LDK product. The advisory is only available to those with an account with Gemalto (not me). We may see an advisory from NCCIC-ICS on these vulnerabilities.

Tuesday, March 19, 2019

2 Advisories Published – 03-19-19


Today the DHS NCCIC-ICS published two control system security advisories for products from Columbia Weather Systems and AVEVA.

Columbia Advisory


This advisory describes six vulnerabilities in the Columbia Weather MicroServer weather monitoring system. The vulnerabilities were reported by John Elder and Tom Westenberg of Applied Risk. Columbia has a firmware update that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Cross-site scripting (2) - CVE-2018-18875 and CVE-2018-18880;
• Path traversal - CVE-2018-18876;
• Improper authentication - CVE-2018-18877;
• Improper input validation - CVE-2018-18878; and
Code injection - CVE-2018-18879

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow disclosure of data, cause a denial-of-service condition, and allow remote code execution.

AVEVA Advisory


This advisory describes an uncontrolled search path element vulnerability in the AVEVA InduSoft Web Studio, InTouch Edge HMI products. The vulnerability is in a third-party component; Gemalto Sentinel UltraPro encryption keys (separately reported last week). The vulnerability was reported by ADLab of Venustech. AVEVA has updates available to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow execution of unauthorized code or commands.

NOTE: I wonder how many other vendors are using the Gemalto product?

Thursday, March 14, 2019

3 Advisories Published – 03-14-19


Today the DHS NCCIC-ICS published three control system security advisories for products from PEPPERL+FUCHS, Gemalto and Leão Consultoria e Desenvolvimento de Sistemas Ltda (LCDS).

PEPPERL+FUCHS Advisory


This advisory describes a path traversal vulnerability in the PEPPERL+FUCHS WirelessHART-Gateways. The vulnerability was publicly reported (with exploit) by Hamit CİBO. PEPPERL+FUCHS has firmware upgrades to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could use publicly available code to remotely exploit this vulnerability to allow access to files and restricted directories stored on the device through the manipulation of file parameters.

NOTE: I briefly reported on this vulnerability last Saturday.

Gemalto Advisory


This advisory describes an uncontrolled search path element in the Gemalto Sentinel UltraPro. The vulnerability was reported by ADLab of Venustech. Gemalto has a software update to mitigate the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to load and execute a malicious file from the ux32w.dll in Sentinel UltraPro.

NOTE: Gemalto issued an early warning to upgrade the UltraPro software back on January 19th, 2019 with a restricted link to their advisory on this product. I do not know what information was included in that advisory.

LCDS Advisory


This advisory describes an out-of-bounds write vulnerability in the LCDS LAquis SCADA. The vulnerability was reported by Mat Powel via the Zero Day Infitiative. LCDS has a new version that mitigates the vulnerability. There is no indication that Powel was provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow remote code execution.

Friday, February 2, 2018

ICS-CERT Publishes 3 Advisories and 1 Update


Yesterday the DHS ICS-CERT published three control system security advisories for products from Gemalto, Smart Software Solutions (3S), and Fuji Electric. They also updated a previously published control system security advisory for products from NXP Semiconductor.

Gemalto Advisory


This advisory describes multiple vulnerabilities in the Gemalto Sentinel License Manager. The vulnerabilities were reported by Kaspersky Labs. The latest version of the software mitigates the vulnerability. There is no indication that Kaspersky Labs has been provided an opportunity to verify the efficacy of the fix.

The seven reported vulnerabilities are:

• Null pointer dereference - CVE-2017-11498;
• Stack-based buffer overflow (4) - CVE-2017-11497, CVE-2017-11496, CVE-2017-12818 and CVE-2017-12821;
• Heap-based buffer overflow - CVE-2017-12820; and
Improper access control - CVE-2017-12822

NOTE: This is essentially the same vulnerability that I have discussed previously (here and here). The Kaspersky article on this problem actually list 14 vulnerabilities not the seven being reported here. I mentioned earlier that there may be as many as 40,000 products (not all being ICS, obviously) being affected by this issue. If the Gemalto dongle is clearly identified as being a ‘Sentinel License Manager’, then this advisory is clearly a much more effective means of addressing the issue rather than issuing advisories on each of the affected product lines. If the using vendors, however, have relabeled their dongles, then this advisory will not be effective in those cases. But that is not ICS-CERT’s fault.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities and that could lead to remote code execution or cause a denial-of-service condition, rendering the Sentinel LDK License Manager service unavailable (and the supported product also being unavailable).

3S Advisory


This advisory describes a stack-based buffer overflow in the 3S CODESYS Web Server. The vulnerability was reported by Zhu WenZhe of Istury IOT security lab. 3S has released a security patch to mitigate this vulnerability. There is no indication that Zhu was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability causing the device to crash, resulting in a buffer overflow condition that may allow remote code execution.

Fuji Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Fuji V-Server VPR. The vulnerability was reported by Ariele Caltabiano (kimiya) via the Zero Day Intitiative. Fuji has produced a new firmware version that mitigates the vulnerability. There is no indication that Caltabiano has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability  to view sensitive information and disrupt the availability of the device.


NXP Update


This update provides new information for an advisory that was originally published on October 12th, 2017. The update provides links to the new version of the single remaining product that was not previously fixed.

 
/* Use this with templates/template-twocol.html */