Showing posts with label Georgia Tech. Show all posts
Showing posts with label Georgia Tech. Show all posts

Saturday, May 18, 2019

2 Advisories Published – 05-16-19


On Thursday the DHS NCCIC-ICS published two control system security advisories for products from Fuji Electric and Schneider Electric.

Fuji Advisory


This advisory describes an out-of-bounds read vulnerability in the Fuji Alpha7 PC Loader motor controller. The vulnerability was reported by kimiya of 9SG Security Team via the Zero Day Initiative. Fuji has a new version that mitigates the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to crash the device..

Schneider Advisory


This advisory describes a use of insufficiently random values vulnerability in the Schneider Modicon M580, Modicon M340, Modicon Premium, and Modicon Quantum products. The vulnerability was reported by David Formby and Raheem Beyah of Fortiphyd Logic and Georgia Tech. Schneider has a firmware update available for one of the products and has provided generic workarounds for the others. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to to hijack TCP connections or cause information leakage.

Tuesday, May 23, 2017

ICS-CERT Publishes 3 Advisories

Today the DHS ICS-CERT published two industrial control system advisories for products from Rockwell and Moxa. They also published a medical control system advisory for products from B Braun Medical. The Rockwell advisory was previously published on the NCCIC Portal on April 25th, 2017. The Braun Medical advisory was previously published on the NCCIC Portal on March 23rd, 2017l

B Braun Medical Advisory


This advisory describes an open redirect vulnerability on the B Braun Medical SpaceCom module. The vulnerability was reported by Marc Ruef and Rocco Gagliardi of scip AG. Braun has produced a software update that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to  allow URL redirection to untrusted web sites.

Rockwell Advisory


This advisory describes multiple vulnerabilities in the Allen-Bradley MicroLogix 1100 and 1400 PLCs. The three of the vulnerabilities were reported by David Formby and Raheem Beyah of Georgia Tech and Fortiphyd Logic, Inc with the last one being reported by Ilya Karpov of Positive Technologies. Rockwell has provided a firmware update for one of the affected products and recommends disabling the web server as an alternative and/or additional mitigation measure. There is no indication that the researchers have been provide an opportunity to verify the efficacy of the fix.

The reported vulnerabilities are:

• Predictable value range from previous values - CVE-2017-7901;
• Reusing a nonce, key pair in encryption - CVE-2017-7902;
• Information exposure - CVE-2017-7899;
• Improper restriction of excessive authentication attempts- CVE-2017-7898; and
• Weak password requirements - CVE-2017-7903

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerabilities  to gain unauthorized access to the affected programmable logic controllers and to spoof or disrupt TCP connections.

Moxa Advisory


This advisory describes three vulnerabilities in the Moxa OnCell IP gateways. The vulnerabilities were reported by Maxim Rupp. Moxa reports that the latest version of two of the products mitigate the vulnerabilities and provides a work around for the remainder. There is no indication that Rupp was provided an opportunity to verify the efficacy of the fix.

The reported vulnerabilities are:

• Improper restriction of excessive authentication attempts - CVE-2017-7915;
• Plain text storage of a password - CVE-2017-7913; and
• Cross-site request forgery - CVE-2017-7917


ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to allow an attacker to use brute force to determine parameters needed to access the application. An attacker may also obtain credentials by obtaining files that store passwords in clear text.

Thursday, March 30, 2017

ICS-CERT Publishes 2 Schneider Advisories and Medical IOT Alert

Today the DHS ICS-CERT published two control system advisories for products from Schneider Electric. They also published a medical control system alert for a medical lab device from Miele.

Modicon Advisory


This advisory describes multiple vulnerabilities in the Schneider Modicon PLCs. The vulnerabilities were reported by David Formby and Raheem Beyah of Georgia Tech and Fortiphyd Logic, Inc. Schneider has produced new firmware versions to mitigate two of the vulnerabilities and work arounds for the remaining vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Predictable value range from previous values - CVE-2017-6030;
• Use of insufficiently random values - CVE-2017-6026; and
• Insufficiently protected credentials - CVE-2017-6028

ICS-CER reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to spoof or disrupt Transmission Control Protocol (TCP) connections, sniff sensitive account information, and gain unauthorized access to a current web session.

Schneider has taken the unusual move of publishing separate Security Notification documents for each vulnerability (here, here, and here).

Wonderware Advisory


This advisory describes multiple vulnerabilities in the Schneider Wonderware InTouch Access Anywhere. The vulnerabilities were reported by Ruslan Habalov and Jan Bee of the Google ISA Assessments Team. Schneider has produced a new version to mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Cross-Site Request Forgery - CVE-2017-5156;
• Information Exposure - CVE-2017-5158; and
• Inadequate Encryption Strength - CVE-2017-5160

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability  to perform actions on behalf of a legitimate user, perform network reconnaissance, and gain access to resources beyond those intended with normal operation of the product.

The Schneider Security Bulletin reports a fourth vulnerability; Ability to escape out of remote InTouch applications and launch other processes. No CWE information is provided for the fourth vulnerability. Schneider also reports that the researchers have verified the efficacy of the fix.

Miele Alert


This alert describes a publicly reported path traversal vulnerability in the Miele Professional PG 8528, a large capacity cleaner and disinfector used in hospitals and laboratory settings. ICS-CERT does report that Jens Regel publicly disclosed this vulnerability without providing a link to the disclosure on the Full Disclosure web site.

The Miele press release on this vulnerability minimizes the criticality of the problem (perhaps legitimately so). What is more interesting is their comment on their failure to respond to Regel’s attempt at responsible disclosure:

“The technical aspects in this case are entirely separate from the fact that the Miele company failed to respond to several notifications regarding this issue. Executive Directors view this as a serious shortcoming, the details of which have already been investigated in depth with a view to preventing any repeat occurrence in future. They stress that they would like to thank Jens Regel, the source of this evidence, for his information – and for his perseverance.”


While the initial disclosure response was deficient, this certainly reflects a more helpful attitude of the upper management of the company.

Thursday, March 10, 2016

ICS-CERT Publishes Schneider Advisory

This afternoon the DHS ICS-CERT published an advisory for an improper Ethernet frame padding vulnerability in the Schneider Electric Telvent SAGE 2300 and 2400 remote terminal units (RTUs). The vulnerability was reported by David Formby and Raheem Beyah of Georgia Tech. A previously released software version mitigates the vulnerability. The researchers have validated the efficacy of the current software to fix the vulnerability.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to read the leaked packet data.

This is the same ‘IEEE conformance issue’ that this research team has reported in systems from other two suppliers (here and here). Interestingly the most recent other example (first one listed here) included an early release of the advisory on the US CERT Secure Portal, even though as in this case, the vulnerability had been corrected in a previously released version of the software.

GPS Timing Issue



While looking at the Schneider web site for information on this vulnerability (I did not find any) I came across a very interesting notice about a GPS timing issue that had been identified (no attribution of identification was provided) in the Trimble GPS card. Those cards are now reporting dates with year 1996 instead of 2016 and have been since February 14th, 2013 because of an error in the firmware. I suppose that system owners that actually use those affected 0x41 and 0x8F-20 messages will have already noticed this problem. According to Trimble (.PDF download) they are not able to update the firmware to correct this problem, so it has to be corrected in the software/firmware that uses the reported data. The Schneider notice reports that they have updated the firmware for their C3413 and C3414 CPU Cards.

Tuesday, November 24, 2015

ICS-CERT Publishes Two Advisories

This afternoon the DHS ICS-CERT published two control system advisories for systems from Eaton’s Cooper and Moxa.

Eaton’s Cooper Advisory

This advisory describes an IEEE conformance issue involving improper frame padding in Eaton’s Cooper Power Systems Form 6 controls and Idea/IdeaPLUS relays equipped with Ethernet. The vulnerability was reported by David Formby and Raheem Beyah of Georgia Tech. An updated version of the systems (associated with another recent ICS-CERT Advisory) has been confirmed by the researchers to be free of the vulnerability.

ICS-CERT reports that a relatively unskilled attacker with network access to unencrypted packets would be able to read the leaked data.

This advisory was published on the US CERT Secure Portal on October 22nd, 2015. Again, the early notification is available to all critical infrastructure owners and legitimate researchers granted access by ICS-CERT. See bottom of the ICS-CERT landing page for information on how to apply for this access.

This is the second advisory for this sort of issue. Both were based upon reports by Formby and Beyah. How many more systems will they find with this vulnerability? Who knows, perhaps vendors should start looking themselves? Or not. Maybe Formby and Beyah can build a startup business on their technique for finding this vulnerability and then expand it into other areas of vulnerability research. I seem to recall another team that started out in a similar manner.

BTW: Eaton’s Cooper calls this a TCP/IP protocol stack vulnerability. It sounds a little bit more impressive, but perhaps not quite as descriptive.

Moxa Advisory

This advisory describes two vulnerabilities in the Moxa OnCell Central Manager Software. The vulnerabilities were reported through the Zero Day Initiative by Andrea Micalizzi. Moxa has produced a new version but there is no indication that Micalizzi has been provided an opportunity to verify the efficacy of the fix.

The two vulnerabilities are:

• Use of hard-coded credentials - CVE-2015-6481; and
• Authentication by-pass issues - CVE-2015-6480.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to gain full system access.


BTW: The Moxa release notes on the new version do list the authentication by-pass issue, but does not mention the hard-coded credentials

Thursday, July 16, 2015

ICS-CERT Publishes Eaton’s Cooper Advisory

This morning the DHS ICS-CERT published a new advisory for a predictable TCP sequence vulnerability in Eaton’s Cooper Power Systems controls and relays. The vulnerability was initially reported by Dr. Raheem Beyah, David Formby, and San Shin Jung of Georgia Tech. Eaton’s Cooper has produced a patch to mitigate the vulnerability and ICS-CERT reports that the researchers have validated the efficacy of the patch.

ICS-CERT reports that a skilled attacker could remotely exploit this vulnerability to execute a  man-in-the-middle attack.

The Eaton’s Cooper advisory notes that by “ensuring that controls are not accessible from external networks and that appropriate physical security measures are provided at network access points, any risks associated with this vulnerability are greatly minimized”. They also note that the “vulnerability could allow for the potential of spoofing attacks and session hijacking”.

ICS-CERT reports that they had released this advisory to the US-CERT Secure Portal on January 6th. The company advisory was not issued until July 6th after the patches had been made available. The fact that the advisory was issued on the Secure Portal so early in the coordination process indicates how serious this vulnerability can be. And this reinforces the need for system owners to regularly check the Secure Portal for information on critical vulnerabilities.


BTW: The Schneider update is still not listed on the ICS-CERT landing page. I wonder what is going on. The updated advisory is available; it is just not listed.

Thursday, June 18, 2015

ICS-CERT Publishes Two Advisories

This afternoon the DHS ICS-CERT published two advisories for vulnerabilities in industrial control systems from Schneider Electric and Wind River.

Schneider Advisory

This advisory describes a fixed search path vulnerability (Schneider calls it a binary planting vulnerability) in the Wonderware System Platform. The vulnerability was reported by Ivan Sanchez of WiseSecurity Team. Schneider has produced a patch to mitigate the vulnerability and according to ICS-CERT Sanchez has verified the efficacy of the fix.

ICS-CERT reports that this vulnerability would require a social engineering attack to get an authorized user to load a specially configured DLL file. A successful exploit would allow execution of arbitrary code.

Wind River Advisory

This advisory describes a TCP predictability vulnerability in the VxWorks operating system. The vulnerability was reported by Raheem Beyah, David Formby, and San Shin Jung of Georgia Tech. Wind River has produced patches for the vulnerability, but there is no indication that the Georgia Tech team has been given the opportunity to verify the efficacy of the fix.

ICS-CERT reports that VxWorks is used in a number of ICS devices from a number of vendors. The VxWorks web site notes that the operating system is used in drones, medical devices and consumer IOT devices in addition to the ICS devices. ICS-CERT has contacted a number of vendors about the vulnerability. To date only Schneider Electric has produced a firmware patch to fix the VxWare vulnerability in some of their SAGE RTUs. Additional updates to the advisory will be issued when additional vendor information becomes available.


ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to spoof or disrupt TCP connections to the affected devices. The Schneider advisory [.PDF Download] for the Sage RTUs notes that a successful exploit could allow a man-in-the-middle attack.

Tuesday, June 2, 2015

ICS-CERT Publishes Two Advisories

This morning the DHS ICS-CERT published two new control system advisories; one for Moxa SoftCMS and the other for Beckwith Electric TCP.

Moxa Advisory

This advisory describes a buffer overflow vulnerability in the SoftCMS software package that manages large scale surveillance systems. The vulnerability was reported through HP’s Zero Day Initiative (ZDI) by Ariele Caltabian. Moxa has developed a new version that mitigates the vulnerability but there is no indication that Caltabian has been given the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to execute arbitrary code.

Beckwith Electric Advisory

This advisory describes a TCP initial sequence numbers vulnerability in two of Beckwith Electric’s digital voltage regulator controllers. The vulnerability was initially reported by Raheem Beyah, David Formby, and San Shin Jung of Georgia Tech in two devices. Subsequent work by Beckwith Electric disclosed similar vulnerabilities in four other devices. Beckwith has produced firmware updates for five of the six devices and the researchers have verified the efficacy of the fix in the original two devices. A separate mitigation measure is being made available for the other device (the M-6280 Digital Capacitor Bank Control).

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to spoof a TCP connection to the device.

As always I would like to commend Beckwith Electric for taking the extra effort to uncover similar vulnerabilities in other devices. This indicates a proactive approach to control system security design.
 
/* Use this with templates/template-twocol.html */