Showing posts with label Gervais. Show all posts
Showing posts with label Gervais. Show all posts

Monday, September 23, 2013

ICS-CERT Updates (again) Schneider Advisory

Today the DHS ICS-CERT published a second update for a series of Schneider Electric alerts and advisories dating back to December 2011 (12-12-11 Alert, 1-17-12 Advisory, 3-5-13 Alert, and 6-4-13 Advisory Update). The original alert was based upon a partially coordinated disclosure (we still haven’t heard the whole story on that) by Ruben Santamarta. The second alert was based upon an S4 Conference disclosure by Arthur Gervais.

This advisory update reports that:

• This advisory corrects and expands on the details in the specified alert and subsequent advisory updates;
• ICS-CERT has coordinated with Schneider Electric, and they have produced patches and firmware upgrades for Quantum and other affected products;
• Schneider Electric has created firmware upgrades that resolve the Telnet and Windriver debug port vulnerabilities for all affected products by removing the Telnet and Windriver services from these modules; and
• Schneider has also released a firmware upgrade to address the FTP service vulnerability by allowing the user to disable the FTP service.

The ICS-CERT advisory provides a link to the Schneider Electric download site but I cannot find a reasonably identifiable upgrade that deals with removing the Telnet and Windriver services from the Quantum Ethernet Module. Of course this fix was supposedly developed in 2011 for two of the affected modules so it may take some searching to find these upgrades. Hopefully someone in the Schneider Electric service department will be able to help owners locate the appropriate upgrades.

The advisory notes that the removal of these two services should not impact operations since they were included only for “advance troubleshooting use” and were not intended to be used by customers.


ICS-CERT left language in the updated advisory {pg 5} that would seem to indicate that additional mitigation measures are expected. It is not clear from reading the rest of the updated advisory if this was simply an editorial oversight or if additional work is actually expected from Schneider.

Thursday, January 17, 2013

ICS-CERT Publishes another S4 Alert and an Advisory


I should have waited a little longer before posting yesterday since just before 5 pm EST ICS-CERT published another S4 related alert (Siemens) along with a Schneider advisory. Arguably the Schneider advisory is of more concern.

Siemens Alert


This alert addresses a brute force password tool that could allow an attacker to the challenge-response data extracted from TCP/IP traffic file off-line to expose credentials used for communications with Siemens S7 PLCs. The tool was introduced at the S4 conference by Alexander Timorin and Dmitry Sklyarov of SCADA Strangelove.

The ICS-CERT advisory notes that an attacker using the tool must have access to an ‘adjacent network’ to acquire the information necessary to use the tool. They also note that the “possibility exists that this code may be modified to be used against other vendor products” (page 1).

NOTE: This was an extremely fast response from ICS-CERT as Dale tweeted about this presentation at about 2:00 pm EST yesterday. Okay the SCADA Strangelove blog post came a bit earlier than that, but it was still a pretty impressive response.

Schneider Advisory


This advisory outlines an authentication communication risk vulnerability in the Schneider Electric software update (SESU) utility used by a number of Schneider products. According to the advisory a moderately skilled attacker could exploit the lack of authentication of update messages to execute arbitrary code on the system.

Schneider has updated their SESU server to support both HTTP and HTTPS communications (HTTPS does ensure signed communications). The SESU client will be updated this month using the existing HTTP protocol. Schneider will not completely switch to using the HTTPS protocol until May 2013. (NOTE: There is an interesting typo – I think – in the advisory that notes that this “means that only HTTP [emphasis added] will be supported during SESU client updates from that time forward” I think that should read “only HTTPS”.

Product updates are an important part of any software support system and there must be a method to verify that the updates are coming from the actual vendor. It is very disturbing that this very basic security procedure has not already been in place.

I do understand that the delay until May to completely implement this change on the client side of the SESU system is driven by an effort to ensure that all systems in place are updated with the changed communications protocol before eliminating the HTTP-based updates, but that is a very big window of opportunity for the exploitation of this vulnerability. At the very least, I would expect that many systems could have backdoor access installed via this mode to allow future access to the systems.

Wednesday, January 16, 2013

ICS-CERT Publishes First 2013 S4 Alert


This afternoon the DHS ICS-CERT published the first alert for a vulnerability reported at the Digital Bond SCADA Security Scientific Symposium (S4) conference; one that Dale hasn’t mentioned in his tweets yet (Hash Tag - #S4x2013). The alert covers multiple vulnerabilities reported by Arthur Gervais in the some products from Schneider Electric.

The four remotely executable vulnerabilities are listed below:

• BMX NOE 0110 – Unauthenticated SOAP/HTTP Interface – Remote code execution

• Modicon M340 – TCP connection resource exhaustion – Denial of Service

• Magelix XBT – HMI 6001/TCP hard coded credential – Loss of integrity

• Modicon M340 – Cross site request forgery – Unauthorized access

BTW: There was a Tweet® from Reid Wightman about an older Schneider vulnerability - "1825-day vuln in WinCC reminded me to check @digitalbond Schneider clock: 2224 days with a publicly-disclosed FTP backdoor."
 
/* Use this with templates/template-twocol.html */