Showing posts with label Ghirmay Desta. Show all posts
Showing posts with label Ghirmay Desta. Show all posts

Friday, September 28, 2018

4 ICS Advisories


Yesterday the DHS NCCIC-ICS (okay, I finally gave in; ICS-CERT is gone; please clean up the web site) published four control system security advisories for products from Delta Electronics, Fuji Electric (2) and Emerson.

Delta Advisory

This advisory describes an out-of-bounds read vulnerability in the Delta Industrial Automation PMSoft software development tool. The vulnerability was reported by Mat Powell via ZDI. Delta has an update available that mitigates the vulnerability. There is no indication that Powell has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to read confidential information.

FRENIC Advisory


This advisory describes three vulnerabilities in the Fuji FRENIC HVAC drive devices. The vulnerability was reported by Michael Flanders and Ghirmay Desta via ZDI. Fuji is working on mitigation measures.

The three reported vulnerabilities are:

• Buffer over-read - CVE-2018-14790;
• Out-of-bounds read - CVE-2018-14798; and
Stack-based buffer overflow - CVE-2018-14802

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow for arbitrary remote code execution affecting the availability of the device.

Alpha5 Advisory


This advisory describes two buffer-overflow vulnerabilities in the Fuji Alpha5 Smart Loader servo drive. The vulnerability was reported by Michael Flanders via ZDI. Fuji is working on mitigation measures.

The two reported vulnerabilities are:

• Classic buffer overflow - CVE-2018-14788; and
• Heap-based buffer overflow - CVE-2018-14794

NCCIC-ICS reports that a relatively low-skilled attacker could remotely use publicly available exploits to allow for arbitrary remote code execution on the device.

NOTE: It is disappointing that Fuji was not even able to provide workaround security measures for these two product lines. Does anyone know if NCCIC-ICS is still giving the 45-day grace period before publishing their advisories?

Emerson Advisory


This advisory describes two vulnerabilities in the Emerson AMS Device Manager. The vulnerabilities were reported by Sergey Temnikov of Kaspersky Lab and Emerson. Emerson has patches available to mitigate the vulnerabilities. There is no indication that Temnikov has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper access control - CVE-2018-14804; and
• Improper privilege management - CVE-2018-14808

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to

Tuesday, July 31, 2018

ICS-CERT Publishes 5 Advisories


Today the DHS ICS-CERT published five control system security advisories for products from AVEVA (2), WECON, Johnson Controls and Davolink.

Wonderware Advisory


This advisory describes an improper restriction in operations within the bounds of a memory buffer vulnerability in the AVEVA Wonderware License Server; the vulnerability is in the 3rd party  Flexera FlexNet Publisher software. The vulnerability was reported to AVEVA by an anonymous researcher. AVEVA has an update that mitigates the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability to effect remote code execution with administrative privileges.

NOTE: This vulnerability was also reported in the Rockwell Factory Talk Activation Manager earlier this year. There is an interesting blog post from 2016 about this vulnerability over at Security Mumblings.

InTouch Advisory


This advisory describes a cross-site scripting vulnerability in the AVEVA InTouch Access Anywhere product. The vulnerability was reported by Google’s Security Team. AVEVA has an update that mitigates the vulnerability. The AVEVA security advisory indicates that the researchers have verified the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability to obtain sensitive information and/or execute Javascript or HTML code.

WECON Advisory


This advisory describes two buffer overflow vulnerabilities in the WECON LeviStudioU. The vulnerabilities were reported by NSFOCUS security team, Ghirmay Desta and Mat Powell via the Zero Day Initiative.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-10602; and
Heap-based buffer overflow - CVE-2018-10606

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to execute remote code.

NOTE: Reading between the lines of the advisory, it looks like ICS-CERT did not get much cooperation from WECON on these vulnerabilities.

Johnson Controls Advisory


This advisory describes an information exposure through an error message vulnerability in the Johnson Controls Metasys and BCPro products. The vulnerability was reported by Dan Regalado of Zingbox. Newer versions mitigate the vulnerability. There is no indication that Regalado was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker on an adjacent network could exploit the vulnerability to obtain technical information about the Metasys or BCPro server, allowing an attacker to target a system for attack.

Davolink Advisory


This advisory describes a use of password hash with insufficient computational effort vulnerability in the Davolink DVW-3200N network switch. The vulnerability was reported by Ankit Anubhav of NewSky Security. There is new firmware for the device that mitigates the vulnerability. There is no indication that Anubhav was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to obtain the password to the device.

Thursday, July 12, 2018

ICS-CERT Publishes an Advisory and an Update


Today the DHS ICS-CERT published a control system security advisory for products from Eaton. They also updated a medical device security advisory for products from Medtronic.

Eaton Advisory


This advisory describes a stack-based buffer overflow in the Eaton 9000X Drive. The vulnerability was reported by Ghirmay Desta working with the Zero Day Initiative. Eaton has an update available that mitigates the vulnerability. There is no indication that Desta was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that an uncharacterized attacker could remotely exploit the vulnerability to allow remote code execution.

Medtronic Update

This update provides additional information for an advisory that was originally published on May 17th, 2018. The update adds a second vulnerability (Protection mechanism failure - CVE-2018-10631). This necessitated an increase of the CVSS (v3) ranking from 4.6 to 6.3 and an expanded risk evaluation section of the advisory.

Thursday, April 26, 2018

ICS-CERT Publishes 2 Alerts and Updates Meltdown Alert


Today the DHS ICS-CERT published two control system security advisories for products from WECON Technology and Delta Electronics. They also updated their control system security alert for the Meltdown/Spectre vulnerabilities.

WECON Advisory


This advisory describes a stack-based buffer overflow vulnerability in the WECON LEVI Studio HMI Editor and PI Studio HMI Project Programmer. The vulnerability was reported by Sergey Zelenyuk of RVRT and Michael DePlante of Leahy Center for Digital Investigation via the Zero Day Initiative (ZDI). WECON has a new version that mitigates the vulnerability. There is no indication that either researcher was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow remote code execution.

Delta Advisory


This advisory describes multiple stack-based buffer overflows (on a single CVE) in the Delta PMSoft, a software development tool for motion controllers. The vulnerabilities were reported by Ghirmay Desta via ZDI. Delta has a new version available that mitigates the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to cause the application to crash; stack-based buffer overflow conditions may allow arbitrary code execution.

Meltdown Update


This update provides new information on an alert that was originally published on January 11th, 2018 and updated on January 16th, 2018, January 17th, 2018, January 30th, 2018, February 20th, 2018, February 22nd, 2018 and again on March 1st, 2018. The update provides a link to a new vendor report from:


Not specifically mentioned in the update, but the current links also provide access to updated information from:

Siemens (which I mentioned Saturday); and

Thursday, March 1, 2018

ICS-CERT Published 3 Advisories and Update the Meltdown Alert


Today the DHS ICS-CERT published three new control system security advisories for products from Delta Industrial Automation, Moxa and Siemens. They also updated the previously published alert for the Meltdown and Spectre chip vulnerabilities.

Delta Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Delta DOPSoft human machine interface. The vulnerability was reported by Ghirmay Desta via the Zero Day Initiative. Delta has a new version that mitigates the vulnerability. There is no indication that Desta has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause the device the attacker is accessing to crash; a buffer overflow condition may allow remote code execution.

Moxa Advisory


This advisory describes three vulnerabilities in the Moxa OnCell high-speed industrial-grade IP gateway. The vulnerabilities were reported by Kirill Nesterov, Eugenie Potseluevskaya, and Radu Motspan of Kaspersky Labs. Moxa has released a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Reliance on cookies without validation and integrity checking - CVE-2018-5455;
• Improper handling of length parameter inconsistency - CVE-2018-5453; and
Null pointer dereference - CVE-2018-5449

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability  to remotely execute code on the device.

Siemens Advisory


This advisory describes multiple vulnerabilities in the Siemens SIMATIC, SIMOTION, and SINUMERIK industrial computers. These vulnerabilities were self-reported by Siemens. The Siemens security advisory reports that these are 3rd party vulnerabilities in the Intel Management Engine (ME), Intel Server Platform Services (SPS), and Intel Trusted Execution Engine (TXE)

The eight reported vulnerabilities are:

• Stack-based buffer overflow (5) - CVE-2017-5705, CVE-2017-5706, CVE-2017-5707, CVE-2017-5712, and CVE-2017-5711; and
• Permissions, privileges, and access controls (3) - CVE-2017-5708, CVE-2017-5709, and CVE-2017-5710

ICS-CERT reports that a relatively low-skilled attacker could remotely (some of the vulnerabilities require local access) to execute arbitrary code or gain unauthenticated access to sensitive data.

NOTE: Again, with 3rd party vulnerabilities one has to wonder what other systems will be affected. But, since Intel is such a small company (right) it is unlikely that any other vendors will use this vulnerable code (pardon the sarcasm).

Meltdown Update


This update provides additional information on an alert that was originally published on January 11th, 2018 and updated on January 16th, 2018, January 17th, 2018, January 30th, 2018, February 20th, 2018, and again on February 22nd, 2018.

The advisory provides links to new vendor reports on the vulnerabilities:

Dräger;
Pepperl+Fuchs; and

 
/* Use this with templates/template-twocol.html */