Showing posts with label Gjoko Krstic. Show all posts
Showing posts with label Gjoko Krstic. Show all posts

Saturday, October 3, 2020

Public ICS Disclosures – Week of 9-26-20

This week we have ten vendor disclosures for products from WAGO (3), IBM, Bosch, B&R Automation (2), Moxa, BD, and Philips.

WAGO Advisories

CERT-VDE published an advisory describing an improper authentication and authorization vulnerability in the WAGO 750-8XX series PLCs. The vulnerability was reported by Maxim Rupp. WAGO has new firmware versions that mitigate the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

CERT-VDE published an advisory describing an improper authentication and access control vulnerability in the WAGO 750-36X and WAGO 750-8XX series PLCs. The vulnerability was reported by Maxim Rupp. WAGO has new firmware versions that mitigate the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

CERT-VDE published an advisory describing an improper neutralization of input during web page generation vulnerability in the Web-UI for WAGO 750-88X and WAGO 750-89X series PLCs. This vulnerability was reported by Secuninja. WAGO has new firmware versions that mitigate the vulnerability. There is no indication that Secuninja has been provided an opportunity to verify the efficacy of the fix.

IBM Advisory

IBM published an advisory describing an authentication bypass vulnerability in their Maximo Asset Management product. The vulnerability is being self-reported. IBM has updates that mitigate the vulnerability.

Bosch Advisory

Bosch published an advisory describing three vulnerabilities in their PRAESIDEO Network Controller and the PRAESENSA System Controller products. The vulnerabilities were reported by Gjoko Krstic of Applied Risk. Bosch has software updates for the supported products that mitigate the vulnerabilities. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Cross-site scripting - CVE-2020-6777,

• Cross-site request forgery - CVE-2020-6776, and

• Nonce reuse attack - CVE-2020-15688

NOTE: The last is a third-party vulnerability (GoAhead web server).

B&R Advisories

B&R published an advisory describing four vulnerabilities in their GateManager product. These vulnerabilities were reported by NCCIC-ICS on July 28th as being for the Secomea GateManager.

B&R published an advisory describing six vulnerabilities in their SiteManager and GateManager procucts. These vulnerabilities were reported by NCCIC-ICS last Tuesday, but the B&R advisory was not available when I published my blog post. It is not clear if the Secomea versions of these products are also affected by these vulnerabilities.

Moxa Advisory

Moxa published an advisory describing a device information leak vulnerability in their EDR-810 Series Industrial Secure Routers. The vulnerability was reported by the National Security Agency (yep, that is what the advisory says). Moxa has provided generic workarounds to mitigate the vulnerability.

BD Advisory

BD published an advisory describing a remote code execution vulnerability (CVE-2020-1147) in a third-party component (Microsoft) of a long list of their products. BD is working on testing and validation of the Microsoft patch.

Philips Advisory

Philips published an advisory describing a privilege elevation vulnerability (CVE-220-1472) in a third-party component (Microsoft) of an undisclosed number of Philips products. No mitigation information has been provided.

Tuesday, March 24, 2020

2 Advisories Published – 3-24-20


Today the CISA NCCIC-ICS published two control system security advisories for products from Schneider and VISAM.

Schneider Advisory


This advisory describes two vulnerabilities in the Schneider Interactive Graphical SCADA System (IGSS). The vulnerabilities were reported by the Zero Day Initiative. Schneider has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Path traversal - CVE-2020-7478;
• Missing authentication for critical function - CVE-2020-7479

NCCIC-ICS reported that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow unauthorized access to sensitive data and functions.

NOTE: I briefly discussed these vulnerabilities earlier this month.

VISAM Advisory


This advisory describes five vulnerabilities in the VISAM VBASE automation platform. The vulnerabilities were reported by Gjoko Krstic of Applied Risk. VISAM has not responded to NCCIC-ICS inquiries about these vulnerabilities.

The five reported vulnerabilities are:

• Relative path traversal - CVE-2020-7008;
• Incorrect default permissions - CVE-2020-7004;
• Inadequate encryption strength - CVE-2020-10601;
• Insecure storage of sensitive information - CVE-2020-7000; and
• Stack-based buffer overflow - CVE-2020-10599

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to read the contents of unexpected files, escalate privileges to system level, execute arbitrary code on the targeted system, bypass security mechanisms, and discover the cryptographic key for the web login.

Tuesday, December 3, 2019

2 Advisories Published – 12-03-19


Today the CISA NCCIC-ICS published two control system security advisories for products from Moxa and Reliable Controls.

Moxa Advisory


This advisory describes 14 vulnerabilities in the Moxa AWK-3121 wireless access point. The vulnerabilities were reported by Samuel Huntley. This product has reached end-of-life and is no longer supported.

The 14 reported vulnerabilities are:

• Cleartext transmission of sensitive information (3) - CVE-2018-10690, CVE-2018-10694 and CVE-2018-10698;
• Sensitive cookie without ‘HTTPONLY’ flag - CVE-2018-10692;
• Improper restriction of operations within the bounds of a memory buffer (4) - CVE-2018-10693, CVE-2018-10695, CVE-2018-10701 and CVE-2018-10703;
• Cross-site request forgery - CVE-2018-10696;
• Command injection (3) - CVE-2018-10697, CVE-2018-10699 and CVE-2018-10702; and
• Cross-site scripting - CVE-2018-10700;

NCCIC-ICS reports that a relatively low-skilled attacker could remotely use publicly available exploits to allow an attacker to view sensitive information, cause availability issues, and execute remote code.

Reliable Controls Advisory


This advisory describes an unquoted search path or element vulnerability in the Reliable Controls License Manager. The vulnerability was reported by Gjoko Krstic of Applied Risk. Reliable Controls has a new version that mitigates the vulnerability. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to crash the system, view sensitive data, or execute arbitrary commands.

NOTE: Both of these product vulnerabilities were publicly reported back in June by the listed researcher. It appears that in at least one of the cases (probably both) the vendor did not reply or adequately address the researchers concerns even after there was public disclosure. The researchers then apparently turned to NCCIC-ICS for assistance.

Friday, November 15, 2019

6 Advisories and 2 Updates Published – 11-14-19


Yesterday the CISA NCCIC-ICS published five control system security advisories for products from ABB, Omron and Siemens (3); and one medical device security advisory for products from Philips. They also updated two previously published advisories for products from Siemens.

ABB Advisory


This advisory describes an authentication bypass using an alternate path or channel vulnerability in the ABB Power Generation Information Manager (PGIM) and Plant Connect monitoring platforms. This vulnerability was reported by Rikard Bodforss. ABB reports that PGIM will transition to a limited support phase in January 2020, and Plant Connect is already obsolete.

NCCIC reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a remote attacker to bypass authentication and extract credentials from the device.

NOTE: I briefly reported on this vulnerability earlier this month.

Omron Advisory


This advisory describes a use of obsolete function vulnerability in the Omron CX-Supervisor. The vulnerability was reported by Michael DePlante of the Zero Day Initiative. Omron has a new version that mitigates the vulnerability. There is no indication that DePlante has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to result in information disclosure, total compromise of the system, and system unavailability.

Desigo PX Advisory


This advisory describes an external control of assumed immutable web parameter vulnerability in the Siemens Desigo PX automation controllers. The vulnerability was reported by Gjoko “LiquidWorm” Krstic from Zero Science Lab. Siemens has updates that mitigate the vulnerability. There is no indication that Kristic has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to cause a denial-of-service condition on the device’s web server, requiring a reboot to recover the web interface.

S7-1200 Advisory


This advisory describes an exposed dangerous method or function vulnerability in the Siemens S7-1200 CPU. The vulnerability was reported by Ali Abbasi from Ruhr University of Bochum. Siemens has provided generic workarounds for this vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to  expose additional diagnostic functionality to an attacker with physical access to the UART interface during boot process. The Siemens advisory notes that the attacker must have physical access to the UART interface during boot process to exploit the vulnerability (feature).
NOTE: I briefly discussed this vulnerability last weekend.

Mentor Nucleus Advisory


This advisory describes an improper input validation vulnerability in the Siemens Mentor Nucleus Networking Module. The vulnerability was reported by Armis. Siemens has updates that mitigate the vulnerability. There is no indication that Armis was provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to affect the integrity and availability of the device. According to the Siemens advisory adjacent network access (but no authentication and no user interaction) is required to exploit the vulnerability

Philips Advisory


This advisory describes an inadequate encryption strength vulnerability in the Philips IntelliBridge EC40 and EC80 data transfer devices. The vulnerability was reported by The Medical Technology Solutions team of NewYork-Presbyterian Hospital. Philips has provided generic workarounds while developing formal mitigation.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow an attacker unauthorized access to the IntelliBridge EC40/80 hub and may allow access to execute software, modify system configuration, or view/update files, including unidentifiable patient data.

PROFINET Update


This update provides additional information on an advisory that was originally published on October 10th, 2019. The new information includes new affected version information and mitigation measures for:

• SINAMICS S120 V4.7;
• SINAMICS S150;
• SINAMICS G130 V4.7;
• SINAMICS G150; and
• SINAMICS SL150 V4.7

Industrial Products Update


This update provides additional information on an advisory that was was originally published on September 10th, 2019 and most recently updated on October 8th, 2019. The new information includes:

• Updated version information and mitigation link for SIMATIC MV500; and
• Removed SIMATIC RF166C from affected products.

Other Siemens Updates


On Tuesday Siemens also published two other advisory updates that have not yet been addressed by NCCIC-ICS, nor do I expect them to be addressed as the underlying vulnerabilities have not been reported by NCCIC-ICS. I will report on them tomorrow.

Tuesday, July 30, 2019

2 Advisories and 1 Alert Published – 07-30-19


Today the DHS NCCIC-ICS published a control system security alert for CAN bus network implementation in avionics and two control system security advisories for products from Prima Systems ad Wind River.

CAN Bus Alert


This alert briefly describes a public report about insecure implementation of CAN bus networks affecting aircraft. The report was published by Patrick Kiley of Rapid7.

Prima Systems Advisory


This advisory describes nine vulnerabilities in the Prima Systems FlexAir access control platform. The vulnerabilities were reported by Gjoko Krstic of Applied Risk. Prima Systems has a new version that mitigates the vulnerabilities. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

The nine reported vulnerabilities are:

OS command injection - CVE-2019-7670;
Unrestricted upload of file with dangerous type (2) - CVE-2019-7669 and CVE-2019-9189;
Cross-site request forgery - CVE-2019-7281;
Small space of random values - CVE-2019-7280;
Cross-site scripting - CVE-2019-7671;
Exposure of a backup file to an unauthorized control sphere - CVE-2019-7667;
Improper authentication - CVE-2019-7666; and
Use of hard-coded credentials - CVE-2019-7672

NOTE 1: NCCIC-ICS does not include a default credentials vulnerability, CVE-2019-7668, reported by Krstic.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to execute commands directly on the operating system, upload malicious files, perform actions with administrative privileges, execute arbitrary code in a user’s browser, discover login credentials, bypass normal authentication, and have full system access.

NOTE 2: I briefly described the Rapid7 report back in May.

Wind River Advisory


This advisory describes eleven vulnerabilities in the Wind River VxWorks operating system. The vulnerabilities were reported by Armis researchers Gregory Vishnepolsky, Dor Zusman, and Ben Seri. Wind River has patches to mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The eleven reported vulnerabilities are:

Stack-based buffer overflow - CVE-2019-12256;
Heap-based buffer overflow - CVE-2019-12257;
Integer underflow - CVE-2019-12255;
Improper restrictions of operations within the bounds of a memory buffer (2) - CVE-2019-12260 and CVE-2019-12261;
Race condition - CVE-2019-12263;
Argument injection or modification (4) - CVE-2019-12258, CVE-2019-12262, CVE-2019-12264 and CVE-2019-12265; and
Null pointer dereference - CVE-2019-12259;

Since the affected operating systems are used in a large number of IoT and ICS systems we can expect advisories from affected vendors implementing the Wind River mitigations measures. The NCCIC-ICS advisory already lists 2 vendor advisories and the Armis report adds a third. The three vendor advisories available to date include:

Rockwell,
Xerox, and

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow remote code execution.

Friday, June 7, 2019

Two Advisories Published – 06-06-19


This advisory describes two vulnerabilities in the Panasonic Control FPWIN Pro PLC programming software. The vulnerability was reported by kimiya of 9sg Security Team via the Zero Day Initiative. Panasonic has a new version that mitigates the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Heap-based buffer overflow - CVE-2019-6530; and
Type Confusion - CVE-2019-6532

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to crash the device and allow remote code execution.

Optergy Advisory


This advisory describes eight vulnerabilities in the Optergy Proton/Enterprise Building Management System. The vulnerabilities were reported by Gjoko Krstic of Applied Risk. Optergy has a new version that mitigates the vulnerability. There is no indication that Krstic has been provided an opportunity to verity the efficacy of the fix.

The eight reported vulnerabilities are:

Information exposure (2) - CVE-2019-7272 and CVE-2019-7277;
Cross-site request forgery - CVE-2019-7273;
Unrestricted upload of file with dangerous type - CVE-2019-7274;
Open redirect - CVE-2019-7275;
Hidden functionality - CVE-2019-7276
Exposed dangerous method or function - CVE-2019-7278; and
Use of hard-coded credentials - CVE-2019-7279

NOTE: I briefly reported on these vulnerabilities last month. Interestingly, the Applied Risk advisory describes six vulnerabilities but provided all eight of the above CVE’s.

Tuesday, May 21, 2019

Two Advisories Published – 05-21-19


Today the DHS NCCIC-ICS published two control system security advisories for products from Mitsubishi Electric and Computrols.

Mitsubishi Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the Mitsubishi MELSEC-Q series Ethernet module. The vulnerability was reported by Younes Dragoni and Alessandro Di Pinto of Nozomi Networks. Mitsubishi has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to render the device unresponsive, requiring a physical reset of the PLC (Programmable Logic Controller).

Computrols Advisory


This advisory describes nine vulnerabilities in the Computrols CBAS Web, a Web Building Management System (BMS). The vulnerabilities were reported by Gjoko Krstic of Applied Risk. Computrols has new firmware versions that mitigate the vulnerabilities. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

The nine reported vulnerabilities are:

Cross-site request forgery - CVE-2019-10847;
Information exposure through discrepancy - CVE-2019-10848;
Cross-site scripting - CVE-2019-10846;
Command injection - CVE-2019-10854;
Information exposure through source code - CVE-2019-10849;
Hard-coded encryption key - CVE-2019-10851;
SQL injection - CVE-2019-10852;
Authentication bypass using alternate path or channel - CVE-2019-10853; and
Inadequate encryption strength - CVE-2019-10855

NOTE: the Applied Risk report and the Computrols advisory also include an additional vulnerability; default credentials - CVE-2019-10850.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow unauthorized actions with administrative privileges, disclosure of sensitive information, execution of code within a user’s browser, execution of unauthorized OS commands, unauthorized access to the database, execution of unauthorized SQL commands, authentication bypass, or decryption of passwords.

NOTE: I briefly discussed these vulnerabilities on Saturday.

Saturday, February 16, 2019

Public ICS Disclosures – Week of 02-09-19


This week we have five vendor disclosures for products from Kunbus, Schneider (3) and Rockwell; five vendor updates from Siemens; one coordinated disclosure for products from Resource Data Management and one exploit for a previously disclosed vulnerability for products from AVEVA.

Kunbus Advisory


Kunbus published an advisory for five vulnerabilities in its KUNBUS-GW Modbus TCP PR100088 product. The vulnerabilities were reported by Nicolas Merle of Applied Risk. Kunbus is working on an update to mitigate the vulnerabilities.

The five reported vulnerabilities are:

• Conditional authentication bypass;
• Missing authentication for critical function;
• Denial of service;
• Publication of information by parameter data in an HTTP GET request; and
Plain text storage of passwords

Schneider Advisories


Schneider has published an advisory describing six vulnerabilities in its Sarix Enhanced and Spectra Enhanced cameras. The vulnerabilities were reported by Deng Yongkai (NSFOCUS) and Gjoko Krstic (Zero Science). Schneider has a new firmware version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• A permissions, privileges, and access control vulnerability - CVE-2018-7816;
• A command injection vulnerability (2) - CVE-2018-7825 and CVE-2018-7826;
• A cross-site scripting (XSS) vulnerability (2) - CVE-2018-7827 and CVE-2018-7828; and
• An improper neutralization of special elements in query vulnerability - CVE-2018-7829


Schneider has published an advisory describing a buffer error vulnerability in its Vijeo Designer Lite software. The vulnerability is self-reported. Schneider has provided generic mitigations as the product has reached end-of-life status.


Schneider has published an advisory describing three vulnerabilities in its  Modicon M221 and
SoMachine Basic products. The vulnerabilities were reported by Matthias Niedermaier (Hochschule Augsburg), Jan-Ole Malchow (Freie Universität Berlin), Florian Fischer (Hochschule Augsburg) and Reid Wightman (Dragos Inc.). Schneider has updates available to mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• An environment vulnerability (2) - CVE-2018-7821 and CVE-2018-7823; and
• An incorrect default permissions vulnerability - CVE-2018-7822

Rockwell Advisory


Rockwell has published an advisory describing two vulnerabilities in its PowerMonitor 1000 monitor that were publicly reported (with exploits) in December (here and here) by Luca Chiou. Rockwell has provided generic mitigation measures pending development of updates. It also provides a link to intrusion prevention system (by CheckPoint) rules to detect the cross-site scripting vulnerability.

The two reported vulnerabilities are:

• Cross-site scripting - CVE-2019-19615; and
• Authentication bypass - CVE-2019-19616

 Siemens Updates


Siemens published an update for their advisory on Spectre and Meltdown Vulnerabilities in Industrial Products. They added updated affected version data and provided links to mitigations for:

• SIMATIC ET 200 SP Open Controller; and
• SIMATIC IPC547E

NOTE: NCCIC-ICS updated their alert (ICS-ALERT-18-011-01) for this vulnerability when Siemens added a new advisory. That technically included this update since the link provided in the alert goes to the latest version of the Siemens advisory.


Siemens published an update for their advisory on Spectre-NG (Variants 3a and 4) Vulnerabilities in Industrial Products. They added updated version data and provided links to mitigations for:

• SIMATIC ET 200 SP Open Controller:
• SIMATIC ET 200 SP Open Controller (F);
• SIMATIC S7-1500 Software Controller;
• SIMATIC IPC547E;
• SIMATIC ITP1000;
• SIMATIC IPC3000 SMART V2;
• SIMATIC IPC347E;
• SIMATIC HMI Basic; and
• Panels 2nd Generation:

They also removed the following unaffected products from the advisory:

• SIMATIC IPC227E;
• SIMATIC IPC277E;
• SIMATIC IPC327E; and
• SIMATIC IPC377E

NOTE: NCCIC-ICS is expected to update their advisory.


Siemens published an update for their advisory on Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP. They added two additional vulnerabilities to the list for these products:

• CVE-2018-1000876; and
• CVE-2018-16862
NOTE: NCCIC-ICS has not published an advisory/alert on these vulnerabilities.

Siemens has published an update for their advisory on Denial-of-Service in SICAM A8000 Series. They updated the CVSS vector due to known exploit.


Siemens has published an update for their advisory on Foreshadow / L1 Terminal Fault Vulnerabilities in Industrial Products. They updated the affected version data and provided links to the mitigation measures for:

• SIMATIC IPC547E;
• SIMATIC IPC547G;
• SIMATIC ITP1000;
• SIMATIC IPC3000 SMART V2; and
• SIMATIC IPC347E

They also removed the following unaffected products from the advisory:

• SIMATIC IPC227E;
• SIMATIC IPC277E;
• SIMATIC IPC327E; and
• SIMATIC IPC377E
NOTE: NCCIC-ICS has not published an advisory/alert on these vulnerabilities.

Resource Data Management


Safety Detective published an article describing default credential vulnerabilities for commercial refrigeration systems from Resource Data Management. The article describes how the researchers were able to locate vulnerable systems, change settings, and manipulate controls in systems in hospitals and stores.

AVEVA Exploit


Jacob Baines published an exploit for vulnerabilities in the AVEVA InduSoft Web Studio. The vulnerabilities were reported by NCCIC-ICS earlier this month.

Friday, November 2, 2018

Four Advisories and One Update Published


Yesterday the DHS NCCIC-ICS published four new control system security advisories for products from Fr. Sauter, Circontrol, Schneider Electric, AVEVA. They also updated a previously published advisory for products from Rockwell.

Sauter Advisory


This advisory describes an improper restriction of XML external entity reference in the Sauter CASE Suite application. The vulnerability was reported by Gjoko Krstic of Applied Risk. Sauter has an update that mitigates the vulnerability. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low skilled attacker could remotely exploit the vulnerability to allow an attacker to remotely retrieve unauthorized files from the system.

Circontrol Advisory


This advisory describes two vulnerabilities in the Circontrol CirCarLife electric vehicle charging station. The vulnerabilities were reported by Ankit Anubhav of NewSky Security, M. Can Kurnaz Senior Consultant at KPMG Netherlands, Alim Solmaz Security Consultant at Atos, Michael John Chief Information Security Officer at WePower Network, and Gyorgy Miru Security Researcher at Verint. Circontrol has a new version that mitigates the vulnerability. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Authentication bypass using an alternate path or channel - CVE-2018-17918; and
Insufficiently protected credentials - CVE-2018-17922

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow a remote attacker to retrieve credentials stored in clear text to bypass authentication, and see and access critical information.

Schneider Advisory


This advisory describes a DLL hijacking vulnerability in the Schneider Software Update (SESU) installed with a wide variety of Schneider products. The vulnerability was reported by Haojun Hou of ADLab of Venustech. Schneider has an update that mitigates the vulnerability. There is no indication hat Haojun has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to execute arbitrary code on the target system.

NOTE: I had previously discussed this vulnerability last weekend.

AVEVA Advisory


This advisory describes two vulnerabilities in the AVEVA InduSoft Web Studio and InTouch Edge HMI. These vulnerabilities were reported by Tenable. AVEVA has new versions that mitigate the vulnerabilities. There is no indication that Tenable was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-17916; and
• Empty password in configuration file - CVE-2018-17914

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an unauthenticated user to remotely execute code.

Rockwell Update


This update provides additional information on an advisory that was originally published on October 26th, 2017. The update provides new mitigation information based upon new limitations on the impact of the vulnerability.

NOTE: This is the KRACK vulnerability advisory for the Rockwell Stratix 5100 Wireless Access Point/Workgroup Bridge.


Tuesday, July 10, 2018

ICS-CERT Publishes 2 Advisory – Updates Spectre Alert


Today the DHS ICS-CERT published two control system security advisories for products from Schweitzer Engineering and Universal Robots. They also updated their alert for Meltdown/Spectre vulnerabilities.

Schweitzer Advisory


This advisory describes three vulnerabilities in the Schweitzer Compass and AcSELerator Architect products. The vulnerabilities were reported by Gjoko Krstic of Applied Risk. The latest versions of the software mitigate the vulnerability. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Incorrect default permissions - CVE-2018-10604;
• Improper restriction of XML external entity reference - CVE-2018-10600; and
Uncontrolled resource consumption - CVE-2018-10608

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability with publicly available exploit code to allow modification/replacement of files within the Compass installation directory, disclosure of information, or denial of service.

Universal Robots Advisory


This advisory describes two vulnerabilities in the Universal Robots Robot Controllers. The vulnerabilities were reported by Davide Quarta, Mario Polino, Marcello Pogliani, and Stefano Zanero from Politecnico di Milano as well as Federico Maggi with Trend Micro Inc. Universal Robots has described generic workarounds to mitigate the vulnerabilities. There is no indication that any of the researchers have been provided with an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Use of hard-coded credentials - CVE-2018-10633; and
• Missing authentication for critical function - CVE-2018-10635

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to run arbitrary code on the device.

Meltdown/Spectre Update


This update provides additional information on an alert that was originally published on January 11th, 2018 and updated on January 16th, 2018, January 17th, 2018, January 30th, 2018, February 20th, 2018, February 22nd, 2018, March 1st, 2018 and again on April 26th, 2018 (typo in ICS-CERT update says 4-27-18). The update provides a link to the new PEPPERL+FUCHS (ecom mobile devices) advisory that I discussed on Saturday.

Thursday, June 7, 2018

ICS-CERT Publishes an Advisory and an Update


Today the DHS ICS-CERT published a new control system security advisory for products from Rockwell. They also published an update to a control system security advisory for products from Delta Electronics.

Rockwell Advisory


This advisory describes an unquoted search path or element vulnerability in the Rockwell RSLinx Classic and FactoryTalk Linx Gateway. The vulnerability was reported byGjoko Krstic of Zero Science Lab. Rockwell has new versions available that mitigate the vulnerability. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an authorized, but non-privileged local user to execute arbitrary code and allow a threat actor to escalate user privileges on the affected workstation.

NOTE: The advisory points to an older Rockwell description of an unquoted search path vulnerability and how it works.

Delta Update


This update provides additional information on an advisory that was originally published on May 17th, 2018. The revised version provides a link to a new version that mitigates the vulnerability and additional NCCIC recommendations for generic mitigation measures.

Saturday, March 3, 2018

Public ICS Disclosures – Week of 2-24-18


We have two new vendor security advisories this week from Schneider and Siemens. Siemens also published an update to their ultrasound products notice for the WannaCry vulnerability. I mentioned the Siemens advisory and update in passing earlier this week.

Schneider Advisory


This advisory describes 11 vulnerabilities in the Pelco Sarix Professional fixed IP video surveillance cameras. The vulnerabilities were variously reported by Deng Yongkai of NSFOCUS Security Team, Melih Berk Eksioglu of Biznet Bilisim A.S., and Gjoko Krstic of Zero Science Labs. Schneider has a new firmware version that mitigates the vulnerabilities. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The reported vulnerabilities include:

• Information disclosure - CVE-2018-7227;
• Authentication bypass (3) - CVE-2018-7228, CVE-2018-7229, and CVE-2018-7236;
• XML external entity vulnerability - CVE-2018-7230;
• Command execution vulnerability (4) - CVE-2018-7231, CVE-2018-7232, CVE-2018-7233, and CVE-2018-7235;
• Arbitrary file download - CVE-2018-7234; and
Arbitrary file delete - CVE-2018-7237

ICS-CERT has published some surveillance camera security advisories, but it has been hit and miss. My coverage here has also been hit and miss since I lost (paid) access to the IPVM web site; they are certainly the best information source for vulnerability information (and lots of other information) on video systems. Since Schneider owns Pelco, there will be specific coverage in these weekly posts as appropriate since Schneider publishes a list of advisories as they are issued. That does not mean that other video systems are vulnerability free, just that I have not seen their reports.

Siemens Advisory


This advisory describes 8 vulnerabilities in the Siemens SIMATIC industrial PCs. The vulnerabilities are due to the presence of one or more of three Intel products in the PCs; Intel reported on these vulnerabilities back in November, 2017. Siemens has identified a generic work around for the vulnerabilities and there is no indication that further mitigations are in the works.

The reported vulnerabilities include:

• Buffer overflow (5) - CVE-2017-5705, CVE-2017-5706, CVE-2017-5707, CVE-2017-5711, and CVE-2017-5712; and
• Privilege escalation (3) - CVE-2017-5708, y CVE-2017-5709, and CVE-2017-5710;

The underlying Intel problems are wide spread and relatively serious. The Siemens advisory does not comment on the Intel mitigation measures (required dual firmware and software updates) nor the Intel detection tool. I wonder if they are still checking to see if those mitigations are compatible with their products or whether they are working on updates that will work with the Intel mitigation measures. It is not like Siemens not to provide this type of information.

Siemens Update


This update describes new mitigation information for the WannaCry vulnerability in the Siemens Healthineers ultrasound products. Technically, this update was included (but certainly not mentioned) in the latest ICS-CERT update of their WannaCry Alert (dated June 13th, 2017) since the link for this product line automatically takes one to the latest version.

Thursday, December 21, 2017

ICS-CERT Publishes Two Advisories

Today the DHS ICS-CERT published control system security advisories for products from Schneider and Moxa.

Schneider Advisory 

This advisory describes three vulnerabilities in the Schneider Pelco VideoXpert Enterprise products. The vulnerabilities were reported by Gjoko Krstic. Schneider has released a firmware update that mitigates the vulnerabilities. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Path traversal (2) - CVE-2017-9964, CVE-2017-9965; and
• Improper access control - CVE-2017-9966

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to gain system privileges or allow an unauthorized user to view files.

Moxa Advisory


This advisory describes a credentials management vulnerability in the Moxa NPort serial network interface. The vulnerability was reported to Federico Maggi. Moxa has produced a new firmware version that mitigates the vulnerability. There is no indication that Maggi was provided an opportunity to verify the efficacy of the fix.


ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow unauthorized access.

Tuesday, August 22, 2017

ICS-CERT Publishes 3 Advisories

Today the DHS ICS-CERT published three control system security advisories for products from SpiderControl (2) and Automated Logic Corporation.

SCADA Web Server Advisory 


This advisory describes a path traversal vulnerability in the SpiderControl SCADA Web Server. The vulnerability was reported by Karn Ganeshen via the Zero Day Initiative (ZDI). SpiderControl has produced a new version that mitigates the vulnerability. There is no indication that Ganeshen has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to gain read access to system files through directory traversal.

SCADA MicroBrowser Advisory


This advisory describes a stack-based buffer overflow vulnerability in the SpiderControl SCADA MicroBrowser. The vulnerability was reported by Karn Ganeshen via ZDI. SpiderControl has produced a new version that mitigates the vulnerability. There is no indication that Ganeshen has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to gain access to the system, manipulate system files, and potentially render the system unavailable.

Automated Logic Advisory


This advisory describes three vulnerabilities in the ALC WebCTRL, i-Vu, and SiteScan Web. The vulnerabilities were reported by Gjoko Krstic from Zero Science Lab. ALC has produced patches that mitigate the vulnerabilities. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Unquoted search path or element - CVE-2017-9644;
• Path traversal - CVE-2017-9640; and
• Unrestricted upload of file with dangerous type - CVE-2017-9650


ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerabilities to elevate his or her privileges to execute arbitrary code on the system.
 
/* Use this with templates/template-twocol.html */