Showing posts with label Gleb Gritsai. Show all posts
Showing posts with label Gleb Gritsai. Show all posts

Tuesday, December 17, 2019

2 Advisories Published – 12-17-19


Today the CISA NCCIC-ICS published two control system security blogs for products from Siemens and GE.

Siemens Advisory


This advisory describes 54 vulnerabilities in the Siemens SPPA-T3000 servers. The vulnerabilities were reported by Gleb Gritsai, Eugenie Potseluevskaya, Sergey Andreev, and Radu Motspan from Kaspersky Lab; Vyacheslav Moskvin, and Ivan B from Positive Technologies; and Can Demirel from Biznet Bilisim Sistemleri ve Danışmanlık. Siemens has an update that mitigates three of the vulnerabilities on one of the affected products. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

Sorry, I am not going to list the 54 vulnerabilities.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to execute arbitrary code on the server, cause a denial-of-service condition, view and modify passwords, gain root privileges, access sensitive information, and read and write arbitrary files on the local system.

NOTE: This is the new vulnerability of the Siemens monthly drop from last week. I briefly discussed these vulnerabilities last Saturday.

GE Advisory


This advisory describes a cross-site scripting vulnerability in the GE S2020/S2020G Fast Switch 61850, a managed Ethernet switch. The vulnerability was reported by Murat Aydemir of Biznet Bilisim A.S.. GE has a new version that mitigates the vulnerability. There is no indication that Aydemir has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to inject arbitrary code and allow disclosure of sensitive data.

Wednesday, December 12, 2018

Two Advisories and Three Updates Published – 12-11-18


Yesterday the DHS NCCIC-ICS published two control system security advisories and updates to two previously published control system advisories; all for products from Siemens. They also published a medical device security advisory for products from Philips.

SINUMERIK Advisory


This advisory describes ten vulnerabilities in the Siemens SINUMERIK Controllers. The vulnerabilities were reported by Anton Kalinin, Danila Parnishchev, Dmitry Sklyar, Gleb Gritsai, Kirill Nesterov, Radu Motspan, and Sergey Sidorov from Kaspersky Lab. Siemens has updates for several of the products and provides work arounds for the others. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The ten reported vulnerabilities are:

• Heap-based buffer overflow - CVE-2018-11457;
• Integer overflow or wraparound - CVE-2018-11458;
• Protection mechanism failure (2) - CVE-2018-11459 and CVE-2018-11460;
• Permission, privileges and access control (2) - CVE-2018-11461 and CVE-2018-11462;
• Stack-based buffer overflow - CVE-2018-11463; and
Uncaught exception (3) - CVE-2018-11464, CVE-2018-11465 and CVE-2018-11466

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to cause denial-of-service conditions, privilege escalation, or allow remote code execution.

SINAMICS Advisory


This advisory describes an improper access control vulnerability in the Siemens SINAMICS PERFECT HARMONY GH180 (based upon a 3rd party vulnerability – McAffee Application and Change Control). The vulnerability was reported by McAffee. Siemens recommends installing a McAffee update to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with physical access could exploit the vulnerability to compromise the HMI, and by extension, the drive system.

PROFINET Update


This update provides new information on an advisory that This update provides additional information on an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th,  November 28th, 2017January 18th, 2018, January 25th, 2018, January 27th, 2018, March 6th, 2018, May 3rd, 2018 and most recently on November 13th, 2018. The update provides new affected version information and mitigation measures for:

• SIMATIC ET 200MP IM155-5 PN HF; and
• SIRIUS ACT 3SU1 interface module PROFINET

Industrial Products Update


This update provides new information on an advisory that This update provides additional information on an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th, November 28th, February 27th, 2018, May 3rd, 2018 May 15th, 2018, September 11th, 2018, October 9th, 2018 and most recently on November 13th, 2018. This update provides new mitigation information for SIMATIC ET 200MP IM155-5 PN HF.

Philips Update


This update provides new information on an advisory that was originally published on March 27th, 2018. This update slips the new version expected date from ‘December 2018’ to ‘Q1 of 2019’.

Other Siemens Updates


Yesterday Siemens published a total of three new advisories and seven updates. We may see more from NCCIC-ICS later this week, but some will not be specifically addressed by NCCIC-ICS. I will have further information on the remainder on Saturday.

Thursday, July 30, 2015

ICS-CERT Updates one Advisory and Publishes Another

This afternoon the DHS ICS-CERT updated a Siemens advisory for SIMATIC HMI Devices and publishes a new advisory for Schneider Electric InduSoft Wb Studio.

Siemens Update

This update notes that Siemens is now reporting that all of the affected HMI devices now have updates available to mitigate the three vulnerabilities reported in the original advisory back in April. It also adds three different types of SIMATIC HMI panels to the list of affected and mitigated products.

Schneider Advisory

This advisory describes a clear-text storage of sensitive information vulnerability in Schneider’s Electric InduSoft Web Studio and InTouch Machine. The vulnerability was originally reported by Gleb Gritsai, Alisa Esage Shevchenko, Ilya Karpov, and the team from Positive Technologies Security. Schneider has produced patches to mitigate the vulnerability but there is no indication that the researchers have been given the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker with local access can obtain project passwords from the configuration file. These can then be used to execute arbitrary code.


NOTE: The link provided in the Advisory for the Schneider report on the InduSoft version of this vulnerability does not get to the report; Schneiderdoes not yet have the vulnerability listed. Here is the direct link.

Thursday, March 26, 2015

ICS-CERT Published Schneider Advisory

Today the DHS ICS-CERT published an advisory for multiple vulnerabilities in two Schneider Electric products, InduSoft WebStudio and InTouch Machine. The vulnerabilities were reported by Gleb Gritsai, Ilya Karpov, and Kirill Nesterov of Positive Technologies Security Lab and independent researcher Alisa Esage Shevcheckno. Schneider has produced patches for the products, but there is no indication that the researchers were provided the opportunity to verify the efficacy of the fix.

The vulnerabilities include:

∙ Hard-coded credentials - CVE-2015-0996;
∙ Authentication - CVE-2015-0997; and
∙ Clear-text transmission of sensitive information - CVE-2015-0998 and CVE-2015-0999.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to execute arbitrary code. They also mention that there may be exploits for these vulnerabilities publicly available.


Schneider published separate advisories for the two product lines (here and here). The two advisories are nearly identical and neither mention publicly available exploits. They were also both published over a month ago. There is no indication about why ICS-CERT only recently got the information.

Thursday, July 24, 2014

ICS-CERT Publishes Two More Advisories

Some weeks it seems that everyday there is a new set of advisories from DHS ICS-CERT; this is one of those weeks. Today ICS-CERT published advisories for Siemens WinCC and the Morpho Itemizer. Oh, and they missed listing the Morpho advisory on both the landing page and the Advisories page; they did tweet about it though. When you get busy, mistakes happen unless you have good administrative controls in place.

Siemens Advisory

This advisory is based upon coordinated disclosures from an anonymous researcher and a separate report from Sergey Gordeychik, Alexander Tlyapov, Dmitry Nagibin, and Gleb Gritsai of Positive Technologies. Siemens has prepared an update that is reported to mitigate the multiple vulnerabilities, but there is no indication that the researchers have had a chance to verify the efficacy of the fix.

The vulnerabilities include:

• Forced browsing - CVE-2014-4682 – could allow unauthenticated access to data;
• Session fixation - CVE-2014-4683 – could allow remote privilege escalation;
• Improper privilege management - CVE-2014-4684 – could allow database privilege escalation;
• Permissions, privileges and access control - CVE-2014-4685 – could allow local user to escalate their privileges; and
• Hard-coded cryptographic key - CVE-2014-4686 – cold allow privilege escalation.

ICS-CERT reports that a low-to-moderately skilled attacker could remotely (except CVE-2014-4685) exploit these vulnerabilities. Siemens reports that they have produced an update that mitigates the vulnerabilities in WinCC and expect an update for Simatic PCS7 next month. In addition they suggest the following actions be taken until a hard fix can be established:

• Limit the WebNavigator server access to trusted networks/clients only
• Ensure that the WebNavigator clients authenticate themselves against the WebNavigator server (e.g. use client certificates)
• Restrict access to the WinCC database server at port 1433/tcp to trusted entities
• Deactivate all unnecessary OS users on WinCC server
• Run WinCC server and engineering stations within a trusted network, or
• Ensure that the WinCC server and the engineering stations communicate via encrypted channels only (e.g. establish a VPN tunnel).

Morpho Advisory

This advisory looks at a single hard-coded-credential vulnerability reported by Billy Rios and Terry McCorkle. ICS-CERT reports that: “Morpho has decided not to address this vulnerability at this time.” Since the Itemizer® 3 is not strictly speaking an industrial control system (it’s an analytical system controller) it could look like this is no big thing. It could, however, have an effect on police investigations that would rely on these pieces of equipment to identify drug and explosives trace evidence. A cyber savvy defense attorney could use this uncorrected vulnerability to cause a judge to question the validity of test data from this machine and potentially reverse a drug or explosives conviction or the use of the evidence in court.


ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability to gain administrative access to the system. Not much you can’t do once you have that access.


Tuesday, February 4, 2014

ICS-CERT Publishes Two Advisories

This afternoon the DHS ICS-CERT published advisories for control systems from two major vendors, Siemens and Rockwell. Both advisories were based upon vulnerabilities discovered by outside researchers that were revealed in coordinated disclosures.

Siemens Advisory

This advisory is based upon information disclosed in a Siemens ProductCERT advisory released Monday morning for SIMATIC WinCC OA. The multiple vulnerabilities covered in these advisories were discovered by Gleb Gritsai, Ilya Karpov, and Kirill Nesterov of Positive Technologies. The vulnerabilities were:

• Improper control of generation of code, CVE-2014-1697;
• Relative path traversal, CVE-2014-1698;
• Improper input validation, CVE-2014-1699; and
• Use of password hash with insufficient computational effort, CVE-2014-1696
NOTE: The CVE links have not yet become active.

Both advisories note that a moderately skilled attacker could remotely exploit the vulnerabilities to escalate their privileges, perform remote code execution, traverse through file systems, or cause a denial of service. Siemens does note that an attacker would have to have network access to exploit these vulnerabilities.

Siemens has produced software updates for systems affected by these vulnerabilities. Neither advisory mentions if the vulnerability discoverers have had a chance to verify the efficacy of the updates.

Rockwell Advisory

This advisory is based upon a vulnerability reported by Stephen Dunlap in a coordinated disclosure. Dunlap reported an insufficiently protected credential vulnerability in the RSLogix 5000 software. This advisory was previously posted to the US-CERT protected portal to allow system owners a chance to upgrade their systems before the vulnerability became public.

The vulnerability could allow an attacker to access and tamper with information in controller configuration programs. Not mentioned in the advisory is the fact that these files would provide invaluable information for an attacker to develop an exploit based upon some other access to the system.

ICS-CERT notes that a moderately skilled attacker could exploit the vulnerability through local access to the system when an authorized user accesses their password.


Rockwell has produced new versions of the RSLogix 5000 software that addresses these vulnerabilities. There is no mention of whether or not Dunlap has been provided an opportunity to verify the efficacy of the update software versions. Project files modified with the newer versions of the software cannot be opened by earlier versions. This means that an organization would have to upgrade all of their systems operating on the RSLogix 5000 software.
 
/* Use this with templates/template-twocol.html */