Showing posts with label HART DTM. Show all posts
Showing posts with label HART DTM. Show all posts

Tuesday, March 10, 2015

ICS-CERT Publishes 5 Advisories

This morning DHS ICS-CERT published five advisories for industrial control system vulnerabilities. The affected systems come from GE, Elipse, SCADA Engine, ABB, and CIMON.

GE Advisory

This advisory describes a predictable TCP sequence vulnerability in GE Digital Energy’s Hydran M2 device. The vulnerability was reported by Raheem Beyah, David Formby, and San Shin Jung of Georgia Tech. GE has eliminated this vulnerability in versions of the product produced after October 2014. There is no indication that the researchers have verified that the vulnerability has been removed from newer versions of the device. This vulnerability was originally reported on the US-CERT Secure Portal on February 10th.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to send counterfeit packets as if they came from the device.

Since the vulnerable devices cannot be fixed they either have to be replaced or protected by other measures which would isolate them from the attack.

Elipse Advisory

This advisory describes a process control vulnerability in the Elipse E3 application; the vulnerability is actually located in a third-party (Telerik) DLL. The vulnerability was reported by Ivan Sanchez from Nullcode Team. Elipse has produced a new version which mitigates the vulnerability. ICS-CERT reports that Sanchez has verified the efficacy of the fix.

ICS-CERT reports that the vulnerability could not be remotely exploitable but goes on to explain that a social engineering attack could cause an authorized operator to load a compromised DLL.

ICS-CERT reports that Telerik has notified its other affected customer of the problem with its DLLs and has provided them with updated version that do not include the vulnerability. Hopefully those other un-named vendors will notify their customers of the vulnerability.

SCADA Engine Advisory

This advisory describes three vulnerabilities in the SCADA Engine BACnet OPC Server. These vulnerabilities were reported by Josep Pi Rodriguez. SCADA Engine has produced a new software version that mitigates the vulnerabilities. ICS-CERT reports that Rodriquez has verified the efficacy of the fix.

The three vulnerabilities are:

● Heap-based buffer overflow - CVE-2015-0979;
● Input validation - CVE-2015-0980; and
● Authentication - CVE-2015-0981

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to execute arbitrary code or modify the OPC Server database.

ABB Advisory

This advisory reports on the CodeWright HART DTM vulnerability in ABB products. The base information provided in this advisory is the same as that found in the latest version of the CodeWright advisory. ICS-CERT reports that ABB has begun to integrate the new CodeWright library but ABB reports that they have updated versions for the affected products which include the corrected CodeWright libraries.

CIMON Advisory

This advisory describes a DLL hijacking vulnerability in the CIMON CmnView.exe application. The vulnerability was reported by Ivan Sanchez of Wise. CIMON has produced a patch that mitigates the vulnerability but there is no indication that Sanchez has verified the efficacy of the patch.

ICS-CERT reports that the vulnerability is remotely exploitable via a social engineering attack. No exploit is publicly available for this specific system but there are publicly available exploits for this ‘attack vector’.

Fix Verification

Some people have asked me why I make a big deal out of announcing whether or not the researcher who discovered a vulnerability has verified the efficacy of the fix. After all, I am asked, isn’t it in the best interest of the vendor for the fix to work? Today a report from the Zero Day Initiative showed why it may be important for an outsider to verify fixes.

One of the key vulnerabilities exploited by Stuxnet was the now infamous Microsoft MS10-046 vulnerability. This vulnerability allowed systems to automatically run DLL files from USB devices without the operator initiating the action or even knowing that it took place. Microsoft patched that vulnerability four years ago. Earlier this year Michael Heerklotz reported that the patch did not work.

If Microsoft can convince themselves that a flawed patch mitigates a vulnerability then anyone can. A researcher that discovers a vulnerability looks at it in a different light than does a software engineer that is fixing it under a deadline. Two ways of looking at the problem may not actually be enough, but it is certainly better than just one way.


I’ll continue to be the gadfly that reports whether or not ICS-CERT is reporting that an outsider has verified the efficacy of the mitigation measure being reported.

Tuesday, February 17, 2015

ICS-CERT Publishes 3 Advisories and an Update

Today the DHS ICS-CERT published an update of a Siemens advisory from last year, two new Siemens advisories and an advisory for Yokogawa. Siemens also updated their GNU Bash advisory but that did not necessitate an update of the ICS-CERT supplement for that vulnerability.

Siemens Update

As I predicted ICS-CERT had to issue update ‘G’ to their Siemens OpenSSL Advisory. They did me one better though. They waited until Siemens published the notice of the availability of the update for APE V2.0.2 and ROX V2.6.0 with ELAN before they updated the advisory. This should effectively close out this set of vulnerabilities.

Yokogawa Advisory

This advisory concerns the HART DTM vulnerability for Yokogawa devices that use the CodeWrights  DTM library. The language in this advisory is the same as that found in the latest CodeWrights advisory. The only odd thing about this advisory is that Yokogawa was not listed as a CodeWrights customer on that earlier advisory. I wonder how many other vendors will also turn out to be affected.

Note: Both the Yokogawa advisory and the JP CERT advisory referenced in the ICS-CERT document are in Japanese. I would have thought that Yokogawa would have produced an English language version for the US market.

Siemens WinCC TIA Portal Advisory

This advisory describes twin authentication vulnerabilities in the Siemens WinCC TIA Portal. The vulnerabilities were originally reported by Gleb Gritsai, Roman Ilin, Aleksandr Tlyapov, and Sergey Gordeychik from Positive Technologies. Siemens has produced a new service pack that mitigates these vulnerabilities, but there is no indication that the researchers were given the opportunity to verify the efficacy of the fix.

The two vulnerabilities are:

● Insufficiently protected credentials - CVE-2015-1358; and
● Hard coded cryptographic key - CVE-2014-4686 (NOTE: This same vulnerability was reported by the same researchers in Siemens WinCC last July)

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to reconstruct passwords or escalate privileges on the network. Siemens notes that an exploit of the first vulnerability requires capturing network traffic of the remote management module.

Siemens WinCC Step 7 TIA Portal Advisory

This advisory describes twin authentication vulnerabilities in the WinCC Step 7 TIA Portal. The vulnerabilities were reported by Aleksandr Timorin from Positive Technologies. Siemens has produced a service pack that mitigates the vulnerabilities but there is no indication that Timorin has been given the opportunity to verify the efficacy of the fix.

The vulnerabilities are:

● Weak password hashing - CVE-2015-1355; and
● Permissions, privileges and access control - CVE-2015-1356



ICS-CERT reports that an exploit would require a social engineering attack that could result in remote exploitation of this vulnerability to reconstruct passwords or gain permission to access the system.  Siemens notes that the second vulnerability requires local access to the TIA project file.

Thursday, January 29, 2015

ICS-CERT Publishes Another HART DTM Advisory

This afternoon the DHS ICS-CERT published another HART DTM advisory, this time for systems from Honeywell. This new advisory lists the affected Honeywell systems and reports that Honeywell has validated the CodeWrights fix in their equipment. Honeywell has made a patch available.

I guess that ICS-CERT has decided against listing all of the vulnerable systems in the CodeWrights advisory as they had originally reported. I can see pros and cons for either method of reporting.


I won’t describe these vulnerabilities in detail when I report them; no sense in just repeating the same words each time. Instead, I’ll just refer back to the original Emerson advisory since that is the only one so far to specifically mention physical security of the communications loop.

Monday, January 12, 2015

ICS-CERT Extends Emerson Advisory

Today the DHS ICS-CERT published a new advisory for the vulnerability they reported in the Emerson HART DTM last week. The difference is that instead of just limiting the advisory to Emerson HART DTM they are extending it to all versions of the DTM that use the same DTM libraries produced by CodeWrights. Specifically they include HART systems from:

● ABB,
● Berthold Technologies,
● Emerson,
● Endress+Hauser,
● Magnetrol, and
● Pepperl+Fuchs.

As with the revised advisory published on Friday, ICS-CERT claims that there are no publicly available exploits of these vulnerabilities. CodeWrights has developed a new version of the library and Emerson has tested the library to validate its efficacy. No one has apparently asked the original researcher, Alexander Bolshev, to validate the new library efficacy.


At this point it seems that only Emerson has fixed the vulnerability in their use of the libraries. ICS-CERT states that it will update this advisory when additional reports of fixes have been provided. They also note that CodeWrights is only providing the updated libraries to ‘customers with current support agreements’. This would seem to suggest that other vendors with HART applications may be using the same affected libraries.

Friday, January 9, 2015

ICS-CERT Updates Yesterday’s Emerson Advisory

This afternoon the DHS ICS-CERT updated the advisory they published yesterday for an improper input vulnerability in the Emerson HART DTMs. Recent readers will be familiar with the revision published today; ICS-CERT reversed their claim that; “Exploits that target this vulnerability are known to be publicly available.” They now report that:  “No known public exploits specifically target this vulnerability.”

There was nothing in the Emerson Security Report that mentioned the existence of exploits. I noted a BlackHat 2014 presentation about DTMs made by Alexander Bolshev, the researcher who reported the vulnerability, but it does not actually show an exploit. Bolshev’s S4x14 talk shows a number of HART exploits, but not one I can point to as being this one.


I guess the key here is that Emerson probably complained that there is no public exploit of the specific vulnerability reported in this advisory. Not being able to point to a specific exploit, ICS-CERT was forced to print their ‘correction’.
 
/* Use this with templates/template-twocol.html */