Showing posts with label HMI. Show all posts
Showing posts with label HMI. Show all posts

Saturday, August 22, 2026

Review - TSA Sends HMI Threat Assessment ICR to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received an extension without change of a currently approved collection from the DHS’ Transportation Security Administration for their “Security Threat Assessment for Individuals Applying for a Hazardous Materials Endorsement for a Commercial Driver's License” information collection request (ICR). The 30-day ICR notice was published earlier this week in the Federal Register (91 FR 53889-53890). The 60-day ICR notice was published on May 6th, 2026. 

The OMB reports that the following burden estimate data was provided to them by the TSA: 

Public Comments  

TSA and OIRA are soliciting public comments on the data being provided in the 30-day ICR notice that is currently being reviewed by OIRA. Comments may be submitted by going to OIRA’s Agency Submission page for this ICR and clicking on the “COMMENT” button near the top of the page. Comments should be submitted by September 21st, 2026. 

Commentary  

While not a function of the information collection process, the generally declining number of applicants and renewal requests reported by TSA for these security threat assessments for CDL hazardous materials indorsements presages an increasing problem for the chemical industry. The chemical industry can ill afford to deal with a declining number of truck drivers that are legally qualified to haul hazardous material loads. Industry is going to have to become more actively involved in recruiting truck drivers in general and HMI qualified drivers in particular. 

Thursday, April 9, 2015

ICS-CERT Publishes Siemens HMI Advisory

This morning the DHS ICS-CERT published an advisory for multiple vulnerabilities in a variety of Siemens HMI devices. The vulnerabilities were reported by the Quarkslab team and Ilya Karpov from Positive Technologies. Siemens has produced updates for most affected products (others are still in the works) but there is no indication that the researchers have been provided an opportunity to verify the efficacy of the fixes.

The vulnerabilities are:

∙ Man-in-the-Middle - CVE-2015-1601;
∙ Resource exhaustion - CVE-2015-2822; and
∙ Use of password hash instead of password for authentication - CVE-2015-2823

ICS-CERT reports that a moderately skilled attacker could remotely exploit these vulnerabilities to conduct man-in-the-middle attacks, denial‑of‑ service attacks, and possibly authenticate themselves as valid users depending on the vulnerability exploited.

With the large number of systems susceptible to these vulnerabilities I would suspect that they were only reported in one or two systems by the researchers. This would fit with the recent Siemens history of self-identifying vulnerabilities. If true Siemens is to be congratulated on their commitment improving the security of their systems. Some vendors recently identified with vulnerabilities in a portion of their product line would do well to emulate the Siemens model and proactively determine if the same vulnerability affects similar devices.

NOTE 1: It only took ICS-CERT a day to publish this advisory, they are getting better. My TWITTER followers will remember that this was announced yesterday morning my Siemens.


NOTE 2: Siemens appears to have developed a complicated internal method of determining when ‘enough’ systems have protections available to make it worthwhile to publish their advisories. We have seen this in a number of instances lately where ‘most’ of the affected systems have fixes in place and the other fixes come out over subsequent weeks and months. I hope that the researchers involved are aware of the risks that Siemens is taking with their more timely publication of vulnerabilities.
 
/* Use this with templates/template-twocol.html */