Showing posts with label Haojun Hou. Show all posts
Showing posts with label Haojun Hou. Show all posts

Tuesday, October 22, 2019

1 Advisory Published – 10-22-19


Today he CISA NCCIC-ICS published a control system security advisory for products from Schneider

Schneider Advisory


This advisory describes three vulnerabilities in the Schneider ProClima building and automation control products. The vulnerabilities were reported by Haojun Hou, Kushal Arvind Shah, Fortinet, Yongjun Liu, NSFOCUS, and Telus. Schneider has released a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

Code injection - CVE-2019-6823;
Improper restriction of operations within the bounds of a memory buffer - CVE-2019-6824; and
Uncontrolled search path element - CVE-2019-6825

NCCIC-ICS reported that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system.

NOTE: According to the Schneider advisory these vulnerabilities were reported on June 11th, and I briefly reported on them on June 15th. What NCCIC-ICS is actually addressing is an update to the original advisory that adjusted the CVSS Base Score and Vector for CVE2019-6823 and CVE-2019-6824.

Saturday, June 15, 2019

Public ICS Disclosure – Week of 06-08-19


This week we have two new vendor notifications from Schneider and 18 researcher reports from Talos of vulnerabilities in products from Schneider. We also have four updated notifications from Schneider (2) and Siemens (2). Additionally, we have two vendor updates for advisories about the Microsoft® RDP vulnerability from Philips and Drager.

Schneider Advisories


1. Schneider published an advisory for a credential exposure vulnerability in the Schneider PowerSCADA Expert product (NOTE: According to Schneider this also affects the AVEVA CitecSCADA, but no AVEVA advisory has yet been published). This vulnerability is apparently self-reported. Schneider has a new version that mitigates the vulnerability.

2. Schneider published an advisory for three vulnerabilities in the Schneider ProClima product. The vulnerabilities were reported by Kushal Arvind Shah (Fortinet), Telus, and Haojun Hou and
Yongjun Liu (NSFOCUS). Schneider has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

Code injection - CVE-2019-6823;
Buffer errors - CVE-2019-6824; and
Uncontrolled search path element - CVE-2019-6825

Talos Reports on Schneider Vulnerabilities


Talos has provided reports with exploits on 18 vulnerabilities in two products from Schneider; Modicon 580 UMAS and UnityPro PLC. These are coordinated disclosures, but Schneider has not yet published advisories for these vulnerabilities. Because of the volume I am not going to attempt to go into details.

Modicon 580 UMAS

Information disclosure - CVE-2018-7845;
Denial of service - CVE-2018-7854;
Denial of service - CVE-2018-7853;
Denial of service - CVE-2018-7849;
Improper authentication - CVE-2018-7842;
Unauthenticated file write - CVE-2018-7847;
Denial of service - CVE-2018-7855;
Denial of service - CVE-2019-6807;
Denial of service - CVE-2018-7856;
Information disclosure - CVE-2018-7844;
Information disclosure - CVE-2019-6806;
Information disclosure - CVE-2018-7848;
Denial of service - CVE-2018-7852;
Denial of service - CVE-2018-7846;
Denial of service - CVE-2018-7857; and
Denial of service - CVE-2018-7843

UnityPro

Remote code execution - CVE-2019-6808;
Untrusted inputs - CVE-2018-7850;

NOTE: There are still 10 reports pending on Schneider vulnerabilities on the Talos Zeroday Reports web page. Someone has been spending a great deal of time testing Schneider equipment.

Schneider Updates


1. Schneider updated an advisory for the Schneider Embedded Web Servers for Modicon V2 (Note: this has not been reported by NCCIC-ICS). The new information is the addition of researcher acknowledgements.

2. Schneider updated an advisory for the Schneider – U.motion Builder software (Note: this has not been reported by NCCIC-ICS). Schneider is reporting that this vulnerability has been exploited by Mirai malware. Schneider is making an unusual recommendation: “It is imperative customers cease using U.motion Builder software and remove it from their systems immediately.”

Siemens Updates


1. Siemens updated an advisory for Foreshadow/L1 terminal fault vulnerabilities in Industrial Products (Note: this has not been reported by NCCIC-ICS). The new information is added mitigation measures for:

SIMATIC S7-1500 Software Controller;
SIMATIC ET 200 SP Open Controller; and
SIMATIC ET 200 SP Open Controller (F)

2. Siemens updated an advisory for Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU. The update adds information for new firmware V2.6.1

RDP Vulnerability


Two vendor advisories were updated this week:

Philips; and
Drager

Friday, November 2, 2018

Four Advisories and One Update Published


Yesterday the DHS NCCIC-ICS published four new control system security advisories for products from Fr. Sauter, Circontrol, Schneider Electric, AVEVA. They also updated a previously published advisory for products from Rockwell.

Sauter Advisory


This advisory describes an improper restriction of XML external entity reference in the Sauter CASE Suite application. The vulnerability was reported by Gjoko Krstic of Applied Risk. Sauter has an update that mitigates the vulnerability. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low skilled attacker could remotely exploit the vulnerability to allow an attacker to remotely retrieve unauthorized files from the system.

Circontrol Advisory


This advisory describes two vulnerabilities in the Circontrol CirCarLife electric vehicle charging station. The vulnerabilities were reported by Ankit Anubhav of NewSky Security, M. Can Kurnaz Senior Consultant at KPMG Netherlands, Alim Solmaz Security Consultant at Atos, Michael John Chief Information Security Officer at WePower Network, and Gyorgy Miru Security Researcher at Verint. Circontrol has a new version that mitigates the vulnerability. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Authentication bypass using an alternate path or channel - CVE-2018-17918; and
Insufficiently protected credentials - CVE-2018-17922

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow a remote attacker to retrieve credentials stored in clear text to bypass authentication, and see and access critical information.

Schneider Advisory


This advisory describes a DLL hijacking vulnerability in the Schneider Software Update (SESU) installed with a wide variety of Schneider products. The vulnerability was reported by Haojun Hou of ADLab of Venustech. Schneider has an update that mitigates the vulnerability. There is no indication hat Haojun has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to execute arbitrary code on the target system.

NOTE: I had previously discussed this vulnerability last weekend.

AVEVA Advisory


This advisory describes two vulnerabilities in the AVEVA InduSoft Web Studio and InTouch Edge HMI. These vulnerabilities were reported by Tenable. AVEVA has new versions that mitigate the vulnerabilities. There is no indication that Tenable was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-17916; and
• Empty password in configuration file - CVE-2018-17914

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an unauthenticated user to remotely execute code.

Rockwell Update


This update provides additional information on an advisory that was originally published on October 26th, 2017. The update provides new mitigation information based upon new limitations on the impact of the vulnerability.

NOTE: This is the KRACK vulnerability advisory for the Rockwell Stratix 5100 Wireless Access Point/Workgroup Bridge.


Saturday, October 27, 2018

Public ICS Disclosures – Week of 10-20-18


This week we have two vendor notifications for products from Schneider Electric and Eaton.

Schneider Advisory


This advisory describes a DLL hijacking vulnerability in the Schneider Electric Software Update (SESU) which is installed with a wide variety of Schneider products. The vulnerability was reported by Haojun Hou (ADLab of Venustech). Schneider has an update available to mitigate the vulnerability. There is no indication that Haojun has been provided an opportunity to verify the efficacy of the fix.

Eaton Advisory


This advisory mentions an un-explicated vulnerability in the Eaton Network Card-MS for UPS. This vulnerability is apparently being self-reported. Eaton has a newer version of the firmware that mitigates the vulnerability.

NOTE: This is about the most worthless security notification that I have ever seen. Not only does it not describe the vulnerability (or provide a CVE number, or describe the associated risk), but the “link” to cybersecurity whitepaper which presumably provides potentially useful generic workaround information for power distribution systems is not actually a link; it is just the blue-underlined word “here”. Oh, and by the way, how many people know the firmware version number of the network communication card is in their UPS?

Tuesday, March 6, 2018

ICS-CERT Publishes 3 Advisories and One Siemens Update


Today the DHS ICS-CERT published three new control system security advisories for products from Eaton, Schneider Electric, and Hirschmann Automation. The also updated a previously issued advisory for products from Siemens.

Eaton Advisory


This advisory describes an improper input validation vulnerability in the Eaton ELCSoft programming software. The vulnerability was reported by Ariele Caltabiano (kimiya) and axt working with the Zero Day Initiative. Eaton has produced a new version of the software (ICS-CERT mistakenly refers to ‘firmware’) to mitigate this vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to execute arbitrary code. The Eaton Security Update Advisory [.PDF Download] notes that the vulnerability only affects the Windows® based PCs that run the software, not the programmable logic controllers being programed.

Schneider Advisory


This advisory describes an uncontrolled search path element vulnerability in the Schneider SoMove software and DTM software components. The vulnerability was reported by ADLab of Venustech (NOTE: The Schneider security notification credits Haojun Hou from Adon with reporting the vulnerability). Schneider has produced new software versions that mitigate the vulnerabilities. There is no indication that the researchers have been afforded an opportunity to verify the efficacy of the fix.

ICS-CERT reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerability to execute arbitrary code.

Hirschmann Advisory


This advisory describes multiple vulnerabilities in the Hirschmann Classic Platform Switches. These vulnerabilities were reported by Ilya Karpov, Evgeniy Druzhinin, Mikhail Tsvetkov, and Damir Zainullin of Positive Technologies. Hirschmann provides workarounds to mitigate the vulnerabilities; there is no indication that additional mitigation measures are forthcoming. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Session fixition - CVE-2018-5465;
• Information exposure through query strings in get requests - CVE-2018-546;
• Cleartext transmission of sensitive information - CVE-2018-5471;
• Inadequate encryption strength - CVE-2018-5461; and
Improper restriction of excessive authentication requests - CVE-2018-5469

ICS-CERT reports that a highly-skilled attacker could remotely exploit these vulnerabilities to hijack web sessions, impersonate a legitimate user, receive sensitive information, and gain access to the device.

Siemens Update


This update provides new information on an advisory that was was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th,  November 28th, 2017, and most recently January 18th, 2018, January 25th, 2018, and most recently on January 27th, 2018. The new information is a link to mitigation measures for SCALANCE X-200IRT. ICS-CERT did not update the affected version information for this product to include the latest information in the Siemens security advisory; all versions before V5.4.0 are affected.

 
/* Use this with templates/template-twocol.html */