Showing posts with label Healthineers. Show all posts
Showing posts with label Healthineers. Show all posts

Saturday, November 19, 2022

Review – Public ICS Disclosures – Week of 11-12-22

This week we have two new OpenSSL 3.0 vendor disclosures from Eurotech, Ruckus Wireless. There are 24 other vendor disclosures from ABB, BD (2), Genetec, Hitachi Energy (2), HPE (2), Inductive Automation, Insyde (8), Mitsubishi, Moxa, OPC Foundation, Phoenix Contact, Sick (2), and Siemens Healthineers. There are three vendor updates from HPE, Mitsubishi (2), Palo Alto Networks. Finally, we have an exploit for products from Siemens.

OpenSSL 3.0 Vendor Disclosures

Eurotech published an OpenSSL 3.0 advisory. Eurotech reports that none of their products are affected.

Ruckus Wireless published an OpenSSL 3.0 advisory. Ruckus reports that none of their products are affected.

Vendor Disclosures

ABB Advisory - ABB published an advisory that describes a clear-text storage of credentials vulnerability in their PCM600 tool.

BD Advisory #1 - BD published an advisory that discusses an authentication bypass vulnerability with known exploit in their Kiestra products.

BD Advisory #2 - BD published a Third-Party Software Component End of Support notice for their Alaris products (products available in US are not affected).

Genetec published an advisory that discusses an improper authentication vulnerability in their Sipelia and Mission Control products (and various plugins).

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory that discusses a clear-text storage of credentials vulnerability in their IED Connectivity Packages (IED ConnPacks) and PCM600 Products.

Hitachi Energy Advisory #2 - Hitachi Energy published an advisory that describes an input validation vulnerability in their MicroSCADA Pro/X SYS600 products.

HPE Advisory #1 - HPE published an advisory that describes an unauthorized access vulnerability in their NetBatch-Plus software.

HPE Advisory #2 - HPE published an advisory that describes an authentication bypass vulnerability in their OfficeConnect network switches.

Inductive Automation Advisory - Inductive Automation published an advisory that discusses the Text4Shell vulnerability.

Insyde Advisory #1 - Insyde published an advisory that describes an untrusted pointer vulnerability in their UsbCoreDxe file.

Insyde Advisory #2 - Insyde published an advisory that describes an untrusted input vulnerability in their AhciBusDxe file.

Insyde Advisory #3 - Insyde published an advisory that describes an incorrect pointer check vulnerability in their FwBlockServiceSmm driver.

Insyde Advisory #4 - Insyde published an advisory that describes an incorrect pointer check vulnerability in their NvmExpressDxe driver.

Insyde Advisory #5 - Insyde published an advisory that describes an untrusted pointer vulnerability in their SdHostDriver and SdMmcDevice.

Insyde Advisory #6 - Insyde published an advisory that describes a race condition vulnerability in their UsbCoreDxe.

Insyde Advisory #7 - Insyde published an advisory that describes an initialization function vulnerability in their PnpSmm file.

Insyde Advisory #8 - Insyde published an advisory that describes an input address manipulation vulnerability in their PnpSmm function 0x52 file.

Mitsubishi Advisory - Mitsubishi published an advisory that discusses a denial-of-service vulnerability in multiple consumer products.

Moxa Advisory - Moxa published an advisory that describes an improper authentication vulnerability in their NE-4100T Series.

OPC Foundation Advisory - The OPC Foundation published an advisory that describes a privilege escalation advisory in their local discovery server.

Phoenix Contact Advisory - Phoenix Contact published an advisory that describes a denial-of-service vulnerability in their FL MGUARD and TC MGUARD devices.

Sick Advisory #1 - Sick published an advisory that describes an improper authorization vulnerability in their FlexiCompact products.

Sick Advisory #2 - Sick published an advisory that describes six missing authentication for critical function vulnerabilities in their SIM products.

Siemens Healthineers - Siemens published an advisory that describes seven vulnerabilities in their syngo Dynamics servers.

Vendor Updates

HPE Update - HPE published an update for their B-series SAN Switches advisory that was originally published on November 11th, 2022.

Mitsubishi Update #1 - Mitsubishi published an update for their Multiple FA Engineering Software Products advisory that was originally published on July 30th, 2020 and most recently updated on July 28th, 2022.

Mitsubishi Update #2 - Mitsubishi published an update for their Multiple FA Engineering Software Products advisory that was originally published on February 18th, 2021 and most recently updated on July 28th, 2021.

Palo Alto Networks Update - Palo Alto Networks published an update for their Cortex XSOAR advisory that was originally published on November 9th, 2022.

Exploits

Siemens Exploit - Mr me published an Metasploit module for a remote code execution vulnerability in the VMware NSX Manager XStream.


For more information on these disclosures, including links to researcher reports, 3rd party advisories, exploits, and one Russian commentary, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11-f60 - subscription required.


Wednesday, October 16, 2019

Siemens Restricting Access to Healthineers Cybersecurity Advisories?


It looks like Siemens is taking the unusual (for Siemens) step of limiting access to cybersecurity advisories for their Healthineer products by publishing those advisories on a customer restricted access web site. Previously issued advisories are still publicly available on the Siemens CERT web page. It is not clear if future Healthineer advisories will continue to be published in that public forum.

The Announcement


Yesterday Siemens announced on TWITTER® that: “Starting by October 15 all topics related to the Siemens Healthineers Cyber Security (including security advisories) will be published at the Siemens Healthineers Cyber Security webpage”. The link provided takes you to the following statement:

“Security publications Siemens Healthineers Security Advisories: All current Siemens Healthineers reports of security issues and Security Advisories for validated security vulnerabilities that directly involve our products and require applying an update, performing an upgrade, or other customer action can be found at the Siemens Healthineers LifeNet customer online portal.”

That LifeNet customer online portal is currently accessible only to registered users. I attempted to register and received the following in an email from Suzanne Blevins, Siemens Medical Solutions USA, Inc., LifeNet Support Team:

“We are only able to provide LifeNet to customers that own Siemens equipement. I am not able to find any equipment owned by your company.”

I have sent an email to Siemens Medical Solutions requesting clarification.

Commentary


Okay, let me start by saying that Siemens (and any other company) can publish their cybersecurity advisories in whatever venue they deem most appropriate, as long as users of the affected equipment can reasonably be expected to be able to access that information in a timely manner to make appropriate risk assessment decisions about the disclosed vulnerabilities.

I suspect that this is an issue of protecting the safety of patients, and one is hard pressed to find a group more worthy of protection; especially since many (vast majority?) of the patients have nothing to do with the selection, operation, maintenance or security of the devices into which their care is placed.

One just has to look at the most recent Healthineers advisory concerning the DejaBlue vulnerabilities in Healthineer products. The advisory was published on August 9th, 2019. The advisory notes that most of the affected products can be fixed by applying Microsoft® patches available when the advisory was published. But it also noted that at least two of the affected products would need Siemens patches that would not be available for months, and for another product Siemens recommended disabling the RDP functionality of the device. Arguably, the publication of this advisory may have increased the risk for some of the patients using the currently unfixable products.

While this is type of risk problem is also found in many of the industrial product advisories published by Siemens (as we can see in the large number of periodic updates published providing mitigation measures for yet another covered product on the original vulnerability list), the situation is a tad bit different. One should expect owners of industrial control system devices to be better masters of their cybersecurity environment than are patients hooked up to medical devices.

I am concerned, however, about how well Siemens will be able to communicate their advisories to the medical device owners. While Siemens may be able to push advisories to registered owners (and I do not know that they will be pushing advisories as opposed to just statically publishing them on their LifeNet web site) the reality of the situation is that Siemens has no way to track who is using their devices once they are sold to the initial customer (see for example this  2005 Siemens 1.5T Magnetom Espree for sale on Ebay). How is Siemens going to deal with ensuring that owners of devices sold in the aftermarket get these advisories?

Siemens has been proactive in publicly publishing cybersecurity advisories across their entire product line. Not only do they publish advisories for vulnerabilities reported by independent security researchers (directly reported or coordinated through a variety of CERTS), but they also self-disclose vulnerabilities in many of their advisories. I expect that this will continue. But if Siemens is restricting access to their Healthineer advisories to just registered owners gadflies like myself and security researchers are not going to be able to monitor their security efforts to make sure that they are taking all appropriate steps to protect the patients from undue cybersecurity risks.

 
/* Use this with templates/template-twocol.html */