Showing posts with label HeartBleed. Show all posts
Showing posts with label HeartBleed. Show all posts

Tuesday, December 9, 2014

ICS-CERT Publishes OpenSSL Update and 2 New (Almost) Advisories

The afternoon the DHS ICS-CERT updated (up to ‘F’ now) their Situational Awareness Alert for the OpenSSL vulnerability. They also published new advisories for vulnerabilities in systems from Trihedral Engineering and Yokogawa.

HeartBleed

This update adds ABB to the list of vendors with affected products. The Relion 650 series has a patch available to mitigate the vulnerability. There is no explanation as to why this update was so long in coming. The last HeartBleed update was published back in April and ABB published their advisory in July.

Trihedral Advisory

This advisory describes an integer overflow vulnerability in their VTS and VTScada products. The vulnerability was reported by an anonymous researcher through ZDI. ICS-CERT reports that Trihedral has produced a patch that mitigates the vulnerability.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to cause the application to crash.

Interestingly the Trihedral update page says nothing about this vulnerability in their upgrade descriptions. ZDI does report that they notified Trihedral of this vulnerability (ZDI-CAN-2599) on November 19th so this was a very quick response.

Yokogawa Advisory

This advisory reports an XML external entity processing vulnerability in the Yokogawa FAST/TOOLS application. The vulnerability was reported by Timur Yunusov, Alexey Osipov, and Ilya Karpov of Positive Technologies Inc. ICS-CERT reports that Yokogawa has developed a service pack that mitigates this vulnerability, but no mention is made that the researchers have verified the efficacy of the fix.

ICS-CERT reports that it would be difficult to craft an exploit of this vulnerability and local access would be required. Yokogawa also reports (in their CVSS calculation) that local access is required, but note that it can be exploited by an attacker that “intrudes into the WebHMI server in any way”. Something may be lost in translation there because that sounds to me like remote access could be used to exploit this vulnerability.


I mentioned earlier that Yokogawa had publicly reported this vulnerability over a week and a half ago; not very timely reporting by ICS-CERT.

Thursday, August 21, 2014

ICS-CERT Updates Siemens HeartBleed Advisory Again

Today the DHS ICS-CERT published another update to the Siemens HeartBleed advisory that was updated just a week ago. The latest update provides a link to the patch for the CP 1543-1 Ethernet interface for the S 1500 system. This leaves just the RuggedCom ROX I and ROX II operating systems to be patched for this vulnerability.

Wednesday, July 23, 2014

ICS-CERT Updates Two Advisories

This afternoon the DHS ICS-CERT published two updated advisories for control system vulnerabilities in Sierra Wireless AirLink products and various Siemens products. Both updates seem to be relatively minor changes to the ICS-CERT document. ICS-CERT does not report on the new information from Sierra Wireless, it just provides a link to the information.

Sierra Wireless Update

This advisory was originally published on January 8th, 2014 and has already been updated once. The purpose of today’s update was to include a link (.PDF download link) to an updated security advisory from Sierra Wireless. The earlier Sierra Wireless publication noted that they would investigate “methods to perform secure firmware updates remotely, and will provide information on this method when available”. The latest update (from May 28th; I wonder why it took ICS-CERT so long to update their advisory? I suspect that they were not informed by Sierra Wireless of the new information) provides those “details”:

• “Directly attaching a PC running the firmware update tool to the device via an Ethernet cable; or
• “Connecting to the device via VPN and performing the update over the VPN tunnel.”

I can see why it would take five months to come up with those useful techniques (SARCASM).

There is something even more interesting in the newest version of the Sierra Wireless documents that ICS-CERT missed in their update. To be fair, I also missed it in looking at the January Sierra Wireless document. The ICS-CERT advisory is specifically targeted at the ‘AirLink Raven X EV-DO product’. Sierra Wireless reports that the same vulnerability exists on the ‘Raven X, Raven XE, Raven XT, PinPoint X, PinPoint XT and MP Products’.

The ‘PinPoint’ products are all listed as “Discontinued, Not Supported” fortunately, the new mitigation measures will work just as well on the older models so perhaps that is why their vulnerability was not reported by ICS-CERT.

Siemens Vulnerability Update

The new data in this update was not provided by Siemens, but was more likely a response to a Siemens complaint about the wording in the initial advisory that made it seem that there were specific exploits directed at the Siemens products. ICS-CERT wrote in the original advisory (no longer available on-line) that:

“Exploits that target these vulnerabilities are known to be publicly available.”

While there are certainly HeartBleed exploits in play, we haven’t heard anything that would specifically point to their use against the Siemens products listed in this advisory (nor any ‘proof’ that they haven’t).

In any case ICS-CERT revised the wording to read:

“Exploits that target OpenSSL vulnerabilities are publicly available. ICS-CERT is unaware of any OpenSSL exploits that target Siemens’ products specifically.”

They are, of course, not saying that no one (sorry about the double negative but it is important and an appropriate use in this context) has specifically targeted these vulnerabilities in the Siemens products. That would be impossible to prove. We can probably take small comfort in the assumption that they probably would not have made this change if they had any reliable information indicating a possible HeartBleed related compromise of  a Siemens system.


BTW: Yesterday’s advisories are now listed on the ICS-CERT landing page.

Tuesday, July 8, 2014

ICS-CERT Updates ABB HeartBleed and Publishes Yokogawa Overflow

Today the DHS ICS-CERT updated a two-month old HeartBleed advisory for the ABB 650 Series application and issued a new buffer overflow advisory for Yokogawa Centum products. Yokogawa also updated an earlier advisory that has not yet been noticed by ICS-CERT.

ABB HeartBleed Update

This advisory update provides notice that ABB has produced a maintenance Release (available through customer service) that mitigates the OpenSSL bug in the 650 Series application. ABB has also updated their Cyber Security Advisory for the HeartBleed bug in their equipment. Interestingly the ABB published advisory can’t make up its mind (at the top of page 2) if the CVSS Score is 5.0 or 4.8 (not that there is much difference). ICS-CERT reports a score of 5.0.

Yokogawa Advisory

This advisory reports a single buffer stack overflow vulnerability in Yokogawa Centum products that was reported by Rapid7 in a coordinated disclosure. Yokogawa has produced a patch that mitigates the vulnerability but there is no indication in the advisory that Rapid7 has been able to verify the efficacy of the patch.

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to execute arbitrary code. Yokogawa reports that the vulnerability only is accessible when the Expanded Test Functions Package is in use.

A Yokogawa Update

While following the ICS-CERT link to the Yokogawa report referenced above, I noticed that the Company had also updated an earlier report about four buffer overflow vulnerabilities reported earlier. I don’t know why ICS-CERT is reporting on the update (yet?).


The new data in this update is found in the Table 1 list of affected products and fixes. It reports a newer patch for the CENTUM 3000, CENTUM VP, and Exaopc Server products that addresses both the earlier vulnerabilities and the one reported by ICS-CERT today. It also reports that earlier versions of ProSafe-RS that were earlier reported as having no patches available may now be corrected.

Tuesday, May 20, 2014

ICS-CERT Publishes Siemens HeartBleed Update

Today the DHS ICS-CERT published an updated version of the HeartBleed advisory for a number of Siemens products. This is the second update for this advisory. The first was published on April 29th, 2014 and the original advisory was published on April 15th, 2014.

Siemens now reports that they have released product updates for all systems identified as vulnerable to the HeartBleed vulnerability.


ICS-CERT did not publish an updated version of their HeartBleed advisory nor have they updated their downloadable spreadsheet listing the HeartBleed status of a wide variety of control system products.

Thursday, May 15, 2014

ICS-CERT Publishes 3 HeartBleed, 1 SQL Injection and 1 Certificate Advisories

Today the DHS ICS-CERT published five advisories; one an update of the generic OpenSSL Alert and two new control system HeartBleed advisories, a security certificate advisory and a good ‘old-fashioned’ SQL Injection advisory.

Generic OpenSSL Advisory

Instead of continuing to provide ‘letter’ updates to the original OpenSSL Alert (last updated 4-29-14), ICS-CERT upgraded the document to an Advisory. There is a lot of new information in the new Advisory, including discussions of:

• Impact;
• Background;
• The vulnerability;
• Mitigation overview;
• OpenSSL scanning;
• Detection signatures;
• Specialized search engines;

At first glance it is disappointing that there is not a list of affected and unaffected systems included in the Advisory the way there was in the earlier Alert. On closer inspection there is a download link to a spread sheet that provides that information in much more detail. I would have preferred something that would have let you know the latest date that the list had been updated (today’s was last updated 5-15-14).

Two Product Specific HeartBleed Advisories

The two product specific Advisories are for products from Unified Automation and Schneider. The UA advisory contains a link to their description of the HeartBleed vulnerability. The Schneider advisory notes that the problem is not actually theirs; it exists in a third party component (from Tableau Software). As always this raises the question of what other vendors may be using the offending application in their products and thus have the same vulnerability.

SQL Injection

This advisory is for an SQL injection advisory for CSWorks software. The vulnerability was reported by John Leitch in a coordinated disclosure via the Zero Day Initiative. CSWorks has produced an updated version that mitigates the vulnerability, though there is no mention if Leitch has verified the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to possibly execute arbitrary code.

The CSWorks security release for this vulnerability reminds system administrators that under “no circumstances should administrators give root access to CSWorks”.

Certificate Vulnerability

This advisory is for a certificate verification vulnerability in the Siemens RuggedCom Rox devices. This is apparently a self-identified vulnerability and Siemens is still working on firmware updates for the affected systems.

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to execute a man-in-the-middle attack.

Pending the production of firmware updates Siemensrecommends the following interim mitigation measures:

• Secure Syslog: Siemens recommends placing the syslog server inside the trusted
network boundary until a corrected update is made available.
• Software upgrade: When updating devices running the affected ROX versions, the
identity of the update server cannot be ensured. Siemens recommends placing the
upgrade server inside the trusted network boundary.

• FTPS: Siemens recommends using SFTP for data transfer until a corrected update is available.

Thursday, May 8, 2014

ICS-CERT Publishes Digi HeartBleed Advisory

Earlier today the DHS ICS-CERT published an advisory for the HeartBleed vulnerability in various products from Digi. I discussed most of this information in my last HeartBleed post. New information: ICS-CERT reports that firmware updates are available “for most vulnerable Digi International devices”, but does not provide a list. The link provided takes one to a generic product support page where you enter your product name or select a key word to search for; neither HeartBleed nor OpenSSL are available terms.

ICS-CERT is again publishing a HeartBleed advisory without updating their Situational Awareness Alert. I almost don’t blame them as they would be quickly going to have to go to double letters to identify new updates if they updated the SA every time new information became available.

It would probably have been better to have had a HeartBleed web page to keep updating with new information on vulnerable, formerly vulnerable, and not vulnerable ICS products. Joel Langill over at SCADAHacker.com takes that type of approach. He is currently listing two ‘new’ ICS related vendors, Certes Networks and Unified Automation, as having products with HeartBleed vulnerabilities.

A reader of this blog, Rob Hulsebos, posted a comment on the LinkedIn Cyber Security in Real Time Systems group providing links to HeartBleed information for Emerson, and Insys.


There is probably more ICS HeartBleed information out there if you have the time to search. It sure would be nice if ICS-CERT were doing that for the community.

Tuesday, April 29, 2014

ICS-CERT Publishes 2 HeartBleed Updates and an Advisory

This afternoon the DHS ICS-CERT published updates on a Siemens HeartBleed Advisory, an update of their SA Alert on HeartBleed and one new advisory for an Ecava information disclosure vulnerability.

HeartBleed Updates

My followers on TWITTER® already heard about the Siemens update last Friday morning when Siemens @ProductCert tweeted about the publication of their updated HeartBleed advisory that included notification that their WinCC product now has an update available to fix the HeartBleed bug in that system.

ICS-CERT published their late update of the HeartBleed advisory that they issued on April 15th. The ICS-CERT Situational Awareness Alert was updated to show the new Siemens status. It also adds two new affected industrial control system notifications, one for ABB (Relion 650 series Ver. 1.3.0) and one for Digi (ConnectPort LTS, ConnectPort X2e, Digi Embedded Linux, and Wireless Vehicle Bus Adapter). Separate advisories are in the works. The links above are for the vendor notices.

The ABB mitigation measures are still under development and the Digi updates may already be available (the document was published on 4-18-14 with an availability date for the fix of 4-21-14). Digi is making the remote update service for remote devices available free of charge for 30 days.

ICS-CERT also added a list of Digi devices to the list of unaffected ICS services. This was also found on the Digi web site link identified above.

Ecava Advisory

This advisory reports on an information disclosure vulnerability on the Ecava IntegraXOR product that was reported by Andrea Micalizzi, aka rgod, in a coordinated disclosure via the Zero Day Initiative. Ecava has produced a new version that mitigates the vulnerability, but there is no indication in the advisory that Micalizzi has verified the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to obtain clear text administrative credentials and own the system.


The Ecava vulnerability note provides additional mitigation measures that can be employed to mitigate the vulnerability until the patch is put into place. They note that since the complete project URL is need to exploit this vulnerability, owner/operators should avoid publication of the full URL. They also recommend avoiding the use of the default port number.

Wednesday, April 23, 2014

ICS-CERT Updates HeartBleed Alert

This afternoon the DHS ICS-CERT updated their ‘Situational Awareness Alert for OpenSSL Vulnerability’, commonly referred to as the HeartBleed bug. The information added to date is the most extensive to date and includes:

• An advance notice about an ICS-CERT Advisory for HeartBleed in Atvise;
• An extensive (but probably not exhaustive) list of ICS related applications and devices that have been determined not to be affected by HeartBleed;
• A reminder that while older versions of OpenSSL may not be affected by HeartBleed, they do have their own known vulnerabilities; and
• A reminder that the use of SHODAN and other search engines may make it relatively easy to find ICS components that are susceptible to HeartBleed.

Atvise

ICS-CERT took the unusual step of announcing that an “ICS-CERT advisory [was] coming soon” for the Certec atvise scada products. It provides a link to the atvise notice about the vulnerability. That stilted notice (okay I lived in Berlin for 7 years and my German syntax was way worse at its best than this English language notice) claims that while some versions of their products have the HeartBleed bug “but wasn't affected by known attacks”. Now they “face new kinds of attacks found nearly daily”. I certainly look forward to hearing more about the ‘new kinds of attacks’ on a SCADA system.

Atvise does have a patch available for the vulnerable OpenSSL components.

Systems Not Affected

There is a fairly long list of systems here that are not affected by the HeartBleed bug because either they ‘don’t use OpenSSL’ or ‘don’t use an affected version of OpenSSL’. Unfortunately there is not an actual control system or component on the list. They are all either communications tools or security tools. This list will be invaluable to a security manager or integrator. It does let them concentrate of other parts of their systems, but it is strangely unhelpful for control systems.

The lack of any control system applications or devices on the list is more than a little disconcerting. Two weeks into the public discussion of HeartBleed and we have two vendors (Siemens and atvise) self-identifying their infection with this bug, but no one saying that they are infection free. At this point I think that any ICS system that has not identified itself as being free of HeartBleed should, for the sake of safety and security, must be considered to be infected until proven otherwise.

Other OpenSSL Vulnerabilities

There have been any number of system vendors that have bragged that their system uses an older version of OpenSSL that is not affected by HeartBleed. Today’s update reminds people that earlier versions of the software have their own problems that should not be ignored. The Update provides a link to the OpenSSL web page that lists a large number of reported vulnerabilities in the system. If all of the patches and upgrades have not been applied to earlier versions, there may be more serious problems than HeartBleed.

SHODAN and Others

Any time you have a widespread vulnerability like HeartBleed it is valuable to be reminded that search engines like SHODAN make it relative easy for people to find vulnerable systems. That combined with the wide spread availability of automated attack and exploit tools makes it easier for both the opportunistic and targeted attackers to gain access to improperly secured systems.


ICS-CERT notes in the Alert that: “As tools and adversary capabilities advance, ICS-CERT expects that exposed systems will be more effectively discovered, and targeted.” They also remind owner/operators that they can use many of the same tools to discover if their systems are vulnerable. Knowing that their systems are accessible and vulnerable should allow owners to better protect their systems.

Thursday, April 17, 2014

ICS-CERT Publishes Siemens Advisory and Updates 3 HeartBleeds

Today the DHS ICS-CERT published a new control system advisory for a Siemens product and provided updates on three separate HeartBleed related documents.

Siemens

The new Siemens advisory identifies three vulnerabilities in their SINEMA server. Siemens self-reported the vulnerabilities and has published a software update to mitigate the problems. The identified vulnerabilities include:

• Code injection, CVE-2014-2731 (incorrectly listed as CVE-2014-7231);
• Relative path traversal, CVE-2014-2732; and
• Improper input validation, CVE-2014-2733

According to ICS-CERT a relatively unskilled attacker could remotely exploit these vulnerabilities to execute arbitrary code, traverse through the file system, or cause a DoS.

HeartBleed Updates

ICS-CERT updated their HeartBleed Situational Awareness Alert by adding a list of ICS related products that have been identified as being specifically affected by the OpenSSL vulnerability. Only two vendors currently have products on the list, Innonminate and Siemens.

The Innominate HeartBleed Advisory was also updated. The Phoenix Contact branded versions of the Innominate devices is not affected by the HeartBleed vulnerability, but Innominate has upgraded them to the latest version to alleviate customer concerns. Only the 8.0.0 and 8.0.1 versions of the mGuard firmware are affected by the vulnerability


ICS-CERT has also provided a link to the latest FBI list of Snort Signatures that may be used to detect attempted exploitation of the HeartBleed vulnerability.

Tuesday, April 15, 2014

ICS-CERT Publishes Three Advisories – Two from HeartBleed

Today the DHS ICS-CERT published three advisories for vulnerabilities in industrial control systems applications from Siemens, Progea Movicon, and Innominate. Two of those (the first and last) are related to HeartBleed.

Siemens Advisory

This advisory provides a list of Siemens products that contain or are affected by the HeartBleed vulnerability. They currently only provide one updated to mitigate the vulnerability but do note that they are working on the other product updates. The unusual move to self-identify vulnerable systems before mitigation measures are available was almost certainly undertaken because tools to test for the HeartBleed vulnerability and exploit code for the bug both exist in the wild.

Siemens reports that the following products are affected:

● eLAN-8.2 eLAN < 8.3.3 (affected when RIP is used - update available)
● WinCC OA only V3.12 (always affected)
● S7-1500 V1.5 (affected when HTTPS active)
● CP1543-1 V1.1 (affected when FTPS active)
● APE 2.0 (affected when SSL/TLS component is used in customer implementation)
Siemens has an update available for eLAN (v 8.3.3) and recommends the following interim mitigation measures for the other products until the appropriate update is published:

● WinCC OA V3.12:
o Use VPN for protecting SSL traffic
o Use WinCC OA in a trusted network
●  S7-1500 V1.5:
o Disable the web server, or
o Limit web server access to trusted networks only
o Remove the certificate from the browser
● CP1543-1 V1.1:
o Disable FTPS, or
o Use FTPS in trusted network, or
o Use the VPN functionality to tunnel FTPS
● APE 2.0:
o Update OpenSSL to 1.0.1g before distributing a solution. Follow instructions from Ruggedcom [3] to patch APE 2.0
The VPN recommendations should have come with a caveat that the VPN should have its HeartBleed status investigated before it is used to protect a control system remote access.

Progea Advisory

This advisory is for an information disclosure vulnerability reported by Celil Ünüver of SignalSEC Ltd in a coordinated disclosure. Progea has developed an update that ICS-CERT reports has been checked and validated by Celil.

ICS-CERT reports that a moderately skilled attacker could remotely execute an attack using this vulnerability to gain access of OS version information.

Innominate Advisory

This advisory notes that Bob Radvanovsky of Infracritical notified ICS-CERT that Innominate has updated their mGuard product firmware to deal with the HeartBleed vulnerability included in versions of those devices. The advisory points at the Innominate advisory published last Friday. Bob also reported this last Friday on the SCADASec List.

HeartBleed Reporting

It will be interesting to see how many of these HeartBleed advisories get published by ICS-CERT. Most of these will end up being self-reported (even the Innominate advisory was essentially self-reported). I also doubt that there will be much more information in any of the upcoming advisories than we have seen in these two today.


It may be easier for ICS-CERT to just set up a HeartBleed page and updated it when necessary by listing the vendors that have published firmware or software updates that mitigate the vulnerability. I think it would be easier and more informative.

Saturday, April 12, 2014

ICS-CERT Publishes Unusual Saturday Alert Update

Earlier today the DHS ICS-CERT published an update to their HeartBleed (okay OpenSSL Vulnerability) Alert that was issued and updated earlier this week. They have also provided a link to an FBI “Private Industry Notification” that provides Snort signatures for detecting exploits of the HeartBleed vulnerability.

The updated alert (Version ‘B’) points at the FBI Snort document. It also provides a link to the free ‘Snort Community Rules’ that were updated today (presumably with HeartBleed signatures).

The alert also reports that there are ‘additional indicators of compromise’ available on the Control Systems compartment of the US-CERT secure portal. You might want to check those out.

While I don’t have access to the Secure Portal, I certainly would recommend anyone running an industrial control system consider requesting access. There are too many times that the really good information (I hope it is really good) is kept under limited distribution for legitimate reasons.


“ICS-CERT encourages U.S. asset owners and operators to join the Control Systems compartment of the US-CERT secure portal. Send your name, e-mail address, and company affiliation to ics-cert@hq.dhs.gov.”

Thursday, April 10, 2014

ICS-CERT Updates an Alert and an Advisory and Publishes New Advisory

This afternoon the DHS ICS-CERT published an update of an older advisory for Rockwell Allen-Bradley Micrologic and a new advisory for IOServer’s OPC Drivers. While not listed on the ICS-CERT landing page, they have also updated yesterday’s alert for the HeartBleed vulnerability.

Rockwell Allen-Bradley Update

This advisory was originally published on 12-7-12 and then updated four days later. Today’s update advises that:

• Rockwell has now produced a patch to mitigate the fault generation vulnerability; the previous update noted that Rockwell was considering if a patch would be produced;
• The CVSS v2 base score of 8.5 has been recalculated to be a CVSS v2 base score of 7.1. The new CVSS vector string is (AV:N/AC:M/Au:N/C:N/I:N/A:C); and
• A new Rockwell Automation report (registration required) was published on this vulnerability last summer.

This appears to be a late ICS-CERT response to a less than timely vendor response. To be fair to ICS-CERT, however, Rockwell may not have kept them up to date on the actions taken on this vulnerability.

IOServer Advisory

This advisory addresses a Crain-Sistrunk reported improper input validation vulnerability in the OPC Driver (fooled you, not the DNP3 Driver) from IOServer. It was, as we have come to expect from this duo, a coordinated disclosure.

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to send information to the system that could “lead to parts of the system receiving unintended input, which may result in altered control flow or arbitrary control of a resource”. This sounds very close to saying ‘exploit arbitrary code’.

This advisory is full of surprises. It reports that:

“Adam Crain and Chris Sistrunk updated and tested this version and validated that this vulnerability is resolved.”

We apparently have a new standard for independent researchers; find it, report it, fix it and verify that the fix works. The vendors can now take a long lunch break.

HeartBleed Update

ICS-CERT has updated yesterday’s HeartBleed alert with some information that may be pertinent to control system security. It provides a little more detail about the vulnerability itself and includes a link to a blog post about yesterday’s Sans briefing (with links to the slides for the briefing) by Jacob Williams. This looks like some good technical information, though not specifically about control system vulnerabilities tied to HeartBleed.

The update also includes the intended scare phrase “ICS-CERT is aware of several instances of targeted active exploitation of this vulnerability” while never stating that those exploits have targeted control systems. I would assume that they did not (yet, at least).

The alert now includes instructions for developers for a work around if the new version of OpenSSL cannot be loaded. It also has an example of an IDS signature for detecting an exploit of this vulnerability.


You can’t tell just by looking at this update (it is outside of the red-bordered change areas), but ICS-CERT removed an embarrassing bit of boilerplate from the alert. It no longer refers to using a VPN to remotely access control systems. It would have been better if the boiler plate had been changed instead of removed. It is important that current control system users of VPN’s know that this is a prime potential area for running into HeartBleed and that the VPN should probably not be used until it has been checked for the vulnerability and fixed if necessary.

Wednesday, April 9, 2014

ICS-CERT Updates DNP3 Master and Issues HeartBleed Alert

Today the DHS ICS-CERT published an update of their master DNP3 advisory covering multiple Crain-Sistrunk based advisories and it published an alert concerning the ICS implications of HeartBleed.

DNP3 Master Advisory

Back in October ICS-CERT took the unusual step of providing a single advisory that tied together all of the previous DNP3 advisories that were based upon the Crain-Sistrunk fuzzing. They then had to update that advisory in November when even more vulnerable systems were added. Today they issued their second (and probably not last) update covering the seven additional advisories that have been issued since November. The current public list of vulnerable systems is (vendors in RED are new adds):

• ICSA-13-282-01A, Alstrom;
• ICSA-13-297-01, Catapult Software;
• ICSA-13-346-01, Cooper Power Systems;
• ICSA-13-346-02, Cooper Power Systems/Cybectec;
• ICSA-13-337-01, Elecsys;
• ICSA-13-297-02, GE;
• ICSA-13-161-01, IOServer;
• ICSA-13-213-03, IOServer;
• ICSA-13-226-01, Kepware Technologies;
• ICSA-13-213-04A, MatrikonOPC;
• ICSA-13-352-01, NovaTech;
• ICSA-14-098-01, OSISoft;
• ICSA-14-006-01, Schneider Electric;
• ICSA-14-014-01, Schneider Electric;
• ICSA-13-219-01, Schweitzer Engineering Laboratories;
• ICSA-13-234-02, Software Toolbox;
• ICSA-13-252-01, SUBNET Solutions; and
• ICSA-13-240-01, Triangle MicroWorks.

As I mentioned yesterday, there are still eleven un-named vendors with pending Crain-Sistrunk vulnerabilities working their way through the system.

HeartBleed Alert

This is an alert based upon the US-CERT advisory that I reported on yesterday. ICS-CERT issued it. IT SAYS NOTHING ABOUT CONTROL SYSTEMS. And, most disturbingly, it provides the following useless mitigation information:

“If remote access is required, employ secure methods, such as Virtual Private Networks (VPNs), recognizing that VPN is only as secure as the connected devices.”


Didn’t anybody at ICS-CERT read this???????

Tuesday, April 8, 2014

US-CERT Publishes Heartbleed Bug Alert

This morning the US-CERT (NOT my normal ICS-CERT) published an alert for a TLS/DTLS heartbeat functionality vulnerability in the OpenSSL system. Now I don’t normally follow US-CERT vulnerability announcements very closely, but it has been pointed out  that this vulnerability may have a very big control system component.

The Vulnerability

US-CERT notes that a remote attacker with a publicly available exploit could gain access to sensitive data, possibly including user authentication credentials and secret keys, through incorrect memory handling in the TLS heartbeat extension. This could allow the attacker to decrypt data, obtain log-in credentials, or perform man-in-the-middle attacks using the OpenSSL protocols.

There is an interesting discussion of this vulnerability at HeartBleed.com.

The Control System Connection

The popular press has made the point that this makes a number of supposedly secure communications protocols vulnerable. One such protocol could be an organizations virtual private network (VPN). Since ICS-CERT has been pushing the use of VPN for ‘secure’ remote connections to control systems, a number of people are using the OpenSSL protocol to connect with their control system. These ‘secure’ connections are now vulnerable.

In a post over on the SCADASEC list at Infracritical.com Jake Brodsky notes that “this is a problem with the source code of OpenSSL/TLS. This code is embedded in many places, including many SCADA RTUs and associated network hardware”. People are going to have to do some hard looking to find all of the implementations of this system and get them corrected.

It would be real nice if ICS-CERT were to get out in front of the control system vulnerability side of this issue.
 
/* Use this with templates/template-twocol.html */