Showing posts with label Heinz Füglister. Show all posts
Showing posts with label Heinz Füglister. Show all posts

Saturday, November 16, 2019

Public ICS Disclosures – Week of 11-09-19


This week we have four vendor disclosures for products from ABB, Gemalto and Schneider (2). We also have updates for products from Schneider (6) and Siemens (2). Finally, we have 26 exploits published for products from Siemens and several building access control systems.

ABB Advisory


ABB published an advisory describing an Active-X/Java Script vulnerability in the ABB Automation Builder and Drive Application Builder products. The vulnerability is in a third-party component from 3S. The vulnerability was reported by Heinz Füglister of WRH Walter Reist Holding AG. ABB provides generic workarounds pending development of new versions that will mitigate the vulnerability.

Gemalto Advisory


Gemalto published an advisory (available to registered customers only) for undisclosed vulnerabilities in the Sentinel LDK License Manager.

Schneider Advisories


Schneider published an advisory describing a failure to preserve web page structure vulnerability in the Andover Continuum line of controllers. The vulnerability was reported by Ken Pyle, DFDR Consulting. Schneider recommends disabling the web server in this legacy product.

Schneider published an advisory describing and information exposure vulnerability in the Modicon Controllers. The vulnerability is self-reported. Schneider has provided generic workarounds to mitigate the vulnerability.

Schneider Updates


Schneider published an update for their  URGENT/11 advisory. The new information includes:

• Updated Remediations for ConneXium Industrial Firewall, Easergy Micom C264 Controller, and Modicon M262 Logic/Motion Controller;
• Enhanced product list with additional details for Modicon X80 I/O modules;
• Added Modicon Quantum Head 140 CRP and Modicon Momentum Unity; and
• Removed TMSES4 Ethernet Module from affected products

Schneider published an update for their DejaBlue advisory.  The new information includes:

• Added EcoStruxure Technology Platform (ETP) to the affected product list;
• Updated remediation for EcoStruxure Substation Operation Gateway (page 4), and
• Updated the affected product details for Conext Control

Schneider published an update for their BlueKeep advisory. The new information includes updated “Conext Control” affected products and remediation detail.

Schneider published an update for their ZombieLoad advisory. The new information includes updated affected product details for “Conext Control” product.

Schneider published an update for their ConneXium Gateway advisory that was originally published on May 14th, 2019. The new information includes updated affected products to include EGX100 and
ECI850 variants.

Schneider published an advisory for their Triconex advisory that was originally published on March 12th, 2019. The new information includes remediations updated.

Siemens Updates


Siemens published an update for their GNU/Linux advisory that was originally published on November 27th, 2018. The new information includes adding six new CVE’s:

• CVE-2017-18551;
• CVE-2018-5390;
• CVE-2018-20856;
• CVE-2019-15902,
• CVE-2019-15916; and
• CVE-2019-15921

Siemens published an update for their ZombieLoad advisory. The new information includes updated version and mitigation information for:

• SIMOTION P320-4E;
• SIMOTION P320-4S; and
• SIMATIC IPC547G

Siemens Exploit


LiquidWorm published an exploit for a previously disclosed vulnerability in the Siemens Desigo PX automation controllers.

Building Automation Exploits


LiquidWorm published a series of exploits for building automation vulnerabilities that were described in a white paper by Applied Risk in June.

Friday, September 13, 2019

6 Advisories Published – 09-12-19


Yesterday the DHS NCCIC-ICS published five control system security advisories for products from 3S and a medical device security advisory for products from Philips.

Communication Server Advisory


This advisory describes a detection of error condition without action vulnerability in the CODESYS V3 products containing a CODESYS communication server. The vulnerability was reported by Martin Hartmann from cirosec GmbH. 3S has a new version that mitigates the vulnerability. There is no indication that Hartmann has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to cause a denial-of-service condition.

OPC UA Server Advisory


This advisory describes a null pointer dereference vulnerability in the CODESYS Control V3 OPC UA Server. The vulnerability is self-reported. 3S has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial-of-service condition.

Online User Management Advisory


This advisory describes an incorrect permission assignment for critical resource vulnerability in the CODESYS Control V3 online user management. The vulnerability is apparently self-reported. 3S has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow unauthorized actors access to unintended functionality and/or information.

Library Manager Advisory


This advisory describes a cross-site scripting vulnerability in the CODESYS V3 Library Manager. The vulnerability was reported by Heinz Füglister of WRH Walter Reist Holding AG. 3S has a new version that mitigates the vulnerability. There is no indication that Füglister has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow malicious content from manipulated libraries to be displayed or executed.

Web Server Advisory


This advisory describes two vulnerabilities in the CODESYS V3 web server. The vulnerability was reported by Ivan Cheyrezy of Schneider Electric. 3S has new versions that mitigate the vulnerability. There is no indication that Cheyrezy has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Path traversal - CVE-2019-13532; and
Stack-based buffer overflow - CVE-2019-13548

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to create a denial-of-service condition, to perform remote code execution, or to access restricted files.

NOTE 1: It is good to see cooperative sharing of vulnerability information between vendors, but I suspect that Schneider reported these vulnerabilities because they found them in their own product that used the CODESYS web server as a third-party component of one or more of their products. It will be interesting to see how long it takes Schneider to report these vulnerabilities.

NOTE 2: 3S has not yet reported any of the vulnerabilities in the above advisories on their web site. They did, however, publish an advisory on another product earlier this week that I will discuss tomorrow.

Philips Advisory


This advisory describes two vulnerabilities in the Philips IntelliVue WLAN, portable patient monitors. The vulnerabilities were reported by Shawn Loveric of Finite State, Inc. One of the affected WLAN versions is out-of-support and will not receive mitigation actions. Philips intends to have a patch available by the end of the year.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerabilities to cause corruption of the IntelliVue WLAN firmware and impact to the data flow over the WLAN Version A and WLAN Version B wireless modules. This would lead to an inoperative condition alert at the device and Central Station. The Phillips Advisory reports that it would take “an unauthorized user with a high skill level and access to the device’s local area network” to exploit the vulnerabilities.

Saturday, August 3, 2019

Public ICS Disclosures – Week of 07-27-19


It has been a very busy week in the ICS disclosure arena. We have vendor disclosures about the VxWorks vulnerabilities announced earlier this week; disclosures from Siemens, ABB, Schneider and Belden. We also have vendor disclosures from 3S and an update from Rockwell. Finally, we have new Metasploit module for a previously disclosed vulnerability from Schneider.

VxWorks Vulnerability


The Wind River OS vulnerabilities were just reported this week and we already have three (major) ICS vendors adding their advisories to the list of vulnerable products:

Siemens (in an out-of-cycle report);
Schneider; and
ABB, in:
AC 800PEC;
Belden

It will be interesting to see if NCCIC-ICS updates their advisory for each new vendor that adds to the list of covered products. Unfortunately, I do not expect NCCIC-ICS to provide any information about future updates (and there will be many as fixes are further applied) to the advisories published.

3S Advisories


This week, as earlier noted, 3S published 8 advisories for their CODESYS operating system, two of which NCCIC-ICS has reported. The remaining six advisories are covered below:

OPC UA Server Advisory

3S published an advisory describing a null pointer dereference vulnerability in the CODESYS Control V3 OPC UA Server. The vulnerability is self-reported. 3S has an update available to mitigate the vulnerability.

Communications Server Advisory

3S published an advisory describing a detection of error condition without action vulnerability in CODESYS V3 products containing a CODESYS communication server. The vulnerability was reported by Martin Hartmann from cirosec GmbH. 3S has a new version that mitigates the vulnerability. There is no indication that Hartmann has been provided an opportunity to verify the efficacy of the fix.

Library Manager Advisory

3S published an advisory describing a cross-site scripting vulnerability in the CODESYS V3 Library Manager. The vulnerability was reported by Heinz Füglister of WRH Walter Reist Holding AG. 3S has an update that mitigates the vulnerability. There is no indication that Füglister has been provided an opportunity to verify the efficacy of the fix.

On-Line User Management Advisory

3S published an advisory describing an incorrected inherited permissions vulnerability in the CODESYS Control V3 online user management. The vulnerability was reported by Martin Hartmann from cirosec GmbH. 3S has updates available that mitigate the vulnerability. There is no indication that Martin has been provided an opportunity to verify the efficacy of the fix.

Channel Management Advisory

3S published an advisory describing an uncontrolled memory allocation vulnerability in CODESYS Gateway V3 memory management. The vulnerability was reported by Martin Hartmann from cirosec GmbH. 3S has an update available that mitigates the vulnerability. There is no indication that Martin has been provided an opportunity to verify the efficacy of the fix.

Web Server Advisory

3S published an advisory describing a directory traversal vulnerability in the CODESYS V3 web server. The vulnerability was reported by Ivan Cheyrezy of Schneider Electric. 3S has an update that mitigates the vulnerability. There is no indication that Cheyrezy has been provided an opportunity to verify the efficacy of the fix.

Rockwell Update


Rockwell published an update to their advisory on PanelView 5510 Graphic Terminals that was originally published on July 9th, 2019. The update includes:

Modified description of the vulnerability;
Revision of the recommended work arounds; and
Provided a link for CVE-2019-10970

Schneider Metasploit


Lucas Dinucci published a Metasploit module for a previously disclosed vulnerability in the Schneider Electric Pelco Endura NET55XX webUI.

Friday, December 21, 2018

Public ICS Disclosure – Week of 12-15-18


This week we have five vendor notifications for products from Schneider Electric (3), Yokogawa and 3S (5).

Schneider Advisories


Schneider published an advisory for three vulnerabilities in their EVLink Parking product. The vulnerabilities were reported by Vladimir Kononovich and Vyacheslav Moskvin (Positive
Technologies). Schneider has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three vulnerabilities are:

• Hard-coded credentials - CVE-2018-7800;
• Code injection - CVE-2018-7801; and
SQL injection - CVE-2018-7802

Schneider published an advisory for an input validation vulnerability in their Pro-Face GP-Pro EX product. The vulnerability was reported by Yu Quiang (ADLab of Venustech). Schneider has a new version that mitigates the vulnerability. Schneider has an update that mitigates the vulnerability. There is no indication that Yu has been provided an opportunity to verify the efficacy of the fix.

Schneider published an advisory for three vulnerabilities in their IIoT Monitor product. The vunlerabilities were reported by rgod via the Zero Day Initiative. Schneider has a new product that mitigates the vulnerability. There is no indication that rgod has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Path traversal - CVE-2018-7835;
• Unrestricted upload of file with dangerous type - CVE-2018-7836; and
• Improper restriction of XML esternal reference entity reference - CVE-2018-7837

NOTE: I expect that we will see these three advisories reported by NCCIC-ICS next week if they are allowed to continue to report during the upcoming financial idiocy. NCCIC will operate, but the ICS reporting function might not be allowed to continue until a funding bill is signed by the President.

Yokogawa Advisory


Yokogawa published an advisory for a denial of service vulnerability in their  Vnet/IP Open
Communication Driver. The vulnerability appears to be self-reported. Yokogawa has a patch for many of the products to mitigate the vulnerability, but many of the affected products are no longer supported.

3S Advisories


3S published an advisory for an information exposure vulnerability in their CODESYS Development System V3. The vulnerability was reported by Heinz Füglister of WRH Walter Reist Holding AG. 3S has a new version that mitigates the vulnerability. There is no indication that Füglister has been provided an opportunity to verify the efficacy of the fix.

3S published an advisory for two denial of service vulnerabilities in their CODESYS V3 products. The vulnerabilities were reported by ABB Switzerland Ltd. and Jérôme Vialle of Schneider Electric. 3S has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

3S published an advisory for two denial of service vulnerabilities in their CODESYS Development System V3 Alarm configuration application. These vulnerabilities are being self-reported. 3S has a new version that mitigates the vulnerabilities.

3S published an advisory for two denial of service vulnerabilities in their CODESYS Control V3 TLS socket communication application. These vulnerabilities were reported by an unidentified OEM customer. 3S has new versions that mitigate the vulnerabilities. There is no indication that the customer was provided an opportunity to verify the efficacy of the fix.

3S published an advisory for two denial of service vulnerabilities in the CODESYS Control V3 Trace Manager application. These vulnerabilities were reported by an unidentified OEM customer. 3S has new versions that mitigate the vulnerabilities. There is no indication that the customer was provided an opportunity to verify the efficacy of the fix.

NOTE: As is obvious from the researchers who identified most of the 3S vulnerabilities, 3S software is used by a number of ICS vendors. It will be interesting to see how many of those vendors self-identify these vulnerabilities in their products. Since 3S does not report CVE numbers for any of these vulnerabilities, it will be hard to track.


 
/* Use this with templates/template-twocol.html */