Showing posts with label Hospira. Show all posts
Showing posts with label Hospira. Show all posts

Thursday, January 21, 2016

ICS-CERT Publishes Two Advisories

This morning the DHS ICS-CERT published two advisories for control systems from Hospira and CAREL.

Hospira Advisory

This advisory describes a buffer overflow vulnerability in two older versions of Hospira infusion pumps. The vulnerability was reported by Jeremy Richards of SAINT Corporation. Existing newer versions of the software do not contain the vulnerability.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to “to remotely execute code on the affected device”. ICS-CERT notes that neither Hospira or Richards have demonstrated the code execution outcome, but it includes the possibility out of an abundance of caution.

In addition to updating to newer versions of the software, ICS-CERT recommends the following mitigation measures for these devices:

• Ensure that unused ports are closed on the affected devices to include Port 20/FTP, Port 21/FTP, and Port 23/TELNET.
• Ensure that the default password used to access Port 8443 has been changed, or verify that the port is closed.
• Closing Port 5000/TCP does not impact the intended use of the device.
• Monitor and log all network traffic attempting to reach the affected products, to include Port 20/FTP, Port 21/FTP, Port 23/TELNET, Port 8443, and Port 5000/TCP.
• Isolate all medical devices from the Internet and untrusted systems.
• Produce a hash of key files to identify any unauthorized changes.

Hospira’s infusion pump web site contains two cybersecurity links for previously identified infusion pump vulnerabilities. It does not, however, mention this newly discovered vulnerability.

CAREL Advisory

This advisory describes an authorization bypass vulnerability in the CAREL PlantVisor application. The vulnerability was reported by Maxim Rupp. CAREL will not be fixing the vulnerability since the devices is no longer supported (replaced by newer product in 2007).


ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to gain system access.

Wednesday, June 10, 2015

ICS-CERT Updates Hospira Advisory and Issues a New One

Today the DHS ICS-CERT updated an advisory issued last month for Hospira infusion pump and published a new advisory for similar problems in a newer line of Hospira pumps.

Hospira Update

This is one of the most extensive updates I have seen since I have been watching ICS-CERT advisories with 9 separate changes being made. The changes include adding a new researcher (Kyle Kamke of Ramparts, LLC), an impact update, four new vulnerabilities, updating the exploitability rating, modifying the attacker skill level, and adding two new mitigation measures.

The new vulnerabilities are:

Stack-based buffer overflow - CVE-2015-3955;
Insufficient verification of data authenticity - CVE-2014-5406;
Key management error- CVE-2015-3957; and
Uncontrolled resource consumption - CVE-2015-3958

ICS-CERT is now reporting that a relatively low skilled attacker could remotely exploit most of these vulnerabilities which may allow the attacker to impact the core functions of the device.

Hospira Advisory

This advisory is a near duplicate of the updated advisory reported above. The only significant difference is that it is for a newer generation of Hospira Infusion Pumps. Hospira is releasing a new version of the infusion pump system that mitigates these vulnerabilities, but there is no indication that Rios has been given the opportunity to verify the efficacy of the fix.

Other Information

The FDA advisory that was reported at the time of the last Hospira update has not been changed to reflect the new vulnerabilities or the new equipment. In fact, the link on that advisory still takes one to the old ICS-CERT advisory, which is no longer available. This is not an unusual problem when government agencies provide links to other agency web sites; very little inter-silo communication.


Billy Rios has an interesting blog post about the whole Hospira fiasco from his perspective as the researcher who has been working the issue for over a year now.

Tuesday, March 31, 2015

ICS-CERT Publishes 3 Advisories and an Update

Today the DHS ICS-CERT published three new advisories for control systems from Hospira, Ecava and Inductive Automation and an update for a recently released advisory for Schneider Electric.

Schneider Update

This update is for the Schneider advisory released last week for the InduSoft WebStudio and InTouch Machine applications. The update provides a link to additional information about the vulnerabilities, but it is only available to registered Wonderware customers, external partners or distributors.

Hospira Advisory

This advisory describes multiple vulnerabilities in the Hospira MedNet server software. The vulnerabilities were reported by Billy Rios. Hospira has produced a new version of the software and provided additional mitigation measures, but there is no indication that Billy has been given the opportunity to verify the efficacy of the fix.

The four vulnerabilities are:

∙ Password in configuration file - CVE-2014-5400;
∙ Improper control of generation code - CVE-2014-5401;
∙ Hard-coded cryptographic key - CVE-2014-5403; and
∙ Hard-coded password - CVE-2014-5405

ICS-CERT reports that a relatively low skilled attacker could remotely exploit three of the vulnerabilities; the pass in configuration file vulnerability is locally exploitable.

ICS-CERT explains that the new version of the MedNet server software addresses three of the vulnerabilities. The fourth vulnerability (improper control of generation of code) is found in “the vulnerable version of JBoss Enterprise Application Platform [link added] software, used in the MedNet software”. There is no indication which version of the EAP software is involved. MedNet has issued two reports (Improving Security in Hospira MedNet 5.5 and 5.8) discussing mitigation methods for this vulnerability. They are reportedly available from MedNet technical support.

NOTE: It goes without saying that vendors that use JBoss EAP should contact RedHat for details about this vulnerability. It will be interesting to see how long it is before this shows up in other ICS application advisories.

Ecava Advisory

This advisory describes a DLL loading vulnerability on the Ecava  IntegraXor SCADA Server. The vulnerability was reported by Praveen Darshanam. Ecava has produced a patch that mitigates the vulnerability and Darshanam has verified the efficacy of the patch.

ICS-CERT reports that a social engineering attack is required to get an authorized user to load a compromised DLL. A successful attack could result in the ability to run malicious code at the authorization level of the DLL.

Inductive Automation Advisory

This advisory describes multiple vulnerabilities in the Inductive Automation Ignition software (HMI/SCADA). The vulnerabilities were reported by Evgeny Druzhinin, Alexey Osipov, Ilya Karpov, and Gleb Gritsai of Positive Technologies. Inductive Automation has produced a patch that mitigates the vulnerability but there is no indication that the researchers have been given an opportunity to verify the efficacy of the fix.

The six vulnerabilities are:

∙ Cross-site scripting - CVE-2015-0976;
∙ Information exposure through error message - CVE-2015-0991;
∙ Insecure storage of sensitive information - CVE-2015-0992;
∙ Insufficient session expiration - CVE-2015-0993;
∙ Credentials management - CVE-2015-0994; and
∙ Use of password hash with insufficient computational effort - CVE-2015-0995


ICS-CERT explains that a relatively low skilled attacker can only locally exploit these vulnerabilities, though they earlier report that the vulnerabilities are remotely exploitable (which sounds more reasonable). The advisory does not describe potential consequences, but it would seem that a successful exploit should allow running of arbitrary code.
 
/* Use this with templates/template-twocol.html */