Showing posts with label Howest. Show all posts
Showing posts with label Howest. Show all posts

Tuesday, September 17, 2019

3 Advisories Published – 09-17-19


Today the DHS NCCIC-ICS published three control system security advisories for products from Honeywell, Siemens and Advantech.

Honeywell Advisory


The advisory describes an information exposure vulnerability in the Honeywell  Performance IP Series cameras and Performance Series NVRs are affected. The vulnerability was reported by Ismail Bulbil. Honeywell has an update that mitigates the vulnerability. There is no indication that Bulbil has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to view device configuration information.

NOTE 1: The Honeywell advisory for this vulnerability was published on April 30th, 2019. Two additional advisories were published last Friday. I will discuss these on Saturday unless NCCIC-ICS publishes their advisories later this week.

NOTE 2: The link to the Honeywell advisory in this advisory does not work.

Siemens Advisory


The advisory describes four vulnerability in the Siemens SINEMA Remote Connect Server. The vulnerabilities were reported by Hendrik Derre and Tijl Deneut from HOWEST. Siemens has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

Improper restriction of excessive authentication attempts - CVE-2019-13918;
Information exposure - CVE-2019-34623;
Cross-site request forgery - CVE-2019-13920; and
Use of password hash with insufficient computational effort - CVE-2019-13922

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerabilities to allow an attacker unauthorized access to the web interface, improper access to privileged user and device information, and may allow successful CSRF attacks.

NOTE: I briefly reported on these vulnerabilities last Saturday.

Advantech Advisory


The advisory describes four vulnerabilities in the Advantech WebAccess HMI platform. The vulnerabilities were reported by Peter Cheng of Elextec Security Tech. Co., and Mat Powell of the Zero Day Initiative. Advantech has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported advisories are:

Code injection (2) - CVE-2019-13558, and CVE-2019-13552;
Stack-based buffer overflow - CVE-2019-13556; and
Improper authorization - CVE-2019-13550

Saturday, September 14, 2019

Public ICS Disclosures – Week of 09-07-19


This week we have 11 vendor disclosures for products from Siemens (3), Schneider (3), Bosch (2), 3S, Eaton, and Draeger. We also have 3 vendor updates from Schneider (2) and Siemens.

Siemens Advisories


DejaBlue Advisory

Siemens published an advisory describing the Microsoft Windows® DejaBlue vulnerabilities in the Siemens Healthineers Products. In most of the affected products Siemens is recommending applying the appropriate MS patches.

Siemens repeatedly makes the following observation: “The compatibility of Microsoft security patches with products from Siemens Healthineers that are beyond their End of Support date cannot be guaranteed.”

RUGGEDCOM URGENT/11 Advisory

Siemens published an advisory describing the Wind River URGENT/11 vulnerabilities in the Siemens RUGGEDCOM Win base stations. Siemens provides generic workarounds for the vulnerabilities.

SINEMA Advisory

Siemens published an advisory describing four vulnerabilities in the Siemens r SINEMA Remote Connect Server. The vulnerabilities were reported by Hendrik Derre and Tijl Deneut from HOWEST. Siemens has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

Password guessing - CVE-2019-13918;
Privilege escalation - CVE-2019-13919;
Cross-site request forgery - CVE-2019-13920; and
Password hash - CVE-2019-13922

Siemens Update


Siemens published an update for an advisory that was originally published on June 9th, 2019. This update provides corrected version information and mitigation information for:

FieldPG M4;
FieldPG M5; and
ITP1000

Schneider Advisories


U.Motion Server Advisory

Schneider published an advisory describing six vulnerabilities in the Schneider U.motion din rail and touch panel servers. The vulnerabilities were reported by Zhu Jiaqi and Constantin-Cosmin Craciun. Schneider has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

Cross-site scripting - CVE-2019-6835;
Improper access control (3) - CVE-2019-6836, CVE-2019-6838 and CVE-2019-6839;
Server-side request forgery - CVE-2019-6837; and
Format string - CVE-2019-6840

Modicon Quantum Advisory

Schneider published an advisory describing an improper check for unusual or exceptional conditions vulnerability for the Schneider Modicon Quantum 140 NOE771x1 controllers. The vulnerability is self-reported. Schneider has a new version that mitigates the vulnerability.

TwidoSuite Advisory

Schneider published an advisory describing two vulnerabilities in the Schneider TwidoSuite product. The vulnerability is self-reported. This product is no longer supported.

The two reported vulnerabilities are:

Untrusted search path;
Input validation

Schneider Updates


BlueKeep Update

Schneider published an update for an advisory that was originally published on July 12, 2019. The update includes:

Exploit information; and
Updated affected product versions

 Floating License Manager Update

Schneider published an update for an advisory that was originally published on May 14th, 2019. The update provides updated affected product information.

Bosch Advisories


Bosch published two advisories (here and here) describing vulnerabilities in the Access Professional access control system. The vulnerabilities were reported by Oleksii Orekhov. Bosch has a new version that mitigates the vulnerabilities. There is no indication that Orekhov has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Hard-coded credentials - CVE-2019-11898; and
Improper access control - CVE-2019-11899

3S Advisory


3s published an advisory describing a stack-based buffer overflow vulnerability in the CODESYS V2.3 ENI servers. This vulnerability was reported by Chen Jie from NSFOCUS. 3S has an update that mitigates the vulnerability. There is no indication that Chen has been provided an opportunity to verify the efficacy of the fix.

Eaton Advisory


Eaton published an advisory describing multiple undisclosed vulnerabilities in the Eaton Intelligent Power Protector. The vulnerabilities are apparently self-reported. Eaton has a new version that mitigates the vulnerabilities.

NOTE: Eaton continues to publish unusable security advisories.

Drager Advisory


Drager published an advisory describing the Microsoft Windows® DejaBlue vulnerabilities in Drager products.

Wednesday, September 28, 2016

ICS-CERT Publishes Siemens Advisory

Yesterday the DHS ICS-CERT published a new control system security advisory for products from Siemens. Two recently published Siemens updates have yet to be reported by ICS-CERT

Siemens SCALANCE Advisory


This advisory describes a web security vulnerability in the Siemens SCALANCE M-800 and S615 modules. The vulnerability was reported by Alexander Van Maele and Tijl Deneut from HOWEST (University College West Flanders). Siemens has produced a new firmware version, but there is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that the vulnerability is remotely exploitable, but that it would be difficult to develop an exploit that could allow an attacker in a privileged network position to obtain web session cookies under certain circumstances. The Siemens Security Advisory explains that an attacker would have to be in a privileged network position to obtain web session cookies under certain circumstances.

This vulnerability was publicly reported by Siemens last Thursday.

Recent Siemens Updates


Last week on the same day that Siemens announced their update for the vulnerabilities described above they also announced an update for their glibc vulnerability that ICS-CERT reported on in July. I had expected to see the ICS-CERT update their advisory yesterday.

Yesterday Siemens announced an additional update on multiple vulnerabilities in their SIMATIC WinCC, PCS 7 and WinCC Runtime Professional products. ICS-CERT initially reported on these vulnerabilities in April and updated the report in June and again in July. With this only being publicly reported by Siemens yesterday, it was probably too much to expect that ICS-CERT would also be updating their advisory on the same day.


Hopefully we will be seeing ICS-CERT updating these two advisories in the coming days.

Friday, July 29, 2016

ICS-CERT Publishes Four Advisories

Earlier this week the DHS ICS-CERT published four advisories for industrial control system vulnerabilities in products from Rockwell and Siemens.

Rockwell Advisory


This advisory describes two authentication vulnerabilities in the Rockwell Automation FactoryTalk EnergyMetrix application. These vulnerabilities were self-reported. This advisory was originally released on the US CERT Secure Portal on June 21, 2016.

The two vulnerabilities are:

• Insufficient session expiration - CVE-2016-4531; and
• SQL injection - CVE-2016-4522

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to gain unauthenticated access to the affected system.

Siemens SINEMA Advisory


This advisory describes a cross-site scripting vulnerability in the Siemens SINEMA Remote Connect Server (VPN) application. The vulnerability was reported by Antonio Morales Maldonado of INNOTEC SYSTEM, and Alexander Van Maele and Tijl Deneut of Howest. Siemens has produced an update to mitigate the vulnerability but there is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to gain ongoing access to these devices, but a social engineering attack would be required.

Siemens SIMATIC Net PC Advisory


This advisory describes a denial-of-service vulnerability in the Siemens SIMATIC NET PC-Software. The vulnerability was reported by Vladimir Dashchenko and Sergey Temnikov from Kaspersky Labs. Siemens has produced a new version to mitigate the vulnerability but there is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to cause a denial-of-service of the OPC-Unified Architecture (UA) service. Siemens reports that the attacker would require network access to exploit this vulnerability.

Siemens SIMATIC WinCC Advisory


This advisory describes two separate input validation vulnerabilities in the Siemens SIMATIC WinCC, PCS 7, and WinCC Runtime Professional applications. The vulnerabilities were reported by Sergey Temnikov and Vladimir Dashchenko from Kaspersky Lab. Siemens has produced updates to mitigate these vulnerabilities, but there is no indication that the researchers have been provided an opportunity to verify the efficacy of the fixes.


ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to extract arbitrary files or remotely execute arbitrary code. Siemens reports that the attacker would require network access to exploit this vulnerability.
 
/* Use this with templates/template-twocol.html */