Showing posts with label ICONICS. Show all posts
Showing posts with label ICONICS. Show all posts

Tuesday, December 3, 2024

Review – 6 Advisories and 2 Updates Published – 12-3-24

Today CISA’s NCCIC-ICS published six control system security advisories for products from Fuji Electric (2), ICONICS (and Mitsubishi), Open Automation, Siemens, and Ruijie. They also updated advisories for products from ICONICS (and Mitsubishi) and ETIC.

Advisories

Fuji Advisory #1 - This advisory describes five vulnerabilities in the Fuji Electric Tellus Lite V-Simulator.

Fuji Advisory #2 - This advisory describes 10 out-of-bounds write vulnerabilities in the Fuji Electric Monitouch V-SFT screen configuration software.

ICONICS Advisory - This advisory describes three vulnerabilities in the ICONICS GENESIS64 and Mitsubishi MC Works64 products.

Open Automation Advisory - This advisory describes an incorrect execution-assigned privileges vulnerability in the Open Automation Software package.

Siemens Advisory - This advisory discusses four vulnerabilities (two listed in CISA’s Known Exploited Vulnerabilities catalog) in the Siemens RUGGEDCOM APE1808 products.

Ruijie Advisory - This advisory describes ten vulnerabilities in the Ruijie Reyee OS.

Updates

ICONICS Update - This update provides additional information on the ICONICS and Mitsubishi advisory that was originally published on July 2nd, 2024.

ETIC Update - This update provides additional information on the Remote Access Server advisory that was originally published on November 3, 2022, and most recently updated on July 27th, 2023.

 

For more information on these advisories, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-and-2-updates-published-ee4 - subscription required.

Tuesday, July 2, 2024

Review – 3 Advisories and 4 Updates Published

Today, CISA’s NCCIC-ICS published three control system security advisories for products from ICONICS, mySCADA, and Johnson Controls. They also updated advisories for products from Johnson Controls.

Advisories

ICONICS Advisory - This advisory discusses five vulnerabilities (one with known exploit) in the ICONICS product suite.

mySCADA Advisory - This advisory describes a use of hard-coded credentials vulnerability in the mySCADA myPRO product.

Johnson Controls Advisory - This advisory describes an exposure of sensitive information to an unauthorized actor vulnerability in the Johnson Controls Kantech KT series door controllers.

Updates

Johnson Controls Update #1 - This update provides additional information on the Johnson Controls Illustra Essentials Gen 4 advisory that was originally published on June 27th, 2024.

Johnson Controls Update #2 - This update provides additional information on the Johnson Controls Illustra Essentials Gen 4 advisory that was originally published on June 27th, 2024.

Johnson Controls update #3 - This update provides additional information on the Johnson Controls Illustra Essentials Gen 4 advisory that was originally published on June 27th, 2024.

Johnson Controls Update #4 - This update provides additional information on the Johnson Controls Illustra Essentials Gen 4 advisory that was originally published on June 27th, 2024.

 

For more information on these advisories, including links to 3rd party advisories, exploits, and a brief look at the timing of the Johnson Controls updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-and-4-updates-published-026 - subscription required.

Tuesday, December 13, 2022

Review – 3 Advisories Published – 12-13-22

Today, CISA’s NCCIC-ICS published three control system security advisories for products from Contec, Schneider Electric, and ICONICS/Mitsubishi.

Contec Advisory - This advisory describes an OS command injection vulnerability in the CONPROSYS HMI System (CHS).

Schneider Advisory - This advisory describes four vulnerabilities in the Schneider APC Easy UPS Online.

ICONICS Advisory - This advisory describes a path traversal vulnerability in the ICONICS (Mitsubishi) ICONICS Product Suite.

 

For more details about these advisories, including a down-the-rabbit-hole look at how Contec looks at secure control systems, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-published-12-13-22 - subscription required.


Thursday, July 21, 2022

Review – 5 Advisories and 1 Update Published – 7-21-22

Today, CISA’s NCCIC-ICS published five control system security advisories for products from AutomationDirect, Mitsubishi Electric, Rockwell Automation, Johnson Controls, and ABB. They also published an update for products from Rockwell.

AutomationDirect Advisory - This advisory describes a cleartext transmission of sensitive information vulnerability in the AutomationDirect Stride Field I/O product.

Mitsubishi Advisory - This advisory describes seven vulnerabilities in the ICONICS Product Suite, and Mitsubishi MC Works64.

Rockwell Advisory - This advisory describes three vulnerabilities in the Rockwell ISaGRAF Workbench.

Johnson Controls - This advisory describes a missing authentication for critical function vulnerability in the Johnson Controls Metasys ADS, ADX, OAS with MUI server.

ABB Advisory - This advisory describes five different improper privilege management vulnerabilities in the ABB Drive Composer, Automation Builder, Mint Workbench products.

Rockwell Update - This update provides additional details on an advisory that was originally published on March 29th, 2022.

NOTE: Rockwell has not updated their advisory, and the new information is not reflected in the original Rockwell advisory.

 

For more details on these advisories and update, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-1-update-published-0f2 - subscription required.

Thursday, January 20, 2022

Review - 1 Advisory and 3 Updates Published – 1-20-22

Today, CISA’s NCCIC-ICS published one control system security advisory for products from Mitsubishi. They also published updates for two control system advisories for products from Mitsubishi and a medical device advisory for products from Philips.

Mitsubishi Advisory - This advisory describes four vulnerabilities in the ICONICS Product Suite and the Mitsubishi Electric MC Works64.

Mitsubishi Update #1 - This update contains additional information on an advisory that was originally published on December 8th, 2020 and was most recently updated on May 11th, 2021.

Mitsubishi Update #2 - This update contains additional information on an advisory that was originally published on May 11th, 2021.

Philips Update - This update contains additional information on an advisory that was originally published on July 6th, 2021.

For more details on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-advisory-and-3-updates-published - subscription required.

Thursday, October 21, 2021

Review - 4 Advisories Published – 10-21-21

Today, CISA’s NCCIC-ICS published three control system security advisories for products from ICONICS/Mitsubishi (2) and Delta Electronics. They also published a medical device security advisory for products from Braun.

ICONICS/Mitsubishi Advisory #1 - This advisory describes an uncontrolled recursion vulnerability in the ICONICS GENESIS64 and Mitsubishi Electric MC Works64 products.

Delta Advisory - This advisory describes ten vulnerabilities in the Delta DIALink industrial automation server.

ICONICS/Mitsubishi Advisory #2 - This advisory describes two vulnerabilities in the ICONICS GENESIS64, Mitsubishi Electric MC Works64 products.

Braun Advisory - This advisory describes five vulnerabilities in the B. Braun Perfusor Space, Infusomat Space, SpaceCom, Battery Pack SP with WiFi products.

For more details on the advisories, including links to 3rd-party vendor reports and researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/4-advisories-published-10-21-21 - subscription required.

Friday, June 19, 2020

11 Advisories and 1 Update Published – 6-18-20


Today the CISA NCCIC-ICS published five control system security advisories for products from Rockwell Automation (2), ICONICS, Mitsubishi Electric, and Johnson Controls; and six medical device security advisories for products from BD, BIOTRONIC and Baxter (6). They also updated the Treck TCP/IP advisory that was published earlier this week.

FactoryTalk View SE Advisory


This advisory describes four vulnerabilities in the Rockwell FactoryTalk View SE. The vulnerabilities were reported by the Zero Day Initiative. Rockwell has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Improper input validation - CVE-2020-12029,
• Improper restriction of operations within a memory buffer - CVE-2020-12031,
• Permissions, privileges, and access control - CVE-2020-12028, and
• Exposure of sensitive information to an unauthorized actor - CVE-2020-12027

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow a remote authenticated attacker to manipulate data of affected devices.

NOTE: These vulnerabilities were discovered in the Pwn-2-Own competition at this year’s S4 Security conference in Miami, Florida.

FactoryTalk Services Platform Advisory


This advisory describes an improper input validation vulnerability in the Rockwell FactoryTalk Services Platform. No vulnerability disclosure information is provided in the advisory. Rockwell provides generic mitigation measures.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an unauthenticated attacker to execute remote COM objects with elevated privileges.

NOTE: These vulnerabilities were discovered in the Pwn-2-Own competition at this year’s S4 Security conference in Miami, Florida.

ICONICS Advisory


This advisory describes five vulnerabilities in the ICONICS GENESIS64 and GENESIS32 products. The vulnerabilities were reported by Tobias Scharnowski, Niklas Breitfeld, Ali Abbasi, Yehuda Anikster of Claroty; Pedro Ribeiro and Radek Domanski of Flashback; Ben McBride of Oak Ridge National Laboratory; and Steven Seeley and Chris Anastasio of Incite. ICONICS has patches that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Out-of-bounds write - CVE-2020-12011,
• Deserialization of untrusted data (3) - CVE-2020-12015, CVE-2020-12009, and CVE-2020-12007, and
• Code injection - CVE-2020-12013

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow remote code execution or denial of service.

NOTE: ICONICS takes an unusual approach to the publication of security advisories. The two separate product advisories for this NCCIC-ICS report (GENESIS64 and GENESIS32) contains summaries of all the vulnerabilities reported to/by NCCIC-ICS (and its predecessor, ICS-CERT) since 2011. If/when new vulnerabilities are reported, they are added to the respective product vulnerability report.

Mitsubishi Advisory


This advisory describes five vulnerabilities in the Mitsubishi MC Works64 MC Works32 products. The vulnerabilities were reported by Tobias Scharnowski, Niklas Breitfeld, Ali Abbasi, Yehuda Anikster of Claroty; Pedro Ribeiro and Radek Domanski of Flashback; Ben McBride of Oak Ridge National Laboratory; and Steven Seeley and Chris Anastasio of Incite. Mitsubishi has patches that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Out-of-bounds write - CVE-2020-12011,
• Deserialization of untrusted data (3) - CVE-2020-12015, CVE-2020-12009, and CVE-2020-12007, and
• Code injection - CVE-2020-12013

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit these vulnerabilities to allow remote code execution, a denial-of-service condition, information disclosure, or information tampering.

NOTE 1: The reporting information and CVE numbers indicate that these are the same vulnerabilities reported in the ICONICS advisory above. It is interesting to note the differing exploit information in the two advisories.

NOTE 2: Mitsubishi now has a publicly available PSIRT page.

Johnson Controls Advisory


This advisory describes an improper verification of cryptographic signature vulnerability in the Johnson Controls exacqVision product. The vulnerability was reported by Michael Norris. Johnson Controls has newer versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow the execution of operating system commands on the system. It would seem that [IMO] a social engineering attack would be required to cause a person with administrative privileges to potentially download and run a malicious executable.

BD Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the BD Alaris PCU. The vulnerability is self-reported. BD provides generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial of service (DoS) on the target system and could cause the BD Alaris PCU to disconnect from the facility’s wireless network.

NOTE: This vulnerability is one of three SACK vulnerabilities reported in the FreeBSD and Linux kernels. It would seem to me that the other two vulnerabilities might also be found in this product.

BIOTRONIK Advisory


This advisory describes five vulnerabilities in the BIOTRONIK CardioMessenger II-S T-Line and CardioMessenger II-S GSM products. The vulnerabilities were reported by Guillaume Bour, Anniken Wium Lie, and Marie Moe. BIOTRONIK has provided generic workarounds to mitigate the vulnerability.

The five reported vulnerabilities are:

• Improper authentication (2) - CVE-2019-18246 and CVE-2019-18252,
• Cleartext transmission of sensitive information - CVE-2019-18248,
• Missing encryption of sensitive data - CVE-2019-18254, and
• Storing passwords in an accessible format - CVE-2019-18256

NCCIC-ICS reports that a relatively low-skilled attacker with physical access to the device could exploit the vulnerabilities to obtain sensitive data, obtain transmitted medical data from implanted cardiac devices with the implant’s serial number or impact Cardio Messenger II product functionality. The same attacker with adjacent access could exploit the vulnerabilities to allow an attacker with adjacent access to influence communications between the Home Monitoring Unit (HMU) and the Access Point Name (APN) gateway network.

NOTE: See this TWITTER thread by Marie Moe about this advisory.

Sigma Spectrum Infusion Pump Advisory


This advisory describes six vulnerabilities in the Baxter Sigma Spectrum Infusion systems. The vulnerabilities are self-reported. Baxter provided generic workarounds to mitigate the vulnerabilities.

The six reported vulnerabilities are:

• Use of hard-coded passwords (3) - CVE-2020-12039, CVE-2020-12045 and CVE-2020-12047,
• Cleartext transmission of sensitive data - CVE-2020-12040,
• Incorrect permission assignment for critical resource - CVE-2020-12041, and
• Operation on a resource after expiration or release - CVE-2020-12043

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow access to sensitive data, alteration of system configuration, and impact to system availability.

NOTE: NCCIC-ICS did not provide a link to the related Baxter advisory.

Phoenix Hemodialysis Advisory


This advisory describes a cleartext transmission of sensitive information vulnerability in the Baxter Phoenix Hemodialysis Delivery System. This vulnerability is self-reported. Baxter provides generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to view sensitive data.

NOTE: NCCIC-ICS did not provide a link to the related Baxter advisory.

PrismaFlex Advisory


This advisory describes three vulnerabilities in the Baxter PrismaFlex and PrisMax medical systems. The vulnerabilities are self-reported. Baxter has new versions that mitigate the vulnerabilities.

The three reported vulnerabilities are:

• Cleartext transmission of sensitive information - CVE-2020-12036;
• Improper authentication - CVE-2020-12035, and
• Use of hard-coded passwords - CVE-2020-12037

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to view and alter sensitive data.

NOTE: NCCIC-ICS did not provide a link to the related Baxter advisory.

ExactaMix Advisory


This advisory describes seven vulnerabilities in the Baxter Baxter ExactaMix systems. The vulnerabilities are self-reported. Baxter has new versions that mitigate the vulnerabilities.

The seven reported vulnerabilities are:

• Use of hard-coded password (2) - CVE-2020-12016 and CVE-2020-12012,
• Cleartext transmission of sensitive information - CVE-2020-12008,
• Missing encryption of sensitive data - CVE-2020-12032,
• Improper access control - CVE-2020-12024,
• Exposure of resource to wrong sphere - CVE-2020-12020, and
• Improper input validation - CVE-2017-0143

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow unauthorized access to sensitive data, alteration of system configuration, alteration of system resources, and impact to system availability.

NOTE: NCCIC-ICS did not provide a link to the related Baxter advisory.

Treck Update


This update provides additional information on an advisory that was originally published on June 16th, 2020. The new information is a link to the Baxter advisory on the issue.

Thursday, March 31, 2016

ICS-CERT Publishes ICONICS Advisory

This morning the DHS ICS-CERT published a new advisory for a directory traversal vulnerability in the ICONICS WebHMI. The vulnerability was reported by Maxim Rupp. A new version of the HMI is available, but there is no indication that Maxim was provided the opportunity to verify the efficacy of the fix. ICONICS has also recommended that the vulnerable version of WebHMI not be exposed directly to the Internet.


ICS-CERT reports that a relatively inexperienced attacker could remotely exploit this vulnerability to download arbitrary files from the target system.

Thursday, February 20, 2014

ICS-CERT Publishes 4 Advisories

Today the DHS ICS-CERT published four advisories for vulnerabilities in control systems. Three were product specific for systems from Siemens, Mitsubishi and Iconics. One was for an open source protocol used by multiple vendors. Two of the advisories were initiated by ICS-CERT, one by a team of Malaysian researchers in a coordinated disclosure, and one by an anonymous researcher in an uncoordinated disclosure.

Iconics Advisory

This advisory was initiated by ICS-CERT (needless to say in a coordinated disclosure) after discovering the vulnerability during an investigation concerning an unrelated product. This is an insecure ActiveX vulnerability in the GENESIS32 system. Interestingly the advisory never states that Iconics has produced a patch or upgrade for this vulnerability.

ICS-CERT reports that a moderately skilled attacker could exploit this vulnerability remotely, but nature of the vulnerability would require an authorized user to visit a specially crafted web site first. A successful exploitation could lead to the execution of arbitrary code.

An Iconics security document (that lists all 8 ICS-CERT Iconics’ advisories) reports that a patch has been developed and ICS-CERT is in the process of validating its efficacy. It also notes that the IcoLaunch.dll can be accessed via command line.

Mitsubishi Advisory

This advisory is also about an ActiveX vulnerability, this time in the McWorX application. The uncoordinated disclosure by Blake included proof-of-concept code was reported in an earlier ICS-CERT Alert. A patch is available for the affected version and newer versions do not include this vulnerability.
ICS-CERT reports that a moderately skilled attacker could use the publicly available exploit code to remotely exploit this vulnerability to execute arbitrary code.

The Mitsubishi patch download page explains that the patch loads a new version of IcoLaunch.dll, the same file that was a problem in the Iconics vulnerability. It would seem that ICS-CERT discovered the Iconics vulnerability while investigating the Mistubishi vulnerability. It makes me wonder what other vendor has used the same vulnerable version of IcoLaunch.dll in their product.

Mitsubishi also notes that the patch removes some functionality from the McWorX application. The report that they will work with individual customers to restore that functionality if necessary.

Siemens Advisory

Those of you who follow @SCADAHacker @DigitalBond, or me on Twitter® will already have heard a discussion about this vulnerability as the Siemens ProductCERT published their alert on early Tuesday morning (US time). This advisory reports an uncontrolled resource consumption vulnerability in Rugged Com ROS devices. The vulnerability was discovered by Ling Toh Koh, Ng Yi Teng, Seyed Dawood Sajjadi Torshizi, Ryan Lee, and Ho Ping Hou of EV-Dynamic, Malaysia.

ICS-CERT reports that skilled attacker could remotely exploit this vulnerability to execute a DoS attack that would disable switching functionality until a cold reboot was executed. Siemens has developed a patch for one of the affected versions and continues to work on the others. ICS-CERT will update this advisory as Siemens produces the other patches.

Siemens is to be congratulated on their early public disclosure of this vulnerability even as much as ICS-CERT is to be castigated for their delay in their conveying this advisory to the US public.

NTP Reflection Advisory

This advisory is more than a little unusual. The vulnerability, a vulnerability to DoS attacks staged using Network Time Protocol (NTP) Reflection, has apparently been in use for some period of time. And the vulnerability is not found in a single device or application, but rather any number of products using the NTP service.

ICS-CERT reports that a low skilled attacker ‘would be able’ to remotely exploit this vulnerability remotely using publicly available ‘exploits’ to execute DoS attacks on various control systems. They go on to report that an upgrade that mitigates this vulnerability has been available since 2010.


I don’t know which is scarier the fact that this vulnerability remains uncorrected in so many systems that ICS-CERT was finally forced to report this vulnerability, or the fact that it has taken almost four years for ICS-CERT to finally report this vulnerability.

Thursday, August 2, 2012

ICS-CERT Has Been Busy


With the Senate debating a cybersecurity bill that actually includes control system coverage, the folks at ICS-CERT have been hard at work trying to keep the control system community up to date on just how vulnerable our systems are. This week they have published, so far, three alerts, four advisories and their Monthly Monitor.

Alerts



The DEFCON 20 conference last week was the source of the disclosure for two of the alerts, both reported by Dr. Wesley McGrew of Mississippi State University. Both deal with credential type issues and neither are remotely executable. The only thing of real  interest here (other than to owners of the affected systems) is that these are the only vulnerabilities to be reported at DEFCON 20 that ICS-CERT has been concerned about.

The third alert comes from an uncoordinated disclosure from Luigi. It’s a directory traversal vulnerability. It is remotely exploitable and Luigi has, as always, published proof of concept code on his web site. As expected, ICS-CERT did not include a link to Luigi’s disclosure, but I will. According to Luigi’s web site this disclosure was made back in June, hardly a timely notification by ICS-CERT.

It turns out that Luigi is also a composer. If you like techno type instrumentals, check out some of his tracks. 

Advisories



Siemens has self-reported vulnerabilities in two separate systems; it seems that they have gotten on the identifying-correcting-reporting bandwagon. Two versions of  SIMATIC S7-400 CPU have DOS vulnerabilities. Siemens has provided a firmware update for the V6.03 CPU but not the V5 as it has reached end-of-life and has been discontinued. Of course everyone has replaced the older version so it isn’t really a problem (SARCASM alert).

The second Siemens advisory deals with a default password in their Synco OZW Web Server device used for building automation systems. This would allow access to the building automation network which may (not mentioned in the ICS-CERT Advisory) include security systems. A firmware update is available, but changing the default passwords is a simpler option.

Dr. McGrew (mentioned above) was responsible for the coordinated disclosure of the authentication by-pass vulnerability in the ICONICS  GENESIS32 and BIZVIS Security Configurator. ICONICS is releasing a patch that disables the backdoor security login in some versions (no word on the others) and plans to implement a “more secure encryption algorithm” in the future. There is a publicly available exploit for this vulnerability. HMMM… did Dr. McGrew talk about this at DEFCON as well? Maybe this should have been an alert instead of an advisory.

The Sielco Sistemi advisory closes out two ICS-CERT Alerts for the Winlog SCADA system (one from a Luigi disclosure and another by Michael Messner). Sielco Sistemi has provided a software update that has been verified by Messner (oops, I guess Luigi is on the outs again).

Monthly Monitor


The latest two-month issue of the Monthly Monitor is, as always, a worthwhile read. They provide an interesting update to their previous report on the apparently on-going phishing attacks on pipeline companies. In my opinion the most important part of that discussion is found in the second paragraph on the first page:

“Recent reports and analysis conducted by ICS-CERT indicate that information pertaining to the ICS/SCADA environment, including data that could facilitate remote unauthorized operations, has been exfiltrated as part of this campaign. Despite this, ICS-CERT has not received any reports of unauthorized access into the ICS environment; however, this may be due to limited monitoring and intrusion detection capabilities in the targeted companies control networks. The intent of the attackers remains unknown.”

While this spear phishing campaign appears to be solely directed at pipeline companies, owners of all control systems need to pay attention to this. It is a classroom lesson in how to go about a systematic attack on control systems; infiltrate the system to gain the knowledge necessary to formulate an effective attack on the system. Much the same thing must have been done to prepare the Stuxnet attack.

There is also an interesting snippet about what may be the ‘next’ systemic vulnerability, inadequate keys or certificates in embedded devices. It is apparent that ICS-CERT is concerned about this apparently wide-spread vulnerability. They note that:

“ICS-CERT is currently coordinating with multiple vendors that could be affected by this vulnerability.”

Typically I would expect silence about a vulnerability that is this important until the vendors either have a chance to fix it, or ICS-CERT gives up on their cooperation. Either ICS-CERT is changing their policy (maybe because this is so important) or the level of cooperation that they are receiving leaves much to be desired. We’ll be watching for advisories on this topic and will wonder when people like Luigi start to look for these on their own.

Sunday, October 2, 2011

ICS-CERT Issues Three SCADA Advisories

On Friday afternoon the DHS Industrial Control System Cyber Emergency Response Team published three advisories on their web site. One was a follow-up to one of the earlier Luigi alerts while the other two were about new vulnerabilities in systems reported by security researchers in ‘properly’ coordinated disclosures. The three advisories deal with the following systems:

• Rockwell RSLogix
• InduSoft ISSymbol
• ICONICS GENESIS32

Rockwell RSLogix


This Advisory updates an earlier alert issued for the vulnerabilities reported by Luigi. Rockwell has developed patches for these denial of service vulnerabilities in two versions their Factory Talk Services Platform (CPR9 SR3 and SR4). Patches are under development for earlier versions of Factory Talk and for RSLogix. ICS-CERT will update this Advisory when those patches become available. [CVE-2011-3489; Base Score 5.0]

InduSoft ISSymbol


Dmitriy Pletnev of Secunia Research reported ActiveX control buffer overflow vulnerabilities in the InduSoft ISSymbol product and developed proof-of-concept exploit code for those vulnerabilities. The vulnerabilities allow a low skilled attacker to conduct DOS attacks while a more skilled attacker could execute arbitrary code. InduSoft has published an upgrade for the affected systems as well as a new service pack. [CVE-2011-0342; Base Score 10.0]

ICONICS GENESIS32


Independent researchers Billy Rios and Terry McCorkle have identified eight separate memory corruption vulnerabilities in components of the GENESIS32 HMI/SCADA product. A low skill level attacker could cause a system crash while a more skilled attacker could execute arbitrary code. This vulnerability would require a social engineering attack causing a user to open specially crafted files. ICONICS has produced patches to mitigate these vulnerabilities.

Thursday, May 12, 2011

ICS-CERT Publish an Alert and an Advisory

Yesterday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published an advisory and an alert on multiple control system related programs. The advisory was for stack overflow vulnerability reported in ICONICS GENESIS32 and BisVis. The alert concerns reported buffer overflow vulnerabilities in Advantech Studio and Advantech ISSSymbol.

ICONICS Advisory

A security researcher has reported a stack overflow vulnerability in a common component (WebHMI) of ICONICS GENESIS32 and BisVis that could allow a moderately skilled remote attacker to run arbitrary code on either system. ICS-CERT reports that a social engineering attack would need to be conducted before the publicly available exploit could be successfully used.

The advisory notes that ICONICS has a patch (WebHMI V9.21Patch) available for both systems and has plans to address the vulnerability in upcoming versions of both programs. They have also updated their security whitepaper with details about this vulnerability.

Advantech Alert

ICS-CERT reports that they have become aware of reports about ‘multiple buffer overflow’ vulnerabilities in Advantech ISSSymbol and Advantech Studio which may allow execution of arbitrary code. ICS-CERT is working with Advantech to confirm and potentially mitigate the reported vulnerabilities.
 
/* Use this with templates/template-twocol.html */