Showing posts with label ICS Advisory. Show all posts
Showing posts with label ICS Advisory. Show all posts

Tuesday, May 2, 2017

ICS-CERT Publishes 3 Advisories

Today the DHS ICS-CERT published three control system security advisories for products from Advantech, CyberVision and Schneider.

Advantech Advisory


This advisory describes a client-side authentication vulnerability in the Advantech B+B SmartWorx MESR901. The vulnerability was originally reported by Maxim Rupp. ICS-CERT reports that Advantech is unable to provide mitigations for this product and is working to replace the product with a new model.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to bypass authentication and access restricted pages.

CyberVision Advisory


This advisory describes a code injection vulnerability in the CyberVision Kaa IoT Platform. The vulnerability was reported Jacob Baines from Tenable Network Security. ICS-CERT reports that CyberVision has been unresponsive to multiple contact requests and has produced no mitigations for this vulnerability.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to allow for the creation of files with custom content, movement of files, and execution of arbitrary OS commands.

Schneider Advisory


This advisory describes an Improper XML Parser Configuration in the Schneider Wonderware Historian Client. The vulnerability was reported by Andrey Zhukov from USSC. Schneider has an update that mitigates the vulnerability. ICS-CERT reports that Zhukov has verified the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker (no discussion of access requirements) to cause denial of service of trend display or to disclose arbitrary files from the local file system to a malicious web site. The Wonderware Security Bulletin reports that a social engineering attack would be required to get an authorized user to load a malicious XML settings file.

Commentary


At this late date it is very disconcerting to see two ICS-CERT advisories reporting that vendors are not fixing reported vulnerabilities. I am disappointed in not seeing ICS-CERT report why Advantech is choosing to not fix their SmartWorx MESR901. I suspect that this is an end-of-life issue, but the product is still being actively advertised on the Advantech web site.


More disturbing is the failure of CyberVision to even respond to ICS-CERT about the reported vulnerability. The Kaa project is advertised as an open-source IOT platform. We have enough problems with IOT security issues without having people acknowledge and try to fix specifically identified security issues with their product.

Monday, July 6, 2015

Another ICS-CERT Advisory to Secure Portal

I am again hearing rumors that ICS-CERT has issued a new control system advisory on the US-CERT Secure Portal. I cannot confirm the rumors because I do not have (actually I have declined) access to the Secure Portal.

As always I would recommend that control system owners regularly access to the Secure Portal to see if there are any new advisories posted for their systems. That is, after all, the purpose of this type semi-public release of control system advisories; let the system owners look at the advisory, make the risk-based decision about applying the identified mitigations, and if appropriate,  applying those steps all before the  vulnerabilities are made public.

Out-of-Date Systems

I am told that there is an interesting side bar involved with this particular vulnerability. It seems that the advisory is for a product that is reaching the end of its commercial life and will soon be removed from the market in the foreseeable future (and that frequently means ‘from support’ not too much further down the line). With the high cost of control system components, these devices frequently remain in service for much longer than their sales life. The problem here would be that once the manufacturer stops supporting a device, any subsequently identified vulnerabilities rarely, if ever get patched. This is becoming a serious issue in the current control system environment.

Just today I had an interesting conversation with a gentleman that has been selling medical monitoring devices for a large number of years and is still active in the field. He was complaining to me about some of the new devices coming into the market place were developed to operate on the Windows 7 OS and had problems interfacing with the computers that his customers were using running Windows XP. And he was particularly proud of the fact that he was using Windows XP Professional.


I suppose at this point in time we really have to consider that every XP based computer is compromised, or at least would be if an attacker was interested in the device. This would mean that any device running on an XP system is at least readily compromisable. But, like my friend, many people are really happy running their XP systems until they die (I mean the machines, of course).
 
/* Use this with templates/template-twocol.html */