Showing posts with label ICS Vulnerability. Show all posts
Showing posts with label ICS Vulnerability. Show all posts

Wednesday, March 16, 2011

Two ICS-CERT Advisories Published

Yesterday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published advisories for two SCADA systems; Progea’s Movicon 11 HMI and WellinTech’s KingView HMI. The vulnerabilities in both cases have been verified and patches are available.

Movicon 11 HMI

The vulnerability in this human machine interface (HMI) software may allow a remote attacker with moderate skill level to manipulate data or crash the server. There is no known exploit available for this vulnerability.

In addition to installing the available patch, ICS-CERT recommends consideration of the following mitigation measures:

• Implement firewall rules to limit network access to the Movicon system on Port 10651/TCP.

• Update Movicon to the latest Version 11.2.

• Minimize network exposure for all control system devices. Critical devices should not directly face the Internet.
KingView HMI

A stack-based buffer overflow vulnerability in this HMI software may allow a remote attacker with moderate skill level to execute arbitrary code. An exploit is publicly available for this vulnerability. ICS-CERT has listed this vulnerability under a different number than their previous alert on the KingView system, so it is apparently a separate vulnerability.

ICS-CERT recommends replacing the vulnerable .DLL file with the updated version available from WellinTech.

Tuesday, January 11, 2011

DHS ICS-CERT Reports WellinTech Vulnerability

Earlier today the DHS Industrial Control System Cyber Emergency Response Team issued an alert about a reported vulnerability in the WellinTech KingView v6.3. The publicly reported buffer overflow vulnerability would allow a remote attacker to crash an affected application or execute arbitrary code.

DHS reports that they have not confirmed the vulnerability but is reporting it because alleged exploit code is publicly available. I have seen this vulnerability discussed on a couple of different sites (sorry I failed to copy pages or links) and I understand that the researcher who discovered the vulnerability tried to report it to WellinTech, a Chinese company, but received no response. The researcher went public this last weekend.

Friday, December 17, 2010

ICS-CERT Updates Netbiter WebSCADA Advisory

This afternoon the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published an updated version of their advisory on multiple vulnerabilities in Intellicom Netbiter WebSCADA. The revision provides information on the software update made available by Intellicom.

Intellicom’s patch for their WS100/WS200 products “limits the ability to read system files and eliminates the ability to perform directory traversals”. The “ISFR-4404-0010.npb” patch is available http://support.intellicom.se.

Thursday, December 16, 2010

DHS ICS-CERT Issues Ecava IntegraXor Advisory

Yesterday afternoon the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) issued an advisory about a buffer overflow vulnerability for the Ecava IntegraXor Human-Machine Interface (HMI). The vulnerability was discovered by Jeremy Brown, an independent security researcher and has been addressed by Ecava, who has released a patch to mitigate the vulnerability.

ICS-CERT notes that this stack based buffer overflow could allow an attacker with an intermediate skill level to remotely exploit the vulnerability, allowing the execution of arbitrary code. There is currently no known exploit published for this vulnerability.

ICS-CERT recommends the following mitigation measures after conducting a proper impact analysis and risk assessment:

• Update IntegraXor to the latest version and install the latest patch. For more information, customers can contact Ecava support at support@integraxor.com.
• Minimize network exposure for all control system devices. Critical devices should not directly face the Internet. Control system networks and remote devices should be located behind firewalls, and be isolated from the business network. If remote access is required, secure methods such as Virtual Private Networks (VPNs) should be utilized.

Friday, November 26, 2010

SCADA Exploit Vulnerabilities

Readers of this blog will have noted that I have been writing more often about identified vulnerabilities in various industrial control systems and even the existence of published exploits to use those vulnerabilities to attack such control systems. Earlier this week I did a posting about the Stuxnet man-in-the-middle attacks that Ralph Langner has identified. On Wednesday Ralph posted a new entry into his blog that builds on the dangers identified in that attack methodology.

Not Patchable

One important point that Ralph continues to make is that we should not be expecting a ‘patch’ from Siemens to ‘correct’ the vulnerabilities used by Stuxnet. He points out that these vulnerabilities are “regular product features that you find in the majority of these systems, regardless of vendor [emphasis added]”. To eliminate these potential attack points is not going to just require a revision of the Siemens soft ware, but also a complete reworking of the programming for each of the millions of controllers currently in place in manufacturing facilities around the world.

It is not realistic to suppose that the multitude of controllers currently in use will be re-worked to avoid the attack techniques that Stuxnet utilized. I’m not sure about future PLC’s (I’ll leave that discussion to the engineers and security professionals), but it is just not practical to make such radical changes to all of the devices currently in the field. It cannot be done piece meal, it will require a simultaneous reload of all control software and PLC firmware in a facility to minimize the risk of compatibility issues. This would make for a very long turnaround time, with extensive (expensive) pre-installation testing and post-installation trouble shooting. Even then, subsequent process problems will be almost inevitable.

Not Limited to Stuxnet

Ralph makes the point that the two attack modes he describes in his Stuxnet analysis blogs are not limited to being used by Stuxnet (they could be carried by other attack vectors) nor are they limited to being applied to just Siemens controlled systems. Since the attacks actually takes aim at the PLC’s not the Siemens work stations, any industrial control system that utilizes programmable logic controllers could be attacked using these two modes.

One of the things that Ralph doesn’t explicitly state in his blog, yet is clearly implicated by his discussion, is that any vulnerability in control systems that allows an attacker to gain system access to allow code injection to the controllers would allow for a Stuxnet like attack on those systems. Ralph does note that the “development tools to aid in the [code injection technique] development are [available] in the wild”.

The hard work has been done. Now all it takes is a reasonably technically proficient person with the necessary intent to launch the next attack on industrial control systems. An attacker without any process knowledge could launch an attack that could randomly disrupt control system operations to the extent that facility shutdown would be required. An attacker with basic process knowledge (from a disgruntled, or cash strapped insider for instance) could cause worst case process upsets resulting in catastrophic failures of processes and/or equipment that could seriously affect the neighboring community.

Thursday, November 18, 2010

DHS ICS-CERT Issues OPC Server Vulnerability Advisory

This afternoon DHS ICS-CERT has issued a new Advisory regarding an identified vulnerability in the Automated Solutions OPC Server. The advisory only applies to the stand alone version of the Modbus/TCP OPC Data Access OPC servers (versions 3.0.0 and earlier versions) produced by Automated Solutions.

The advisory describes this as “a heap corruption vulnerability” that, if exploited, could corrupt the OPC server memory. ICS-CERT estimates that the vulnerability could be exploited by an attacker with an intermediate skill level, but that it would be unlikely that an attacker could use this vulnerability to execute arbitrary commands.

ICS-CERT has confirmed that Automated Solutions’ latest patch mitigates this vulnerability. ICS-CERT recommends the following mitigation steps:

● Upgrade to the latest version and install the latest patch. The patch is available at http://automatedsolutions.com/demos/demoform.asp?code=17.

● Minimize network exposure for all control system devices. Critical devices should not directly face the Internet. Control system networks and remote devices should be located behind firewalls, and be isolated from the business network. If remote access is required, secure methods such as Virtual Private Networks (VPNs) should be utilized.
As always the standard ICS-CERT caution applies; “Owners and operators should exercise caution and consult their control systems vendor prior to making any changes. Proper impact analysis and testing should always be conducted prior to making any changes to control systems.”
 
/* Use this with templates/template-twocol.html */