Showing posts with label ICS-CERT Advisories. Show all posts
Showing posts with label ICS-CERT Advisories. Show all posts

Tuesday, December 1, 2015

ICS-CERT Publishes Three Advisories

This afternoon the DHS ICS-CERT published three advisories for industrial control system vulnerabilities in systems from Siemens, Schneider and Saia Burgess Controls. ICS-CERT also announced an alternative method for notification of the release of advisories, alerts, and other publications.

Siemens Advisory

This advisory describes an authentication bypass vulnerability in a number of Siemens SIMATIC Communications Processor devices. The vulnerability was reported by Lei ChengLin (Z-0ne) from the Fengtai Technologies’ Security Research Team. Siemens has produced a firmware update for one of the devices (SIMATIC CP 343-1) and the other updates are in the works. There is no indication that Lei has been provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to perform administrative operations on the Communication Processor. Network access to Port 102/TCP is required and the Communication Processor’s configuration must be stored on its corresponding CPUs for the vulnerability to be exploited. Siemens notes that firewall functionality of Advanced-CPs must be turned off for port 102/TCP for the vulnerability to be exploited.

NOTE: This vulnerability was announced by Siemens on TWITTER last Friday.
                                       
Schneider Advisory

This advisory describes eleven ActiveX code injection vulnerabilities (listed under a single CVE) in the Schneider ProClima F1 Bookview ActiveX control application. The vulnerabilities were reported through the Zero Day Initiative by Ariele Caltabiano and Fritz Sands ( Sands was mentioned in the Schneider advisory but not the ICS-CERT Advisory). Schneider has produced an update to mitigate these vulnerabilities but there is no indication that Caltabiano was provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to modify arbitrary memory and lead to remote code execution.

Schneider reports that the vulnerabilities reside in the thermal calculation software.

Saia Burgess Controls Advisory

This advisory describes a hard-coded password vulnerability in the Saia Burgess Controls family of PCD controllers. The vulnerability was reported by Artyom Kurbatov. Saia has produced a new firmware version that mitigates the vulnerability and Kurbatov has validated the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to gain administrative access to the target device and resources.

Saia cautions that the upgraded firmware will still not protect the PCD controllers if they are connected directly to the Internet. Their Security Rules document provides recommended details for protecting the security of these controllers.

GovDelivery

You can now get ICS-CERT publications sent directly to your email via GovDelivery. Simply register for the service, click on which publications you want and wait for the emails. Publications from National Cyber Awareness System Mailing Lists and the Critical Infrastructure Cyber Community Voluntary Program (C3VP) are also available from this system.


DHS has tried these email notification systems for a number of their web sites. I’ve signed up for a bunch of them and the notifications seem to dry up after a while. Maybe this one will be different. Go ahead, give it a try; I did. We all take perverse pride in our inflated inboxes.

Tuesday, February 3, 2015

ICS-CERT Published Two Siemens Advisories

Today the DHS ICS-CERT published two control system advisories from products from Siemens. Both advisories are related to system communications services. The affected products are Ruggedcom WIN devices and SCALANCE-X switches.


This advisory describes multiple vulnerabilities in Ruggedcom WIN devices. The vulnerabilities were reported by IOActive in a coordinated disclosure. Siemens has produced firmware updates that mitigate these vulnerabilities but there is no indication that IOActive has confirmed the efficacy of those updates.

The vulnerabilities are:

● Improper authentication - CVE- 2015-1448;
● Buffer overflow - CVE- 2015-1449; and
● Storing passwords in a recoverable format - CVE- 2015-1357

ICS-CERT reports that a relatively unskilled attacker with network access to the devices could exploit these vulnerabilities to perform administrative actions over the network or execute arbitrary code. The Siemens advisory notes that an attacker must be able to access the log files to exploit the third vulnerability.

SCALANCE Advisory

This advisory describes an apparently self-reported user impersonation vulnerability in the SCALANCE X-200IRT Switch Family. Siemens has developed a firmware  update that mitigates the vulnerability.

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to impersonate a legitimate user on the system. The Siemens advisory notes that a successful exploit requires network access while a legitimate user is signed into the switches’ web interface.


NOTE: It is taking much less time for the CVE links in the ICS-CERT advisories to point to active pages. It used to take a day or two (business days). The CVE’s in both advisories were active this evening. That may be because they were originated yesterday. Still it is nice to see live links being provided instead of early links.

Tuesday, January 13, 2015

ICS-CERT Publishes 5 Advisories and 1 Update

It was a busy day for ICS-CERT today with four new advisories, an almost three month old advisory being publicly published and one update of an advisory that was published yesterday. Did anyone mention that S4x15 started today?

GE DNP3 Advisory

Let’s get the old advisory out of the way first. This advisory was originally published back on October 14th on the US-CERT Secure Portal. It describes a Crain-Sistrunk improper input validation vulnerability in the DNP3 implementation used by GE iFix and Cimplicity products. The implementation was produced by Catapult Software who developed a patch that mitigates the vulnerability and GE has verified the efficacy of the patch. It does not appear that Crain-Sistrunk have verified the efficacy.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to effect a DOS attack.

According to the Project Robus web site it now looks like 29 of the 30 DNP3 vulnerabilities reported by Crain-Sistrunk have now been publicly disclosed by ICS-CERT.

NOTE: There is no reason given for the unusually long delay between the US-CERT publication and the ICS-CERT public notification.

GE Multilink Advisory

This advisory describes two vulnerabilities that effect the GE Multilink line of switches. The vulnerabilities were found by Eireann Leverett of IOActive in one of the Multilink switch lines and GE notified ICS-CERT that other lines were affected as well. A firmware upgrade is available.

The two reported vulnerabilities are:

● Resource consumption vulnerability - CVE-2014-5418; and
● Hard-coded key - CVE-2014-5419

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to conduct a DOS attack or decrypt traffic. ICS-CERT reports that there is no public exploits for these specific vulnerabilities while GE restricts that claim specifically only to the ML800 switches.

Phoenix Contact Software Advisory

This advisory describes an authentication vulnerability in applications developed by Phoenix Contact Software. These applications are used by undisclosed vendors to run process control and manage IEC 61131 logic. The vulnerabilities were originally reported by Reid Wightman of Digital Bond. Phoenix Contact Software is considering developing a fix for these vulnerabilities.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to inject arbitrary commands into the protocol.

The end use product may or may not contain mitigation measures to protect against this vulnerability.

GOOD LUCK. Caveat emptor.

Clorius Controls Advisory

This advisory describes an insecure Java client web authentication vulnerability in the Clorius Controls A/S ISC SCADA server. The vulnerability was originally reported by  Aditya Sood  who has validated the efficacy of the update that has been made available.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to gain complete access to the server.

Siemens Advisory

I noted the Siemens release of their advisory about this vulnerability this morning on Twitter and am now happy to report the ICS-CERT prompt release of their advisory. It describes three separate authentication vulnerabilities in the WinCC Sm@rtClient iOS Application. The vulnerabilities were originally reported by Kim Schlyter, Seyton Bradford, and Richard Warren from FortConsult. Siemens has produced an update to mitigate the vulnerability, but there is no report that the researchers have validated its efficacy.

The vulnerabilities include:

● Insufficiently protected credentials - CVE-2014-5231 and CVE-2014-5233; and
● Improper authentication - CVE-2014-5232

ICS-CERT reports that a relatively low skilled attacker with local access to the mobile device could exploit these vulnerabilities to gain access to the application and then presumably (my guess, not mentioned in the advisory) remotely access the control system with the full rights of the mobile device owner.

CodeWrights Advisory Update

Yesterday’s advisory was updated today to clarify that while ABB is a customer of CodeWrights HART DTM  library that they have not yet verified that any of their systems are affected by the identified vulnerability. The update provides a link to the ABB security advisory page where ABB will make the notification if any systems are found to be vulnerable.

I think that it is probably safe to assume that ICS-CERT has not yet verified that any other of the potentially affected vendors listed actually have products with the vulnerabilities. They apparently made the somewhat reasonable assumption that if these vendors (including ABB) had bought the rights to use the vulnerable libraries that there products using those libraries would be affected.


I guess we will just have to wait and see. I know which way I would bet.

Tuesday, January 14, 2014

ICS-CERT Publishes 3 Advisories

Today DHS ICS-CERT published three advisories; a unique Crain-Sistrunk DNP3 vulnerability, a mitigation effort update and an advisory from the secure portal.

Schneider Advisory

This advisory addresses an Uncontrolled Resources Consumption Vulnerability in the Schneider Electric ClearSCADA series of products. The vulnerability in the DNP3 system was reported by Crain-Sistrunk in a coordinated disclosure. Schnieder has produced a new software version that mitigates the vulnerability and Adam Crain has verified the efficacy of the fix.

ICS-CERT reports that a moderately skilled attacker could remotely exploit the vulnerability to cause DNP3Driver.exe to hang causing an interruption in the system processing. Essentially this is a denial of service (DOS) attack vector.

According to the Schneider Electric web site – they publicly disclosed this vulnerability on December 5th, 2013.

Sierra Wireless Advisory Update

This advisory update provides additional information about mitigation measures for the vulnerability reported last week. Sierra Wireless provides a vulnerability note dated January 10th suggesting that over-the-air firmware updates should not be done because “the update process, password data is transmitted to the device”. It recommends that the over-the-air programing feature be disabled.

The vulnerability note also as a recommendation for high-security applications:

“For high-security applications such as critical infrastructure monitoring, Sierra Wireless advises customers to deploy cellular devices using a Private Cellular Network or VPN to reduce the risk of an attacker capturing data transferred to/from the device.”

The pages that I reported last week did not mention that the device was discontinued now contain the following product status note: “Discontinued, still supported”.

This new information provides customers with a little more useable information than did the original advisory which essentially just said “Well we’ve discontinued the defective device, its now your problem”.

WellinTech Advisory

This advisory was originally released on the secure portal (on HSIN) last month and is now being released to the public. The advisory describes twin vulnerabilities affecting a variety of the WellinTech SCADA products. The vulnerability was reported by Andrea Micalizzi via the Zero Day Initiative (ZDI) in a coordinated disclosure. I was not able to find the ZDI listing for this vulnerability.

The twin vulnerabilities are:

• Information disclosure vulnerability, CVE-2013-2826; and
• ActiveX remote code execution vulnerability, CVE-2013-2827
NOTE: The CVE links are not yet active.


ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to either obtain system credentials or run arbitrary code in the dll. WellinTech has provided new versions of the affected software that mitigate the vulnerabilities. There is no mention of anyone verifying the efficacy of the new software versions in fixing these vulnerabilities.

Wednesday, February 8, 2012

ICS-CERT Publishes two more HMI Advisories

Yesterday afternoon and today DHS ICS-CERT published two advisories for vulnerabilities in two separate SCADA human-machine-interface (HMI) programs. Both were identified through coordinated disclosures. The affected systems are the xenon HMI (from Ing. Punzenberger COPA-DATA GmbH) and Wonderware HMI Reports (from Invensys).

Punzenberger Advisory


The twin DOS vulnerabilities for this advisory were reported by Kuang-Chun Hung of the Security Research and Service Institute – Information and Communication Security Technology Center (ICST). They would allow attackers to remotely execute a denial of service attack or possibly remotely execute arbitrary code.

Punzenberger has made available an update to this system that resolves the reported vulnerabilities. They also recommend disabling their ZenSysSrv.exe service except when it is actually needed.

Invensys Advisory


Rios and McCorkle reported these twin vulnerabilities on the Wonderware Report HMI from Invensys. The cross-site scripting vulnerability could allow a low skilled attacker to remotely execute a DOS attack or allow data leakage from the system. The write access violation would require a skilled attacker to execute arbitrary code via a social engineering initiated attack.

Invensys has a new version of this program available that removes the vulnerabilities from the system. It gets a little more complicated though since the owner-operator will also have to migrate the report definitions into the new Quick Reports 2012 format and request a permanent license from the distributor.

BTW: It would be interesting to know if these vulnerabilities were part of the ‘100 vulnerabilities in 100 days’ project that Rios and McCorkle did last year. The timing could be right and it would interesting to see how long it takes all 100 vendors to get their vulnerabilities systems under control. Or how many actually get the problems corrected.

Wednesday, September 7, 2011

ICS-CERT Publishes Advisories on Two Industrial Control Systems

Yesterday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published two control system advisories. One dealt with the Siemens WinCC system while the other dealt with the Scadatec Limited Procyon system.

Siemens WinCC


A new set of security researchers, Billy Rios and Terry McCorkle, have reported a memory corruption vulnerability in WinCC Runtime Advanced Loader, a component of both WinCC flexible and TIA Portal. This vulnerability was reported in limited distribution on the US-CERT secure portal on September 1st.

The vulnerability would allow an attacker with basic skills to use a specially crafted packet to execute a denial of service attack and possibly execute arbitrary code remotely. There is no known exploit publicly available for this vulnerability.

Siemens has not developed, nor is it intending to develop a patch for this vulnerability. They advise customers to keep this feature disabled on their systems except when it is being used to update firmware.

Scadatec Limited Procyon


The nSense Vulnerability Coordination Team has reported a buffer overflow vulnerability in the Scadatec Limieted Procyon HMI/SCADA product. This vulnerability was originally reported on the US-CERT secure portal on August 4th.

This vulnerability would allow a moderately skilled attacker to use a specially crafted packet to cause a buffer overflow via the Telnet daemon allowing for a denial of service attack and potentially allow the remote execution of arbitrary code.

Scadatec Limited has produced an updated version of Procyon HMI/SCADA product that is free of this vulnerability. Current customers can download the new version from http://scadatec.co.uk/existing_users.html.

General Comments


The increased visibility of SCADA system vulnerabilities has started to produce the additional attention of security researchers that has been predicted by a number of commentators in the ICS security arena. We must assume that the portion of the Black Hat community actively interested in attacking systems has also increased their attention on industrial control systems. We should start to see apparently random attacks on such systems. Hopefully system owners will report such attacks to ICS-CERT and/or RISI.

It is interesting to see Siemens specifically decline to produce a patch or update to deal with this new vulnerability. It is good to see that the vulnerable system is disabled by default, but it is unreasonable to assume that all users will remember to re-disable the loader when they are done using it to update firmware. They are setting their customers up for failure.
 
/* Use this with templates/template-twocol.html */