Showing posts with label ICS-CERT Advisory. Show all posts
Showing posts with label ICS-CERT Advisory. Show all posts

Thursday, September 13, 2018

ICS-CERT Publishes Honeywell Advisory


Today the DHS ICS-CERT published a control system security advisory for mobile computers from Honeywell. The advisory describes an improper privilege management vulnerability. The vulnerability was reported by the Google Android Team. Honeywell has updates available to mitigate the vulnerability.

ICS-CERT reports that a skilled attacker could remotely exploit the vulnerability to allow a malicious third-party application to gain elevated privileges. This could enable the attacker to obtain access to keystrokes, passwords, personal identifiable information, photos, emails, or business-critical documents.

It is too early to tell if this vulnerability affects all Android devices (probably?) so other mobile ICS devices might also be affected. Of course (sarcasm alert), no one would use non-approved applications on a device used to access a control system, so this really is not a problem (SIGH).

Thursday, September 6, 2018

ICS-CERT Publishes Ice Qube Advisory


Today the DHS ICS-CERT published a control system security advisory for products from Ice Qube. The advisory describes two vulnerabilities in the Thermal Management Center. The vulnerabilities were reported by Maxim Rupp. Ice Qube has a new version available that mitigates the vulnerabilities. There is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper authentication - CVE-2017-14026; and
Unprotected storage of credentials - CVE-2017-16714

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to gain unauthorized access to configuration files or obtain sensitive information.

Tuesday, September 4, 2018

ICS-CERT Publishes Opto22 Advisory


Today the DHS ICS-CERT published a control system security advisory for the Opto22 PAC Control product. The vulnerability was reported by Robert Hawes. Opto22 has a new version that mitigates the vulnerability. There is no indication that Hawes was offered an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to crash the device being accessed, and a buffer overflow condition may then allow remote code execution.

Friday, August 31, 2018

ICS-CERT Publishes Advisory and 2 Updates


Yesterday the DHS ICS-CERT published a control system security advisory for products from Philips. They also published updates for previous published advisory; one for control system products from Martem and one for medical device products from Philips.

Philips Advisory


This advisory describes 9 vulnerabilities in the Philips e-Alert Unit. The vulnerability is self-reported. Phillips has a version available that mitigates some of the vulnerabilities. A new version dealing with the remainder will be published by the end of the year.

The nine reported vulnerabilities are:

• Improper input validation - CVE-2018-8850;
• Improper neutralization of input during web page generation - CVE-2018-8846;
• Information exposure - CVE-2018-14803;
• Incorrect default permission - CVE-2018-8848;
• Cleartext transmission of sensitive information - CVE-2018-8842;
• Cross-site request forgery - CVE-2018-8844;
• Session fixation - CVE-2018-8852;
• Uncontrolled resource consumption - CVE-2018-8854; and
Use of hard-coded credentials - CVE-2018-8856

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit some of the vulnerabilities to allow attackers to provide unexpected input into the application, execute arbitrary code, display unit information, or potentially cause e-Alert to crash. The other vulnerabilities could only be exploited from the same subnet.

Martem Update


This update provides new information on an advisory that was previously published on May 22nd, 2018 and updated on May 24th, 2018. The new information includes:

• An additional vulnerability (incorrect default permissions);
• An additional risk consequence (full control over RTU);
• Updated affected version information; and
• Mitigation information for new vulnerability


Philips Update


This update provides new information on an advisory that was originally published on August 21st, 2018. The new information removes the ‘remotely exploitable’ language and notes that the “vulnerability is exploitable from within the same local device subnet”.

Thursday, August 23, 2018

ICS-CERT Publishes BD Advisory


Today the DHS ICS-CERT published a medical device security advisory for BD Alaris syringe pumps. The advisory describes an improper authentication vulnerability. The vulnerability was reported by Elad Luz of CyberMDX. BD has identified work arounds and there is no indication that BD intends to further mitigate this vulnerability.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability  to gain unauthorized access to various Alaris Syringe pumps and impact the intended operation of the pump when it is connected to a terminal server via the serial port.

Tuesday, August 21, 2018

ICS-CERT Publishes 2 Advisories and an Update


Today the DHS ICS-CERT published a control system security advisory for products from Yokogawa and a medical device security advisory for products from Philips. They also updated a previously published control system advisory for products from GE. The Yokogawa vulnerability is one of the two that I briefly addressed on Saturday.

Yokogawa Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Yokogawa iDefine, STARDOM, ASTPLANNER, and TriFellows. The vulnerability affects the licensing function of the products. The vulnerability is being self-reported. Yokogawa has updates available to mitigate the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow arbitrary code execution, or the stopping of the license management function.

Philips Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the Philips  IntelliVue Information Center iX. An unidentified user notified Philips of the problem. Philips has identified work arounds and expects to provide an update in the 3rd quarter, 2018.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability to effect a denial of service, the operating system will become unresponsive due to the network attack, which will affect the applications ability to meet the intended use.

GE Update


This update provides additional information on an advisory that was originally published on June 27th, 2012. The update provides a link to the GE advisory that was last updated on February 22nd, 2013. A document linked to in that advisory provides a more detailed description of the vulnerabilities and mitigation measures. That document was updated this weekend to correct broken links to the ICS-CERT; interestingly I cannot find any ICS-CERT links in either GE document.

Friday, August 17, 2018

ICS-CERT Publishes 3 Advisories


Yesterday the DHS ICS-CERT published two control system security advisories for products from Tridium and Emerson and a medical device security advisory for products from Philips. The Tridium advisory was previously published on the HSIN ICS-CERT library on July 10, 2018. For more on this HSIN resource see the final section below.

Tridium Advisory


This advisory describes two vulnerabilities in the Tridium Niagara controller. The vulnerabilities were reported by Johnathan Gains and Leet Cyber Security. Tridium has updates available that mitigate the vulnerability. There is no indication that that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Path traversal - CVE-2017-16744; and
Improper authentications - CVE-2017-16748

ICS-CERT reports that an uncharacterized attacker could remotely exploit these vulnerabilities to crash the device being accessed; a buffer overflow condition may allow remote code execution.

Emerson Advisory


This advisory describes four vulnerabilities in the Emerson DeltaV DCS Workstations. The vulnerabilities were reported by Younes Dragoni of Nozomi Networks, Ori Perez of CyberX. Emerson has a patch available that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Uncontrolled search path element - CVE-2018-14797;
• Relative path traversal - CVE-2018-14795;
• Improper privilege management - CVE-2018-14791; and
• Stack-based buffer overflow - CVE-2018-14793

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow arbitrary code execution, malware injection, or malware to spread to other workstations.

Philips Advisory


This advisory describes two vulnerabilities in the Philips PageWriter Cardiographs. Philips is self-reporting these vulnerabilities to ICS-CERT. Philips has produced generic workarounds and plans to issue updates to mitigate the vulnerabilities in the middle of next year.

The two reported vulnerabilities are:

• Improper input validation - CVE-2018-14799; and
• Use of hard-coded credentials - CVE-2018-14801

ICS-CERT reports that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to allow buffer overflows or allow an attacker to access and modify settings on the device.

HSIN Library


It has been a while since I mentioned the ICS-CERT library on the Homeland Security Information Network. This restricted access, on-line resource provides ICS-CERT a method of sharing information with the user community for vulnerabilities that may affect critical homeland resources. This restricted release is designed to allow owners a chance to implement mitigation measures before the vulnerability becomes public knowledge.

For more information about this program and to request access see this ICS-CERT page.

Tuesday, August 14, 2018

ICS-CERT Publishes 4 Advisories


Today the DHS ICS-CERT published three control system security advisories for products from Siemens and one medical device security advisory for products from Philips. The three Siemens advisories were briefly discussed here over the weekend.

Automation License Manager Advisory


This advisory describes two vulnerabilities in the Siemens Automation License Manager. The vulnerabilities were reported by Vladimir Dashchenko from Kaspersky Lab. Siemens has updates available to mitigate the vulnerability. There is no indication that Dashchenko was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Relative path traversal - CVE-2018-11455; and
Improper input validation - CVE-2018-11456

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow remote code execution or allow an attacker to determine port status on another remote system.

OpenSSL Advisory


This advisory describes a cleartext transmission of sensitive information vulnerability in the Siemens Industrial Products. The vulnerability is being self-reported by Siemens. Siemens has updates for some of the affected products and continues to work on the remainder.

ICS-CERT reports that an uncharacterized attacker could remotely exploit this vulnerability to result in unencrypted data being transmitted by the SSL/TLS record layer.

SIMATIC Advisory


This advisory describes two incorrect default permissions vulnerabilities in the Siemens SIMATIC STEP 7 (TIA Portal) and SIMATIC WinCC (TIA Portal). The vulnerabilities were reported by Younes Dragoni from Nozomi Network. Siemens has updates that mitigate the vulnerabilities. There is no indication that Dragoni has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker with local access could exploit the vulnerability to manipulate files and cause a denial-of-service-condition, or execute code both on the manipulated installation as well as devices configured using the manipulated installation.

Philips Advisory


This advisory describes two vulnerabilities in the Philips Philips’ IntelliSpace Cardiovascular (ISCV)/Xcelera server products. Philips identified the problem due to a customer complaint. Philips has produced a work around pending publication of an updated version.

The two reported vulnerabilities are

• Improper privilege management - CVE-2018-14787; and
• Unquoted search path or element - CVE-2018-14789

ICS-CERT reports that a relatively low-skilled attacker with local access and users privileges to the ISCV/Xcelera server to escalate privileges on the ISCV/Xcelera server and execute arbitrary code.

Thursday, August 9, 2018

ICS-CERT Publishes Two Advisories


Today the DHS ICS-CERT published two control system security advisories for products from NetComm and Crestron.

NetComm Advisory


This advisory describes four vulnerabilities in the NetComm 4G LTE Light Industrial M2M Router. The vulnerabilities were reported by Aditya K. Sood. NetComm has new firmware that mitigates the vulnerabilities. There is no indication that Sood has been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Information exposure - CVE-2018-14782;
• Cross-site request forgery - CVE-2018-14783;
• Cross-site scripting - CVE-2018-14784; and
Information exposure through directory listing - CVE-2018-14785

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow for the exposure of sensitive information.

Crestron Advisory


This advisory describes four vulnerabilities in the Crestron TSW-X60 and MC3 products. The vulnerabilities were independently reported by Jackson Thuraisamy (via Security Compass) and Ricky “HeadlessZeke” Lawshae (via the Zero Day Initiative). Crestron has firmware versions available that mitigate the vulnerabilities. There is no indication that either researcher has been offered an opportunity to verify efficacy of the fix.

The four reported vulnerabilities are:

• OS command injection (2) - CVE-2018-11228 and CVE-2018-11229);
• Improper access control - CVE-2018-10630; and
• Insufficiently protected credentials - CVE-2018-13341

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow remote code execution with escalated system privileges.

NOTE: Is it just me or does it seem odd that the same vulnerabilities are found in a touch-screen device and a control system processor controller?

Tuesday, August 7, 2018

ICS-CERT Publishes 3 Advisories


Today the DHS ICS-CERT published one control system security advisory for products from Delta Electronics and two medical device security advisories for products from Medtronic.

Delta Advisory


This advisory describes two vulnerabilities in the Delta CNCSoft and ScreenEditor products. The vulnerability was reported by Mat Powell via the Zero Day Initiative. Delta has an updated version of CNCSoft that mitigates the vulnerabilities. There is no indication that Powell was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-10636; and
Out-of-bounds read - CVE-2018-10598

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to gain remote code execution with administrator privileges.

MiniMed Advisory


This advisory describes two vulnerabilities in the Medtronic MiniMed 508 Insulin Pump. The vulnerabilities were reported by Billy Rios, Jesse Young, and Jonathan Butts of Whitescope LLC. Medtronic does not intend to develop a mitigation for these vulnerabilities (see note below).

The two reported vulnerabilities are:

• Cleartext transmission of sensitive information - CVE-2018-10634; and
• Authentication bypass by capture replay - CVE-2018-14781

ICS-CERT reports that an uncharacterized attacker could remotely exploit these vulnerabilities to allow an attacker to replay captured wireless communications and cause an insulin (bolus) delivery.

NOTE: The Medtronic security advisory reports that the following must occur for these vulnerabilities to be exploited:

1. The remote option for the pump would need to be enabled. This is not a factory-delivered default, and a user must choose this option.
2. The user’s remote controller ID needs to be registered to the pump.
3. The easy bolus option would need to be turned on and easy bolus step size programmed in the pump.
4. An unauthorized individual would need to be within close proximity to the user, with
necessary equipment to copy the RF signals activated, when the user is delivering a bolus
using the remote controller.
5. The unauthorized individual would need to be within the vicinity of the userto play back the RF signals to deliver a malicious remote bolus.
6. The user would need to ignore the pump alerts, which indicates that a remote bolus is being delivered.

MyCareLink Advisory


This advisory describes two vulnerabilities in the Medtronic MyCareLink Patient Monitor. The vulnerabilities were reported by Billy Rios, Jesse Young, and Jonathan Butts of Whitescope LLC. Medtronic is making (has made for one of the vulnerabilities) server side updates to mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Insufficient verification of data authenticity - CVE-2018-10626; and
• Storing passwords in a recoverable format - CVE-2018-10622

ICS-CERT reports that an uncharacterized attacker with physical access to the device could exploit the vulnerabilities to obtain per-product credentials that are utilized to authenticate data uploads and encrypt data at rest. Additionally, an attacker with access to a set of these credentials and additional identifiers can upload invalid data to the Medtronic CareLink network.

Thursday, July 19, 2018

ICS-CERT Publishes 4 Advisories


Today the DHS ICS-CERT published four control system security advisories for products from Moxa, Echelon, and AVEVA(2).

Moxa Advisory


This advisory describes a resource exhaustion vulnerability in the Moxa NPort serial network interface. The vulnerability was reported by Mikael Vingaard. The latest firmware mitigates the vulnerability. There is no indication that Vingaard has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability  to send TCP SYN packages, causing a resource exhaustion condition that would cause the device to become unavailable.

Echelon Advisory


This advisory describes four vulnerabilities in the Ecelon Smart Server and i.LON products. The vulnerabilities were reported by Daniel Crowley and IBM’s X-Force Red team. Echelon has a new version that mitigates three of the vulnerabilities and provides a workaround for the fourth. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Information exposure - CVE-2018-10627;
• Authentication bypass using an alternate path or channel - CVE-2018-8859;
• Unprotected credentials - CVE-2018-8851; and
Clear text transmission of critical information - CVE-2018-885

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow for remote code execution on the device.

In Touch Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Aveva InTouch HMI. This vulnerability was reported by George Lashenko of CyberX. Aveva has updates available that mitigate the vulnerabilities. There is no indication that Lashenko has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability to remotely execute code with the same privileges as those of the InTouch View process which could lead to a compromise of the InTouch HMI.

InduSoft Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Aveva InduSoft Web Studio and InTouch Machine Edition HMIs. This vulnerability was reported by Tenable Research. Aveva has updates available that mitigate the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow remote code execution.

Tuesday, July 17, 2018

ICS-CERT Publishes 3 Advisories and 1 Update


Today the DHS ICS-CERT published three new control system security advisories for products from PEPPERL+FUCHS, WAGO and ABB. They also updated a previously published advisory for products from Rockwell.

PEPPERL+FUCHS Advisory


This advisory describes an improper authentication vulnerability in the PEPPERL+FUCHS VisuNet RM, VisuNet PC, Box Thin Client (BTC) families of products. The vulnerability was reported by Eyal Karni, Yaron Zinar, and Roman Blachman with Preempt Research Labs. PEPPERL+FUCHS has firmware updates for HMI running RM Shell 4 or RM Shell 5. For HMI running on Windows 7 or Windows 10 platforms the recommendation is to run the applicable Windows update for CVE-2018-0866. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that an uncharacterized attacker with uncharacterized access could exploit this vulnerability to intercept sensitive communications, establish a man-in-the-middle attack, achieve administrator privileges, and execute remote code.

NOTE: I initially reported on this vulnerability on July 7th, 2018.

WAGO Advisory


This advisory describes three vulnerabilities in the WAGO e!DISPLAY Web-Based-Management. These vulnerabilities were reported by T. Weber of SEC Consult. The latest firmware version mitigates the vulnerabilities. There is no indication that Weber has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Cross-site scripting - CVE-2018-12981;
• Unrestricted upload of file with dangerous type - CVE-2018-12980; and
Incorrect permission for critical resource - CVE-2018-12979

ICS-CERT reports that a relatively low-skilled attacker could use publicly available exploits to remotely exploit the vulnerabilities to execute code in the context of the user, execute code within the user’s browser, place malicious files within the filesystem, and replace existing files to allow privilege escalation.

NOTE: I initially reported on these vulnerabilities on July 14th, 2018.

ABB Advisory


This advisory describes an improper input validation vulnerability in the ABB Panel Builder 800. The vulnerability was reported by Michael DePlante of Leahy Center and Michael Flanders of Trend Micro vis the Zero Day Initiative. ABB has provided work arounds pending further investigation of the vulnerabilities.

ICS-CERT reports that an uncharacterized attacker with uncharacterized access could conduct a social engineering attack to exploit this vulnerability to insert and run arbitrary code.

NOTE: I initially reported on these vulnerabilities on July 7th, 2018.

Rockwell Update


This update provides new information on an advisory that was originally published on June 21st 2018. The new information is an expansion of the affected versions for all affected products.

Thursday, July 12, 2018

ICS-CERT Publishes an Advisory and an Update


Today the DHS ICS-CERT published a control system security advisory for products from Eaton. They also updated a medical device security advisory for products from Medtronic.

Eaton Advisory


This advisory describes a stack-based buffer overflow in the Eaton 9000X Drive. The vulnerability was reported by Ghirmay Desta working with the Zero Day Initiative. Eaton has an update available that mitigates the vulnerability. There is no indication that Desta was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that an uncharacterized attacker could remotely exploit the vulnerability to allow remote code execution.

Medtronic Update

This update provides additional information for an advisory that was originally published on May 17th, 2018. The update adds a second vulnerability (Protection mechanism failure - CVE-2018-10631). This necessitated an increase of the CVSS (v3) ranking from 4.6 to 6.3 and an expanded risk evaluation section of the advisory.

Tuesday, July 3, 2018

ICS-CERT Publishes Rockwell Advisory


Today the DHS ICS-CERT published a control system security advisory for Rockwell Allen-Bradley Stratix 5950 security appliances. The advisory describes five vulnerabilities in software from the Cisco Adaptive Security Appliance which Rockwell uses as the central operating system for their Stratix 5950 security appliance. Sharp eyed readers will recognize that I reported on these vulnerabilities almost two weeks ago shortly after Rockwell published their advisory.

There are system setup workarounds that reduce the risk of a denial of service attack from one of the improper input validation vulnerabilities and a Cisco provided Snort Rule for one of the others. There are currently no mitigation measures for the remaining three vulnerabilities.

The five reported vulnerabilities are:

• Improper input validation (3) - CVE-2018-0228, CVE-2018-0231, and CVE-2018-0296;
• Improper certificate validation - CVE-2018-0227; and
Resource management errors - CVE-2018-0240

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to bypass client certification to create connections to the affected device or cause the device to crash.

*Insert standard third-party vulnerability rant*

Thursday, June 28, 2018

ICS-CERT Publishes 1 Advisory and 1 Update for Medtronic Products


Today the DHS ICS-CERT published a medical device security advisory for products from Medtronic. They also updated a previously published medical device security advisory for products from the same company.

Medtronic Advisory


This advisory describes two vulnerabilities in the Medtronic MyCareLink Patient Monitor. The vulnerabilities were reported by Peter Morgan of Clever Security. Medtonic will be installing an automatic update to mitigate the vulnerabilities. There is no indication that Morgan has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Use of hard-coded password - CVE-2018-8870; and
Exposed dangerous method or function - CVE-2018-8868

The Medtronic advisory makes a very important point about these vulnerabilities in particular that may include an important lesson to learn for all medical devices:

“Medtronic encourages patients to only use home monitors obtained directly from Medtronic or their clinician. Patients should not use a pre-owned MyCareLink Patient Monitor or one that is purchased secondhand or online. Monitors obtained through unofficial means are at an increased risk for exploitation associated with the vulnerabilities identified.”

ICS-CERT reports that an uncharacterized attacker with physical access to the monitor can exploit these vulnerabilities to allow privileged access to the monitor’s operating system.

Medtronic Update


This update provides new information on an advisory that was originally published on February 27th, 2018. The update includes:

• A change in format of the advisory;
• New information in the ‘Risk Evaluation’ section (formerly the ‘Impact’ section);
• Removal of the second and third paragraphs from the old ‘Impact’ section;
• Addition of a new vulnerability (Improper restriction of communication channel to intended endpoints - CVE-2018-10596); and
• Addition of a new work around (disconnecting the programmer from the network).

The revised Medtronic advisory contains some information that does not entirely match up with the new information in ICS-CERT update. They note, for instance that: “After issuing this advisory on Feb. 27, 2018, Medtronic was made aware of additional vulnerabilities [emphasis added] in the CareLink 2090 Programmer and its accompanying software deployment network.” Since Medtronic does not name the ‘vulnerabilities’ it is possible that they have been lumped into the single vulnerability listed in the ICS-CERT report.

Thursday, June 14, 2018

ICS-CERT Publishes Two Advisories and an Update


Today the DHS ICS-CERT published a control system security advisory for products from Siemens and a medical device security advisory for products from Naus Xltek. They also updated a control system security advisory for products from Siemens.

NOTE: There are still three Siemens advisories and two Siemens updates that were announced by Siemens on Tuesday that have not been covered by ICS-CERT. I will address those in my Saturday post.

Siemens Advisory


This advisory describes a permissions, privileges and access controls vulnerability in the Siemens SCALANCE X switches, RUGGEDCOM WiMAX, RFID 181-EIP, and SIMATIC RF182C. The vulnerability was reported by Dr. Ang Cui and Joseph Pantoga from Red Balloon Security. Siemens has provided updates for some of the affected products. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that an uncharacterized attacker on the same local network segment could exploit the vulnerability to execute arbitrary code.

Natus Xltek Advisory


This advisory describes 8 vulnerabilities in the Natus Xltek NeuroWorks software. The vulnerabilities were reported by Cory Duplantis from Cisco Talos. Natus Xltek has produced an update to mitigate the vulnerabilities. There is no indication that Duplantix has been provided an opportunity to verify the efficacy of the fix.

The eight reported vulnerabilities are:

• Out-of-bounds read (4) - CVE-2017-2852, CVE-2017-2858, CVE-2017-2860, and CVE-2017-2861; and
Stack-based buffer overflow (4) - CVE-2017-2853, CVE-2017-2867, CVE-2017-2868, and CVE-2017-2869.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to crash the device being accessed; a buffer overflow condition may allow remote code execution.

Siemens Update


This update provides additional information on an advisory that was originally issued on November 8, 2016 and then updated November 22nd, 2016; December 23rd, 2016; February 14th, 2017; March 2nd, 2017,  May 9th, 2017, June 20th, 2017, and again on January 25th, 2018. The update provided corrected affected version numbers and a link to a mitigation measure for PCS 7 V8.2.

Wednesday, June 13, 2018

ICS-CERT Publishes 2 Advisories and Updates 3 Siemens Advisories


Yesterday the DHS ICS-CERT published two control system security advisories for products from Siemens and Schneider. It also updated three control system security advisories for products from Siemens.

BTW: I discussed the Schneider advisory Saturday.

Siemens Advisory


This advisory describes two cross-site scripting vulnerabilities in the Siemens SCALANCE X switches. The vulnerabilities were reported by Marius Rothenbücher and Ali Abbas. Siemens has provided updates that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a highly-skilled attacker could remotely exploit the vulnerability to to store script code on the website and execute cross-site scripting (XSS), affecting the website’s confidentiality, integrity, and availability. The Siemens advisory notes that one of the vulnerabilities requires the attacker to log into the web application, but the other can be exploited via a social engineering attack.

Schneider Advisory


This advisory describes four vulnerabilities in the Schneider U.motion Builder. The vulnerabilities were reported by Wei Gao of Ixia and bigric3@360A-TEAM. Schneider has a firmware patch that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-7784;
• OS command injection - CVE-2018-7785;
• Cross-site scripting - CVE-2018-7786; and
Improper input validation - CVE-2018-7787

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow for remote code execution.

SIMATIC Update


This update provides new information on an advisory that was originally published on February 14th, 2017 and updated on June 15th, on July 6th and again on November 31st, 2018. The update corrects the version affected data for PCS 7.


SIMATIC PCS7 Update


This update provides new information on an advisory that was originally published on November 2nd, 2018. The update corrects the affected version data for PCS 7 v8.2 and provides information about the update available to mitigate the vulnerability.

SIMATIC WinCC Update


This update provides new information on an advisory that was originally published on March 29th, 2018 and updated on April 24th, 2018. The update corrects the affected version data for PCS 7 v8.2 and provides information about the update available to mitigate the vulnerability. In both this and the previous update, the new service pack for PCS 7 v8.2 is available from ‘local support’.

NOTE: Siemens announced a total of 5 new advisories and 5 updates yesterday. I expect that we will see the remainder Thursday.

Thursday, May 24, 2018

ICS-CERT Publishes 2 Advisories and 3 Updates

Today the DHS ICS-CERT published a control system security advisory for products from Schneider Electric and a medical device security advisory for products from BeaconMedaes. They also published updates to previously published advisories for products from Rockwell, Siemens, and Martem.

Schneider Advisory


This advisory describes three vulnerabilities in the Schneider Floating License Manager. The vulnerabilities are being self-reported. Schneider has new versions available to mitigate the vulnerabilities.

The three reported vulnerabilities are:

• Heap-based buffer overflow - CVE-2016-2177;
• Improper restriction of operations within bounds of a memory buffer - CVE-2016-10395; and
• URL redirection to an untrusted site - CVE-2017-5571

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to cause a denial of service, allow arbitrary execution of code with system level privileges, or send users to arbitrary websites.

BeaconMedaes Advisory


This advisory describes three vulnerabilities in the BeaconMedaes TotalAlert Scroll Medical Air Systems web application. These vulnerabilities were reported by Maxim Rupp. BeaconMedaes has a new version that mitigates the vulnerability, There is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Improper access control - CVE-2018-7526;
• Insufficiently protected credential - CVE-2018-7518; and
• Unprotected storage of credentials - CVE-2018-7515;

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities  to view and potentially modify some device information and web application setup information, which does not include access to patient health information.

NOTE: These vulnerabilities were not reported on the FDA Medical Device Safety Communication site.

Rockwell Update


This update provides new information on an advisory that was originally published on May 10th, 2018. The new information is supposed to be a link to the Rockwell security advisory [log-in required]. Unfortunately, that link is to the Rockwell Arena advisory (the ICS-CERT advisory for that was publicly published on the same day as the Factory Talk advisory that is currently being updated here. The correct link is https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1073133.


Siemens Update


This update provides new information on an advisory that was originally published on May 8th, 2018. The new information is a revision to the instructions as to how owner/operators should go about getting the updated version. It removed the original link to the ‘hotfix’ and substitutes the instruction to “Obtain the update via the local Siemens representative”.

Martem Update



This update provides new information on an advisory that was originally published on May 22nd, 2018. The new information is links to the Martem advisories for vulnerability CVE-2018-10603 and CVE-2018-10607. A link to the Martem advisory for the third vulnerability was already included in the initial ICS-CERT advisory.

Tuesday, May 22, 2018

ICS-CERT Publishes 2 Advisories


Today the DHS ICS-CERT published a control system security advisory for products from Martem. They also published a medical device security advisory for products from Becton, Dickinson and Company (BD).

Martem Advisory


This advisory describes three vulnerabilities in the Martem TELEM-GW6/GWM products. The vulnerabilities were reported by Bernhards Blumbergs and Arturs Danilevics of CERT.LV, Latvia. Martem has described work arounds to mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Missing authentication for critical function - CVE-2018-10603;
• Uncontrolled resource consumption - CVE-2018-10607; and
Cross-site scripting - CVE-2018-10609

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to allow execution of unauthorized industrial process control commands, denial of service, or client-side code execution.

BD Advisory


This advisory describes three separate SQL related vulnerabilities in the BD BD Kiestra and InoqulA systems. These vulnerabilities are being self-reported. BD intends to have mitigations in place by July. In the mean-time BD has described workarounds to mitigate the vulnerabilities.

The following applications in the affected products fail to warn users of unsafe actions:

• Database (DB) Manager;
• ReadA Overview; and
• PerformA

ICS-CERT reports that an uncharacterized attacker with access to an adjacent network could exploit the vulnerabilities which may lead to loss or corruption of data.

NOTE: These vulnerabilities have not been reported on the FDA Medical Device Safety Communications site.

Tuesday, May 15, 2018

ICS-CERT Publishes Advantech Advisory and Updates Siemens Advisory


Today the DHS ICS-CERT published a control system security advisory for products from Advantech. They also updated a previously issued advisory for products from Siemens.

Advantech Advisory


This advisory describes eleven vulnerabilities in the Advantech WebAccess products. The vulnerabilities were reported by Mat Powell and rgod, working with ZDI; Steven Seeley of Offensive Security, working with ZDI; and Donato Onofri and Simone Onofri of Business Integration Partners S.p.A. Advantech released a new version that mitigates the vulnerabilities. There is no indication that any of the researchers were provided an opportunity to verify the efficacy of the fix.

The eleven reported vulnerabilities are:

• SQL injection - CVE-2018-7501;
• Information exposure through directory listing - CVE-2018-10590;
• Improper authorization - CVE-2018-7505;
• Path traversal (2) - CVE-2018-7503, and CVE-2018-10589;
• Stack-based buffer overflow - CVE-2018-7499;
• Heap-based buffer overflow - CVE-2018-8845;
• Untrusted pointer dereference - CVE-2018-7497;
• External control of file name or path - CVE-2018-7495;
• Origin validation error - CVE-2018-10591; and
Improper privilege management - CVE-2018-8841

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilitie to disclose sensitive information from the host and/or target, execute arbitrary code, or delete files.

Siemens Update


This update provides additional information for an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th, November 28th, February 27th, 2018 and most recently on May 3rd, 2018. The new information includes links to new versions for version 4.7 of:

• SINAMICS G130;
• SINAMICS G150;
• SINAMICS S120; and
• SINAMICS S150

The Siemens security advisory provided undated version information for the same products, but that was not reported in the ICS-CERT advisory

NOTE: Siemens also reported two other updated advisories (here and here) and a new advisory (here) today when they reported this update. Hopefully ICS-CERT will publish their versions later this week.

 
/* Use this with templates/template-twocol.html */