Showing posts with label ICS-CERT Advisory Update. Show all posts
Showing posts with label ICS-CERT Advisory Update. Show all posts

Wednesday, April 19, 2017

ICS-CERT Updates an Advisory and an Alert

Yesterday the DHS ICS-CERT updated two control system security notices; one an alert for the BrickerBot vulnerability and the other affecting products from Belden Hirschmann.

BrickerBot Update


This update provides new information on the alert that was originally published on April 12th, 2017. The update more specifically acknowledges the Radware contribution to the state of current knowledge about BrickerBot. It also provides:

• A slightly more detailed and updated description of the operation of both BrickerBot.1 and BrickerBot.2; and
• A new mitigation measure; updating Ubiquiti device firmware.

Belden Hirschmann Update


This update provides new information on the advisory that was originally published on January 26th, 2017. The update expands the scope of the advisory; adding three new vulnerabilities that were apparently fixed with the originally reported new software version. The newly reported vulnerabilities are:

• Server-side request forgery - CVE-2017-6036;
• Cross-site request forgery - CVE-2017-6038; and
• Information exposure - CVE-2017-6040

Belden did not change their original Security Bulletin. Instead, they issued an additional Security Bulletin to describe the ‘new’ request forgery vulnerabilities. Belden actually describes the cross-site request forgery as a subset of the server-side request forgery, rather than specifically listing it as a separate vulnerability. Belden never does specifically acknowledge the ‘information exposure’ vulnerability reported by ICS-CERT.


Interestingly, the only change that ICS-CERT makes to their ‘impact’ statement designed to reflect the additional vulnerabilities is to change the words ‘of this vulnerability’ to ‘of these vulnerabilities’. It does not acknowledge the Belden report that the ‘new’ vulnerabilities may allow an attacker to “trick administrators into changing the configuration of the device”.

Wednesday, May 18, 2016

ICS-CERT Updates Meteocontrol Advisory

This morning the DHS ICS-CERT published an updated advisory for control system vulnerabilities reported in the Meteocontrol WEB'log. The Advisory was originally published last week and I reported on potential problems with the advisory yesterday. Additionally, the Karn Ganeshen memo to Full Disclosure on this topic is now available.

Revised Advisory


ICS-CERT made changes to two areas of the Advisory. First they added a new paragraph to the ‘Impact’ section of the advisory. That new paragraph reads:

“Successful exploitation of these vulnerabilities can allow silent execution of unauthorized actions on the device such as modifying plant data; modifying modbus/inverter/other devices; configuration parameters; and saving modified configuration and device reboot.”

ICS-CERT also made a number of changes to the vulnerability overview section of the advisory. They changed the title and description of the first two vulnerabilities and added a third new vulnerability.

The ‘Information Exposure’ vulnerability (CVE-2016-2296) was changed to ‘Improper Access Control’ with this new description:

“All application functionality, and configuration pages, including those accessible after administrative login, can be accessed without any authentication.”

The ‘No Authentication’ vulnerability (CVE-2016-2297) was changed to ‘Command Shell Accessible’ with this new description:

“The application has a hidden/obscured access command shell-like feature that allows anyone to run a restricted set of system commands. This shell can be accessed directly without any authentication.”

Finally, ICS-CERT added a Cross-Site Request Forgery vulnerability (CVE-2016-4504).

Full Disclosure Memo


I mentioned yesterday that Karn Ganeshen had reportedly sent a memo to the Full Disclosure list explaining the deficiencies in the original Meteocontrol Advisory. Today that memo has been published on the site. In that memo, Karn has provided sample URLs that would allow access to the information on WEB’log devices without authentication.


I’m not sure if this information rises to the level of ‘exploit code’ since some additional work (I think) would have to be done to get these sample URL’s to work. In any case ICS-CERT continues in this version of the Advisory to report that: “No known public exploits specifically target these vulnerabilities.” Then again, they may not have known about the existence of this Full Disclosure memo when they revised the Advisory.

Tuesday, May 3, 2016

ICS-CERT Updates Siemens Advisory

Today the DHS ICS-CERT updated a control system advisory for an authentication bypass vulnerability in a number of SIMATIC products. The advisory was originally published on December 1st, 2015 and then updated on February 2nd, 2016. This update provides information on another product for which a mitigating firmware update is now available. Updates are now available on all of the affected products.


Siemens Product-CERT announced the release of their updated advisory last Friday via TWITTER®. At the same time, they also announced an update or another advisory that was originally published last October. The corresponding ICS-CERT advisory has not yet been updated.

Thursday, March 17, 2016

ICS-CERT Updates Advisory and Publishes New Advisory

This morning the DHS ICS-CERT published an update for an advisory published in December for a cross-site scripting vulnerability in the in XZERES 442SR turbine generator operating system (OS). It also published a new advisory for a vulnerability in the ABB Panel Builder 800.

XZERES Update


This update corrects the CVE number for the vulnerability. The CVE number published in the original advisory was actually for another cross-site scripting vulnerability in the same equipment that was reported by ICS-CERT in an advisory published in March of last year.

ABB Advisory


This advisory describes a DLL hijacking vulnerability in the ABB Panel Builder 800. The vulnerability was reported by Ivan Sanchez from Nullcode Team. ABB has produced a new version of the software that mitigates the vulnerability. There is no indication that Sanchez has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that an attacker must get malicious code to a specific directory in the file system and then convince an authorized operator to execute the code. ICS-CERT says that this cannot be exploited remotely.


The ABB Security Advisory (not referenced in this advisory) for this vulnerability has a workaround that can be used pending the updating of the software to the newer version. Thanks to Joel Langill for tweeting about this document this morning.

Thursday, December 11, 2014

ICS-CERT Updates Siemens Advisory

This afternoon the DHS ICS-CERT updated their advisory for the Siemens vulnerability that they recently noted may be involved in some of the BlackEnergy attacks. Siemens reported two additional product variants for which there is now version that is resistant to the exploit of this vulnerability. Neither Siemens nor ICS-CERT have yet identified exactly what the vulnerabilities are; just what could result from a successful exploit. Hopefully that will change when the last two products are also protected.


I was a little surprised to see ICS-CERT get this update out this afternoon; after all Siemens only published their version this morning. I guess that now that ICS-CERT thinks that this might be involved in the BlackEnergy series of attacks (that ICS-CERT is only really explaining in classified briefings), they think that it may be important to get this information out to owners of  potentially affected systems.

Tuesday, October 7, 2014

ICS-CERT Updates Two Advisories – Ignores Siemens GNU Bash Report

This afternoon the DHS ICS-CERT updated two earlier advisories, one from Siemens and one from Schneider. Interestingly they ignore the unique Siemens ProductCERT report on GNU Bash vulnerabilities in Siemens products.

Siemens Update

This advisory was originally published back in July. Since then Siemens has provided a new update for the still vulnerable SIMATIC PCS7. The original advisory was published with only a SIMATIC WinCC update available.

Schneider Update

This advisory was originally published almost three weeks ago. Since then Schneider has made the promised service packs available to correct the vulnerabilities:

• ClearSCADA 2010 R3.2, Released October 2014, and
• SCADA Expert ClearSCADA 2014 R1.1, Released October 2014.

Siemens GNU Bash Report

ICS-CERT has not yet published an advisory for the recently self-reported ProductCERT advisory for separate vulnerabilities related to the GNU Bash problem. Siemens tweeted about this advisory yesterday morning.

The advisory reports specific vulnerabilities in the DHCP client (ROX 1 and ROX 2 products) and the web interface of their ELAN system (APE Linux); nothing especially new here.


The interesting report here is the mention of a ‘generic Bash’ vulnerability in a number of listed products, but only after “major custom modifications by the user (such as installation of additional software or custom scripts)”. The public identification of a post-modification vulnerability marks a real commitment to customer support.

Thursday, August 21, 2014

ICS-CERT Updates Siemens HeartBleed Advisory Again

Today the DHS ICS-CERT published another update to the Siemens HeartBleed advisory that was updated just a week ago. The latest update provides a link to the patch for the CP 1543-1 Ethernet interface for the S 1500 system. This leaves just the RuggedCom ROX I and ROX II operating systems to be patched for this vulnerability.

Tuesday, May 20, 2014

ICS-CERT Publishes Siemens HeartBleed Update

Today the DHS ICS-CERT published an updated version of the HeartBleed advisory for a number of Siemens products. This is the second update for this advisory. The first was published on April 29th, 2014 and the original advisory was published on April 15th, 2014.

Siemens now reports that they have released product updates for all systems identified as vulnerable to the HeartBleed vulnerability.


ICS-CERT did not publish an updated version of their HeartBleed advisory nor have they updated their downloadable spreadsheet listing the HeartBleed status of a wide variety of control system products.

Monday, October 21, 2013

ICS-CERT Updates Latest Crain-Sistrunk Advisory

This afternoon the DHS ICS-CERT updated the latest single product advisory for a DNP3 vulnerability reported by Adam Crain and Chris Sistrunk that was originally published less than two weeks ago. The updated information explains the vulnerability differences when the devices is used in two different modes; serial communications and IP communications modes.

ICS-CERT now separates the improper input validation vulnerability into two separate vulnerabilities with their own CVE # (IP -  CVE-2013-2787; Serial - CVE- 2013-2818) and different CVSS v2 base scores (IP – 7.1; Serial – 4.7) based upon the different modes of access. The higher base score for the IP installation is based upon the fact that the vulnerability is remotely accessible.

ICS-CERT also notes that the skill level necessary to exploit the vulnerabilities is different, noting that it takes less skill (moderate) to exploit the IP based installation as compared to the high skill level required to exploit the serial based implementation vulnerability. It appears that they base that distinction solely on the fact that physical contact with the device is required for a serial exploit.

I’m not sure that I agree with the exploit skill level assessment. It takes different skills to defeat physical security than to gain network access, but I’m not sure that I would call it higher skills. There are certainly more people out there with the ability to penetrate a remote facility protected by fences and cameras (I can certainly do that as can most ex-infantry soldiers, gang bangers and B&E specialists to name a few; hell an 80-year old nun did it earlier this year at a nuke weapons installation) than can penetrate network defenses to access to a port on a device.

It seems to me that this is an attempt to understate the potential threat to electric (gas and water) transmission systems that employ these devices. There has been a lot of discussion in the cybersecurity press about the physical vulnerability of these types of devices at remote sites. Those discussions describe the ease of plugging a device into a serial port and how uncomplicated TCP packet can be used to put the outstation into an endless loop. This type of attack would make it impossible to control the control systems at that outstation until the system was reset.


Other than those concerns, the new updated does more accurately describe how the vulnerability can be exploited and the different ways the vulnerability can be exploited based upon how the device is employed.

Monday, October 7, 2013

ICS-CERT Updates Rockwell Advisory with New Vulnerabilities

Today the DHS ICS-CERT published an update for the control system advisor they published back on April 5th, 2013. The update adds three additional vulnerabilities in the Rockwell Automation FactoryTalk and RSLinx applications. These new vulnerabilities were also discovered by Carsten Eiram of Risk Based Security after the earlier vulnerability updates were made to the Rockwell software. It is not clear why ICS-CERT issued an update instead of publishing a new advisory.

The update adds the following vulnerabilities:

• Out of bounds read, CVE-2013-2805;
• Integer overflow, CVE-2013-2807; and
• Integer overflow, CVE-2013-2806.

NOTE: Links may not work for a couple of days; not shutdown related.

The advisory reports that all three new vulnerabilities can be remotely exploited via Port 4444/UDP to conduct a denial of service attack. Rockwell has produced a new set of patches for these vulnerabilities. There is no indication that Carsten or any other outside agency has validated the efficacy of the most recent patch.

Monday, September 23, 2013

ICS-CERT Updates (again) Schneider Advisory

Today the DHS ICS-CERT published a second update for a series of Schneider Electric alerts and advisories dating back to December 2011 (12-12-11 Alert, 1-17-12 Advisory, 3-5-13 Alert, and 6-4-13 Advisory Update). The original alert was based upon a partially coordinated disclosure (we still haven’t heard the whole story on that) by Ruben Santamarta. The second alert was based upon an S4 Conference disclosure by Arthur Gervais.

This advisory update reports that:

• This advisory corrects and expands on the details in the specified alert and subsequent advisory updates;
• ICS-CERT has coordinated with Schneider Electric, and they have produced patches and firmware upgrades for Quantum and other affected products;
• Schneider Electric has created firmware upgrades that resolve the Telnet and Windriver debug port vulnerabilities for all affected products by removing the Telnet and Windriver services from these modules; and
• Schneider has also released a firmware upgrade to address the FTP service vulnerability by allowing the user to disable the FTP service.

The ICS-CERT advisory provides a link to the Schneider Electric download site but I cannot find a reasonably identifiable upgrade that deals with removing the Telnet and Windriver services from the Quantum Ethernet Module. Of course this fix was supposedly developed in 2011 for two of the affected modules so it may take some searching to find these upgrades. Hopefully someone in the Schneider Electric service department will be able to help owners locate the appropriate upgrades.

The advisory notes that the removal of these two services should not impact operations since they were included only for “advance troubleshooting use” and were not intended to be used by customers.


ICS-CERT left language in the updated advisory {pg 5} that would seem to indicate that additional mitigation measures are expected. It is not clear from reading the rest of the updated advisory if this was simply an editorial oversight or if additional work is actually expected from Schneider.

Monday, August 26, 2013

ICS-CERT Updates Sixnet Advisory

Today the DHS ICS-CERT updated an advisory they published last week for an undisclosed function vulnerability in the Sixnet universal protocol. As I noted earlier the original advisory did not state that anyone had validated the efficacy of the RTU firmware upgrade. This update explains that the Intelligent Systems Research Lab at the University of Louisville has validated the upgrade.

Wednesday, December 12, 2012

ICS-CERT Updates Rockwell Advisory


Yesterday the folks at DHS ICS-CERT updated their advisory for their fault generation advisory for various PLC controllers from Rockwell Automation Allen-Bradley. That earlier advisory was issued last Friday.

Not much new here, particularly if one had read Dale Peterson’s blog post on Monday. Apparently most of this information had already been available on the Rockwell web site (I’m not absolutely sure that’s true since you have to be a registered user to access that information, actually a pretty reasonable requirement), so I’m not sure why it wasn’t included in the original advisory. The updates do help paint a more complete picture of the vulnerability even though much of the new information could have been deduced from the original document.
 
/* Use this with templates/template-twocol.html */