Showing posts with label ICS-CERT Advisory Updates. Show all posts
Showing posts with label ICS-CERT Advisory Updates. Show all posts

Wednesday, July 23, 2014

ICS-CERT Updates Two Advisories

This afternoon the DHS ICS-CERT published two updated advisories for control system vulnerabilities in Sierra Wireless AirLink products and various Siemens products. Both updates seem to be relatively minor changes to the ICS-CERT document. ICS-CERT does not report on the new information from Sierra Wireless, it just provides a link to the information.

Sierra Wireless Update

This advisory was originally published on January 8th, 2014 and has already been updated once. The purpose of today’s update was to include a link (.PDF download link) to an updated security advisory from Sierra Wireless. The earlier Sierra Wireless publication noted that they would investigate “methods to perform secure firmware updates remotely, and will provide information on this method when available”. The latest update (from May 28th; I wonder why it took ICS-CERT so long to update their advisory? I suspect that they were not informed by Sierra Wireless of the new information) provides those “details”:

• “Directly attaching a PC running the firmware update tool to the device via an Ethernet cable; or
• “Connecting to the device via VPN and performing the update over the VPN tunnel.”

I can see why it would take five months to come up with those useful techniques (SARCASM).

There is something even more interesting in the newest version of the Sierra Wireless documents that ICS-CERT missed in their update. To be fair, I also missed it in looking at the January Sierra Wireless document. The ICS-CERT advisory is specifically targeted at the ‘AirLink Raven X EV-DO product’. Sierra Wireless reports that the same vulnerability exists on the ‘Raven X, Raven XE, Raven XT, PinPoint X, PinPoint XT and MP Products’.

The ‘PinPoint’ products are all listed as “Discontinued, Not Supported” fortunately, the new mitigation measures will work just as well on the older models so perhaps that is why their vulnerability was not reported by ICS-CERT.

Siemens Vulnerability Update

The new data in this update was not provided by Siemens, but was more likely a response to a Siemens complaint about the wording in the initial advisory that made it seem that there were specific exploits directed at the Siemens products. ICS-CERT wrote in the original advisory (no longer available on-line) that:

“Exploits that target these vulnerabilities are known to be publicly available.”

While there are certainly HeartBleed exploits in play, we haven’t heard anything that would specifically point to their use against the Siemens products listed in this advisory (nor any ‘proof’ that they haven’t).

In any case ICS-CERT revised the wording to read:

“Exploits that target OpenSSL vulnerabilities are publicly available. ICS-CERT is unaware of any OpenSSL exploits that target Siemens’ products specifically.”

They are, of course, not saying that no one (sorry about the double negative but it is important and an appropriate use in this context) has specifically targeted these vulnerabilities in the Siemens products. That would be impossible to prove. We can probably take small comfort in the assumption that they probably would not have made this change if they had any reliable information indicating a possible HeartBleed related compromise of  a Siemens system.


BTW: Yesterday’s advisories are now listed on the ICS-CERT landing page.

Tuesday, May 27, 2014

ICS-CERT Updates Two Siemens Advisories

Today the DHS ICS-CERT published updates for advisories for two separate vulnerabilities reported in the Siemens RuggedCom ROS devices. The original versions of these advisories were published in February and March of this year. Both of these updates (Improper input validation; and Uncontrolled resource consumption) now report that updates are available for all of the affected products and it seems that updating for either one will take care of the problem for both advisories. German efficiency in action.

Wednesday, June 5, 2013

ICS-CERT Updates Two (Three?) Schneider Advisories

Yesterday afternoon the DHS ICS-CERT updated two earlier advisories for Schneider systems and referenced a third in both of those updates. The earlier advisories addressed:

• Schneider Electric Quantum Ethernet Module Hard-Coded Credentials - ICSA-12-018-01;
• Schneider Electric PLCS Multiple Vulnerabilities – ICSA-13-077-01A; and
• Schneider Electric Multiple Vulnerabilitiesa – ICS-ALERT-13-016-01A.

Ethernet Module Firmware Updates

In addition to the earlier mitigations developed by Schneider, the revised advisory reports that two new firmware updates are now available for 140NOE77101 and 140NOE77111. The updated advisory does not mention if the original researcher, Rubén Santamarta, has been provided an opportunity to verify the efficacy of the updates.

There are still un-mitigated vulnerabilities on this advisory.

PLC Updates

The updated advisory notes that Schneider has developed a patch for HTTP and FTP services that allows the HTTP to be disabled on certain modules. The link for these patches is a generic link that takes one to the Schneider site with no immediately apparent method to find the patches. Schneider still hasn’t produced a patch for the vulnerabilities in the Modicon M340 or Premium PLCs.


Once again there is no indication in the updated advisory that the researcher, Arthur Gervais, has had a chance to verify the efficacy of the patches.

Wednesday, March 27, 2013

ICS-CERT Publishes Two Metasploit Updated Advisories


Late this afternoon ICS-CERT published two updated advisories that were issued earlier this year; one for multiple vulnerabilities in CoDeSys Gateway-Web Servers and the other for a single vulnerability in the WellinTech KingView product. Both updates were necessary because the organization initially reporting the vulnerability had recently released a Metasploit module for exploiting the identified vulnerabilities.

Both Exodus Intelligence and Ioactive have produced Metasploit modules for the vulnerabilities that they reported in coordinated disclosures. EI explains on their web page that it is their intention to provide their customers with exploit tools for vulnerabilities that they discover. Apparently Ioactive has the same policy. This is becoming a more common approach as security researchers explore a variety of business models to make their security research worthwhile.

In both of these cases the exploit modules were published well after the ICS-CERT advisories were published. Thus the vendors had time to produce and distribute patches or updates to fix the vulnerabilities before the exploit tools became publicly available. Of course, no one really knows how many of the system owners actually knew about the vulnerabilities or if they did know actually had a chance to update their systems.
 
/* Use this with templates/template-twocol.html */