Showing posts with label ICS-CERT Alert. Show all posts
Showing posts with label ICS-CERT Alert. Show all posts

Tuesday, March 27, 2018

ICS-CERT Publishes Two Advisories


Today the DHS ICS-CERT published a medical device security advisory for products from Phillips and a control system security advisory for products from Schneider electric.

Phillips Advisory


This advisory describes two vulnerabilities in the Phillips Alice 6 System sleep diagnostic system. The vulnerabilities are apparently self-reported. Phillips plans on producing a new product version in December that will mitigate the vulnerability.

The two reported vulnerabilities are:

• Improper authentication - CVE-2018-5451; and
Missing encryption of sensitive data - CVE-2018-7498

ICS-CERT reports that a relatively low-skilled attacker using publicly available exploits could remotely exploit the vulnerabilities to gain visibility to usernames/passwords and personal data. Insufficient encryption and cryptographic integrity checks can lead to altered, corrupted, or disclosed sensitive data. Disclosure of personal data can occur by replacing a trusted node with a malicious node.

NOTE: These vulnerabilities were not reported on the FDA Medical Device Safety Communications page.

Schneider Advisory


This advisory describes three vulnerabilities in the Schneider Modicon products. The vulnerabilities were separately reported by Nikita Maximov, Alexey Stennikov, and Kirill Chernyshov of Positive Technologies as well as Meng Leizi and Zhang Daoquan. Schneider has described generic work arounds to mitigate the vulnerabilities.

The three reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-7240;
• Use of hard-coded credentials - CVE-2018-7241; and
• Use of broken or risky cryptographic algorithm - CVE-2018-7242

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow a remote unauthorized attacker access to the file transfer service on the device, which could result in arbitrary code execution or malicious firmware installation.

NOTE: These are the Modicon FTP vulnerabilities that I reported on Saturday.

Friday, January 12, 2018

ICS-CERT Publishes Alert, 3 Advisories and 1 Update

Yesterday ICS-CERT published an alert for the Intel Meltdown and Spectre vulnerabilities. They published three control system security advisories for products from Phoenix Contact, Moxa, and WECON. They also updated a previously published advisory for products from Advantech.

Meltdown Alert


This alert describes the CPU hardware vulnerable to side-channel attacks vulnerabilities known as  Meltdown and Spectre. The alert provides links to the following vendor notifications about these vulnerabilities:

ABB;
Rockwell Automation (account required for login); and
Siemens

The alert also provides a generic link to the ICS-CERT recommended practices page. It is disappointing that, in light of the problems seen with the Windows Update for Meltdown seen on some systems (here and here for example), ICS-CERT has not specifically mentioned the need for checking any updates on a test platform before uploading to a live control system.

Phoenix Contact Advisory


This advisory describes two vulnerabilities in the Phoenix Contact FL Switch product line. The vulnerabilities were reported by Ilya Karpov and Evgeniy Druzhinin of Positive Technologies. Newer versions of the firmware mitigate these vulnerabilities. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper authorization - CVE-2017-16743; and
• Information exposure - CVE-2017-16741

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to gain administrative privileges and expose information to unauthenticated users.

Moxa Advisory


This advisory describes an unquoted search path vulnerability in the Moxa MXview network management software. The vulnerability was reported by Karn Ganeshen. Moxa has produced a firmware update that mitigates the vulnerability. There is no indication that Ganeshen was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker with locally authorized access could exploit the vulnerability to escalate privileges by inserting arbitrary code into the unquoted service path.

WECON Advisory


This advisory describes two vulnerabilities in the WECON LeviStudio HMI Editor. The vulnerabilities were reported by Sergey Zelenyuk of RVRT, HanM0u of CloverSec Labs, and Brian Gorenc via the Zero Day Initiative. The latest version of the software mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2017-16739; and
• Heap-based buffer overflow - CVE-2017-16737

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to effect arbitrary code execution.

Advantech Update


This update updates information on an advisory that was originally published on January 4th, 2018. This update adds two vulnerabilities to those previously reported:

• Unrestricted upload of file with dangerous type - CVE-2017-16736 and

• Use after free - CVE-2017-16732

Thursday, December 7, 2017

ICS-CERT Publishes 3 Advisories and 1 Alert

Today the DHS ICS-CERT published three control system security advisories for products from Phoenix Contact, Rockwell and Xiongmai Technology. The also published a control system security alert for a WAGO programable logic controller (PLC).

Phoenix Contact Advisory


This advisory describes a cross-site scripting vulnerability in the Phoenix Contact FL COMSERVER, FL COM SERVER, and PSI-MODEM/ETH industrial networking equipment. The vulnerability was reported by Maxim Rupp. Phoenix Contact has released new firmware versions to mitigate the vulnerabilities. There is no indication that Rupp was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to change configuration variables on the device. The VDE-CERT advisory notes that network access is required to exploit the vulnerability.

Rockwell Advisory


This advisory describes an improper input validation vulnerability in the Rockwell FactoryTalk Alarms and Events component of the Factory Talk Services Platform. The vulnerability was reported by an unnamed major oil and gas company. ICS-CERT reports that newer versions or existing patches mitigate the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial of service condition in the in the history archiver service running on FactoryTalk Alarms and Events.

QUESTIONS: Does it seem odd to anyone else that a ‘major oil and gas company’ would be using an out-of-date version of this product? Or is this a problem that is endemic to the ICS user community? Did Rockwell notify their customers (or even just their major customers) when they discovered and fixed this vulnerability? (It does not sound like it.)

Xiongmai Technology Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Xiongmai IP Cameras and DVRs. The vulnerability was reported by Clinton Mielke. ICS-CERT reports that has not responded to requests to coordinate with NCCIC/ICS-CERT.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause the device to reboot and return to a more vulnerable state in which Telnet is accessible.

WAGO Alert


This alert describes an unconfirmed improper authentication vulnerability in the WAGO PFC200 PLC. This is the vulnerability that I discussed almost a week ago. SEC Consult reported that they had coordinated with CODESYS and that the vendor was planning on issuing a patch next month.

I am not sure why ICS-CERT issued an alert for the WAGO vulnerability and an advisory for the Xiongmai vulnerability. It would seem to me that those reporting formats probably should have been reversed.


NOTE: There is still no word on the Hikvision vulnerability that I reported in the same blog post as this WAGO vulnerability.

Saturday, August 5, 2017

ICS-CERT Publishes Eaton Alert

Yesterday the DHS ICS-CERT published a control system security alert for products from Eaton. The alert describes two buffer overflow vulnerabilities in the Eaton ELCSoft, a PLC programming software for Eaton Logic Control (ELC) controllers. The vulnerabilities were reported by Ariele Caltabiano (kimiya) via the Zero Day Initiative. ZDI has published advisories on these vulnerabilities (here and here) due to the lack of mitigation response from Eaton.

Friday, July 28, 2017

ICS-CERT Publishes CAN Bus Alert

Today the DHS ICS-CERT published a control system security alert for a vulnerability in the CAN Protocol that allows for a denial-of-service (DoS) attack. A public disclosure of the vulnerability is the reason for the alert, even though the researchers (Andrea Palanca, Eric Evenchick, Federico Maggi, and Stefano Zanero) coordinated with ICS-CERT before the exposure.


ICS-CERT reports that a sophisticated attacker, with knowledge of the CAN bus protocol and physical access to the system can exploit the vulnerability to conduct a DoS attack. Whether or not a system employing the CAN bus protocol will be vulnerable will depend on the implementation of the system.

Tuesday, July 25, 2017

ICS-CERT Published an Alert, an Advisory and 4 Updates

Today the DHS ICS-CERT published a control system security alert for the CRASHOVERRIDE malware and a control system security advisory for products from NXP. The NXP advisory was previously published on the NCCIC Portal on June 1st, 2017. ICS-CERT also updated four previously issued control system advisories for products from Siemens (3) and GE.

CRASHOVERRIDE Alert


This alert briefly describes the CRASHOVERRIDE malware. This malware was previously identified by ESET (on June 12th), Dragos (on June 12th) and US CERT (on June 12th) which ICS-CERT fully credits. All three reports provide much more information than does the ICS-CERT Alert. ICS-CERT has provided a different set of YARA rules for the detection of the malware than those previously published by Dragos. The ICS-CERT rules appear to target different portions of the malware.

NXP Advisory


This advisory describes two vulnerabilities in the NXP i.MX Devices, used on logic boards. The vulnerabilities were reported by Quarkslab. These are hardware vulnerabilities that generally cannot be corrected by a software fix. ICS-CERT notes that the vulnerabilities “are only exploitable when the device is placed in security enabled mode”.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2017-7936; and
• Improper certificate validation - CVE-2017-7932

ICS-CERT reports that a successful attack (by an uncharacterized attacker with uncharacterized access) could exploit the vulnerability to create a denial of service attack or to load an unauthorized image on the device affecting secure boot.

NOTE: These are not stand-alone devices, they are chip sets found on circuit boards on unnamed devices from unnamed supplier. Hopefully one (or more) of those downstream suppliers will develop a successful mitigation for this problem on their devices. But, it has been almost two months since notification was made to those vendors….

S7-300 Update


This update provides new information on an advisory that was originally published on December 13th, 2016 and then updated on May 9th, 2017. The update provides a link to a firmware update for the  S7-CPU 410 CPUs.

GE Update


This update provides new information on an advisory that was originally published on April 27th, 2017, and updated on May 18th, 2017. The new update identifies 8 legacy products that are affected by the vulnerability. It also provides links to previously identified firmware versions and newly mitigated products, including the newly identified legacy products. The firmware update for the URplus platform is still expected to be released this month.

PROFINET 1 update


This update provides new information on an advisory that was originally published on May 9th, 2017 and updated on June 15th, 2017, on June 20th, 2017, and again on July 6th, 2017. The update provides updated version information and mitigation information for the SINEMA Server: All versions < V14.


PROFINET 2 update


This update provides new information on an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017. The update provides new affected version information and mitigation links for:

• SCALANCE XM400, XR500: All versions prior to V6.1;
• S7-400 PN/DP V6 Incl. F: All versions;
• S7-400-H V6: All versions prior to V6.0.7;
• S7-400 PN/DP V7 Incl. F: All versions;
• S7-410: All versions prior to V8.2;
• SINAMICS S110 w. PN: All versions prior to V4.4 SP3 HF5;
• SINAMICS S120 V4.7: All versions prior to V4.7 H27; and

• SINAMICS V90 w. PN: All versions prior to V1.1

Friday, June 30, 2017

ICS-CERT Publishes Petya Alert

Today the DHS ICS-CERT published an alert for the Petya malware variant. It includes a brief description of the action of the worm with the information coming from a number of linked sources. As we saw with the ICS-CERT WannaCry alert, the alert provides links to vendor information about how the malware may be dealt with in their affected systems. The vendors in this initial (I expect to see a large number of updates as more vendor information becomes available) include:

• Rockwell (account required for access).

It is interesting that the US-CERT’s Petya announcement is not include in the Alert links. Nor are links from Drager, Schneider, and ABB; all of which were discussed yesterday on LinkedIn and other outlets. No really new important information in any of these documents; keep Windows OS updated and block ports 139/TCP and 445/TCP, all adequately mentioned in ICS-CERT alert.


One point not really mentioned in any of these, Petya is a poster child for why you should not pay ransom. There are no guarantees that you’ll get your files unlocked even if you pay the requested ransom.

Wednesday, May 17, 2017

ICS-CERT Updates WannaCry Alert and Publishes 4 Advisories

Yesterday the DHS ICS-CERT updated their earlier alert on the WannaCry ransomware. They also published four control system security advisories for products from Schneider Electric (2), Hanwha Techwin, and Detcon.

WannaCry Update


This update provides additional information on the alert that was issued yesterday. The new information includes:

• Links to two new vendor advisories from ABB and Siemens; and
• Links to some generic information (here and here) from the FDA on medical device security.

Siemens makes an important point about medical device cybersecurity:

“We would like to point out that neither the use of an email client nor browsing the internet is part of the intended use of most of the product types covered by this Siemens Security Bulletin.”

The ABB document does mention restricting SMB protocol use but stops short of recommending disabling the protocol as suggested by Microsoft. They do note:

“This will help to prevent spreading of the WannaCry malware from individual compromised computers. For specific guidance please see additional communication for specific ABB solutions and contact your local ABB service organization.”

NOTE: The US-CERT also updated their alert for this malware.

Schneider VAMPSET Advisory


This advisory describes an improper input validation vulnerability in the Schneider VAMPSET tool. The vulnerability was reported by Kushal Arvind Shah from Fortinet's Fortiguard Labs. Schneider has produced a new firmware version to mitigate the vulnerability. There is no indication that Shah has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker with local access could exploit the vulnerability to cause the software to enter a denial-of-service condition. The Schneider Security Notification reports that vulnerability has no effect on the operation of the protection relay to
which VAMPSET is connected.

Techwin Advisory


This advisory describes an improper access control vulnerability in the Hanwha Techwin SRN-4000 network video management platform. The vulnerability was reported by Can Demirel and Faruk Unal of Biznet Bilisim. Techwin reports that a newer version mitigates the vulnerability. ICS-CERT reports that the researchers have verified the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to allow the attacker remote access to the web management portal with admin privileges without authentication.

Schneider SoMachine Advisory

This advisory describes two vulnerabilities in the Schneider SoMachine HVAC software. The vulnerabilities were separately reported by Zhou YU and Himanshu Mehta. Schneider reports that a newer version mitigates the vulnerability. There is no indication that either researcher has been provided the opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2017-7965; and
• Uncontrolled search path element - CVE-2017-7966

ICS-CERT reports that a relatively unskilled attacker (no access characterization) could exploit the vulnerability to allow arbitrary code execution and could cause the device that the attacker is accessing to crash due to a buffer overflow condition.

NOTE: The Schneider Security Notification only addresses the buffer overflow vulnerability.

Detcon Advisory


This advisory describes two vulnerabilities in the Detcon SiteWatch Gateway. The vulnerabilities were reported by Maxim Rupp. ICS-CERT reports that Detcon no longer owns or services the SiteWatch Gateway product, but it attempting to notify customers of the vulnerabilities.

The two reported vulnerabilities are:

• Improper authentication - CVE-2017-6049; and
• Plaintext storage of passwords - CVE-2017-6047


ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to allow remote code execution. An attacker who exploits these vulnerabilities may be able to change settings on the affected product or obtain user passwords.

Tuesday, May 16, 2017

ICS-CERT Publishes WannaCry Alert

Yesterday the DHS ICS-CERT published a control system security alert for the WannaCry ransomware. This alert is a follow-up to the US-CERT alert on the same attack vector. The alert provides links to three vendor sites providing information about indicators of attacks on their Microsoft Windows® based control system products. Those vendors (and their WannaCry links) are:

Rockwell Automation (log on required);

Both the Schneider and BD advisories emphasize that while medical and industrial control systems have been affected this is a Microsoft Windows based ransomware attack. They both recommend ensuring that Microsoft patch for the MS17-010 SMB vulnerability be applied to all Windows based machines (including Windows XP and Windows 8). Interesting that neither vendor alerts nor the ICS-CERT alert discusses the Microsoft suggestion to turn of the SMB file sharing tool.


ICS-CERT expects to update this alert with additional vendor information when it becomes available.

Wednesday, April 12, 2017

ICS-CERT Publishes BrickerBot Alert

Today the DHS ICS-CERT published a control system security alert today about a new botnet attack that affects IOT devices. The attack bricks the affected devices, thus the name, BrickerBot. ICS-CERT identifies Radware as the initial source of the report on BrickerBot and provides a link to their BrickerBot report (originally published a week ago).

ICS-CERT provides the following summary of the two BrickerBot versions (BrickerBot 1 affects Ubiquiti devices and BrickerBot 2 affects Android devices):

• BrickerBot.1 targets devices running BusyBox with an exposed SSH command window and an older version of Dropbear SSH server. Most of these devices were also identified as Ubquiti network devices, some of which are access points or bridges with beam directivity.
• BrickerBot.2 targets Linux-based devices which may or may not run BusyBox or use Dropbear SSH server. However, Brickerbot.2 can only access devices which expose a Telnet service protected by default or hard-coded passwords.


ICS-CERT is working to identify affected devices and will work with vendors to see what equipment specific mitigation measures (if any) will be used to mitigate this vulnerability.

Tuesday, March 14, 2017

ICS-CERT Publishes Advisory and Alert

Today the DHS ICS-CERT published a new control system security advisory for products from Fatek. They also published a control system security alert for a class of micro-electromechanical systems (MEMS) accelerometer sensors from a number of vendors.

Fatek Advisory


This advisory describes a stack-based buffer overflow in Fatek PLCs. An anonymous researcher reported the vulnerability via the Zero Day Initiative (ZDI). Fatek has produced a new version that mitigates the vulnerability. There is no indication that the anonymous researcher has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to crash the affected device or allow remote code execution.

The Fatek release note for the new version of the Fatek Ethernet Module Configuration Tool used in these devices explain that there were two separate changes responding to apparently separate vulnerabilities. It is not clear from the release note if both are necessary to mitigate the vulnerability listed in the ICS-CERT advisory or if there is another vulnerability that was not reported by ICS-CERT.

MEMS Accelerometer Alert


This alert describes a publicly disclosed vibration based design flaw in a number of MEMs accelerometers from a variety of manufacturers. ICS-CERT does not identify the vulnerability reporter, but it appears to be based upon a paper that will be presented at the  IEEE European Symposium on Security & Privacy, Paris, France, April 2017 by Timothy Trippel, Ofir Weisse, Wenyuan Xu, Peter Honeyman, and Kevin Fu.

According to ICS-CERT:

“According to public reporting, the design flaws may be exploitable by playing specific acoustic frequencies in close proximity to devices containing embedded capacitive MEMS accelerometer sensors. At a specific acoustic frequency it may be possible to induce a vibration within vulnerable accelerometers to alter the sensors’ output in a predictable way. The impact of exploitation would be dependent on the function and operation of host devices, but it is understood that during an attack it may be possible to render affected sensors inoperable. This could result in a denial of service for host devices. During a successful attack, the integrity of measured data by vulnerable sensors could also be compromised. In the worst case attack scenario, it may be possible for an attacker to control sensor output data in a predictable way to achieve some level of control over a host device that primarily operates on unvalidated sensor data.”

One device manufacturer, Robert Bosch GmbH, has already produced a vulnerability advisory for MEMs accelerometers that they produce. ICS-CERT is working with other vendors to identify a list of affected products that use the affected capacitive MEMS accelerometers and to determine each vendor’s mitigation plan.

Commentary


The ICS-CERT failure to identify the source of the public disclosure in this particularly alert is extremely short sighted. I understand their desire to encourage coordinated disclosures, but I have never thought that failing to give credit where it is due served that purpose well. In this case this is an academic paper for a vulnerability that looks like it will take a great deal of effort to effectively exploit; particularly in an ICS environment. Failing to provide the details of the vulnerability (through a link to the original paper) is a disservice to the ICS community.

To make matters worse, from a coordinated disclosure point of view, the vulnerability potentially affects nearly all (apparently) MEMS accelerometer manufacturers. There would be no effective way to really coordinate the disclosure with all of the potential vendors. Further, I expect that many solutions are going to depend upon actions of other vendors that actually employ the accelerometers in their equipment.

Oh, and by-the-way, the original paper was publicly disclosed today in a NY Times article.

ICS-CERT really does need to get out a revision to this alert that gives specific credit, and a link to the paper, to the discoverers of this vulnerability.


Oh, in another cute by-the-way, this vulnerability already has a cute name – WALNUT.

Wednesday, October 12, 2016

ICS-CERT Publishes Sierra Wireless Alert

Today the DHS ICS-CERT took the unusual step of issuing a control system security alert for a ‘vulnerability’ being self-reported by the vendor. ICS-CERT reports that Sierra Wireless has issued a technical bulletin [.PDF Download] describing mitigation measures that owners can take to stop the Mirai malware from infecting AirLink gateways that are using the default ACEmanager password and are reachable from the public internet.

ICS-CERT is careful to note “that there is no software or hardware vulnerability being exploited in the Sierra Wireless devices by the Mirai malware”. The problem is in configuration management; using the default password.


It is nice to see that a vendor is taking specific steps to identify problems in configuration management for their products that allow an outside agency to take control of those products to become part of a botnet. And to further share that information with ICS-CERT to help get the word out is something to be commended. It would sure be nice if all vendors were so proactive.

Tuesday, September 20, 2016

ICS-CERT Publishes BINOM3 Alert

Yesterday the DHS ICS-CERT published an alert for publicly disclosed control system vulnerabilities in the BINOM3 Electric Power Quality Meter. The vulnerabilities had previously been disclosed to ICS-CERT by Karn Ganeshen, but ICS-CERT has not been able to get a response from BINOM3 about the vulnerabilities.

The reported vulnerabilities include:

• Reflected and stored Cross-site Scripting;
• Clear Text Passwords;
• Sensitive information leakage in GET request; and
• Access Control Issues


These are the same vulnerabilities that I reported on Saturday.

Monday, September 12, 2016

ICS-CERT Publishes Two Alerts

Today the DHS ICS-CERT published two alerts for publicly disclosed vulnerabilities in control system products from Schneider and FENIKS Pro. It appears that these are based upon the disclosures from Karn Ganeshen that I described on Saturday. ICS-CERT did not identify the researcher doing the uncoordinated disclosure or the location of the public disclosure for either alert.

Schneider Alert


This alert describes  a cross site request forgery (CSRF) vulnerability with proof-of-concept (PoC) exploit code affecting Schneider Electric’s ION Power Meter products.

Karn’s disclosure on the Full Disclosure site lists additional vulnerabilities that I briefly described Saturday. It appears that ICS-CERT either did not consider them to be actual vulnerabilities (as opposed to ‘features’) or that Schneider has not acknowledged the existence of the vulnerabilities that did not make it into the ICS-CERT alert.

ICS-CERT notes that it had already been working with Schneider on their response to the CSRF vulnerability. They also report Schneider has provided interim security mitigation measures that device owners can use.

FENIKS Pro Alert


This alert describes authentication vulnerabilities with proof-of-concept (PoC) exploit code affecting FENIKS PRO Elnet LT Energy & Power analyzer.

The remaining vulnerabilities described in Karn’s second disclosure on the Full Disclosure site are almost certainly considered features (default passwords) by ICS-CERT. Additionally, the lack of a documented password discovery process is not really (?) a security issue; it is just an interesting way to allow the owner to brick their own devices.


ICS-CERT has provided its initial disclosure to FENIKS and is waiting for confirmation of the vulnerabilities and reports of mitigation measures.

Thursday, August 18, 2016

ICS-CERT Publishes Two Navis Alerts and Siemens Update

This alert briefly describes a reported SQL injection vulnerability in the Navis WebAccess application. The vulnerability was publicly reported (NOTE: link was not included in ICS-CERT Alert) by bRpsd without prior coordination.

According to ICS-CERT: “WebAccess, is a web-based application that provides the operator and its constituents with real-time, online access to operational logistics information.” There is currently no mention of ‘WebAccess’ on the Navis web site, but there is a brief Navis promo on the Georgia Ports Authority web site that uses WebAccess.

Navis Incident Response Alert


This alert briefly reports that the vulnerability described in the vulnerability Alert has been publicly exploited, noting that the vulnerability “has been exploited against multiple U.S.-based organizations, resulting in data loss”. ICS-CERT reports that NCCIC Scoring System rates these incidents as ‘LOW’, noting: “Is unlikely to impact public health or safety, national security, economic security, foreign relations, civil liberties, or public confidence.”

Siemens Update


This update updates the list of versions affected by twin vulnerabilities included in the Advisory. It also provides an updated list of links to the updated versions of the affected software.

As noted above, ICS-CERT published this update and announced it on TWITTER® on Tuesday. Siemens, of course, published their ProductCERT update last Thursday; specifically adding “fix information for WinCC V7.2, Route Control and SIMATIC BATCH V8.2”. They announced their update on TWITTER the same day.

Commentary


The incident response alert issued today is the first that I recall seeing from ICS-CERT. According to the blurb on the ICS-CERT landing page describing this alert: “This report is intended to provide awareness to the US Critical Infrastructure community and make available Indicators of Compromise (IOCs) and mitigation recommendations.” This is an important function of ICS-CERT.

Fortunately, this is a relatively low impact vulnerability, at least on the national level. For the individual database owner, this could be costly depending on how much they depend on the ready availability of the database for their (and their customer) operations.


Since this is an SQL injection vulnerability there is not much in the way of ‘indicators or compromise’ for ICS-CERT to share beyond data logging and analysis. While database owners should be doing this anyway (but I suspect very few do), I doubt that this advisory will have much direct effect on the problem in the short run. Hopefully Navis will get an update out quickly and will actively push it to their customers.

Thursday, June 30, 2016

ICS-CERT Publishes Two Advisories and an Alert

This afternoon the DHS ICS-CERT published two new control system security advisories for products from Siemens, Eaton. It also published an alert for a publicly shared vulnerability in a Sierra Wireless product.

Siemens Advisory


This advisory describes two vulnerabilities in the Siemens  SICAM PAS (Power Automation System). The vulnerabilities were reported by Ilya Karpov and Dmitry Sklyarov of Positive Technologies. Siemens has produced a new version and instructions to mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The vulnerabilities are:

• Insufficiently protected credentials - CVE-2016-5848; and
• Information exposure - CVE-2016-5849.

ICS-CERT reports that a relatively unskilled attacker with local access could exploit the vulnerability to obtain sensitive information under certain conditions. The Siemens-CERT advisory reports that the attacker must have local access to the SICAM PAS system and certain database privileges or the database must be in a stopped state.

Siemens reported this vulnerability this morning on TWITTER®.

Eaton Advisory


This advisory describes twin buffer overflow vulnerabilities in the Eaton ELCSoft programming software. The vulnerabilities were reported by Ariele Calgaviano via the Zero Day Initiative (ZDI). Eaton has released a revision to mitigate these vulnerabilities. There is no indication that Eaton has provided Calgaviano an opportunity to verify the efficacy of the fix.

The vulnerabilities are:

• Heap-based buffer overflow - CVE-2016-4509; and
• Stack-based buffer overflow - CVE-2016-4512.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to execute arbitrary code on the target system.

Sierra Wireless Alert


This alert describes three vulnerabilities in the Sierra Wireless AirLink Raven XE and XT gateways. The vulnerabilities were reported in a coordinated disclosure by Karn Ganeshen. Sierra Wireless has reported to ICS-CERT that these devices are end of life and no new firmware releases will be made available. Ganeshen released a public report on four vulnerabilities on the Full Disclosure site on June 22nd, 2016 after he was advised that no updates were planned by Sierra Wireless.

The four vulnerabilities reported by Ganeshen are:

• Weak credential management (not reported in ICS-CERT Alert);
• Ace Manager contains a global CSRF vulnerability;
• Sensitive information leakage via GET requests; and
• Unauthenticated access to directories + Arbitrary File Upload.

ICS-CERT reports that Sierra Wireless has provided written mitigation measures to reduce these vulnerabilities.

NOTE: ICS-CERT did report the name of the reporting researcher, but did not provide a link to the public report.

Unreported Siemens Update



Siemens reported in another TWEET® this morning that they had updated a Siemens-CERT advisory that was reported by ICS-CERT on May 19th, 2016. We may see the updated ICS-CERT advisory tomorrow.

Friday, April 8, 2016

ICS-CERT Publishes Moxa Alert

This afternoon the DHS ICS-CERT published an alert for five publicly reported vulnerabilities in the Moxa NPort 6110, 5100 series, and 6000 series devices. The vulnerabilities were publicly reported [link updated 21:54 EST, 2-18-17] by Digital Bond Labs (not named in the alert) after initial coordination with the vendor failed to respond to the vulnerabilities in a timely manner.

The ICS-CERT alert lists the five vulnerabilities as:

• Unauthenticated retrievable sensitive account information;
• Unauthenticated remote firmware update;  
• Buffer overflow;
• Cross-site scripting;
• Cross-site request forgery

ICS-CERT reports that Moxa has acknowledged three of the five vulnerabilities and announces that Moxa will release a new firmware version in late-August 2016 for the NPort 5100 and 6000 series devices that will address those three vulnerabilities. The NPort 6110 is a discontinued device and no updates are planned.


The Digital Bond Labs write-up contains some very specific recommendations about mitigating the vulnerabilities.

Thursday, February 25, 2016

ICS-CERT Reports on December Ukraine Power Outage

This afternoon the DHS ICS-CERT published an incident response alert for the power outages in the Ukraine that occurred on December 23rd, 2015. ICS-CERT reports that “that power outages were caused by remote cyber intrusions at three regional electric power distribution companies”.

The Report


ICS-CERT reports that the attacks on multiple facilities occurred within 30 minutes of each other. The actual power outage was caused by attackers remotely shutting off breakers either thru “existing remote administration tools at the operating system level or remote industrial control system (ICS) client software via virtual private network (VPN) connections”. To hamper recovery efforts, the attackers:

• Used KillDisc malware to over-write HMI interfaces embedded on remote terminal units (RTU);
• Corrupted firmware on Serial-to-Ethernet communications devices at substations; and
• Scheduled disconnects of UPS devices via their remote management interfaces.

The Alert also reported the previously identified fact that BlackEnergy malware had been detected on systems of the affected utilities, but ICS-CERT noted that they “do not know whether the malware played a role in the cyber-attacks”.

The report contains a relatively lengthy section on mitigation measures for industrial control systems. In addition to the measures reported in the ICS-CERT defense-in-depth strategies publication, the report recommends:

• Implementation of information resources management best practices;
• Develop and exercise contingency plans that allow for the safe operation or shutdown of operational processes in the event that their ICS is breached;
• Use Application Whitelisting (AWL) to detect and prevent attempted execution of malware uploaded by malicious actors;
• Isolate ICS networks from any untrusted networks, especially the Internet; and
• Limit Remote Access functionality wherever possible.

The report concludes by reporting that in addition to the previously identified YARA rules for the identification of BlackEnergy infections additional indicators of compromise developed for this incident can be found in a restricted distribution (TLP Green) publication (IR-ALERT-H-16-043-01P) on the US-CERT Secure Portal.

The Response


The response on TWITTER® was fairly quick this afternoon and was generally less than positive. Most of the negatives were about the lack of detailed data and the references in the report to the lack of technical information available to investigators. A good summary of these concerns about the report deficiencies has been provided in a Sans blog post by Robert M. Lee.

A major concern seems to be that this is more of a political document than a technical report. It has been suggested that the information in this alert should have been releases weeks ago by a political appointee and that this report should have provided more technical analysis that would aid system owners in the United States in detecting, delaying and stopping this type of attack.

Commentary


While certainly overdue (the facts in this report have been publicly reported by a number of cybersecurity organization weeks ago) this report is important because it is an official statement by the US Government that a successful cyber-physical attack did take place against electrical utilities in the Ukraine. What is missing from that declaration, however, is an equally clear statement that a similar successful attack could occur in the United States.

The mitigation measures suggested by this report are important tools in preventing a malware based cyber-attack. What is missing is an admission that even if these measures (with one exception) had been in place in the affected utilities, that the attack would still have been successful. None of the security measures address the fact (not reported here) that the BlackEnergy malware that was put into place by a phishing attack allowed the attackers to gain authorized access to the control systems to execute their attacks that shut down the breakers.

The only mitigation measure mentioned that might have addressed this attack avenue is found in one sentence: “Remote access should be operator controlled, time limited, and procedurally similar to ‘lock out, tag out’.” Even this may not have been adequate since the attackers were using operator level access. A more expansive discussion of what the terms ‘operator controlled’ and ‘time limited’ actually mean may have shown how they could have been used prevent this attack.

The main point of that mitigation measure should have been that remote access should be viewed as a non-standard condition that requires formal management risk assessment and approval; the well-established ‘lock out, tag out’ process. Systems legitimately requiring remote access should have to be taken off-line, physically isolated from the controlled process and then have to be verified operational before they are placed back in-line. This would have stopped the actual attack that shutdown power distribution in the Ukraine in December.

If the ICS-CERT restricted distribution report does have more complete (and effective) indicators of compromise (IOC) than just the BlackEnergy YARA rules, it is disappointing that those indicators were not released in today’s report. Certainly, the initial distribution of IOC, should be limited to critical infrastructure facilities that are likely to be affected by a similar attack. This allows those facilities to take effective measures to search their systems for such indicators and take appropriate mitigation measures.

At some point, however, the remainder of the control system community (owners, vendors, researchers and commentators) needs to be made aware of those IOC. This would allow owners of non-critical infrastructure to take measures (as appropriate) to prevent such attacks on their systems. More importantly it would allow for a more general discussion of the associated vulnerabilities that could lead to prevention of related attacks or development of more effective or cheaper mitigation measures.

We all have to remember, however, that this is the first time that ICS-CERT was allowed to report on an actual successful control system attack resulting in a cyber-physical effect. For what appears to be obvious reasons in hind-sight, ICS-CERT effectively ignored Stuxnet. So, ICS-CERT (and the politicians that control it) are still trying to figure out what they are going to do with actual, clearly identified attack information.


If, as it appears, ICS-CERT is withholding information at this late date (two months since the attack) about details of indicators of compromise, it bodes ill for the DHS mandate to establish a cybersecurity information sharing process. Information about IOC is the main thing that the private sector wants from DHS. If they are not willing to share that information, there is no need for the private sector to share information about attacks with DHS.

Wednesday, February 10, 2016

ICS-CERT Updates Black Energy Alert Yet Again

This afternoon the DHS ICS-CERT updated their alert on Black Energy that was originally published in October and most recently updated on February 1st. As with most of the updates that have been published, today’s modifies the way that the Yara rules for detecting Black Energy are listed.

Today’s update provides a link to the latest version of the Yara tool on GitHub, a separate text file for the Black Energy signature and the Yara documentation site.

It certainly seems like ICS-CERT is going to be using the Yara tool for helping folks detect systemic attacks like Black Energy. While this looks like a very valuable tool for Windows® based systems (and a lot of ICS components are Windows based) ICS-CERT notes that there may be problems in using this tool on other ‘high-end’ ICS components and it almost certainly cannot be used on ‘the majority of field devices’.

It would be extremely helpful is ICS-CERT could do (or have someone else do) some additional research on the use of the Yara tool on some common control system components. This would allow them to provide more information than just the two sentences provided in the Alert:

“Test the use of the signature in the test/quality assurance/development ICS environment if one exists. If not, deploy the signature against backup or alternate systems in the top end of the ICS environment; this signature will not be usable on the majority of field devices.”


The use of tools like Yara will be very valuable as the ICS threat environment continues to get more complex. ICS-CERT should be a leader in developing the use of such tools and helping get them into use in the field. Lacking their leadership, we are going to have to rely on vendors to develop these types of tools for specific use on their systems, and I don’t see any beyond maybe the top three or so having the resources to do that.

Thursday, October 15, 2015

ICS-CERT Publishes Alert and Advisory

This afternoon the DHS ICS-CERT published an alert and an advisory for separate control system vulnerabilities. The alert was for a product from SD Technologies. The advisory was for a product from 3S Smart Software Solutions.

3S Smart Software Solutions Advisory

This advisory describes a NULL pointer dereference vulnerability in the CODESYS Runtime Tool Kit. The vulnerability was reported by Nicholas Miles of Tenable Network Security. 3S has produced a new version which mitigates the vulnerability, but there is no indication that Miles was provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to execute a denial of service attack.

SDG Technologies Alert

This alert describes a reported cross-site scripting vulnerability in the SDG Technologies Plug and Play SCADA that is apparently used in remote metering applications. ICS-CERT is reporting that this vulnerability has been publicly disclosed with exploit code but, has not provided the name of the researcher nor the venue where the exploit was reported.


ICS-CERT reports that it has not yet been able to contact SDG Technologies to verify the existence of the vulnerability or determine what actions SDG Technologies is taking with respect to the reported vulnerability.
 
/* Use this with templates/template-twocol.html */