Showing posts with label ICS-CERT Medical Advisory. Show all posts
Showing posts with label ICS-CERT Medical Advisory. Show all posts

Tuesday, May 23, 2017

ICS-CERT Publishes 3 Advisories

Today the DHS ICS-CERT published two industrial control system advisories for products from Rockwell and Moxa. They also published a medical control system advisory for products from B Braun Medical. The Rockwell advisory was previously published on the NCCIC Portal on April 25th, 2017. The Braun Medical advisory was previously published on the NCCIC Portal on March 23rd, 2017l

B Braun Medical Advisory


This advisory describes an open redirect vulnerability on the B Braun Medical SpaceCom module. The vulnerability was reported by Marc Ruef and Rocco Gagliardi of scip AG. Braun has produced a software update that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to  allow URL redirection to untrusted web sites.

Rockwell Advisory


This advisory describes multiple vulnerabilities in the Allen-Bradley MicroLogix 1100 and 1400 PLCs. The three of the vulnerabilities were reported by David Formby and Raheem Beyah of Georgia Tech and Fortiphyd Logic, Inc with the last one being reported by Ilya Karpov of Positive Technologies. Rockwell has provided a firmware update for one of the affected products and recommends disabling the web server as an alternative and/or additional mitigation measure. There is no indication that the researchers have been provide an opportunity to verify the efficacy of the fix.

The reported vulnerabilities are:

• Predictable value range from previous values - CVE-2017-7901;
• Reusing a nonce, key pair in encryption - CVE-2017-7902;
• Information exposure - CVE-2017-7899;
• Improper restriction of excessive authentication attempts- CVE-2017-7898; and
• Weak password requirements - CVE-2017-7903

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerabilities  to gain unauthorized access to the affected programmable logic controllers and to spoof or disrupt TCP connections.

Moxa Advisory


This advisory describes three vulnerabilities in the Moxa OnCell IP gateways. The vulnerabilities were reported by Maxim Rupp. Moxa reports that the latest version of two of the products mitigate the vulnerabilities and provides a work around for the remainder. There is no indication that Rupp was provided an opportunity to verify the efficacy of the fix.

The reported vulnerabilities are:

• Improper restriction of excessive authentication attempts - CVE-2017-7915;
• Plain text storage of a password - CVE-2017-7913; and
• Cross-site request forgery - CVE-2017-7917


ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to allow an attacker to use brute force to determine parameters needed to access the application. An attacker may also obtain credentials by obtaining files that store passwords in clear text.

Wednesday, October 5, 2016

ICS-CERT Publishes Medical Device Advisory

This morning the DHS ICS-CERT published a medical control system advisory for multiple vulnerabilities in the Animas OneTouch Ping insulin pump system. The vulnerabilities were reported by Jay Radcliff of Rapid7 (Note: ICS-CERT does not credit Jay, just Rapid7). Animas (a subsidiary of Johnson and Johnson) has published compensating controls, but will not (apparently) be releasing a patch or new version to mitigate the vulnerabilities. Animas is directly notifying patients and health care professionals about the vulnerabilities and compensating controls.

The vulnerabilities reported are:

• Cleartext transmission of sensitive information - CVE-2016-5084;
• Use of insufficiently random values - CVE-2016-5085; and
• Authentication bypass by capture-replay - CVE-2016-5086

While ICS-CERT reports that detailed “vulnerability information is publicly available that could be used to develop an exploit that targets these vulnerabilities”, they claim that it would take a skilled attacker to remotely exploit the vulnerabilities. This may because an RF transceiver and relatively close access (normally 10 meters) would be required to exploit these vulnerabilities.

Rapid7 published their report on these vulnerabilities on their web site on September 28th. The Animas patient letter was dated yesterday.

Commentary


I noted in a TWEET® this morning: “Inefficient but effective workarounds, how about an update to correct the problem? Or would that require complete redesign?” ICS-CERT briefly addresses this efficiency issue by noting that the “compensating controls may impact device functionality”. Radcliffe reminds us in the Rapid7 report that:

“First, know that we take risks every day. We leave the house. We drive a car. We eat a muffin. We guess the amount of carbs. All entail risk. This research uncovers a previously unknown risk. This is similar to saying that there is risk of an asteroid hitting you, a car accident occurring or miscalculating the amount of insulin for that muffin you ate. Some of those risks are low (asteroid) some are high (insulin). This knowledge of risk allows individuals to make personal decisions. Most people are at limited risk of any of the issues related to this research. These are sophisticated attacks that require being physically close to a pump. Some people will choose to see this as significant, and for that they can turn off the rf/remote features of the pump and eliminate that risk.”


Individuals can assess their personal risk that someone would conduct an attack on their person using these vulnerabilities to personally harm them by inducing hypoglycemia through an insulin overdose; most people would rate this risk of a personal attack as very low. What would be harder for an individual to assess is the risk of someone using this set of vulnerabilities to conduct an attack on Animas or Johnson and Johnson. Even a small number of publicized attacks on individual OneTouch Ping system owners could have a very serious financial impact on Johnson and Johnson in both liability costs and negative publicity costs. Individual device owners would probably have a difficult time assessing that risk to the operation of their insulin pumps. What is sad is that I suspect that Johnson and Johnson have not really evaluated the possibility of that sort of a corporate attack since their advisory letter sounds as if it had been written by the sales department, not the legal department.

Thursday, July 14, 2016

ICS-CERT Updates Two Advisories and Three New Advisories

Today the DHS ICS-CERT published updates for control system advisories from Honeywell and Siemens. They also published two new control system advisories and a medical control system advisory.


Honeywell Update


This update explains that additional Honeywell processes in the same applications are affected by the same vulnerability and mentions the researchers that reported the vulnerability in those processes. It also provides version numbers for the affected applications. The update also identifies the .DLL file that contains the source of the vulnerability and reports that a replacement .DLL file has been made available for all affected devices.

The original vulnerability was reported in April. This update was actually published on July 12th, but there was no public announcement of the advisory until it was announced today on TWITTER®.

Siemens Update

This update provides version information for the latest device to have an update available to resolve the vulnerability. A link has also been made available for that device. Only one device remains without an update.

The original vulnerability was reported in April and updated once in June. As with the June update, there has been no public announcement of this update. Fortunately, Siemens CERT published a TWEET when they updated their advisory earlier this week.

Philips Medical Advisory


This advisory describes a large number of vulnerabilities in the Philips Xper-IM Connect system. The vulnerabilities were reported by Mike Ahmadi of Synopsys and Billy Rios of Whitescope LLC. A new software version is available and ICS-CERT reports that an independent third-party organization has verified the efficacy of the fixes.

ICS-CERT reports that the vulnerabilities were identified on a system running on Windows XP, Version 1.3.0.065. They identified 272 vulnerabilities associated with the Philips software and an additional 188 vulnerabilities from the unsupported Windows system.

ICS-CERT reported that a relatively low skilled attacker could remotely exploit these vulnerabilities with publicly available exploits to compromise the Xper-IM Connect system.

ICS-CERT has added a new recommendation to their standard list of recommendations to protect medical control systems (and it would apply to all control systems):

“Ensure that nonproduct-related software packages, such as email and web browser software, are not installed on medical devices, as they could contain vulnerabilities, malware, and broaden the attack surface, which could impact the intended function of the device.”

Schneider SoMachine Advisory


This advisory describes an ActiveX control vulnerability in the Schneider SoMachine software. The vulnerability was reported by Andrea Micalizzi via ZDI. Schneider has provided an update to mitigate the vulnerability. There is no indication that Micalizzi was provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to remotely execute arbitrary code.

The Schneider security notification was originally published on June 10th, 2016.

Moxa Advisory


This advisory describes an authentication bypass vulnerability in the Moxa MGate products. The vulnerability was reported by Maxim Rupp. Moxa has produced a new software version that mitigates the vulnerability. There is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that relatively unskilled attacker could remotely exploit the vulnerability to log in as a valid user.

Schneider Pelco Advisory


This advisory describes a hard-coded credential vulnerability in the Schneider Pelco Digital Sentry Video Management System. The vulnerability was self-identified by Schneider.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to gain access to confidential information or execute code on the affected system.


The Schneider security notification was originally published on June 1st, 2016. 
 
/* Use this with templates/template-twocol.html */