Showing posts with label ICSJWG Spring Meeting. Show all posts
Showing posts with label ICSJWG Spring Meeting. Show all posts

Thursday, October 27, 2016

ICS-CERT Publishes Honeywell Advisory and ICS DDOS Warning

Today the DHS ICS-CERT published a control system security advisory for the Honeywell Process Knowledge System (PKS). They also issued a warning about the potential for distributed denial of service (DDOS) attacks on internet facing industrial control system products.

Honeywell Advisory


This advisory describes an improper input validation vulnerability in the Honeywell Experion Process Knowledge System (PKS) platform. This is apparently a self-reported vulnerability. Honeywell has produced patches to mitigate the vulnerability.

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to prevent the Experion PKS client tools from uploading firmware to Series-C devices.

ICS DDOS Warning


ICS-CERT posted a very short and very generic warning about the potential for DDOS attacks on internet facing control systems or components thereof. This is based upon the US-CERT report about recent very large DDOS attacks. There is no information provided that indicates a specific threat against ICS.

ICSJWG Spring Meeting



ICS-CERT recently published a notice concerning the date of the 2017 Spring meeting of the ICSJWG in Minneapolis, MN over April 11th thru 13th, 2017.

Thursday, January 28, 2016

ICS-CERT Publishes Advisory and ICSJWG Notice

This afternoon the DHS ICS-CERT published an advisory for Westermo switches. They also announced registration and request for papers for the Spring 2016 ISJWG meeting.

Westermo Advisory

This advisory describes a hard-coded certificate vulnerability in Westermo Ethernet switches. The vulnerability was reported by Neil Smith. ICS-CERT reports that Westermo has produced a firmware update that mitigates the vulnerability. Smith have verified the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability after conducting a successful man-in-the-middle attack to obtain authenticated access to the device.

Later in the advisory ICS-CERT reports that: “Westermo is working on an update to automate the changing of the key, which will be published on its web site as soon as it is ready.” The advisory then provides a work around for changing the hard-coded SSL certificate. There is nothing about this vulnerability on the public portion of the Westermo web site. The latest version of the WeOS on that website is 4.18.0 (released this month) which according to the advisory is an affected version. So, apparently the fix that Smith validated is the workaround.

ICSJWG Spring Meeting

I reported in an earlier blog post that the date for the Spring 2016 ICSJWG meeting had been set for May 3rd thru 5th. Today ICS-CERT announced that the registration for that meeting was now open. You can register on-line here and there is still no cost to attend the meeting. Registrations should be completed by April 28th, 2016.

ICS-CERT also published a call for abstracts for that meeting. They are looking for four types of presentations:

• Presentation;
• Panel;
• Demonstration;
• Lightning round

Thursday, January 21, 2010

ICSJWG Web Page Update 01-20-10

DHS-CERT updated the Control System Security Program web page dealing with the Industrial Control System Joint Working Group’s (ICSJWG) Spring Meeting. They have now added a link to the electronic form to be used for submitting proposal abstracts for presentations to be made at the April meeting in San Antonio, TX.
 
/* Use this with templates/template-twocol.html */