Showing posts with label Indegy. Show all posts
Showing posts with label Indegy. Show all posts

Tuesday, November 1, 2016

ICS-CERT Publishes 3 Advisories and Malware Trends Paper

Today the DHS ICS-CERT published three new control system security advisories and an in-house paper on malware trends. The three new advisories are for control system products from Schneider and IBHsoftec. One of the Schneider advisories addresses a vulnerability I discussed on Saturday. Neither of the Schneider advisories listed here are the ones referenced in a TWEET® from Critifence that I retweeted this morning.

Schneider Unity Pro Advisory


This advisory describes an insufficient control flow management vulnerability in the Schneider Electric Unity PRO Software product. The vulnerability was reported by Avihay Kain and Mille Gandelsman of Indegy. Schneider produced a new version of the software that mitigates the vulnerability. There is no indication that the Indegy researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that while this vulnerability could be exploited remotely, since a two-stage social engineering attack would be required to exploit the vulnerability, developing a working exploit would be difficult. The Schneider Security Notification implies that direct loading of the corrupted file by the attacker could be possible “when the application program loaded in the simulator is not password protected”.

IHBsoftec Advisory


This advisory describes a buffer overflow vulnerability in the IBHsoftec S7-SoftPLC. The vulnerability was reported by Ariele Caltabiano (kimiya) through ZDI. IHBsoftec has produced a new version to mitigate the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that relatively unskilled attacker could remotely exploit the vulnerability to “be able to affect integrity, confidentiality, and availability of the target device”.

Schneider ConneXium Advisory


This advisory describes a buffer overflow vulnerability in the Schneider Electric ConneXium firewall product. The vulnerability was reported by Nir Giller. According to ICS-CERT,Schneider is developing a firmware update, but the Schneider Security Notification (not listed in the ICS-CERT advisory) indicates that an update is currently available through “your local Schneider Electric representative”.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to execute code during the SNMP (Simple Network Management Protocol) login authentication process.

The Schneider document also provides workaround information for the vulnerability.

Malware Trends


This white paper was produced by the ICS-CERT Advanced Analytic Laboratory (AAL). It is a 24-page review of the current state of malware. Once again ICS-CERT has produced a nice review document suitable for updating non-technical management on cybersecurity issues. It covers the following topics:

• Attacker tactic changes;
• Malware evolution;
• Persistence methods;
• Infection vectors;
• Defensive tactics; and
• Platform challenges

Unfortunately, like most recent ICS-CERT technical documents, it is very light on data specific to the control system (ICS) security community. It is not until page 17 where we see the first specific ICS discussion in a subsection of the platform challenges discussion. Even that discussion is very brief and very light on the details. For example, half of the discussion about Black Energy consists of the following paragraph:

“BlackEnergy is an interesting case of malware that has undergone a dramatic change in its design and target depending on the groups that use it. Initially, BlackEnergy was a DDoS bot primarily used by the Russian hacker underground to take down sites. Support for plugins was added in the next major revision (BlackEnergy2), changing the exclusively DDoS box into a powerful multi-tool. Years later, researchers discovered that threat actors utilized zero-day exploits and spear phishing, combined with BlackEnergy 2 and specially-tailored plugins, to target and compromise ICS networks.”


This is a good overview document that I would have been proud to have authored. The technical skills and experience of the AAL deserve a much better showcase.

Saturday, October 29, 2016

Public ICS Vulnerability Disclosures – 10-29-16

This week saw a public disclosure of a control system security vulnerability at the 2016 Industrial Control Systems (ICS) Cyber Security Conference (the old Joe Weiss conference under new management). Indegy CTO Mille Gandelsman presented a talk, “Ghost in the Machine: SCADA Vulnerability Enables Remote Control of ICS Networks”, about a vulnerability in the Schneider UnityPro software platform. This was a coordinated disclosure with Schneider publishing a Security Notification concerning the vulnerability.

Reading the Indegy blog post about this vulnerability and then looking at the Schneider notification, it almost looks like the two organizations are looking at two separate vulnerabilities. Indegy describes the vulnerability consequences this way:

“The vulnerability in Unity Pro allows any user to remotely execute code directly on any computer on which this product is installed, in debug privileges. The vulnerable software tool is present in every control network in the world that uses Schneider-Electric controllers. Regardless of the SCADA/DCS applications in use, if Schneider Electric controllers are deployed, this software will be used on the engineering workstations. This makes this attack relevant across virtually any process controlled by these PLCs. Since Schneider Electric is one of the largest industrial control equipment providers, this vulnerability is a major concern.”

Schneider simply notes: “This vulnerability is made possible when no application program has been loaded in the simulator or when the application program loaded in the simulator is not password protected.”

Schneider has produced a new version of the software that mitigates the vulnerability. They still note that: “It is up to user responsibility to protect his application by a proper password.”


Schneider published their notification on October 14th and the Indegy presentation was made on October 25th. ICS-CERT has not yet reported on this vulnerability, though it has been widely reported in the press (see for example here and here).
 
/* Use this with templates/template-twocol.html */