Showing posts with label InduSoft. Show all posts
Showing posts with label InduSoft. Show all posts

Thursday, April 24, 2014

ICS-CERT Publishes 4 Advisories – Only 1 HeartBleed

Today the DHS ICS-CERT published four advisories for vulnerabilities in industrial control systems. The included vulnerabilities from InduSoft, Festo, Siemens and Certec. Only one advisory deals with HeartBleed. The advisory of note shows that ICS-CERT can get upset with vendor inaction.

InduSoft Advisory

This advisory describes a path traversal vulnerability in the InduSoft Web Studio application. It was reported by John Leitch in a coordinated disclosure through the Zero Day Initiative (ZDI). This advisory was originally released on the US-CERT secure portal on April 17th. A patch is available, but there is no indication that its efficacy has been evaluated by the researcher.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to gain further access that would allow arbitrary code execution.

Festo Advisory

This advisory describes multiple vulnerabilities in the Festo PLC. The vulnerabilities were reported by Reid Wightman of IOActive in a coordinated disclosure. ICS-CERT reports that Festo has opted to not address these vulnerabilities. The vulnerabilities include:

• Improper authentication (FTP Backdoor), CVE-2014-0760;
• Improper authentication (two unauthenticated ports), CVE-2014-0769;
• Improper access controls (using outdated CoDeSys runtime module), CVE-2012-6068; and
• Directory traversal (same outdated CoDeSys module), CVE-2012-6069

ICS-CERT reports that a relatively low skilled attacker could use publicly available code to remotely exploit these vulnerabilities.

I want to commend ICS-CERT for getting angry in one of their advisories, this is a situation that certainly appears to deserve an adversarial response. I think the best statement from ICS-CERT can be found in the Overview section of the Advisory:

“This advisory is being published to alert critical infrastructure asset owners of the risk of using this equipment [emphasis added] and for them to increase compensating measures if possible.”

I read Reid’s TWEET® about this advisory earlier today and was kind of surprised at his reaction. I am not surprised now. Again, kudos to ICS-CERT for reacting to this callous disregard for customer security. It will be interesting to see if there is a change in attitude Esslingen am Neckar, FRG.

Siemens Advisory

This advisory addresses two vulnerabilities in the Siemens SIMATIC S7-1200 PLC family. This is a mix of self-reported and researcher reported vulnerabilities. The researchers from OpenSource Training are Ralf Spenneberg, Hendrik Schwartke, and Maik Brüggeman. Siemens reports that they have produced a new version that mitigates the vulnerabilities though there is no indication that the researchers have validated the efficacy of the fix. The vulnerabilities include:

• Cross site scripting, CVE-2014-2908; and
• Improper neutralization of CRLF sequences, CVE-2014-2909

ICS-CERT reports that it would take a skilled attacker with physical access gaining the assistance of an authorized user to exploit these vulnerabilities. A successful exploit could result in a DoS attack.

Certec Advisory


This advisory is the one that was foretold in yesterday’s blog post about ICS-CERT HeartBleed publications. The Certec atvise SCADA product is susceptible to the HeartBleed bug. An update that includes a newer version of the OpenSSL software has been made available.

Saturday, March 9, 2013

ICS-CERT Updates an Alert and an Advisory


Friday, ICS-CERT published two advisories, one was an update of an alert from January (Indusoft Advantech Studio) and the other was an update of an advisory published earlier this week (360 Systems Image Server).

Indusoft

This advisory outlines the response of Indusoft (ICS-CERT variously uses Indusoft and InduSoft as the name of the company; the company web site uses InduSoft, I’ll try to stay with that convention) to the uncoordinated disclosure made in January by Nin3. The vulnerability is a directory traversal in both Advantech Studio and InduSoft Studio products. Nin3 published exploit code with the disclosure.

The advisory notes that a relatively low skilled attacker could remotely exploit this vulnerability and gain access to arbitrary files. InduSoft has produced a hotfix for this vulnerability that is available from their customer support (support@indusoft.com).

The advisory notes that “InduSoft products are often integrated as third-party components in other vendors’ products”. I would suspect that InduSoft has notified the vendors that use InduSoft studio as a component in their control system products of the vulnerability and the availability of a hotfix. There is nothing however that says that those vendors have to notify their customers of the vulnerability. And there is nothing that guarantees that the InduSoft hotfix would work properly in those products.

I would like to think that ICS-CERT received a list of those vendors from InduSoft and has contacted them. This would put them under the 45-day ICS-CERT disclosure policy where ICS-CERT would publish an advisory on their product whether or not the vulnerability had been fixed. I don’t think this will happen, that would be just a tad bit too proactive for a government agency.

360 Systems

Earlier this week ICS-CERT published an advisory for the 360 Systems Image Server. I pointed out a discrepancy in the use of ‘default’ password in the vulnerability overview in that advisory. This update corrects that to ‘hardcoded’ password.

Sunday, October 2, 2011

ICS-CERT Issues Three SCADA Advisories

On Friday afternoon the DHS Industrial Control System Cyber Emergency Response Team published three advisories on their web site. One was a follow-up to one of the earlier Luigi alerts while the other two were about new vulnerabilities in systems reported by security researchers in ‘properly’ coordinated disclosures. The three advisories deal with the following systems:

• Rockwell RSLogix
• InduSoft ISSymbol
• ICONICS GENESIS32

Rockwell RSLogix


This Advisory updates an earlier alert issued for the vulnerabilities reported by Luigi. Rockwell has developed patches for these denial of service vulnerabilities in two versions their Factory Talk Services Platform (CPR9 SR3 and SR4). Patches are under development for earlier versions of Factory Talk and for RSLogix. ICS-CERT will update this Advisory when those patches become available. [CVE-2011-3489; Base Score 5.0]

InduSoft ISSymbol


Dmitriy Pletnev of Secunia Research reported ActiveX control buffer overflow vulnerabilities in the InduSoft ISSymbol product and developed proof-of-concept exploit code for those vulnerabilities. The vulnerabilities allow a low skilled attacker to conduct DOS attacks while a more skilled attacker could execute arbitrary code. InduSoft has published an upgrade for the affected systems as well as a new service pack. [CVE-2011-0342; Base Score 10.0]

ICONICS GENESIS32


Independent researchers Billy Rios and Terry McCorkle have identified eight separate memory corruption vulnerabilities in components of the GENESIS32 HMI/SCADA product. A low skill level attacker could cause a system crash while a more skilled attacker could execute arbitrary code. This vulnerability would require a social engineering attack causing a user to open specially crafted files. ICONICS has produced patches to mitigate these vulnerabilities.

Saturday, June 25, 2011

ICS-CERT Publishes 2 and Updates 1 SCADA Advisories

On Friday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published two new control system advisories and updated a current advisory. The update concerns the InduSoft buffer overflow advisory issued last week. The two new advisories affect the AzeoTech DAQFactory and Rockwell’s FactoryTalk systems.

InduSoft ISSymbol

The updated advisory mainly provides gramitical corrections to the advisory with little real added value. The only minor exception to that are the two nearly identical corrections in the exploit areas of the advisory. The revision notes that an exploiter would need to craft a web page for the user to access while the ActiveX component was installed on their target system. Most technically savvy readers would have read that between the lines of the original advisory.

AzeoTech DAQFactory

The advisory notes that:

“The DAQFactory networking feature allows multiple machines running DAQFactory to interact with each other. This interaction includes sending a signal from one device to initiate a reboot or shut down of another device. Because these signals are not encrypted or otherwise protected, a successful attacker could trigger a DAQFactory system reboot or shutdown.”
In a system that is remotely accessible, this could allow an attacker with basic skills to craft an exploit that could cause system elements to shutdown or re-boot.

An upgrade is available that mitigates the vulnerability. For older systems, disabling the networking feature (if not needed) will also solve the problem as will isolating networked systems.

Rockwell Automation FactoryTalk

The Rockwell Automation advisory deals with a memory corruption vulnerability in the FactoryTalk Diagnostics Viewer that could result in a moderately skilled attacker being able to execute arbitrary code on the system. An exploit of this vulnerability would require a social engineering attack to get a user to run a corrupted configuration file.

Upgrading to a newer version of the Diagnostics Viewer should successfully mitigate this vulnerability, but Rockwell Automation notes that this is not available as a stand alone upgrade. It requires an upgrade of the entire FactoryTalk Services Platform. Even then Rockwell recommends that “customers review the Rockwell Automation Software Product Compatibility Matrix to ensure they understand the dependencies and compatibilities that may arise as a result of upgrading this product.”

Interesting Coincidence

It is interesting that earlier this week Dale Peterson at DigitalBond complained that most of the recent ICS vulnerabilities were on systems that were little used in the United States. He explained that the relatively large number of these off-shore (my term not his) vulnerabilities distorted the ICS security picture. This distortion might make it appear that the more common ICS packages used here were much less vulnerable.

Both of the new advisories published Friday affect systems that are relatively common in the United States. I’m not sure if they affect much in the way of ‘critical infrastructure’ or chemical manufacturing facilities, but they do remind the community that ICS systems here in this country are vulnerable.

Saturday, June 18, 2011

ICS-CERT Publishes Another Buffer Overflow Advisory

Yesterday, the DHS Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) another advisory on a SCADA related systems with a buffer overflow vulnerability. This time it concerns three InduSoft applications to develop HMI, SCADA systems and embedded instrumentation solution and one or more of the applications may be bundled as third-party applications in SCADA systems.

Heap-based and stack-based vulnerabilities were identified that would provide a moderately skilled an opportunity to perform arbitrary code execution which could impact the SCADA production environment. A patch is available to fix this vulnerability.

These applications are not typically bought by control system users, but they may be bundled within a control system bought from some other vendor. Once again this points out the importance of a SCADA user knowing what components of other vendors are bundled within their system. In a perfect world the system vendor would automatically include a list of such bundled software in their system documentation provided to the buyer. In the real world the cyber security manager will likely have to request this information from the system vendor.
 
/* Use this with templates/template-twocol.html */