Showing posts with label Industrial Control Systems. Show all posts
Showing posts with label Industrial Control Systems. Show all posts

Tuesday, December 1, 2015

ICS-CERT Publishes Three Advisories

This afternoon the DHS ICS-CERT published three advisories for industrial control system vulnerabilities in systems from Siemens, Schneider and Saia Burgess Controls. ICS-CERT also announced an alternative method for notification of the release of advisories, alerts, and other publications.

Siemens Advisory

This advisory describes an authentication bypass vulnerability in a number of Siemens SIMATIC Communications Processor devices. The vulnerability was reported by Lei ChengLin (Z-0ne) from the Fengtai Technologies’ Security Research Team. Siemens has produced a firmware update for one of the devices (SIMATIC CP 343-1) and the other updates are in the works. There is no indication that Lei has been provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to perform administrative operations on the Communication Processor. Network access to Port 102/TCP is required and the Communication Processor’s configuration must be stored on its corresponding CPUs for the vulnerability to be exploited. Siemens notes that firewall functionality of Advanced-CPs must be turned off for port 102/TCP for the vulnerability to be exploited.

NOTE: This vulnerability was announced by Siemens on TWITTER last Friday.
                                       
Schneider Advisory

This advisory describes eleven ActiveX code injection vulnerabilities (listed under a single CVE) in the Schneider ProClima F1 Bookview ActiveX control application. The vulnerabilities were reported through the Zero Day Initiative by Ariele Caltabiano and Fritz Sands ( Sands was mentioned in the Schneider advisory but not the ICS-CERT Advisory). Schneider has produced an update to mitigate these vulnerabilities but there is no indication that Caltabiano was provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to modify arbitrary memory and lead to remote code execution.

Schneider reports that the vulnerabilities reside in the thermal calculation software.

Saia Burgess Controls Advisory

This advisory describes a hard-coded password vulnerability in the Saia Burgess Controls family of PCD controllers. The vulnerability was reported by Artyom Kurbatov. Saia has produced a new firmware version that mitigates the vulnerability and Kurbatov has validated the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to gain administrative access to the target device and resources.

Saia cautions that the upgraded firmware will still not protect the PCD controllers if they are connected directly to the Internet. Their Security Rules document provides recommended details for protecting the security of these controllers.

GovDelivery

You can now get ICS-CERT publications sent directly to your email via GovDelivery. Simply register for the service, click on which publications you want and wait for the emails. Publications from National Cyber Awareness System Mailing Lists and the Critical Infrastructure Cyber Community Voluntary Program (C3VP) are also available from this system.


DHS has tried these email notification systems for a number of their web sites. I’ve signed up for a bunch of them and the notifications seem to dry up after a while. Maybe this one will be different. Go ahead, give it a try; I did. We all take perverse pride in our inflated inboxes.

Friday, February 7, 2014

NRC to Look at PLCs

Today the Nuclear Regulatory Commission (NRC) published a notice in the Federal Register (79 FR 7406) acknowledging that it had received a petition for rulemaking under 10 CFR 2.802(c) {NOTE: The notice mistakenly lists 10 USC 2.802(c)} that requests that the NRC “NRC require ‘new-design programmable logic computers’ to be installed in the control systems of nuclear power plants to block malware attacks on their industrial control systems of those facilities”.


The notice explains that since the petition was received in proper form that the NRC will officially consider it. The NRC is not requesting public comments on the petition or the topic at this time. A docket has been established on the Federal eRulemaking Portal (www.Regulations.gov; Docket # NRC-2013-0214) that will be used to make information about this petition available.

Sunday, June 20, 2010

S 3480 – Cyber Security

Last week I took a brief look at some concerns being expressed about the new comprehensive cyber security bill coming out the offices of Sen. Lieberman (I, CT) and Sen. Collins (R, ME). At that time I hadn’t had a chance to review the text of the bill. Now that I have had a chance to do so it doesn’t seem that this bill will have serious affects on industrial control systems (ICS), but owners of conventional IT systems at chemical facilities that are considered to be critical infrastructure may be affected. ICS I have to waffle a little bit on the potential affects on ICS. I cannot find anywhere in the bill where the terms ‘industrial control system’ or ‘SCADA’ are mentioned. These are two of the most commonly used descriptors of the computer systems used to control chemical processes. In fact the word ‘industrial’ only shows up once in the legislation and that in regards to industrial espionage {§406(a)(2)(E)}. I don’t think that it is unreasonable to assume that ICS are not covered under the introduced bill. Having said that, there may be a loophole that regulators could use to attempt to regulate ICS in ‘critical industries’. In defining ‘cyberspace’ the legislators expansively state that it includes “the Internet, telecommunications networks, computer systems, and embedded processors and controllers [emphasis added] in critical industries” {§3(2)}. Since this statement is modifying ‘the interdependent network of information infrastructure’, I think that any such ICS regulations would certainly end up in lengthy court battles. Information Systems The major focus of this legislation is the protection of information systems of the Federal Government, but it does potentially apply many of the same controls to privately owned information networks. Covered critical infrastructure is defined as a system “that is on the prioritized critical infrastructure list established by the [DHS] Secretary under section 210E(a)(2)” {§241(4)(A) in §201}. Section 503 provides guidance to the Secretary about the maintenance of the ‘critical infrastructure list’. The catch all phrase “any other security related factor determined appropriate by the Secretary” could certainly be used to include high-risk chemical facilities on this list. I’ll leave the analysis of what specific affects that this bill could have on the managers of IT systems in these high-risk chemical facilities to those with more experience in IT systems; I have only been a user of such systems. Mark-up As I mentioned in a posting on Friday, this bill is currently scheduled to be marked-up in the Senate Homeland Security and Governmental Operations Committee on Thursday. There is no telling what changes will be made at that hearing. In fact, given the way that Senate committees conduct such hearings, we will have little idea of what changes have been made to the legislation until the final committee report is filed. I am certainly not going to predict when that will occur; we are still waiting on the report from this Committee on S 1649, the WMD bill that Sen. Lieberman and Collins pushed last year and upon which mark-ups were finished back in November. If and when a report on this bill is published, I will again look to see if there have been any provisions made that would specifically address ICS at high-risk chemical facilities.
 
/* Use this with templates/template-twocol.html */