Showing posts with label Innominate. Show all posts
Showing posts with label Innominate. Show all posts

Thursday, August 27, 2015

ICS-CERT Updates 2 Siemens Advisories and Publishes 3 New Advisories

Today the DHS ICS-CERT updated two advisories for Siemens products from earlier this year and then published three new advisories for products from Siemens, Innominate mGuard and Moxa.

SIMATIC HMI Update

This update is for an advisory originally published in April and updated in April and July. This adds additional clarification as to the versions of the previously listed products are affected. Similarly the update provisions have been updated. It also added update instructions for TIA V12 SP1 devices and WinCC V7.2.

SIMATIC STEP 7 TIA Portal Update

This update is for an advisory originally published in February. This adds additional clarification as to the versions of the previously listed products are affected. An update has been added for SIMATIC STEP 7 (TIA Portal) V12 SP1.

Innominate mGuard Advisory

This advisory describes a denial-of-service (DoS) vulnerability in the Innominate mGuard device. This vulnerability has bee self-reported. Innominate has produced a firmware patch to mitigate this vulnerability.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to cause a temporary DoS condition in the VPN daemon on the device. Innominate reports that a successful authentication via X.509 certificate or PreShared Secret Key is required to exploit the vulnerability.

Siemens SIMATIC S7-1200 Advisory

This advisory describes a cross-site request forgery vulnerability on the Siemens SIMATIC S7-1200. This vulnerability was reported by Ralf Spenneberg, Hendrik Schwartke, and Maik Brüggemann from OpenSource Training. Siemens has produced a firmware update to mitigate the vulnerability. There is no indication that the researchers have been afforded the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to perform actions at the level of the victim user.

Siemens reports that there are different firmware updates for Standard CPUs and Fail-safe CPUs.

Moxa Softcms Advisory

This advisory describes two different types of buffer overflow vulnerabilities in the Moxa Softcms software package. The vulnerabilities were reported by Carsten Eiram of Risk Based Security and Fritz Sands. The HP Zero Day Initiative coordinated the disclosures on these vulnerabilities. Moxa has released a new version of the software to mitigate these 9 separate vulnerabilities. There is no indication that the researchers have been given the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a moderately skilled attacker could remotely exploit these vulnerabilities to allow remote code execution.


BTW – ICS-CERT has included a formal note on their landing page that they have updated their PGP public key and they have corrected the bad link that I identified in my blog post Tuesday.

Thursday, December 18, 2014

ICS-CERT Publishes 2 Advisories and 2 Updates

Today the DHS ICS-CERT published advisories for vulnerabilities in Honeywell’s Experion Process Knowledge System and Innominate mGuard and updated previously issued advisories for Siemens and Emerson control systems.

Emmerson Update

This update clarifies information that was published in an update two weeks ago. The earlier update added a new vulnerability to the advisory and the wording implied that the previously issued update mitigated that vulnerability as well. There was an interesting twitversation about this wording and it appears that someone may have been listening (a good thing).

ICS-CERT now clarifies that the patch mitigates all but the recently added authentication bypass vulnerability. That vulnerability is what requires the use of the third-party secure router for mitigation. There is also some interesting changes in the wording about the use of that router. Originally ICS-CERT reported that:

“Emerson asserts that by adding the EDR810 between the host and the field device it is virtually impossible for an attacker to eavesdrop on communications or falsify commands.”

The new wording is a bit less bombastic and limited in the claims:

“At this time, Emerson recommends that concerned asset owners install the EDR 810 between the host and the field device to mitigate this vulnerability.”

I suspect that someone’s lawyer got involved.

Siemens Update

This is the update that I described on Tuesday.

Innominate Advisory

This advisory describes a self-reported privilege escalation vulnerability in the Innominate mGuard devices. They have produced a firmware patch that reportedly mitigates the vulnerability.

ICS-CERT reports that a moderately skilled attacker who has admin privileges on the system could remotely exploit this vulnerability to increase those to root privileges to execute arbitrary commands. Innominate reports that in most installations the personnel with admin and root privileges are the same so that this vulnerability would have no effect in those cases.

BTW: Innominate also reported that there is a denial of service vulnerability found in a slightly different set of mGuard devices because of the way they use OpenVPN connection to
tunnel IPSec packets. I wonder why ICS-CERT didn’t publish an advisory for this vulnerability since it was also published yesterday by Innominate.

Honeywell Advisory

This advisory describes five vulnerabilities in the Honeywell  Experion Process Knowledge System (EPKS) application. The vulnerabilities were reported by  Alexander Tlyapov, Gleb Gritsai, Kirill Nesterov, Artem Chaykin and Ilya Karpov of the Positive Technologies Research Team and Security Lab. ICS-CERT reports that Honeywell have developed patch updates for the affected products, but does not say that the researchers have validated the efficacy of the patches.

The five vulnerabilities include:

• Heap-based buffer overflow - CVE-2014-9187;
• Stack-based buffer overflow - CVE-2014-9189;
• Arbitrary memory write - CVE-2014-5435;
• Directory transversal - CVE-2014-5436; and
• File inclusion - CVE-2014-9186


ICS-CERT reports that a moderately skilled attacker could remotely exploit these vulnerabilities to effect remote code execution or potential information disclosure. I can find no information on the public Honeywell web site about these vulnerabilities.

Tuesday, July 29, 2014

ICS-CERT Publishes Advisory for Innominate Security Routers

This morning the DHS ICS-CERT published an advisory for an information disclosure vulnerability in the Innominate mGuard security routers. The advisory had been previously published on the US-CERT secure portal on July 8th. The vulnerability was originally reported by Applied Risk Research in a coordinated disclosure. Innominate has produced a new firmware version and a firmware patch to mitigate the vulnerability. Applied Risk Research has confirmed that the mitigation is effective.

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to gather information about network topology, traffic flows, and other connected systems.


Applied Risk Research reports that the vulnerability probably applies to the Phoenix Contact FL mGuard and Hirschman Eagle mGuard product lines since they share the same firmware codebase. This is not mentioned in the Innominate security bulletin

Thursday, April 17, 2014

ICS-CERT Publishes Siemens Advisory and Updates 3 HeartBleeds

Today the DHS ICS-CERT published a new control system advisory for a Siemens product and provided updates on three separate HeartBleed related documents.

Siemens

The new Siemens advisory identifies three vulnerabilities in their SINEMA server. Siemens self-reported the vulnerabilities and has published a software update to mitigate the problems. The identified vulnerabilities include:

• Code injection, CVE-2014-2731 (incorrectly listed as CVE-2014-7231);
• Relative path traversal, CVE-2014-2732; and
• Improper input validation, CVE-2014-2733

According to ICS-CERT a relatively unskilled attacker could remotely exploit these vulnerabilities to execute arbitrary code, traverse through the file system, or cause a DoS.

HeartBleed Updates

ICS-CERT updated their HeartBleed Situational Awareness Alert by adding a list of ICS related products that have been identified as being specifically affected by the OpenSSL vulnerability. Only two vendors currently have products on the list, Innonminate and Siemens.

The Innominate HeartBleed Advisory was also updated. The Phoenix Contact branded versions of the Innominate devices is not affected by the HeartBleed vulnerability, but Innominate has upgraded them to the latest version to alleviate customer concerns. Only the 8.0.0 and 8.0.1 versions of the mGuard firmware are affected by the vulnerability


ICS-CERT has also provided a link to the latest FBI list of Snort Signatures that may be used to detect attempted exploitation of the HeartBleed vulnerability.

Tuesday, April 15, 2014

ICS-CERT Publishes Three Advisories – Two from HeartBleed

Today the DHS ICS-CERT published three advisories for vulnerabilities in industrial control systems applications from Siemens, Progea Movicon, and Innominate. Two of those (the first and last) are related to HeartBleed.

Siemens Advisory

This advisory provides a list of Siemens products that contain or are affected by the HeartBleed vulnerability. They currently only provide one updated to mitigate the vulnerability but do note that they are working on the other product updates. The unusual move to self-identify vulnerable systems before mitigation measures are available was almost certainly undertaken because tools to test for the HeartBleed vulnerability and exploit code for the bug both exist in the wild.

Siemens reports that the following products are affected:

● eLAN-8.2 eLAN < 8.3.3 (affected when RIP is used - update available)
● WinCC OA only V3.12 (always affected)
● S7-1500 V1.5 (affected when HTTPS active)
● CP1543-1 V1.1 (affected when FTPS active)
● APE 2.0 (affected when SSL/TLS component is used in customer implementation)
Siemens has an update available for eLAN (v 8.3.3) and recommends the following interim mitigation measures for the other products until the appropriate update is published:

● WinCC OA V3.12:
o Use VPN for protecting SSL traffic
o Use WinCC OA in a trusted network
●  S7-1500 V1.5:
o Disable the web server, or
o Limit web server access to trusted networks only
o Remove the certificate from the browser
● CP1543-1 V1.1:
o Disable FTPS, or
o Use FTPS in trusted network, or
o Use the VPN functionality to tunnel FTPS
● APE 2.0:
o Update OpenSSL to 1.0.1g before distributing a solution. Follow instructions from Ruggedcom [3] to patch APE 2.0
The VPN recommendations should have come with a caveat that the VPN should have its HeartBleed status investigated before it is used to protect a control system remote access.

Progea Advisory

This advisory is for an information disclosure vulnerability reported by Celil Ünüver of SignalSEC Ltd in a coordinated disclosure. Progea has developed an update that ICS-CERT reports has been checked and validated by Celil.

ICS-CERT reports that a moderately skilled attacker could remotely execute an attack using this vulnerability to gain access of OS version information.

Innominate Advisory

This advisory notes that Bob Radvanovsky of Infracritical notified ICS-CERT that Innominate has updated their mGuard product firmware to deal with the HeartBleed vulnerability included in versions of those devices. The advisory points at the Innominate advisory published last Friday. Bob also reported this last Friday on the SCADASec List.

HeartBleed Reporting

It will be interesting to see how many of these HeartBleed advisories get published by ICS-CERT. Most of these will end up being self-reported (even the Innominate advisory was essentially self-reported). I also doubt that there will be much more information in any of the upcoming advisories than we have seen in these two today.


It may be easier for ICS-CERT to just set up a HeartBleed page and updated it when necessary by listing the vendors that have published firmware or software updates that mitigate the vulnerability. I think it would be easier and more informative.
 
/* Use this with templates/template-twocol.html */