Showing posts with label IntegraXor. Show all posts
Showing posts with label IntegraXor. Show all posts

Wednesday, January 8, 2014

ICS-CERT Publishes Ecava Advisory

This afternoon the DHS ICS-CERT issued an advisory for an unauthorized file access vulnerability in the Ecava Sdn Bhd IntegraXor application. The vulnerability was reported by an independent researcher “Alphazorx aka technically.screwed” (you gotta love these handles) as a coordinated disclosure through ZDI. Ecava has produced an update to resolve the issue but it has not been validated by the researcher (more on that later).

ICS-CERT reports that the vulnerability can be remotely exploited by a relatively low skilled attacker. Successful exploitation could result in the attack gaining access to project directory files for the SCADA system.

Normally we do not see any information why a patch or update efficacy has not been validated by the discovering researcher. In this case Ecava has provided a brief explanation with their report on this vulnerability. They were notified by ICS-CERT about the vulnerability on November 7th and had a published fix ready on November 11th. Apparently they waited until December 20th for an acknowledgement of the efficacy of their fix (after being advised to proceed without it by DHS on December 5th) then the publicly announced the vulnerability.

There is no word why ICS-CERT waited almost 20 days to publish this advisory. I would like to think that it was to allow the system owners who were (presumably) contacted on the 20th to get the fix installed. If that was the reason it would have been smart for ICS-CERT to make a comment to that effect in the advisory. It would have made them look more responsive. That probably wasn’t the reason though as ZDI published their advisory (ZDI-13-277) on December 15th so the vulnerability was in the public domain for almost a month before ICS-CERT published this advisory.


NOTE: I really should add ZDI and OVDB web sites to my daily crawl. In researching this post I noted that there are two ZDI reported vulnerabilities (ZDI-13-268 and ZDI-13-270) in the ABB MicroSCADA application that have not yet been reported by ICS-CERT; both reported in November by ZDI. Both have fixes in place.

Saturday, March 24, 2012

Ecava IntegraXor ICS-CERT Advisory Published

Yesterday the DHS ICS-CERT folks published an advisory for a Path Transversal vulnerability in the IntegraXor application from Ecava. The vulnerability was reported by Billy Rios in a coordinated disclosure and he has validated the subsequent patch from Ecava.

This vulnerability would allow a moderately skilled attacker to manipulate files on the system or execute arbitrary code. A social engineering attack would be a necessary component of any such remote attack as it would require the opening of a specially crafted HTML file on the server to be successful.

It is interesting to note that the Advisory reports that:

“This vulnerability is only exploitable while using Internet Explorer due to the proprietary Active X component. No other web browsers are affected by this vulnerability[.]”

It is not clear, to me at least, if the IE Active X component that is involved in the vulnerability in the IntegraXor application would have similar effects on other similar SCADA HMI or HMI development applications. I would suspect that Billy Rios is probably looking into this issue with other systems. In fact, I would not be surprised to see similar vulnerability reports coming out of ICS-CERT in the coming weeks.
 
/* Use this with templates/template-twocol.html */