Showing posts with label Interpeak. Show all posts
Showing posts with label Interpeak. Show all posts

Wednesday, May 13, 2020

2 Advisories and 7 Updates Published


Yesterday the CISA NCCIC-ICS published two control system security advisories for products from OSIsoft and Eaton. They also updated previously published advisories for products from 3S, Interpeak, and Siemens (5).

OSIsoft Advisory


This advisory describes ten vulnerabilities in the OSIsoft PI System. The vulnerabilities were reported by William Knowles at Applied Risk. OSIsoft provides workarounds to mitigate the vulnerabilities. There is no indication that Knowles has been provided an opportunity to verify the efficacy of the fix. Applied Risk has verified that Knowles was provided an opportunity to verify the efficacy of the fix (see https://chemical-facility-security-news.blogspot.com/2020/05/verifying-fixes.html) [5-14-20 8:00 EDT]

The ten reported vulnerabilities are:

• Uncontrolled search path element - CVE-2020-10610,
• Improper verification of cryptographic key - CVE-2020-10608,
• Incorrect default permissions - CVE-2020-10606,
• Uncaught exception - CVE-2020-10604,
• Null pointer dereference (2) - CVE-2020-10602 and CVE-2020-10600,
• Improper input validation - CVE-2019-10768,
• Cross-site scripting (2) - CVE-2020-10600 and CVE-2020-10614, and
• Insertion of sensitive information into log file - CVE-2019-18244

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to access unauthorized information, delete or modify local processes, and crash the affected device.

Eaton Advisory


This advisory describes two vulnerabilities in the Eaton Intelligent Power Manager software monitoring and management platform. The vulnerability was reported by Sivathmican Sivakumaran of Trend Micro’s Zero Day Initiative. Eaton has a new version that mitigates the vulnerability. There is no indication that Sivakumaran has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper input validation - CVE-2020-6651, and
• Incorrect privilege assignment - CVE-2020-6652

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to perform command injection or code execution and allow non-administrator users to manipulate the system configurations.

3S Update


This update provides additional information for an advisory that was originally reported on September 12th, 2019. The new information includes a link to an even newer version that more completely mitigates the vulnerability.

NOTE: This is part of the reason that advocate for the researchers that discovered the vulnerability being provided a specific opportunity to verify the efficacy of the reported fix.

Interpeak Update


This update provides additional information for the Urgent/11 advisory that was originally published on October 1st, 2019 and most recently updated on February 18th, 2020. The new information includes a link to the new Siemens Power Meters advisory that was published today.

SIPROTEC Update


This update provides additional information for an advisory that was originally published on July 9th, 2019 and most recently updated on December 10th, 2019. The new information includes affected version numbers and mitigation links for SIPROTEC 5 device types 7SS85 and 7KE85.

SINAMICS Update


This update provides additional information for an advisory that was originally published on August 15th, 2019 and most recently updated on December 10th, 2019. . The new information includes affected version numbers and mitigation links for SINAMICS SL150 V4.8.

SIMATIC Update


This update provides additional information for an advisory that was originally published on February 11th, 2020 and most recently updated on April 14th, 2020. The new information includes affected version numbers and mitigation links for SIMATIC NET PC Software.

KTK Update


This update provides additional information for an advisory that was originally published on April 14th, 2020. The new information includes the addition of the SIMATIC S7-400 H V6 CPU family to the list of affected products.

RUGGEDCOM Update


This update provides additional information for an advisory that was originally published on April 14th, 2020. The new information includes the removal of  IE/PB-Link V3 from the list of affected products.

Other Advisories


Siemens published one additional update that was not covered by NCCIC-ICS yesterday. I will address that on Saturday.

Schneider has also joined the 2nd Tuesday patch club. They published 3 new advisories and 4 updates that I will also address on Saturday.

Tuesday, February 18, 2020

4 Advisories and 1 Update Published – 2-18-20


Today the CISA NCCIC-ICS published two control system security advisories for products from Emerson and Honeywell, two medical device security advisories for products from GE and Spacelabs, and 1 update for products from Interpeak.

Emerson Advisory


This advisory describes a heap-based buffer overflow vulnerability in the Emerson OpenEnterprise SCADA Server. The vulnerability was reported by Roman Lozko of Kaspersky ICS CERT. Emerson has an upgrade that mitigates the vulnerability. There is no indication that Lozko has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit this vulnerability to allow an attacker to execute code on an OpenEnterprise SCADA Server.

Honeywell Advisory


This advisory describes a clear-text storage of sensitive information vulnerability in the Honeywell INNCOM INNControl 3 energy management platform. The vulnerability is self-reported. Honeywell has an upgrade available to mitigate the vulnerability.

NCCIC reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to escalate user privileges within the INNControl application.

GE Advisory


This advisory describes a protection measure failure vulnerability in the GE Ultrasound Products. The vulnerability was reported by Marc Ruef and Rocco Gagliardi of scip AG. GE has provided generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with local access could exploit the vulnerability to allow an attacker to gain access to the operating system of affected devices.

Spacelabs Advisory


This advisory describes the BlueKeep vulnerability in the Spacelabs Xhibit Telemetry Receiver. Spacelabs has an updated version that mitigates the vulnerability.

NOTE: A number of other vendors in both the control system and medical device realms issued advisories on this vulnerability (see my blog post here for example) beginning in May of last year. This is the first acknowledgement of vendor actions on this vulnerability from NCCIC-ICS though there was an obscure advisory on the vulnerability published by NCCIC-ICS.

Interpeak Update


This update provides additional information on the Urgent/11 advisory that was originally published on October 1st, 2019 and most recently updated on December 10th, 2019. The new information includes a link to a vendor advisory from Mitsubishi.

Tuesday, December 10, 2019

7 Advisories and 6 Updates Published – 12-10-19


Today the DHS NCCIC-ICS published seven control system security advisories for products from Siemens and six updates for products from Siemens (5) and Interpeak.

EN100 Ethernet Module Advisory 


This advisory describes three vulnerabilities in the Siemens EN100 Ethernet Module. The vulnerabilities are self-reported. Siemens has a new version that mitigates the vulnerability.

The three reported vulnerabilities are:

• Improper restriction of operations within the bounds of a memory buffer - CVE-2019-13942;
• Cross-site scripting - CVE-2019-13943; and
• Relative path traversal CVE-2019-13944

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to execute remote code, cause a denial-of-service condition, and obtain sensitive information about the device.

SIMATIC S7-1200 Advisory


This advisory describes two vulnerabilities in the Siemens SIMATIC S7-1200 and S7-1500 CPU families. The vulnerabilities were reported by Eli Biham, Sara Bitan, Aviad Carmel, and Alon Dankner from Faculty of Computer Science, Technion Haifa; Uriel Malin and Avishai Wool from School of Electrical Engineering, Tel-Aviv University; and Artem Zinenko from Kaspersky. Siemens has updates that mitigate the vulnerabilities. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Use of a broken or risky cryptographic algorithm - CVE-2019-10929; and
• Missing support for integrity check - CVE-2019-10943

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to modify network traffic or impact the perceived integrity of the user program stored on the CPU.

NOTE: Siemens originally published their advisory for these vulnerabilities back in August, but NCCIC-ICS never reported on it. Siemens published an update for their advisory today.

XHQ Operations Intelligence Advisory


This advisory describes three vulnerabilities in the Siemens XHQ Operations Intelligence. The vulnerabilities are self-reported. Siemens has a new version that mitigates the vulnerabilities.

The three reported vulnerabilities are:

• Cross-site request forgery - CVE-2019-13930;
• Improper neutralization of script-related HTML tags in a web page - CVE-2019-13931; and
• Improper input validation - CVE-2019-13932

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to read or modify contents of the web application.

SIMATIC Products Advisory


This advisory describes a use of broken or risky cryptographic algorithm vulnerability in the Siemens SIMATIC products. The vulnerability was reported by Eli Biham, Sara Bitan, Aviad Carmel, and Alon Dankner from Faculty of Computer Science, Technion Haifa; and Uriel Malin and Avishai Wool from the School of Electrical Engineering, Tel-Aviv University, reported this vulnerability to Siemens. Siemens has updates for three of the affected products. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

An uncharacterized attacker could remotely exploit this vulnerability to allow an attacker already in a man-in-the-middle position to modify network traffic exchanged on Port 102/TCP. The Siemens advisory notes that the attack must conduct a man-in-the-middle attack to exploit the vulnerability.

RUGGEDCOM ROS Advisory


This advisory describes two vulnerabilities in the Siemens RUGGEDCOM ROS. The vulnerabilities are self-reported. Siemens has provided generic workarounds to mitigate the vulnerabilities.

The two reported vulnerabilities are:

• Improper restriction of operations within the bounds of a memory buffer - CVE-2018-18440; and
• Resource management errors - CVE-2019-13103

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to allow a denial-of-service condition or arbitrary code execution. The Siemens advisory reports that an attacker must have local access to exploit these vulnerabilities.

SiNVR Advisory


This advisory describes seven vulnerabilities in the Siemens SiNVR 3 video management solution. The vulnerabilities were reported by Raphaël Rigo from Airbus Security Lab. Siemens has provided generic workarounds for the vulnerabilities.

The seven reported vulnerabilities are:

• Cleartext storage of sensitive information in GUI - CVE-2019-13947;
• Improper authentication (2) - CVE-2019-18337 and CVE-2019-18341;
• Relative path traversal - CVE-2019-18338;
• Missing authentication for critical function - CVE-2019-18339;
• Weak cryptography for passwords - CVE-2019-18340; and
Exposed dangerous method or function - CVE-2019-18342

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to read (and reset) passwords of other SiNVR 3 CCS (Central Control Server) users, read the CCS and SiNVR users database including the passwords of all users in obfuscated cleartext, list arbitrary directories or read files outside of the CCS application context, extract device configuration files and passwords from the user database, read data from the EDIR directory, read or delete arbitrary files, or access other resources on the same CCS server.

SCALANCE Advisory


This advisory describes an improper enforcement of message integrity during transmission in a communication channel vulnerability in the Siemens SCALANCE W700 and W1700 wireless communication devices. The vulnerabilities are self-reported.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to access confidential data. The Siemens advisory notes that the attacker must be within wireless range of the device to exploit the vulnerability.

SCALANCE Update


This update provides additional information on an advisory that was originally published on May 24th, 2013. The new information includes:

• Added Scalance X-200 switch family;
• Updated CVSS Scores from CVSSv2 to CVSSv3.1; and
• SIPLUS devices now explicitly mentioned in the list of affected products

SIMATIC CP 343-1 Update


This update provides additional information on an advisory that was originally published on November 11th, 2016 and most recently updated on March 21st, 2017. The new information includes SIPLUS devices now explicitly mentioned in the list of affected products.

NOTE: Siemens most recently updated their advisory last month and those corrections about the S7-400 CPUs are not included in the NCCIC-ICS update. Unfortunately none of the versions (except the latest) of the Siemens advisory are listed on the Siemens CERT page and I did not see last month’s update.

SIPROTEC 5 Update


This update provides additional information on an advisory that was originally published on July 9th, 2019 and most recently updated on August 13th, 2019. The new information includes an update for SIPROTEC 5 relays with CPU variants CP200 and the respective Ethernet communication modules.

SINAMICS Update


This update provides additional information on an advisory that was originally published on August 15th, 2019 and most recently updated on November 11th, 2019. The new information includes updated version information and mitigation links for:

• SINAMICS SM120 V4.7; and
• SINAMICS SM120 V4.8

Industrial Products Update


This update provides additional information on an advisory that was originally published on September 10th, 2019 and most recently updated on November 14th, 2019. The new information includes:

• Added solution for SCALANCE W700; and
• SIPLUS devices now explicitly mentioned in the list of affected products

Interpeak (ICS) Update


This update provides additional information on an advisory that was originally published on October 1st, 2019 and most recently updated on October 10th, 2019. The new information is the addition for links to vendor advisories for:


NOTE: Both advisory links are to updates published today of Siemens advisories that were published earlier; August 2nd, 2019 and September 10th, 2019 respectively.

Additional Siemens Advisories


Siemens published one additional new advisory and two updates today that did not show up on the NCCIC-ICS page. We will probably see the other new advisory covered on Thursday.

Tuesday, November 5, 2019

1 Advisory and 2 Updates Published


Today the CISA NCCIC-ICS published a control system advisory for products from Omron. They also updated two previously published security advisories for products from Omron and Interpeak (medical device advisory).

Omron Advisory


This advisory describes a use of obsolete function vulnerability in the Omron CX-Supervisor. The vulnerability was reported by Michael DePlante of the Zero Day Initiative. Omron has a new version that mitigates the vulnerability. There is no indication that DePlante has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to result in information disclosure, total compromise of the system, and system unavailability.

Omron Update


This update provides additional information on an advisory that was originally published on May 14th, 2019. The new information includes the announcement of a new version that mitigates the vulnerability.


Interpeak IPnet (medical device) Update


This update provides additional information on an advisory that was originally published on October 1st, 2019 and last updated on October 10th. The new information is the addition of Hillrom to the list of vendors that have also released security advisories related to their affected products. Unfortunately, the link provided takes one to a generic responsible disclosure page with no mention of security advisories.


Friday, October 11, 2019

2 Advisories and 6 Updates Published


Yesterday the DHS NCCIC-ICS published two control system security advisories for products from Siemens. They also published five control system updates for products from Interpeak (2) and Siemens (3) and a medical device update for Philips.

PROFIET Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the Siemens PROFINET Devices. Siemens self-reported the vulnerability. Siemens has new versions for many of the affected versions that mitigate the vulnerability and provides generic workarounds for the rest while formal mitigation measures are developed.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to cause a denial-of-service condition.

IRT Devices Advisory


This advisory describes an improper input validation vulnerability in the Siemens Industrial Real-Time (IRT) Devices. Siemens self-reported the vulnerability. Siemens has new versions for many of the affected versions that mitigate the vulnerability and provides generic workarounds for the rest while formal mitigation measures are developed.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to cause a denial-of-service condition.

Interpeak Update #1


This update provides additional information on an advisory that was originally published on October 1st, 2019 and last updated on October 3rd, 2019. The new information includes:

Updated mitigation information for Enea and Green Hills Software; and
A new vendor information link for Carestream

Interpeak Update #2


This update provides additional information on an advisory that was originally published on October 1st, 2019. The new information includes updated mitigation information for Enea and Green Hills Software.

SIMATIC Update #1


This update provides additional information on an advisory that was originally published on July 11th, 2019 and last updated on September 10th, 2019. The new information includes:

Updated remediation for SIMATIC WinCC Runtime Professional V15;
Updated affected versions and mitigation information for:
SIMATIC WinCC Professional (TIA Portal V14); and
SIMATIC WinCC Professional (TIA Portal V15)

SIMATIC Update #2


This update provides additional information on an advisory that was originally published on July 9th, 2019 and last updated on September 10th, 2019. The new information includes:

Updated remediation for SIMATIC WinCC Runtime Professional V15;
Updated affected versions and mitigation information for:
SIMATIC WinCC Professional (TIA Portal V14); and
SIMATIC WinCC Professional (TIA Portal V15)

Industrial Products Update


This update provides additional information on an advisory that was originally published on November 8th, 2016 and last updated on June 14th, 2018. The new information includes:

Merged WinAC RTX 2010 SP2 and WinAC RTX F 2010 SP2 to SIMATIC WinAC RTX (F) 2010; and
Added mitigation information for SIMATIC WinAC RTX (F) 2010

Philips Update


This update provides additional information on an advisory that was originally published on May 3rd, 2018. The added information includes an additional affected product that is out of support.

Other Siemens Advisories

There is still one advisory and two updates that Siemens published on October 8th that have not been addressed by NCCIC-ICS. I will report on those tomorrow.

Thursday, October 3, 2019

1 Update Published – 10-03-19


Today the DHS NCCIC-ICS published an update to a previously published medical device security advisory for products from Interpeak and vendors who have used their IPnet TCP/IP Stack. The advisory was originally published on 10-01-19. The update adds to additional medical device vendor advisories about the underlying URGENT/11 vulnerabilities. Those two vendors are:

Abbott; and

Tuesday, October 1, 2019

4 Advisories Published – 10-01-19


Today the DHS NCCIC-ICS published three control system security advisories for products from Moxa, Yokogawa and Interpeak and a medical device security advisory for products from Interpeak.

Moxa Advisory


This advisory describes two vulnerabilities in the Moxa Moxa EDR 810 router. According to the Moxa advisory these vulnerabilities was reported by Guillaume Lopes of Randorisec (not included in NCCIC-ICS advisory). Moxa has new firmware that mitigates the vulnerabilities. There is no indication that Lopes was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Improper input validation - CVE-2019-10969; and
Improper access control - CVE-2019-10963

 NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow remote code execution or access to sensitive information.

Yokogawa Advisory


This advisory describes an unquoted search path or element vulnerability in the Yokogawa Exaopc, Exaplog, Exaquantum, Exasmoc, Exarqe, GA10, and InsightSuiteAE products. The vulnerability is self-reported. Yokogawa has revisions or updates for most of the affected products.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow a local attacker to execute malicious files.

NOTE: I briefly reported this vulnerability on Saturday.

Interpeak ICS Advisory


This advisory describes eleven vulnerabilities in Interpeak IPnet stack. These vulnerabilities were previously reported as the Wind River URGENT/11 vulnerabilities. This advisory now reports that the vulnerabilities are also found the following real-time operating systems (RTOS):

ENEA - OSE4 and OSE5;
Green Hills Software - INTREGRITY RTOS;
ITRON; and
IP Infusion – Zebos;

Interpeak Medical Device Advisory


This advisory describes the same URGENT/11 vulnerabilities due to problems in the Interpeak IPnet stack as described above. The only difference is that this version provides links to medical device vendor advisories.

Commentary


The two Interpeak advisories point out (AGAIN) how interconnected software systems are. Vulnerabilities found in one system are frequently found in 3rd party software that is used by vendor instead of writing new code. This is done for a variety of reasons, but frequently it is because a vendor does not have either the resources or the expertise in-house to develop the necessary code. This certainly makes economic sense.

Unfortunately, there does not seem to be a system in place to ensure that other vendors that use the same code are notified in a timely manner so that they can fix the related problems. In some cases, I suspect notifications are made, corrective action is taken, but the vendor never reports the vulnerability. The lack of notification is usually due to not wanting to look bad, but it does little to help owners of the affected products who do not update because their systems are ‘working fine’; their decisions might be made differently (or not) if they knew about the vulnerabilities.

 
/* Use this with templates/template-twocol.html */