Showing posts with label Invensys. Show all posts
Showing posts with label Invensys. Show all posts

Thursday, October 10, 2013

ICS-CERT Publishes Two Advisories

In the midst of a dysfunctional government’s fiscal fiasco the DHS ICS-CERT published two control system security advisories yesterday, one a DNP3 advisory for Alstom e-Terracontrol and another HMI advisory for Wonderware InTouch.

Alstom Advisory

This advisory is for an improper input validation vulnerability reported by Adam Crain and Chris Sistrunk in a coordinated disclosure (#9 of 25 listed on the Project Robus web page). Alstom has produced a patch to mitigate this vulnerability and Adam and Chris have verified the efficacy of that patch.

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to execute a denial of service attack on the system.

Wonderware Advisory

This advisory is for an improper input validation vulnerability reported by Timur Yunusov, Alexey Osipov, and Ilya Karpov of the Positive Technologies Research Team in a coordinated disclosure. Wonderware has produced an updated version of InTouch that mitigates this vulnerability and the team from Positive Technologies has verified the efficacy of the new version. ICS-CERT had released this advisory to the US-CERT secure Portal library on October 03, 2013.

ICS-CERT reports that a relatively low skilled attacker could exploit this vulnerability to gain access to system information or execute a denial of service attack. ICS-CERT says that this vulnerability cannot be remotely exploited; they note that the “exploit is only triggered when a local user runs the vulnerable application and loads the malformed XML files” {page 2}. It seems clear that a remote exploit would be possible through a social engineering attack.

According to the Positive Technologies web site that organization reported this vulnerability to Invensys on 12-16-13 along with three other vulnerabilities in the same system. Those reported vulnerabilities were:

• PT-2013-40: Resource Exhaustion;
• PT-2013-38: Multiple SQL Injection vulnerabilities; and
• PT-2013-37: Multiple Cross Site Scripting (XSS).


Positive Technologies reported that Invensys publicly reported all four vulnerabilities on October 6th. It is not clear why ICS-CERT did not include these other, more serious, vulnerabilities in this advisory especially since Positive Technologies reports that the same Invensys update fixed all four vulnerabilities. The Wonderware notifications are only available to registered system owners so I cannot verify the Positive Technologies claims.

Tuesday, October 1, 2013

Two ICS Vulnerabilities that ICS-CERT Missed

Thanks to a Tweet® from Red Team SCADA I looked at the Open Source Vulnerability Database this morning and noticed that in the last two weeks there were two ICS vulnerabilities listed that have not yet been reported by ICS-CERT. Those are:

• An Triangle Research Nano-10 PLC vulnerability; and
• An Invensys Wonderware InTouch vulnerability

Both of these are listed as coordinated vulnerabilities with mitigation measures available from the vendors.


I don’t suppose that we will hear anything now until the shutdown is lifted. It does beg the question, do we need ICS-CERT’s reporting?

Tuesday, May 7, 2013

ICS-CERT Issues Wonderware Advisory


Earlier today the DHS ICS-CERT published an advisory covering multiple vulnerabilities in Invensys Wonderware Information Server products. The coordinated disclosure was made by Timur Yunusov, Alexey Osipov, and Ilya Karpov of the Positive Technologies Research Team. The multiple vulnerabilities included:

• Cross-site scripting, CVE-2013-0688;
• SQL injection, CVE-2013-0684;
• Inproper input validation, CVE-2013-0686; and
• Resource exhaustion, CVE-2013-0685.

NOTE: These CVE links will not be functional for a couple of days.


ICS-CERT reports that a moderately skilled attacker could remotely exploit these vulnerabilities to execute remote code, disclose information, or perform session credential high jacking. The advisory notes that Invensys has developed a software update (registration required) that has been verified by PTR to mitigate the identified vulnerabilities.

These are old school vulnerabilities that should have been identified a long time back. I think the reason they are just turning up now is that they are in an ICS server. It looks like researchers are expanding the areas in which they are searching for ICS vulnerabilities. How many other types of ICS equipment will have similar vulnerabilities that would allow access to the control system?

BTW: A couple of posts back I noted that ICS-CERT had changed their format for these advisories and that one of the changes was the removal of the Traffic Light Protocol (TLP) markings. I just noticed that this advisory still includes a description of the TLP white marking that shows up near the top of page 3 on the .PDF saved version of the advisory. This is the first time this FAQ has shown up on an advisory since the format change.

Thursday, March 21, 2013

ICS-CERT Publishes Wonderware Advisory


Today the DHS ICS-CERT published an advisory describing a vulnerability in the Invensys Wonderware Win-XML Exporter. The improper input validation vulnerability was reported by Timur Yunusov, Alexey Osipov, and Ilya Karpov of the Positive Technologies Research Team in a coordinated disclosure. This advisory was originally released on the US-CERT Secure Portal on March 8th, 2013.

ICS-CERT reports that an attacker with a moderate skill set could exploit this vulnerability to conduct a DoS attack or gain access to system information. The advisory states that this vulnerability is not remotely exploitable, but it looks like a social engineering attack could cause a system user to access a specially crafted XML file to execute the attack.

Invensys has developed an update for the Win-XML Exporter that mitigates the vulnerability and it is available on the company download site. This has been validated by the original researchers.

Friday, December 14, 2012

ICS-CERT Publishes Two Siemens Advisories


Over the last two days the folks at DHS ICS-CERT have published advisories on two different Siemens Systems; on Thursday one for Siemens Process Suite, and today one for Siemens Automation License Manager. The first involves an ‘out-of-date’ Siemens’ acquired product, but it also affects newer Wonderware InTouch systems. The second affects a wide range of Siemens producs.

ProcessSuite Vulnerability


This poorly encrypted password file vulnerability was reported by Seth Bromberger of NCI Security, LLC and independent researcher Slade Griffin. A relatively low skilled attacker with read-only access to the system could obtain login information, including passwords, from an unencrypted .INI file and subsequently log onto the system with administrator privileges.

The affected Siemens systems are no longer supported and Siemens strongly recommends upgrading to a more recent HMI. The Wonderware situation is not so clear from the Advisory. Early in the document (page 1) ICS-CERT notes that Wonderware InTouch 2012 R2 and previous versions are affected. Later (page 3) it notes that Invensys “recommends using Windows integrated security features or migrating the HMI and OS to versions currently supported and then install their security update”.  

Of course earlier (page 1) ICS-CERT notes that Invensys “recommends using Windows integrated security rather than the InTouch security subsystem but has created a new patch to mitigate this vulnerability”, only there is no patch for this vulnerability listed on the Invensys Cyber Security Updates page. Oh well, it’s been a long week and I may be confused easily.

Automation License Manager Vulnerability


It appears that the uncontrolled resource consumption vulnerability reported in the second advisory was self-reported by Siemens; at least no researchers were named in either the ICS-CERT advisory or the Siemens ProductCert advisory. All Siemens’ products using the vulnerable versions of ALM are affected.

Siemens notes that specially crafted packets sent to TCP Port 4410 can cause data leakage that can enable a denial of service attack. The Siemens’ advisory that the Windows firewall should be configured to enable access to this port only on the local subnet which should mean that an attacker would have to have access to that subnet. If firewall is not properly configured this would certainly be a remotely exploitable vulnerability.

Siemens does provide an updated version of ALM that addresses this vulnerability.

Tuesday, July 24, 2012

ICS-CERT Publishes Three Advisories – Two for Siemens


Yesterday afternoon DHS ICS-CERT published three advisories; one about a recent coordinated disclosure and two about old vulnerabilities identified by the vendor. The new one concerns a single vulnerability in a variety of Invensys systems. Both of the older problems deal with Siemens systems. Oh, and remember this for later the new Advisory and one of the old ones deal with dll vulnerabilities.

Invensys Advisory


This advisory deals with an uncontrolled search path element vulnerability (otherwise known as a dll hijack) in a variety of products in the Wonderware System platform family. The vulnerability was discovered by Carlos Mario Penagos Hollmann. The advisory was first posted on the US-CERT secure portal on July 5th.

A moderately skilled attacker could exploit this vulnerability and place a malicious dll in the system. To exploit this vulnerability the attacker must have physical access to the system or be able to manipulate a user with access to the system.

Invensys has developed a patch for the affected systems which is available on the Wonderware web site.

Siemens Advisories


Siemens self-reported two vulnerabilities that are being addressed in separate advisories. The first is an insecure SQL server vulnerability and the second is dll loading mechanism vulnerability. As if self-reporting is not odd enough (to be encouraged to be sure, but odd), the first vulnerability was patched in 2010 (update V5.5 SP1) and the second in 2011 (update V7.0 SP 2 Update 1).  Both vulnerabilities can be remotely exploited and there are publicly available exploits available for both.

No word about why Siemens wanted these vulnerabilities made public at this late date. It does seem obvious that they are the ones responsible for ICS-CERT publishing these now, but for the life of me I can’t figure out why.

MS DLL Advisory


I’m not sure if Chris Jager knew about the two dll vulnerabilities being reported by ICS-CERT, but in a Tweet this afternoon he pointed us at a Microsoft Security Advisory from earlier this month (actually updated the 17th time earlier this month) about insecure library loading. It discusses the type of dll injection attacks covered in the two advisories published today. It notes that MS has provided guidance to software developers “on how to correctly use the available application programming interfaces to prevent this class of vulnerability”.

More importantly for system owners “Microsoft is releasing a tool that allows system administrators to mitigate the risk of this new attack vector by altering the library loading behavior system-wide or for specific applications”. While this is not a control system specific tool, the fact that this vulnerability has been found in so many ICS systems might make it an important tool that should be in the ICS security tool box.

It might be a good idea for ICS-CERT to partner with Microsoft on making this tool specifically available to ICS owners.

Wednesday, February 8, 2012

ICS-CERT Publishes two more HMI Advisories

Yesterday afternoon and today DHS ICS-CERT published two advisories for vulnerabilities in two separate SCADA human-machine-interface (HMI) programs. Both were identified through coordinated disclosures. The affected systems are the xenon HMI (from Ing. Punzenberger COPA-DATA GmbH) and Wonderware HMI Reports (from Invensys).

Punzenberger Advisory


The twin DOS vulnerabilities for this advisory were reported by Kuang-Chun Hung of the Security Research and Service Institute – Information and Communication Security Technology Center (ICST). They would allow attackers to remotely execute a denial of service attack or possibly remotely execute arbitrary code.

Punzenberger has made available an update to this system that resolves the reported vulnerabilities. They also recommend disabling their ZenSysSrv.exe service except when it is actually needed.

Invensys Advisory


Rios and McCorkle reported these twin vulnerabilities on the Wonderware Report HMI from Invensys. The cross-site scripting vulnerability could allow a low skilled attacker to remotely execute a DOS attack or allow data leakage from the system. The write access violation would require a skilled attacker to execute arbitrary code via a social engineering initiated attack.

Invensys has a new version of this program available that removes the vulnerabilities from the system. It gets a little more complicated though since the owner-operator will also have to migrate the report definitions into the new Quick Reports 2012 format and request a permanent license from the distributor.

BTW: It would be interesting to know if these vulnerabilities were part of the ‘100 vulnerabilities in 100 days’ project that Rios and McCorkle did last year. The timing could be right and it would interesting to see how long it takes all 100 vendors to get their vulnerabilities systems under control. Or how many actually get the problems corrected.

Tuesday, December 20, 2011

Two New ICS-CERT Advisories

Today the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published two new control system advisories; one for Invensys Wonderware, and the other for 7-Technologies Data Server. Both advisories were previously published in the limited distribution on the US-CERT secure portal.

Invensys


The three buffer overflow vulnerabilities described in this Advisory were reported by Kuang-Chun Hung of the Security Research and Service Institute−Information and Communication Security Technology Center (ICST). They would allow a low skilled attacker to execute a denial of service attack and a more skilled attacker to execute arbitrary code on the system. The US-CERT/NIST vulnerability summary is available for these vulnerabilities (Note: The link does work).

Invensys has developed software updates for the affected Wonderware InBatch systems.

7-Technologies


The second advisory involved another buffer overflow vulnerability that was discovered in the 7-Technologies IGSS Data Server by UCQ from the Cyber Defense Institute, Inc. A moderately skilled attacker could use this vulnerability to execute a DOS attack on the system. A CVE number has been assigned to this vulnerability, but it is not yet live on the US-CERT/NIST site.

7T has developed a patch to address this vulnerability and it is currently available on the IGSS web site (NOTE: This link is to a .ZIP file).

Cyber Security Evaluation Tool


The ICS-CERT web page also contains a link to version 4.0.1 of the Cyber Security Evaluation Tool (CSETTM). There is no indication when exactly that new version became available nor is there any explanation on the CSET web site of how the new version differs from version 4.0; though one would expect the differences to be relatively minor.

Wednesday, July 27, 2011

ICS-CERT Issues Wonderware Advisory

Yesterday DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published an advisory for the Invensys Wonderware Information Server that had previously been posted in restricted release on the US-CERT Portal. The Advisory describes a stack-based buffer overflow vulnerability in two different ActiveX controls used by that product.

This vulnerability is remotely exploitable by an attacker with moderate skills. It does require a user to open a malicious file or website so a social engineering attack is required. A successful attack could allow remote code execution on the affected system.

Invensys has developed a patch for this vulnerability.

Thursday, March 3, 2011

ICS-CERT Updates Wonderware Inbatch Advisory

Today the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) up dated their Advisory on the Wonderware Inbatch buffer-overflow vulnerability. The original advisory was released in December because a publicly available exploit was reported. In this update ICS-CERT advises that Invensys has validated the vulnerability and has made a patch available.
 
/* Use this with templates/template-twocol.html */