Showing posts with label Ioactive. Show all posts
Showing posts with label Ioactive. Show all posts

Tuesday, September 22, 2020

2 Advisories Published – 9-22-20

 Today the CISA NCCIC-ICS published two control system security advisories for products from GE.

Reason S20 Advisory

This advisory describes two cross-site scripting vulnerabilities in the GE Reason S20 Ethernet Switch. The vulnerability was reported by IOActive. GE has newer firmware versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow unauthorized accounts manipulation and allow for remote code execution.

APM Advisory

This advisory describes two vulnerabilities in the GE Digital APM Classic data analysis tool. The vulnerability was reported by Guido Marilli of Accenture Security. GE has a new version that mitigates the vulnerabilities. There is no indication that Marilli has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Authorization bypass through user-controlled key - CVE-2020-16240, and

• Use of a one-way hash without a salt - CVE-2020-16244

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow access to sensitive information. The GE Digital advisory states that “GE believes exploitation of the Vulnerabilities is only possible if an attacker was first authenticated.”

Saturday, September 5, 2020

Public ICS Disclosures – Week of 8-29-20


This week we have two new vendor disclosures for products from SICK and BD. There were also three Ripple20 [Corrected link, 10-18-20, 0857] updates published for products from HMS, Braun and Schneider. We also have a vendor update from Yokogawa. There is also one researcher report with exploits for vulnerabilities for products from Red Lion.

SICK Advisory


SICK published an advisory describing an improper handling of exceptional conditions vulnerability in their SOPAS Engineering Tool. The vulnerability was reported by Ruben Santamarta of IOActive. SICK has released new firmware versions that mitigate the vulnerability. There is no indication that Santamarta has been provided an opportunity to verify the efficacy of the fix.

BD Advisory


BD published an advisory describing three third-party (VMware) vulnerabilities in selected BD products. BD is currently testing the VMware update.

The three reported vulnerabilities are:

• Local privilege escalation - CVE-2020-3957,
• Denial of service - CVE-2020-3958, and
• Memory leak - CVE-2020-3959

Ripple20 Updates


HMS published an update of their Ripple20 advisory that was originally published on June 23, 2020. The new information includes adding the following products to the not affected list:

• Anybus M-Bus to Modbus TCP gateway,
• Anybus WLAN Access Points (AWB4xxx), and
• Ewon Netbiter 100, 200 and 300-series

Braun published an update of their Ripple20 advisory that was originally published on June 30th, 2020. The updated information includes more details on the Ripple20 effect on the Outlook 400ES infusion pump.

Schneider published an update of their Ripple20 advisory that was originally published on June 23, 2020 and most recently updated on August 6th, 2020. The new information includes:

• Adding mitigation measures for Cooling Products using NMC2, and
• Adding partial remediations for TM3BC bus coupler module – EIP, TM3BC bus coupler module – SL, and TM3BC bus coupler module – CANOpen

Yokogawa Update


Yokogawa published an update for their CAMS for HIS advisory that was originally published on July 31st, 2020. The new information includes updated affected product data.

Red Lion Report


SEC Consult published a report on multiple vulnerabilities in the Red Lion N-Tron products that were reported last week by CISA NCCIC-ICS. The SEC Consult report includes proof-of-concept exploit code and a list of outdated third-party components.

Saturday, June 6, 2020

Public ICS Disclosures – Week of 5-30-20


This week we have three vendor disclosures from Phoenix Contact, PEPPERL+FUCHS and SICK plus an update of a previous vendor disclosure from Johnson Controls.

Phoenix Contact Advisory


Phoenix Contact published an advisory [.PDF download link] describing a buffer overflow vulnerability in the Linux Point-to-Point Protocol (PPP) daemon in their FL MGUARD, TC MGUARD, TC ROUTER and TC CLOUD CLIENT devices. The vulnerability is apparently being self-reported. Phoenix Contact has firmware versions that mitigate the vulnerability.

NOTE: this is the same vulnerability, CVE-2020-8597, reported the week before by Belden.

PEPPERL+FUCHS Advisory


CERT VDE published an advisory describing two vulnerabilities in the PEPPERL+FUCHS PACTware. The vulnerabilities were reported by Reid Wightman of Dragos, Inc. PEPPERLY+FUCHS has new versions that mitigate the vulnerabilities. There is no indication that Wightman has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Storing passwords in recoverable format - CVE-2020-9403, and
• Unverified password change - CVE-2020-9404

SICK Advisory


SICK published an advisory describing a profile programming vulnerability in their bar code scanners. The vulnerability was reported by Ruben Santamarta of IOActive. SICK provides a workaround to mitigate the vulnerability.

NOTE: This is another ‘a feature is a vulnerability’ situation. These barcode scanners can be ‘programed’ by the barcodes that they scan. Thus, substituting a malicious bar code can upset the system to which the scanner is attached. The fix is to disable the feature.

Johnson Controls Update


Johnson Controls published an update for an advisory that was originally published on May 21st, 2020 and most recently updated on May 29th, 2020. The new information includes a minor modification to the mitigation instruction for American Dynamics victor Video Management System v5.2 (change “Securely delete the installer log file…” to “Delete the installer log file…”).

The NCCIC-ICS published their advisory on these vulnerabilities (ICSA-20-142-01), but has not yet addressed any of the Johnson Controls updates.

Tuesday, June 2, 2020

6 Advisories and 1 Update Published – 6-2-20


Today the CISA NCCIC-ICS published six control system security advisories for products from ABB (4), GE and SWARCO Traffic Systems. They also updated an advisory for products from Inductive Automation

System 800xA Advisory


This advisory describes two incorrect default permissions vulnerabilities in the ABB System 800xA. The vulnerabilities were reported by William Knowles of Applied Risk. ABB provides generic work arounds to mitigate the vulnerabilities.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to escalate privileges, cause system functions to stop, and corrupt user applications.

NOTE: I briefly described these vulnerabilities in early April.

System 800xA Base Advisory


This advisory describes an incorrect permission assignment for critical resource vulnerability in the ABB System 800xA Base. The vulnerabilities were reported by William Knowles of Applied Risk. ABB has a new version that mitigates the vulnerabilities. There is no indication that Knowles has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to escalate privileges and cause system functions to stop or malfunction.

NOTE: I briefly described these vulnerabilities in early April and then I discussed the ABB update later that month. The updated version is being reported by NCCIC-ICS.

System 800xA Products Advisory


This advisory describes seven incorrect default permission vulnerabilities in various ABB System 800xA products. The vulnerabilities were reported by William Knowles of Applied Risk. NCCIC-ICS reports that ABB plans to correct these vulnerabilities in a future version.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to make the system node inaccessible or tamper with runtime data in the system.

NOTE: I briefly described these vulnerabilities in early April and then I discussed the ABB update later that month. The updated version is being reported by NCCIC-ICS.

Central Licensing System Advisory


This advisory describes five vulnerabilities in the ABB Central Licensing System. The vulnerabilities were reported by William Knowles of Applied Risk. ABB has new versions that mitigate the vulnerabilities. There is no indication that Knowles has been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Information exposure - CVE-2020-8481,
• Improper restriction of XML external entity reference - CVE-2020-8479,
• Uncontrolled resource consumption - CVE-2020-8475,
• Permissions, privileges and access controls - CVE-2020-8476, and
• Improper access controls - CVE-2020-8471

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to take control of the affected system node remotely and cause an affected CLS Server node to stop or prevent legitimate access to the affected CLS Server.

I briefly reported these vulnerabilities in late April.

GE Advisory


This advisory describes a missing authentication for critical function vulnerability in the GE Grid Solutions Reason RT Clocks. The vulnerability was reported by Ehab Hussein of IOActive. GE has a new firmware version that mitigates the vulnerability. There is no indication that Hussein has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow access to sensitive information, execution of arbitrary code, and cause the device to become unresponsive.

SWARCO Advisory


This advisory describes an improper access control vulnerability in the SWARCO CPU LS4000. The vulnerability was reported by Martin Aman of ProtectEM. SWARCO has a patch that mitigates the vulnerability. There is no indication that Aman has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow access to the device and disturb operations with connected devices.

I briefly discussed this vulnerability last Saturday.

Inductive Automation Update


This update provides additional information on an advisory that was originally published on May 26th, 2020. The new information includes adding Ignition 7 Gateway to the list of affected products and providing mitigation measures for that product.

Thursday, April 19, 2018

ICS-CERT Publishes Advisory and Three Updates for Siemens Products

Today the DHS ICS-CERT published one new control system security advisory for products from Siemens. They also provided updates for three previously published Siemens control system security advisories.

Siemens Advisory


This advisory describes a file and directory information exposure vulnerability in the Siemens Simatic WinCC OA iOS App. The vulnerability was reported by Alexander Bolshev of IOActive and Ivan Yushkevich of Embedi. Siemens has identified workarounds to mitigate the vulnerability. There is no indication that either researcher was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that an uncharacterized attacker with physical access to the mobile device could exploit the vulnerability to read sensitive data located in the app’s directory.

SIMATIC Update


This update provides additional information on an advisory that was originally published on March 18th, 2018. The update provides links to the updates for all of the affected products.

SIPROTEC Update #1


This update provides additional information on an advisory that was originally published on March 8th, 2018. The ICS-CERT update provided a link to the updated version of the EN100 Ethernet module DNP3 variant with additional mitigation measures. The Siemens update also provided corrected affected version information on the same product.

SIPROTEC Update #2


This update provides additional information on an advisory that was originally published on March 8th, 2018. The ICS-CERT update provided a link to the updated version of the EN100 Ethernet module DNP3 variant with additional mitigation measures. The Siemens update also provided corrected affected version information on the same product.

Friday, March 23, 2018

ICS-CERT Publishes 2 Advisories and Siemens Update


Yesterday the DHS ICS-CERT published two control system security advisories for products from Beckhoff and Siemens. They also updated a previously published advisory for products from Siemens. The two Siemens products were mentioned in a previous blog post.

Beckhoff Advisory


This advisory describes an untrusted pointer dereference vulnerability in the Beckhoff TwinCAT PLC products. The vulnerability was reported by Steven Seeley of Source Incite. According to the Beckhoff security advisory, the company has updates available that mitigate the vulnerability. There is no indication that Seeley has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to escalate privileges. ICS-CERT reports that Matlab modules need to be recompiled after updating.

Siemens Advisory


This advisory describes an improper access control vulnerability in the Siemens SIMATIC WinCC OA UI mobile app. The vulnerability was reported by Alexander Bolshev from IOActive, and Ivan Yushkevich from Embedi. Siemens has updates available that mitigate the vulnerability. There is no indication that the researchers have verified the efficacy of the fix.

ICS-CERT reports that an uncharacterized attacker on an adjacent network could exploit the vulnerability to read and write data from and to the app’s project cache folder. The Siemens security advisory notes that a social engineering attack is required to convince the App user to connect to an attacker-controlled WinCC OA server

Siemens Update


This update provides new information on an advisory that was originally published on January 25th, 2018 and updated on February 6th. The update removes a product from the affected product list.

Thursday, February 15, 2018

ICS-CERT Publishes 4 Advisories and One ABB Update


Today the DHS ICS-CERT published four new control system security advisories for products from Schneider Electric (2), GE and Nortek. Additionally, they provided an update for a previously published advisory for products from ABB.

StructureOn Advisory


This advisory describes an unrestricted upload of file with dangerous type vulnerability in the Schneider StruxureOn Gateway software management program. The vulnerability is being self-reported.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to upload a malicious file to any directory on the device, which could lead to remote code execution. The Schneider security advisory reports that the file must be a .zip file with specifically modified metadata for this vulnerability to be exploited.

IGSS Mobile Advisory


This advisory describes two vulnerabilities in the Schneider IGSS Mobile application (iOS and Android). The vulnerabilities were reported by Alexander Bolshev (IOActive) and Ivan Yushkevich (Embedi). Schneider has produced updates for both versions. There is no indication that either researcher has been provided an opportunity to verify the efficacy of the fix.



The two reported vulnerabilities are:

• Improper certificate validation - CVE-2017-9968; and
Plaintext storage of password - CVE-2017-9969

ICS-CERT reports that a relatively low-skilled attacker with local access (okay they, actually said: “Locally exploitable”; that may not mean ‘local access’) could exploit the vulnerability to execute a man-in-the-middle attack. In addition, passwords can be accessed by unauthorized users.

NOTE: Marc Ayala pointed out to me that anyone can download these apps from the appropriate (iOs/Android) app store. This means that it would be easy to exploit a compromised mobile password. All the attacker needs to do is to get access to the IGSS configuration file on an oh so secure smart phone to compromise the password.

GE Advisory


This advisory describes two vulnerabilities in the GE D60 Line Distance Relay. The vulnerabilities were reported by Kirill Nesterov of Kaspersky Labs. GE has released new firmware that mitigates the vulnerability. There is no indication that Nesterov was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-5475; and
• Improper restriction of operations within bounds of memory buffer - CVE-2018-5473

ICS-CERT reports that relatively low-skilled attacker could remotely exploit the vulnerability to execute arbitrary code on the device.

Nortek Advisory


This advisory describes a command injection vulnerability in the Nortek Linear eMerge E3 Series access control interface. The vulnerability was reported by Evgeny Ermakov and Sergey Gordeychik. Nortek recommends upgrading the system using established procedures. There is no indication that either researcher was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability  to execute malicious code on the system with elevated privileges, allowing for full control of the server.

ABB Update


This update provides additional information on an advisory that was originally published on November 14th, 2017. The update reports that the new update of Mesh OS mitigates the KRACK vulnerability in these devices.

NOTE: The updated ABB security advisory that forms the basis for this ICS-CERT update was published on January 11th, 2018.

Wednesday, October 5, 2016

ICS-CERT Updates 2 Siemens Advisories and Publishes 2 New Advisories

The DHS ICS-CERT recently updated two control system security advisories for products from Siemens (the two I briefly discussed last week). Yesterday they also published two new control system security advisories for products from Indas and Beckhoff.

Siemens SIMATIC Update


This update adds new information for an advisory originally published in July and then updated in August. It provides updated affected version information for SIMATIC WinCC v7.0 SP3 and SIMATICS PCS 7 v8.0. It also provides update links for SIMATIC WinCC v7.0 and SIMATICS PCS 7 v7.2 and v8.0.

Siemens glibc Update


This update adds new information for an advisory that was reported in April and updated once in June and then again in July. It provides updated affected version information for SCALANCE M-800/S615. It also provides a link for a patche for those affected SCALANCE M-800/S615 products.

INDAS Advisory


This advisory describes a path traversal vulnerability in the INDAS Web SCADA application. The vulnerability was reported by Ehab Hussein of IOActive. INDAS has produced a new version of the software to mitigate the vulnerability, but there is no indication that Hussein has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to download arbitrary files from the target system.

Beckhoff Advisory


This advisory describes two vulnerabilities in the Beckhoff Embedded PC Images and TwinCAT Components. The vulnerabilities were publicly reported in February of 2015 at the 1st International Conference on Information Systems Security and Privacy by Marko Schuba from FH Aachen University of Applied Sciences (there may be an earlier report). In 2014 Beckhoff produced a new version of the software and published three security advisories (here, here, and here) to mitigate the vulnerabilities, but there is no indication that Schuba has been provided an opportunity to verify the efficacy of the fixes.

The vulnerabilities described in the advisory are:

• Improper restriction of excessive authentication attempts - CVE-2014-5414; and
• Exposed dangerous method of function - CVE-2014-5415


ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to gain unauthorized access to systems or read and manipulate transmitted information, especially passwords. Interestingly ICS-CERT does not apparently consider the formal academic paper on these vulnerabilities to be a public exploit that “specifically target these vulnerabilities”.

Tuesday, February 3, 2015

ICS-CERT Published Two Siemens Advisories

Today the DHS ICS-CERT published two control system advisories from products from Siemens. Both advisories are related to system communications services. The affected products are Ruggedcom WIN devices and SCALANCE-X switches.


This advisory describes multiple vulnerabilities in Ruggedcom WIN devices. The vulnerabilities were reported by IOActive in a coordinated disclosure. Siemens has produced firmware updates that mitigate these vulnerabilities but there is no indication that IOActive has confirmed the efficacy of those updates.

The vulnerabilities are:

● Improper authentication - CVE- 2015-1448;
● Buffer overflow - CVE- 2015-1449; and
● Storing passwords in a recoverable format - CVE- 2015-1357

ICS-CERT reports that a relatively unskilled attacker with network access to the devices could exploit these vulnerabilities to perform administrative actions over the network or execute arbitrary code. The Siemens advisory notes that an attacker must be able to access the log files to exploit the third vulnerability.

SCALANCE Advisory

This advisory describes an apparently self-reported user impersonation vulnerability in the SCALANCE X-200IRT Switch Family. Siemens has developed a firmware  update that mitigates the vulnerability.

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to impersonate a legitimate user on the system. The Siemens advisory notes that a successful exploit requires network access while a legitimate user is signed into the switches’ web interface.


NOTE: It is taking much less time for the CVE links in the ICS-CERT advisories to point to active pages. It used to take a day or two (business days). The CVE’s in both advisories were active this evening. That may be because they were originated yesterday. Still it is nice to see live links being provided instead of early links.

Thursday, September 4, 2014

ICS-CERT Publishes Traffic Light Sensor Advisory

Today the DHS ICS-CERT published an advisory for a special kind of control system; the the Sensys Networks traffic sensors. The twin vulnerabilities covered in the advisory were initially reported by Cesar Cerrudo of IOActive. Sensys has produced updated versions for two of the three affected products with the third scheduled to be released later this month. There is no indication that Cerrudo has been given the opportunity to verify the efficacy of the mitigation.

The twin vulnerabilities are:

• Download of code without integrity check - CVE-2014-2378; and
• Missing encryption of sensitive data - CVE-2014-2379

ICS-CERT notes that it would take a highly skilled attacker to exploit these vulnerabilities, but it could be done from a neighboring network.

The advisory does not mention that the vulnerabilities were publicly disclosed in an article in Wired magazine and was presented at the 2014 Infiltrate Conference. Nor does it mention that the vulnerabilities were publicly denied by Sensys as late as early last month. So this was hardly a coordinated disclosure and would typically have called for an alert in April.

I can guess why there was no alert from ICS-CERT; this is an industrial control system only in the widest possible definition of the term. Which begs the question; why there was an advisory published today? The only answer that I can think of is that sensor systems like this are destined to become part of a wider network of fully automated traffic systems that would include control of vehicles traversing the system. This advisory may serve as an attempted wake-up call to vehicle control system designers that their un-hackable systems are just as vulnerable as other control systems.


That may be an important effort (if that was the impetus for this advisory), but not if it took away from efforts to deal with control system vulnerabilities that could threaten large populations.

Thursday, September 12, 2013

ICS-CERT Publishes Siemens SCALANCE Advisory

Yesterday the DHS ICS-CERT published a control system security advisory for the Siemens SCALANCE X-200 switch family. The Web session hijack vulnerability was reported by Eireann Leverett of IOActive in a coordinated disclosure.

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to hijack a Web session due to insufficient entropy in the switch’s random number generator. This could allow an attacker to change device configurations.


ICS-CERT reports that Siemens has produced a firmware upgrade that remediates the vulnerability. There is no indication in the advisor or the Siemens-CERT advisory that Leverett or IOActive have verified the efficacy of the upgrade.

Thursday, September 5, 2013

ICS-CERT Publishes ProSoft Advisory

Today the DHS ICS-CERT published a control system advisory for a weak pseudo random number generator (PNRG) in ProSoft Technology RadioLinx ControlScape products. The vulnerability was reported by Lucas Apa and Carlos Mario Penango Hollman, with IOActive in a coordinated disclosure.

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to generate system passwords. ProSoft has produced a patch (WARNING: this is a link to an .EXE file) that reportedly mitigates this but there is no indication that the efficacy has been verified by the IOActive researchers. ProSoft has provided a suggestion for making the current password generation system more secure without the upgrade;

“Changing the default ‘seed’ passphrase will greatly increase the entropy of passphrase generation process.”

Saturday, July 6, 2013

ICS-CERT Publishes Two Advisories

Back on Wednesday (holiday delay) the DHS ICS-CERT published two advisories affecting products from Alstom Grid and Monroe Electronics. The Alstom Grid products are used to configure protective relays sold by that company. The Monroe Electronics products are used to broadcast Emergency Alert System (EAS) messages.

Alstom Grid

This advisory concerns a self-reported improper authorization vulnerability in their MicCOM S1 Agile Software and older MiCOM S1 Studio Software (Versions of MiCom S1 Studio software from other vendors are not addressed in this advisory). This vulnerability is not remotely exploitable and requires local access action by an authorized user. The vulnerability does allow for privilege escalation.

ICS-CERT reports that Alstom Grid has released an updated version of the software that mitigates the problem. Since the vulnerability is self-reported so is the efficacy of the mitigation.

Monroe Electronics

This advisory reflects an SSH Key vulnerability reported by Mike Davis, a researcher with IOActive, in a coordinated disclosure. It affects the DASDEC-I and DASDEC-II products. It allows a moderately skilled attack to gain remote ‘root access’ to the system, allowing complete control of the system.

ICS-CERT reports that Monroe Electronics has produced a software update that mitigates this vulnerability. It does not report whether or not Mike Davis or IOActive have verified the efficacy of the update.

Expanding ICS

Both of these products are specialized control system applications that are used in relatively limited systems. Both, of course, have the capability to affect operations well outside of their control domain. There are probably thousands of these limited use control systems in use. I would bet that because the organizations producing them do not have large software development shops that there concerns with security programing are relatively limited.


I suppose that it is a sign of the increased interest in ICS security that vulnerabilities in limited application systems like these are starting to be addressed by security researchers. It is especially heartening in this instance to see a Alstom Grid self-reporting their vulnerability. That they detected it in-house is a good sign in and of itself. That they reported it to ICS-CERT is always a good thing.

Sunday, May 19, 2013

ICS-CERT Publishes TURK Gateway Advisory


On Friday (okay, it was dated Thursday, Tweeted Thursday, but it wasn’t posted on the public site until Friday) ICS-CERT published an advisory for a hard-coded credential vulnerability in two programmable gateways from TURK. The vulnerability was reported by Ruben Santamarta of IOActive in a coordinated disclosure.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability to execute arbitrary code or shut down the system, or just about anything else someone with direct access to a PLC could do (okay I added the last).

The advisory notes that TURK has developed a firmware update that removes the FTP service, but it does not state that Santamarta or anyone else from IOActive has verified the efficacy of the update. Unfortunately neither link provided in the advisory for downloading the firmware updates takes you any closer to the updates than a search page on the TURCK web site and none of the typical search terms (BL20 Update, BL20 Firmware, BL 67 Update, BL 67 Firmware, or Firmware Update) work.

Oh well, I guess it wasn’t important anyway.

Wednesday, March 27, 2013

ICS-CERT Publishes Two Metasploit Updated Advisories


Late this afternoon ICS-CERT published two updated advisories that were issued earlier this year; one for multiple vulnerabilities in CoDeSys Gateway-Web Servers and the other for a single vulnerability in the WellinTech KingView product. Both updates were necessary because the organization initially reporting the vulnerability had recently released a Metasploit module for exploiting the identified vulnerabilities.

Both Exodus Intelligence and Ioactive have produced Metasploit modules for the vulnerabilities that they reported in coordinated disclosures. EI explains on their web page that it is their intention to provide their customers with exploit tools for vulnerabilities that they discover. Apparently Ioactive has the same policy. This is becoming a more common approach as security researchers explore a variety of business models to make their security research worthwhile.

In both of these cases the exploit modules were published well after the ICS-CERT advisories were published. Thus the vendors had time to produce and distribute patches or updates to fix the vulnerabilities before the exploit tools became publicly available. Of course, no one really knows how many of the system owners actually knew about the vulnerabilities or if they did know actually had a chance to update their systems.
 
/* Use this with templates/template-twocol.html */