Showing posts with label Ivan Cheyrezy. Show all posts
Showing posts with label Ivan Cheyrezy. Show all posts

Friday, September 13, 2019

6 Advisories Published – 09-12-19


Yesterday the DHS NCCIC-ICS published five control system security advisories for products from 3S and a medical device security advisory for products from Philips.

Communication Server Advisory


This advisory describes a detection of error condition without action vulnerability in the CODESYS V3 products containing a CODESYS communication server. The vulnerability was reported by Martin Hartmann from cirosec GmbH. 3S has a new version that mitigates the vulnerability. There is no indication that Hartmann has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to cause a denial-of-service condition.

OPC UA Server Advisory


This advisory describes a null pointer dereference vulnerability in the CODESYS Control V3 OPC UA Server. The vulnerability is self-reported. 3S has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial-of-service condition.

Online User Management Advisory


This advisory describes an incorrect permission assignment for critical resource vulnerability in the CODESYS Control V3 online user management. The vulnerability is apparently self-reported. 3S has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow unauthorized actors access to unintended functionality and/or information.

Library Manager Advisory


This advisory describes a cross-site scripting vulnerability in the CODESYS V3 Library Manager. The vulnerability was reported by Heinz Füglister of WRH Walter Reist Holding AG. 3S has a new version that mitigates the vulnerability. There is no indication that Füglister has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow malicious content from manipulated libraries to be displayed or executed.

Web Server Advisory


This advisory describes two vulnerabilities in the CODESYS V3 web server. The vulnerability was reported by Ivan Cheyrezy of Schneider Electric. 3S has new versions that mitigate the vulnerability. There is no indication that Cheyrezy has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Path traversal - CVE-2019-13532; and
Stack-based buffer overflow - CVE-2019-13548

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to create a denial-of-service condition, to perform remote code execution, or to access restricted files.

NOTE 1: It is good to see cooperative sharing of vulnerability information between vendors, but I suspect that Schneider reported these vulnerabilities because they found them in their own product that used the CODESYS web server as a third-party component of one or more of their products. It will be interesting to see how long it takes Schneider to report these vulnerabilities.

NOTE 2: 3S has not yet reported any of the vulnerabilities in the above advisories on their web site. They did, however, publish an advisory on another product earlier this week that I will discuss tomorrow.

Philips Advisory


This advisory describes two vulnerabilities in the Philips IntelliVue WLAN, portable patient monitors. The vulnerabilities were reported by Shawn Loveric of Finite State, Inc. One of the affected WLAN versions is out-of-support and will not receive mitigation actions. Philips intends to have a patch available by the end of the year.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerabilities to cause corruption of the IntelliVue WLAN firmware and impact to the data flow over the WLAN Version A and WLAN Version B wireless modules. This would lead to an inoperative condition alert at the device and Central Station. The Phillips Advisory reports that it would take “an unauthorized user with a high skill level and access to the device’s local area network” to exploit the vulnerabilities.

Saturday, August 3, 2019

Public ICS Disclosures – Week of 07-27-19


It has been a very busy week in the ICS disclosure arena. We have vendor disclosures about the VxWorks vulnerabilities announced earlier this week; disclosures from Siemens, ABB, Schneider and Belden. We also have vendor disclosures from 3S and an update from Rockwell. Finally, we have new Metasploit module for a previously disclosed vulnerability from Schneider.

VxWorks Vulnerability


The Wind River OS vulnerabilities were just reported this week and we already have three (major) ICS vendors adding their advisories to the list of vulnerable products:

Siemens (in an out-of-cycle report);
Schneider; and
ABB, in:
AC 800PEC;
Belden

It will be interesting to see if NCCIC-ICS updates their advisory for each new vendor that adds to the list of covered products. Unfortunately, I do not expect NCCIC-ICS to provide any information about future updates (and there will be many as fixes are further applied) to the advisories published.

3S Advisories


This week, as earlier noted, 3S published 8 advisories for their CODESYS operating system, two of which NCCIC-ICS has reported. The remaining six advisories are covered below:

OPC UA Server Advisory

3S published an advisory describing a null pointer dereference vulnerability in the CODESYS Control V3 OPC UA Server. The vulnerability is self-reported. 3S has an update available to mitigate the vulnerability.

Communications Server Advisory

3S published an advisory describing a detection of error condition without action vulnerability in CODESYS V3 products containing a CODESYS communication server. The vulnerability was reported by Martin Hartmann from cirosec GmbH. 3S has a new version that mitigates the vulnerability. There is no indication that Hartmann has been provided an opportunity to verify the efficacy of the fix.

Library Manager Advisory

3S published an advisory describing a cross-site scripting vulnerability in the CODESYS V3 Library Manager. The vulnerability was reported by Heinz Füglister of WRH Walter Reist Holding AG. 3S has an update that mitigates the vulnerability. There is no indication that Füglister has been provided an opportunity to verify the efficacy of the fix.

On-Line User Management Advisory

3S published an advisory describing an incorrected inherited permissions vulnerability in the CODESYS Control V3 online user management. The vulnerability was reported by Martin Hartmann from cirosec GmbH. 3S has updates available that mitigate the vulnerability. There is no indication that Martin has been provided an opportunity to verify the efficacy of the fix.

Channel Management Advisory

3S published an advisory describing an uncontrolled memory allocation vulnerability in CODESYS Gateway V3 memory management. The vulnerability was reported by Martin Hartmann from cirosec GmbH. 3S has an update available that mitigates the vulnerability. There is no indication that Martin has been provided an opportunity to verify the efficacy of the fix.

Web Server Advisory

3S published an advisory describing a directory traversal vulnerability in the CODESYS V3 web server. The vulnerability was reported by Ivan Cheyrezy of Schneider Electric. 3S has an update that mitigates the vulnerability. There is no indication that Cheyrezy has been provided an opportunity to verify the efficacy of the fix.

Rockwell Update


Rockwell published an update to their advisory on PanelView 5510 Graphic Terminals that was originally published on July 9th, 2019. The update includes:

Modified description of the vulnerability;
Revision of the recommended work arounds; and
Provided a link for CVE-2019-10970

Schneider Metasploit


Lucas Dinucci published a Metasploit module for a previously disclosed vulnerability in the Schneider Electric Pelco Endura NET55XX webUI.

Saturday, February 23, 2019

Public ICS Disclosures – Week of 02-16-19


This week we have one vendor disclosure for products from CODESYS and two exploits for previously disclosed vulnerabilities for products from NUOO.

CODESYS Advisory


CODESYS has published an advisory that describes a directory traversal vulnerability in their runtime system. This vulnerability was reported by Ivan Cheyrezy of Schneider Electric. 3S has released a new version that mitigates the vulnerability. There is no indication that Cheyrezy has been provided an opportunity to verify the efficacy of the fix.

NOTE: Somehow, I suspect that Schneider identified this vulnerability in one of their products and traced it back to CODESYS code in that product. We may be seeing a Schneider advisory for this vulnerability in the near future.

NUOO Exploits


Pedro Ribeiro published two Metasploit modules for two vulnerabilities (here and here) that he had previously disclosed through NCCIC-ICS for vulnerabilities in the NUOO Central Management Software platform.

The two vulnerabilities for which the Metasploit modules were published are:

• Unrestricted upload of file of dangerous type; and
SQL injection


 
/* Use this with templates/template-twocol.html */