Showing posts with label JanTek. Show all posts
Showing posts with label JanTek. Show all posts

Saturday, November 4, 2017

Public ICS Disclosure – Week of 10-29-17

This week Karn Ganeshen provided proof of concept (POC) information on three previously published ICS-CERT vulnerabilities and Joel Langill provided a link to an ABB KRACK advisory.

POC Information


Karn continues to use the FullDisclosure web site to provide to provide additional information about control system vulnerabilities that he has previously disclosed through the DHS ICS-CERT. This week he has provided POC information on the following control system vulnerabilities:

Progea Movicon SCADA/HMI – earlier reported here (there was no mention of publicly available POC in the ICS-CERT advisory);
JanTek JTC-200 – earlier reported here (publicly available POC was mentioned in ICS-CERT advisory); and
SpiderControl SCADA Web Server – earlier reported here (there was no mention of publicly available POC in the ICS-CERT advisory)

Based upon past experience, I do not expect ICS-CERT to update their vulnerability reports to reflect the fact that POC information is now available. Given the fact that ICS-CERT has reported that relatively low skilled attackers could exploit these vulnerabilities, I think that it is important that owners of these systems has this information available to help them appropriately assess the risks to their systems.

KRACK Vulnerability


Joel’s post on LinkedIn pointed at a cybersecurity advisory from ABB for their  ABB TropOS wireless mesh products concerning the WPA2 Key Reinstallation Vulnerabilities (also known as the Key Reinstallation Attack – KRACK).

As I pointed out in the resulting LinkedIn conversation this is the second vendor specific advisory on the KRACK vulnerability. Unlike the earlier report, ABB includes 7 of the 10 CVE found in the KRACK report, indicating that they have probably reviewed all 10 of the vulnerabilities in their system.


I continue to be disappointed in ICS-CERT for not having published a control system alert for the KRACK problem since these vulnerabilities will affect almost all ICS products that use WPA2 security for wireless communications in their control system products.

Tuesday, October 10, 2017

ICS-CERT Publishes 2 Advisories and Updates 5

Today the DHS ICS-CERT published two new control system security advisories for products from JanTek and Lava Computers MFG. They also updated five previously published control system security advisories from GE and Siemens (4).

JanTek Advisory


This advisory describes two vulnerabilities in the JanTek JTC-200 TCP/IP converter. The vulnerabilities were reported by Karn Ganeshen. JanTek will not fix the vulnerability as a replacement product is expected later this year.

The two reported vulnerabilities are:

• Cross-site request forgery - CVE-2017-5789; and
• Improper authentication - CVE-2017-5791

ICS-CERT reports that a relatively low skilled attacker could use a publicly available exploit to remotely exploit the vulnerability to allow for remote code execution on the device with elevated privileges.

Lava Advisory


This advisory describes an authentication bypass spoofing vulnerability in the Lava Ether-Serial Link. The vulnerability was reported by Maxim Rupp. ICS-CERT reports that Lava Computer MFG has not responded to requests to work with ICS-CERT on this reported vulnerability.

ICS-CERT reports that a relatively low skilled attacker with uncharacterized access to spoof the IP address of an authenticated user, assume the authenticated user’s identity, and gain privileges or access to the system.

GE Update


This update provides additional information on an advisory that was originally published on October 5th, 2017. The new information includes a link to a new version that mitigates the vulnerability. There is no indication that the researcher reporting the vulnerability was provided an opportunity to verify the efficacy of the fix.

Ruggedcom Update


This update provides additional information on an advisory that was originally published on September 28th, 2017. The new information is a new link for contacting Siemens about the firmware update that mitigates the vulnerability.

SIPROTEC Update


This update provides additional information on an advisory that was was originally published on July 6th, 2017, and updated on July 18th and again on July 28th. The new information includes updated affected version information on (and firmware update information for):

• Firmware variant Modbus TCP: All versions prior to V1.11.00;
• SIPROTEC 7SJ66: All versions prior to V4.20;
• SIPROTEC 7SJ686: All versions prior to V4.83;
• SIPROTEC 7SD686: All versions prior to V4.03

PROFINET 1 Update


This update provides additional information on an advisory that was was originally published on May 9th, 2017 and updated on June 15th, 2017, on June 20th, 2017, on July 6th, 2017, on July 25th, 2017 and again on August 17th, 2017. The update provides new affected version information and mitigation links for SIMATIC WinCC:

• V7.2 and prior: All versions
• V7.3: All versions prior to V7.3 Update 15
• V7.4: All versions prior to V7.4 SP1 Upd1

PROFINET 2 Update


This update provides additional information on an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017 and again on August 17th, 2017. The update provides new affected version information and mitigation links for:

• SIMATIC CP 1243-1 and CP 1243-1 IRC: All versions prior to V2.1.82;
• SIMATIC CP 1243-1 IEC: All versions;
• SIMATIC CP 1243-1 DNP3: All versions;
• SCALANCE M-800,S615: All versions prior to V04.03;

• SINAMICS DCM: All versions prior to V1.4 SP1 HF5;
 
/* Use this with templates/template-twocol.html */