Showing posts with label John Leitch. Show all posts
Showing posts with label John Leitch. Show all posts

Thursday, July 17, 2014

ICS-CERT Publishes Three New Advisories

Today the DHS ICS-CERT published three new control system advisories affecting control system products from Advantech, Cogent and Siemens.

Advantech Advisory

This advisory reports on 5 different vulnerabilities in the Advantech WebAccess application. The vulnerabilities were reported by Dave Weinstein, Tom Gallagher, John Leitch, and others via the Zero Day Initiative (ZDI, but not currently listed on their ‘published advisories’ page). ICS-CERT notes that a new version of the application is available that corrects the problems but there is no indication that the reporting researchers have been given a chance to verify the efficacy of the mitigation efforts.

The vulnerabilities include:

• Stack-based buffer overflows (11 separate instances), CVE-2014-2364;
• Remote code execution, CVE-2014-2365;
• Password disclosure, CVE-2014-2366;
• Remote authentication bypass, CVE-2014-2367
• Unsafe ActiveX control marked safe for scripting, CVE-2014-2368

ICS-CERT reports that a moderately skilled attacker could use the publicly available exploits for these vulnerabilities to execute arbitrary code on the system. The advisory notes that the new version 7.2 corrects these deficiencies. The WebAccess site reports that the v7.2 available for download is ‘Trial Software’ and still has v7.1 available for free download without mention of these vulnerabilities.

Cogent Advisory

This advisory reports a code injection vulnerability in the Cogent DataHub application. The vulnerability was reported by John Leitch via ZDI (but again not currently listed there). A new version of DataHub is available that reportedly corrects these vulnerabilities, but there is no indication that Leitch has had an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could use the publicly available exploit to remotely execute arbitrary code.

In addition to making an updated version available for download, Cogent advises that an owner/operator could mitigate the vulnerability by:

• Disabling the web server component in their Cogent DataHub installation, or
• Configuring their network security to block access to the Cogent DataHub web server from untrusted locations.

Siemens Advisory

This advisory reports four vulnerabilities that relate to the OpenSSL software used by previously unreported Siemens applications. These vulnerabilities were self-reported by Siemens. Upgrades are available for some of the applications and Siemens has provided alternative mitigation measures for the others.

ICS-CERT reports that the four vulnerabilities include:

• A man-in-the-middle vulnerability, CVE-2014-0224; and
• Three separate improper input validation vulnerabilities, CVE-2014-0198, CVE-2010-5298, and CVE-2014-3470
NOTE: All of these CVE are existing OpenSSL vulnerability reports

The Siemens ProductCERT advisory reports that the updated versions of APE 2.0.2 and WinCC OA (PVSS) 3.12-P009 are available. Updates for the below listed products are being prepared, but the advisory provides alternative mitigation measures to be used in the interim.

• ROX 1: all versions (only affected if Crossbow is installed)
• ROX 2: all versions (only affected if eLAN or Crossbow is installed)
• S7-1500: all versions

• CP1543-1: all versions

Thursday, May 15, 2014

ICS-CERT Publishes 3 HeartBleed, 1 SQL Injection and 1 Certificate Advisories

Today the DHS ICS-CERT published five advisories; one an update of the generic OpenSSL Alert and two new control system HeartBleed advisories, a security certificate advisory and a good ‘old-fashioned’ SQL Injection advisory.

Generic OpenSSL Advisory

Instead of continuing to provide ‘letter’ updates to the original OpenSSL Alert (last updated 4-29-14), ICS-CERT upgraded the document to an Advisory. There is a lot of new information in the new Advisory, including discussions of:

• Impact;
• Background;
• The vulnerability;
• Mitigation overview;
• OpenSSL scanning;
• Detection signatures;
• Specialized search engines;

At first glance it is disappointing that there is not a list of affected and unaffected systems included in the Advisory the way there was in the earlier Alert. On closer inspection there is a download link to a spread sheet that provides that information in much more detail. I would have preferred something that would have let you know the latest date that the list had been updated (today’s was last updated 5-15-14).

Two Product Specific HeartBleed Advisories

The two product specific Advisories are for products from Unified Automation and Schneider. The UA advisory contains a link to their description of the HeartBleed vulnerability. The Schneider advisory notes that the problem is not actually theirs; it exists in a third party component (from Tableau Software). As always this raises the question of what other vendors may be using the offending application in their products and thus have the same vulnerability.

SQL Injection

This advisory is for an SQL injection advisory for CSWorks software. The vulnerability was reported by John Leitch in a coordinated disclosure via the Zero Day Initiative. CSWorks has produced an updated version that mitigates the vulnerability, though there is no mention if Leitch has verified the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to possibly execute arbitrary code.

The CSWorks security release for this vulnerability reminds system administrators that under “no circumstances should administrators give root access to CSWorks”.

Certificate Vulnerability

This advisory is for a certificate verification vulnerability in the Siemens RuggedCom Rox devices. This is apparently a self-identified vulnerability and Siemens is still working on firmware updates for the affected systems.

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to execute a man-in-the-middle attack.

Pending the production of firmware updates Siemensrecommends the following interim mitigation measures:

• Secure Syslog: Siemens recommends placing the syslog server inside the trusted
network boundary until a corrected update is made available.
• Software upgrade: When updating devices running the affected ROX versions, the
identity of the update server cannot be ensured. Siemens recommends placing the
upgrade server inside the trusted network boundary.

• FTPS: Siemens recommends using SFTP for data transfer until a corrected update is available.
 
/* Use this with templates/template-twocol.html */