Showing posts with label Johnson and Johnson. Show all posts
Showing posts with label Johnson and Johnson. Show all posts

Saturday, September 25, 2021

Review - Public ICS Disclosures – Week of 9-18-21

This week we have seven vendor disclosures from ABB, Pilz, Hitachi, Johnson and Johnson, Philips, SonicWall, and VMware.

ABB Advisory - ABB published an advisory describing an integrity check bypass vulnerability in their free@home System Access Point products.

Pilz Advisory - VDE CERT published an advisory discussing the  INFRA:HALT vulnerabilities in Pilz products.

Hitachi Advisory - Hitachi published an advisory describing an authentication bypass vulnerability in their Disk Array Systems.

Johnson and Johnson Advisory - Johnson and Johnson published an advisory discussing the BadAlloc vulnerabilities in their products.

Philips Advisory - Philips published an advisory discussing two recently reported Apple® vulnerabilities.

SonicWall Advisory - SonicWall published an advisory describing an improper limitation of a file path to a restricted directory vulnerability in their SMA 100 Series Appliances.

VMware Advisory - VMware published an advisory describing 19 vulnerabilities in their vCenter Server and Cloud Foundation products.

For more details about the advisories, including listing of VMware multiple vulnerabilities and links to researcher advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-9-7bc - subscription required.

Saturday, September 18, 2021

Review - Public ICS Disclosures – Week of 9-11-21 – Part 1

This week we have nine vendor disclosures from BD, HPE, Johnson and Johnson, Milestone, Moxa (2), and Ovarro (3). We have two updates from Mitsubishi. We also have four vendor reports from Tenable about vulnerabilities in GPS systems. Finally, we have an exploit for Geutebruck cameras.

BD Advisory - BD published an advisory discussing the BadAlloc vulnerabilities.

HPE Advisory - HPE published an advisory describing six vulnerabilities in their SAN Switches with Brocade Fabric OS.

Johnson and Johnson Advisory - Johnson and Johnson published an advisory discussing the PrintNightmare vulnerability.

Milestone Advisory - Milestone published an advisory describing an unsecured credential storage vulnerability in their XProtect® VMS product.

Moxa Advisory #1 - Moxa published an advisory describing nine vulnerabilities in their MXview Series Network Management Software.

Moxa Advisory #2 - Moxa published an advisory describing two uncontrolled resource vulnerabilities in their MGate MB3180/MB3280/MB3480 Series Protocol Gateways.

Ovarro Advisory #1 - Ovarro published an advisory describing a classic buffer overflow vulnerability in their MS-CPU32-S2 and LT2 products.

Ovarro Advisory #2 - Ovarro published an advisory describing a path traversal (?) vulnerability in their TWinSoft product.

Ovarro Advisory #3 - Ovarro published an advisory describing a weak encryption vulnerability in their TWinSoft product.

Mitsubishi Update #1 - Mitsubishi published an update for their WEB Functions of Air Conditioning Systems advisory that was originally published on July 1st, 2021.

Mitsubishi Update #2 - Mitsubishi published an update for their Denial-of-Service Vulnerability in Multiple Air Conditioning Systems advisory that was originally published on July 1st, 2021.

GPS Report #1 - Tenable published a report on five vulnerabilities in the LandAirSea Silver Cloud web site.

GPS Report #2 - Tenable published a report describing five vulnerabilities in the Spytec GPS platform web site.

GPS Report #3 - Tenable published a report describing 12 vulnerabilities in the Optimus GPS platform web site.

GPS Report #4 - Tenable published a report describing three vulnerabilities in the Tracki/Trackimo GPS platform web site.

Geutebruck Exploit - Titouan Lazard and Ibrahim Ayadhi have published a Metasploit module for a buffer overflow vulnerability in the Geutebruck G-Cam EEC-2xxx and G-Code EBC-21xx, EFD-22xx, ETHC-22xx, and EWPC-22xx devices.

For more details on these advisories and reports, including links to third party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-7ed - subscription required.

Saturday, January 9, 2021

Public ICS Disclosures – Week of 1-2-21

This week we have six vendor disclosures from Siemens Healthineers, PEPPERL+FUCHS, Johnson and Johnson, Meinberg, Ruckus, and WIBU systems. There is an updated disclosure from HMS. Finally, there is a researcher report on vulnerabilities in products from Rockwell Automation.

Siemens Advisory

Siemens published an advisory describing a third-party (Telerik UI) java script deserialization vulnerability in their syngo.via software. The vulnerability was reported by Ryan Wincey from Securifera and Austin Nuttal. Siemens has patches for some of the affected versions. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NOTE: There are exploits available (here and here) for the underlying Telerik vulnerability.

PEPPERL+FUCHS Advisory

CERT VDE published an advisory describing six vulnerabilities in the PEPPERL+FUCHS Comtrol IO-Link Master product. The vulnerabilities were reported by T. Weber of SEC Consult Vulnerability Lab. PEPPERL+FUCHS has new versions that mitigate the vulnerabilities. There is no indication that Weber has been provide an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Cross-site scripting (2) - CVE-2020-12511 and CVE-2020-12512,

• OS Command injection - CVE-2020-12513,

• Null pointer dereference - CVE-2020-12514,

• Out-of-bounds read - CVE-2018-20679, and (CISCO vuln, exploit available)

• Key management errors - CVE-2018-0732 (OpenSSL vuln)

Johnson and Johnson Advisory

Johnson and Johnson published an advisory announcing a new version of the Biosense Webster CARTO® 3 Systems that provides mitigation measures for a number of third-party (Windows OS) vulnerabilities.

Meinberg Advisory

Meinberg published an advisory describing a third-party (OpenSSL) null pointer dereference vulnerability in their LANTIME firmware. This vulnerability is self-reported. Meinberg has new versions that mitigate the vulnerability.

Ruckus Advisory

Ruckus published an advisory describing an arbitrary file read vulnerability in their Access Point products. The vulnerability is self-reported. Ruckus has new firmware versions available that mitigate the vulnerability.

WIBU Systems Advisory

WIBU Systems published an advisory describing three third-party (XStream) vulnerabilities in their AxProtector for Java product. The vulnerabilities are self-reported. They note that the AxProtector for Java is not affected itself by any of these vulnerabilities because a whitelist is used, but they are providing an update that mitigates the XStream vulnerabilities. Exploits are available for all three vulnerabilities at the links below.

The three reported vulnerabilities are:

• Command injection - CVE-2020-26217,

• Server-side request forgery - CVE-2020-26258, and

• OS command injection - CVE-2020-26259

HMS Update

HMS published an update of their Amnesia:33 vulnerabilities advisory that was originally published on December 11th, 2020. The new information includes adding additional products to the ‘confirmed not affected’ list.

Rockwell Report

Talos published a report describing a denial-of-service vulnerability in the Rockwell RSLinx classic ethernet/IP server. This is a coordinated disclosure, but Rockwell has not yet published an advisory describing this vulnerability. The Talos report contains proof-of-concept code.

Saturday, November 7, 2020

Public ICS Disclosures – Week of 10-31-20

This week we have seven vendor disclosures from BD, Johnson and Johnson, Moxa (2), Philips, Rockwell, and Sick. We also have two researcher reports about in the wild exploits for a vulnerability in products from Oracle that apparently affects a product from Siemens.

BD Advisory

BD published an advisory discussing the Netlogon vulnerability affect on products from BD. The advisory contains a list of potentially affected products. BD provides generic guidance on mitigation measures for this vulnerability.

Johnson and Johnson Advisory

Johnson and Johnson published an advisory discussing the Ryuk ransomware advisory from the Federal Government. The advisory notes that there are no Johnson and Johnson medical device products directly affected.

Moxa Advisories

Moxa published an advisory describing an incorrect default permissions vulnerability in their MXview Series network management software. The vulnerability was reported by Yuri Kramarz of Cisco Talos. Moxa has a new firmware version that mitigates the vulnerability. There is no indication that Kramarz has been provided an opportunity to verify the efficacy of the fix.

NOTE: The Talos report includes proof of concept code.

Moxa published an advisory describing six vulnerabilities in their EDR-810 series security router. The vulnerabilities were reported by BDU FSTEC. Moxa has new firmware that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities include:

• Execute Arbitrary Commands - BDU:2020-01269,

• Denial of Service - BDU:2020-04912, and

• No response from system (4) - BDU:2020-04913, BDU:2020-04914, BDU:2020-04915, and BDU:2020-04916.

NOTE 1: BDU FSTEC reports (see here for example) that these vulnerabilities were discovered in July 2018. This may be of concern since FSTEC is the Russian Federal Service for Technical and Export Control. I do not know what sort of links FSTEC may have to Russian intelligence or security services.

NOTE 2: The ‘BDU’ numbers are the FSTEC reporting numbers (similar to CVE’s?). They can be found here.

Philips Advisory

Phillips published an advisory discussing the Oracle WebLogic RCE vulnerability. Philips currently lists just one product (Tasy EMR v12.2.1.3) as being affected by this vulnerability.

Rockwell Advisory

Rockwell published an advisory discussing an HTTP session management vulnerability in their Stratix 5700 switch. This is a third-party (classic Cisco IOS) vulnerability. The vulnerability was reported by Amazon. Rockwell has a new version that mitigates the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

Sick Advisory

Sick published an advisory [.PDF download link] discussing a Windows® TCP/IP remote code execution vulnerability (CVE-2020-16898) in their Package Analytics product. Sick recommends applying the applicable Windows update.

Oracle Reports

FireEye published two reports (here and here) about on-going exploits of a classic buffer overflow vulnerability the Oracle Solaris enterprise operating system. Normally I would not cover vulnerabilities in this product, but Ralph Langner published a Tweet indicating that this vulnerability affected the Siemens SPPA-T2000.

Commentary

We are seeing an increasing number of reports of third-party vulnerabilities. I suspect that these reports are just sightings of the tips of the various control system icebergs out there. We will not know really how wide-spread and dangerous these vulnerabilities are until vendors are forced to look at reported vulnerabilities in their component systems provided by third parties.

Wednesday, October 5, 2016

ICS-CERT Publishes Medical Device Advisory

This morning the DHS ICS-CERT published a medical control system advisory for multiple vulnerabilities in the Animas OneTouch Ping insulin pump system. The vulnerabilities were reported by Jay Radcliff of Rapid7 (Note: ICS-CERT does not credit Jay, just Rapid7). Animas (a subsidiary of Johnson and Johnson) has published compensating controls, but will not (apparently) be releasing a patch or new version to mitigate the vulnerabilities. Animas is directly notifying patients and health care professionals about the vulnerabilities and compensating controls.

The vulnerabilities reported are:

• Cleartext transmission of sensitive information - CVE-2016-5084;
• Use of insufficiently random values - CVE-2016-5085; and
• Authentication bypass by capture-replay - CVE-2016-5086

While ICS-CERT reports that detailed “vulnerability information is publicly available that could be used to develop an exploit that targets these vulnerabilities”, they claim that it would take a skilled attacker to remotely exploit the vulnerabilities. This may because an RF transceiver and relatively close access (normally 10 meters) would be required to exploit these vulnerabilities.

Rapid7 published their report on these vulnerabilities on their web site on September 28th. The Animas patient letter was dated yesterday.

Commentary


I noted in a TWEET® this morning: “Inefficient but effective workarounds, how about an update to correct the problem? Or would that require complete redesign?” ICS-CERT briefly addresses this efficiency issue by noting that the “compensating controls may impact device functionality”. Radcliffe reminds us in the Rapid7 report that:

“First, know that we take risks every day. We leave the house. We drive a car. We eat a muffin. We guess the amount of carbs. All entail risk. This research uncovers a previously unknown risk. This is similar to saying that there is risk of an asteroid hitting you, a car accident occurring or miscalculating the amount of insulin for that muffin you ate. Some of those risks are low (asteroid) some are high (insulin). This knowledge of risk allows individuals to make personal decisions. Most people are at limited risk of any of the issues related to this research. These are sophisticated attacks that require being physically close to a pump. Some people will choose to see this as significant, and for that they can turn off the rf/remote features of the pump and eliminate that risk.”


Individuals can assess their personal risk that someone would conduct an attack on their person using these vulnerabilities to personally harm them by inducing hypoglycemia through an insulin overdose; most people would rate this risk of a personal attack as very low. What would be harder for an individual to assess is the risk of someone using this set of vulnerabilities to conduct an attack on Animas or Johnson and Johnson. Even a small number of publicized attacks on individual OneTouch Ping system owners could have a very serious financial impact on Johnson and Johnson in both liability costs and negative publicity costs. Individual device owners would probably have a difficult time assessing that risk to the operation of their insulin pumps. What is sad is that I suspect that Johnson and Johnson have not really evaluated the possibility of that sort of a corporate attack since their advisory letter sounds as if it had been written by the sales department, not the legal department.
 
/* Use this with templates/template-twocol.html */