Showing posts with label KRACK. Show all posts
Showing posts with label KRACK. Show all posts

Saturday, March 23, 2019

Public ICS Disclosures – Week of 03-16-19


CERT-VDE published an advisory describing nine vulnerabilities in the ENDRESS-HAUSER Field Xpert hand-held devices. These are the KRACK WPA2 vulnerabilities. The vulnerabilities are being self-reported. ENDRESS-HAUSER points to 3rd party mitigations for the affected devices.

NOTE: It is disappointing to note that we can still see original reporting of KRACK vulnerabilities when these were first reported in the ICS environment back in October of 2017. It is particularly aggravating in this case since the vulnerability was already reported in the affected devices by the manufacturer.

Tuesday, January 29, 2019

5 Advisories Published – 01-29-19


Today the DHS NCCIC-ICS published three control system security advisories for products from AVEVA, Mitsubishi, and Yokogawa. They also published two medical device security advisories for products from BD and Stryker.

AVEVA Advisory


This advisory describes an insufficiently protected credential vulnerability in the AVEVA
Wonderware System Platform. The vulnerability was reported by Vladimir Dashchenko from Kaspersky Lab. AVEVA has an update that mitigates the vulnerability. There is no indication that Daschenko has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow unauthorized access to the credentials for the ArchestrA Network User Account.

NOTE: I briefly discussed this advisory last Saturday.

Mitsubishi Advisory


This advisory describes a resource exhaustion vulnerability in the Mitsubishi MELSEC-Q series PLCs. The vulnerability was reported by Tri Quach of Amazon’s Customer Fulfillment Technology Security (CFTS) group. Mitsubishi has a new firmware version that mitigates the vulnerability. There is no indication that Tri has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a remote attacker to send specially crafted packets to the device, causing Ethernet communication to stop.

Yokogawa Advisory


This advisory describes an unrestricted upload of files with dangerous type vulnerability in the Yokogawa License Manager Service. The vulnerability was reported by Kaspersky Lab. The latest version mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NOTE: I briefly discussed this advisory last Saturday.

BD Advisory


This advisory describes an improper access control vulnerability in the BD FACSLyric. This vulnerability was self-reported. BD will directly apply mitigation measures to the affected systems.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to gain unauthorized access to administrative level privileges on a workstation, which could allow arbitrary execution of commands. This vulnerability does not impact BD FACSLyric flow cytometry systems using the Windows 7 Operating System.

NOTE: This is not the BD advisory that I briefly discussed last Saturday.

Stryker Advisory


This advisory describes a reusing a nonce vulnerability. advisory for the Stryker Secure II MedSurg Bed, S3 MedSurg Bed, and InTouch ICU Bed products. This is for the Key Reinstallation Attack – (KRACK) set of vulnerabilities. This advisory only reports nine of the ten CVE’s for the KRACK vulnerability. Stryker has software updates to mitigate the vulnerability.

Friday, November 2, 2018

Four Advisories and One Update Published


Yesterday the DHS NCCIC-ICS published four new control system security advisories for products from Fr. Sauter, Circontrol, Schneider Electric, AVEVA. They also updated a previously published advisory for products from Rockwell.

Sauter Advisory


This advisory describes an improper restriction of XML external entity reference in the Sauter CASE Suite application. The vulnerability was reported by Gjoko Krstic of Applied Risk. Sauter has an update that mitigates the vulnerability. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low skilled attacker could remotely exploit the vulnerability to allow an attacker to remotely retrieve unauthorized files from the system.

Circontrol Advisory


This advisory describes two vulnerabilities in the Circontrol CirCarLife electric vehicle charging station. The vulnerabilities were reported by Ankit Anubhav of NewSky Security, M. Can Kurnaz Senior Consultant at KPMG Netherlands, Alim Solmaz Security Consultant at Atos, Michael John Chief Information Security Officer at WePower Network, and Gyorgy Miru Security Researcher at Verint. Circontrol has a new version that mitigates the vulnerability. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Authentication bypass using an alternate path or channel - CVE-2018-17918; and
Insufficiently protected credentials - CVE-2018-17922

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow a remote attacker to retrieve credentials stored in clear text to bypass authentication, and see and access critical information.

Schneider Advisory


This advisory describes a DLL hijacking vulnerability in the Schneider Software Update (SESU) installed with a wide variety of Schneider products. The vulnerability was reported by Haojun Hou of ADLab of Venustech. Schneider has an update that mitigates the vulnerability. There is no indication hat Haojun has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to execute arbitrary code on the target system.

NOTE: I had previously discussed this vulnerability last weekend.

AVEVA Advisory


This advisory describes two vulnerabilities in the AVEVA InduSoft Web Studio and InTouch Edge HMI. These vulnerabilities were reported by Tenable. AVEVA has new versions that mitigate the vulnerabilities. There is no indication that Tenable was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-17916; and
• Empty password in configuration file - CVE-2018-17914

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an unauthenticated user to remotely execute code.

Rockwell Update


This update provides additional information on an advisory that was originally published on October 26th, 2017. The update provides new mitigation information based upon new limitations on the impact of the vulnerability.

NOTE: This is the KRACK vulnerability advisory for the Rockwell Stratix 5100 Wireless Access Point/Workgroup Bridge.


Saturday, June 9, 2018

Public ICS Disclosures – Week of 06-02-18


This week we have a vendor disclosure (mentioned here in passing last week) from Schneider, a vendor update from BD, and two researcher coordinated disclosures for products from Ocularis and Foscam.

Schneider Advisory


Schneider reported four vulnerabilities in their U.motion Builder product. The vulnerabilities were reported by Wei Gao from Ixia. Schneider has an update to mitigate the vulnerability. There is no indication that Wei was provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Print format vulnerability - CVE-2018-7784;
• Remote command injection - CVE-2018-7785;
• Cross-site scripting - CVE-2018-7786; and
Improper input validation - CVE-2018-7787

BD Update


BD provided a brief update to their KRACK advisory. They advised users of versions of Pyxis products that are end-of-life, end-of support, or are running unsupported, operating systems to contact their service representatives for assistance.

Ocularis Vulnerability


Talos reported a denial of service vulnerability in the Ocularis Recorder video management system which is touted as a Physical Security Information Management (PSIM) platform. The report includes proof-of-concept exploit code. Talos reported this vulnerability to the vendor on March 5th, 2018.

Foscam Vulnerabilities


The VDOO Vulnerability Research Team reported on the Full Disclosure mailing list three vulnerabilities in the Foscam IP Camera models and provided a link to their detailed report. The report includes proof-of-concept exploit code.

The three reported vulnerabilities are:

• Arbitrary file deletion vulnerability - CVE-2018-6830;
• Stack-based buffer overflow - CVE-2018-6832; and
Shell command injection vulnerability - CVE-2018-6831;

Wednesday, April 25, 2018

ICS-CERT Publishes 4 Advisories and 2 Siemens Updates


Yesterday the DHS ICS-CERT published three control system security advisories for products from Advantech, Intel and Vecna. They published a medical device security advisory for products from Becton, Dickinson and Company (BD). They also updated two control system security advisories previously published for products from Siemens. I have previously reported these two updates (here and here).

Advantech Advisory


This advisory describes three vulnerabilities in the Advantech WebAccess HMI Designer. The vulnerabilities were reported by Steven Seeley of Source Incite thru the Zero Day Initiative. No mitigation measures have yet been provided.

The three reported vulnerabilities are:

• Heap-based buffer overflow - CVE-2018-8833;
• Double free - CVE-2018-8835; and
Out-of-bounds write - CVE-2018-8837

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to remotely execute arbitrary code.

Intel Advisory


This advisory describes a classic buffer overflow vulnerability in the Intel 2G modem products. The vulnerability was reported by Dr. Ralph Phillip Weinmann and Dr. Nico Golde from Comsecuris. Intel is making firmware updates available to device manufacturers that protect systems from this vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The Intel advisory notes that: “The vulnerability affects Intel® 2G Modem products where the Earthquake Tsunami Warning System (ETWS) feature is enabled in Modem firmware.”

ICS-CERT reports that an uncharacterized attacker could remotely exploit this vulnerability to allow remote code execution.

It will be interesting to see if ICS-CERT provides us a list of the affected vendors as they update their products with the new Intel firmware. Given that this is Intel, I suspect that the list of affected vendors could be extensive.

Vecna Advisory


This advisory describes two vulnerabilities in the Vecna VGo Robot, a mobile robotic assistant. The vulnerability was reported by Dan Regalado from Zingbox. Vecna has released an update that mitigates the vulnerability. There are no indications that Regalado has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• OS command injection - CVE-2018-8866; and
• Clear transmission of sensitive information - CVE-2018-8860

ICS-CERT reports that a relatively low-skilled attacker on an adjacent network could exploit the vulnerability to capture firmware updates through network traffic and could allow remote code execution.

BD Advisory


This advisory describes the KRACK vulnerabilities in the BD BD Pyxis Products. BD is reporting being affected by 9 of the 10 reported KRACK vulnerabilities (not reporting - CVE-2017-13084: Reinstallation of the STK key in the PeerKey handshake). BD has implemented third-party vendor patches through BD's routine patch deployment process that resolves these vulnerabilities for most devices. The BD advisory that for three of the affected products coordination with customers is necessary to properly deploy patches and they are contacting the affected customers.

SIMATIC Update


This update provides new information on an advisory that was originally published on March 29th, 2018. The update provides new affected version information and mitigation measures for SIMATIC BATCH V8.0 and V8.1.

SCALANCE Update


This update provides new information on an advisory that was originally published on November 14th, 2017 and updated on December 5th, 2017, December 19th, 2017 and again on January 25th, 2018. The update provides new affected version information and mitigation measures for SCALANCE W1750D.

Tuesday, December 19, 2017

ICS-CERT Publishes 5 Advisories and 2 Updates

Today the DHS ICS-CERT published control system security advisories for products from WECON, Siemens, Ecava, PEPPERL+FUCHS and ABB. They also published updates for two previous published advisories for products from Siemens.

WECON Advisory


This advisory describes a heap-based buffer overflow in the WECON LeviStudio HMI. The vulnerability was reported by Michael DePlante working with the Zero Day Initiative (ZDI). WECON notes that the current version mitigates the vulnerability. There is no indication that DePlante was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to crash the device and a buffer overflow condition may allow remote code execution.

Siemens Advisory


This advisory describes a download of code without integrity check vulnerability in the Siemens LOGO! Soft Comfort engineering software product. The vulnerability was reported by Tobias Gebhardt. Siemens is providing SHA-256 checksums for all LOGO! Soft Comfort software packages via a secured HTTPS channel.

ICS-CERT reports that an uncharacterized attacker could remotely exploit the vulnerability to manipulate a software package during download. The Siemens security advisory reports that a successful exploitation would require that the attacker must be able to gain a privileged network position allowing him to capture and modify the affected system’s network communication.

Ecava Advisory


This advisory describes two SQL injection vulnerabilities in the Ecava IntegraXor. The vulnerabilities were independently reported by Steven Seeley of Source Incite, and Michael DePlante and Brad Taylor (working with ZDI). Ecava reports that a newer version mitigates the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to disclose sensitive information from the database or generate an error in the database log.

PEPPERL+FUCHS Advisory


This advisory describes the key reinstallation attacks (KRACK) vulnerabilities in various WLAN enabled products from PEPPERL+FUCHS. This report lists 9 of the 10 KRACK CVE’s. The vendor is still working on fixes for their Android® based products. For their Windows® based products they are recommending that users apply the security update provided by Microsoft. If users are using WPA-TKIP in their WLAN, users should switch to AES-CCMP immediately.

ABB Advisory


This advisory describes an unprotected transport of credentials vulnerability in the ABB Ellipse. ICS-CERT reports that this vulnerability was self-reported by ABB, but the ABB security advisory notes that ABB had received information about this vulnerability through responsible disclosure from an unnamed researcher. ABB has released product updates to mitigate the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to discover authentication credentials by sniffing the network traffic. ABB notes that local network access is required for the exploit.

NOTE: I reported on this vulnerability earlier this month.

Industrial Products Update


This update provides additional information on an advisory that was originally published on December 5th, 2017. It provides updated affected version information and mitigation information for:

• SIMATIC S7-400 H V6: All versions prior to V6.0.8,
• SIMATIC S7-1500: All versions prior to V2.0,
• SIMATIC S7-1500 Software Controller: All versions prior to V2.0,

SCALANCE Update


This update provides additional information on an advisory that was originally published on November 14th, 2017 and updated on December 5th, 2017. It provides updated affected version information and mitigation information for:

• RUGGEDCOM RX1400 with WLAN interface: All versions prior to V2.11.2
• SIMATIC RF350M: All versions with Summit Client Utility prior to V22.3.5.16
• SIMATIC RF650M: All versions with Summit Client Utility prior to V22.3.5.16.


Note: Siemens has issued a separate security advisory for the last two products listed above. That advisory only lists two of the 10 KRACK CVEs instead of the 10 listed in the original Siemens KRACK advisory. It is not clear why ICS-CERT merged these two advisories.

Tuesday, December 5, 2017

ICS-CERT Publishes 1 Advisory and 1 Update

Today the DHS ICS-CERT published a control system security advisory for a product from Siemens. It also updated a previously issued advisory for products from Siemens.

Siemens Advisory


This advisory describes an improper input validation vulnerability in the Siemens Industrial Products. The vulnerability was reported by George Lashenko of CyberX. Siemens has produced a firmware update that mitigates the vulnerability. There is no indication that Lashenko was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to conduct a denial-of-service (DoS) attack. The Siemens security advisory notes that the attacker requires network access to the affected devices.

Siemens Update


This update provides additional information for an advisory that was originally published on November 14th, 2017. The new information is updated affected version and mitigation information for:

• SCALANCE W-700 (IEEE 802.11n): All versions prior to V6.2.1

The associated Siemens updated security advisory also provides additional mitigating factors for:

• SCALANCE W-700 devices operated in Access Point;
• RUGGEDCOM RX1400 and RS9xxW;

KRACK Rant


The first vendor has now published a fix for the Key Reinstallation Attack – (KRACK) set of vulnerabilities that make control systems utilizing wireless systems using WPA2 security vulnerable to man-in-the-middle attacks; this is good news. Unfortunately, ICS-CERT still has not issued an alert outlining the extent of the vulnerability to the control system community. Nor have they even provided links to either the KRACK web site or the original paper describing the vulnerabilities. So much for ICS-CERT being interested in keeping the ICS community up to date on wide ranging vulnerabilities.

Wednesday, November 22, 2017

ICS-CERT Publishes Another Vendor KRACK Advisory

Yesterday the DHS ICS-CERT published a control system security advisory for WLAN enabled products from Phoenix Contact. This is for the  Key Reinstallation Attack – (KRACK) set of vulnerabilities. ICS-CERT credits the original KRACK researcher, Mathy Vanhoef of imec-DistriNet, for reporting the vulnerability, but this instance was self-reported by Phoenix Contact.

This advisory only reports three of the ten reported KRACK CVE. It is not clear if the vendor has evaluated the other potential KRACK instances and found them missing (not implemented) on their devices, or just thought that these were the most serious implementation issues in their devices.

The Phoenix Contact advisory at CERT@VDE provides much more detailed information about the extent of the vulnerability. They report:

“PHOENIX CONTACT embedded devices running in AP mode are not affected by these vulnerabilities. If devices are used in client or repeater mode, an attacker could in theory decrypt any packet sent by the client. Devices of the FL WLAN 110x, 210x, and 510x product families are only affected to a very limited extent. With these devices, only data packets sent within three seconds after key renewal could possibly be decrypted by a successful attacker. In general, if TCP SYN packets are decrypted, this can be used to hijack TCP connections and inject malicious traffic into unencrypted protocols. However, to perform the attack, the attacker must be significantly closer to the WLAN client than the access point. In industrial or indoor applications, the attacker would have to be inside the plant. A successful external attack therefore seems to be very difficult. Furthermore, the WPA2 password cannot be compromised using a KRACK attack. It is not possible for the attacker to gain full access to the network. However, note that if WPA-TKIP is used instead of AES-CCMP, the impact of this vulnerability is much more severe, because an attacker can then not only decrypt packets, but also forge and inject packets directly into the WLAN.”


TIRADE ALERT – Another vendor provides information on KRACK and ICS-CERT has still failed to publish an alert about the vulnerability, or even just a link to the original paper. I have been complaining about this inaction on the part of ICS-CERT where ever I talk about ICS security issues. I had an interesting conversation with Anton Shipulin, of Kaspersky Labs, over on LinkedIn about the issue and he noted that this could be the result of the recent NCCIC reorganization that ‘moved’ ICS-CERT into NCCIC. I still have not seen anything from DHS about the move, but if the reorganization changed the information sharing responsibilities of ICS-CERT to the control system security community, then DHS needs to reverse that change as quickly as possible. Perhaps Congress needs to look into this.

Wednesday, November 15, 2017

ICS-CERT Publishes 3 Advisories and Updates 2

Yesterday the DHS ICS-CERT published one medical system security advisory and two control system security advisories. Those advisories were for products from Philips, ABB and Siemens. They also updated two Siemens advisories.

Philips Advisory


This advisory describes an insufficiently protected credentials vulnerability in the Philips IntelliSpace Cardiovascular and Xcelera cardiac image and information management systems. This vulnerability were apparently self-reported. The Philips security page notes that the vulnerability was reported to Philips by a customer. Philips has produced a hot fix update to mitigate the vulnerability.

ICS-CERT reports that an uncharacterized attacker could remotely exploit this vulnerability to access sensitive information stored on the system, modify device configuration, and gain access to connected devices.

NOTE: The Philips security page also has a note about the KRACK vulnerability potential effect on Philips products. Research is ongoing at Philips.

ABB Advisory


This advisory describes multiple security features vulnerabilities in the ABB TropOS. These are the KRACK vulnerabilities in this product that I discussed earlier. ICS-CERT reports that ABB is still working on mitigation measures.

ICS-CERT reports that an uncharacterized attacker within radio range of the product could exploit these vulnerabilities to decrypt, replay, and forge some frames on a WPA2 encrypted network.

Siemens Advisory


This advisory describes multiple security features vulnerabilities in the Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products. These are the KRACK vulnerabilities. Siemens is continuing to work on updates.

ICS-CERT reports that an uncharacterized attacker within radio range of the product could exploit these vulnerabilities to decrypt, replay, and forge some frames on a WPA2 encrypted network.

PROFINET 1 Update


This update provides new information for an advisory that was originally published on May 9th, 2017 and updated on June 15th, 2017, on June 20th, 2017, on July 6th, 2017, on July 25th, 2017 on August 17th, 2017 and most recently on October 10th. The update provides new affected version information and mitigation links for:

• SIMATIC NET PC-Software: All versions prior to V14 SP1

PROFINET 2 Update


This update provides new information for an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, and most recently on October 10th. The update provides new affected version information and mitigation links for:

• Softnet PROFINET IO for PC-based Windows systems: All versions prior to V14 SP1
• SIMATIC ET 200AL: All versions prior to V1.0.2

KRACK Commentary



ICS-CERT publishes two vendor reports (one two-week old and the other almost a week old) of the KRACK vulnerability in wireless networks (and misses the publicly available information from a third vendor), and still does not see a problem common to all industrial and medical control systems that allow for wireless access, a problem severe enough to provide an alert on the vulnerabilities? SHAME on DHS for allowing this blindness to continue.
 
/* Use this with templates/template-twocol.html */