Showing posts with label Kaspersky. Show all posts
Showing posts with label Kaspersky. Show all posts

Saturday, July 17, 2021

Review - Public ICS Disclosures – Week of 7-10-21

This week we have eleven vendor disclosures from Aruba Networks, Carestream, CODESYS, Hitachi-ABB Power Grids, Philips, PulseSecure (2), SonicWall (2), and VMware (2). We have an updated disclosure from HMS. There are ten researcher reports for products from Advantech (4), Rockwell (5), and Schneider. Finally, we have three exploits for products from VMware, and Aruba (2).

Aruba Advisory - Aruba published an advisory describing four vulnerabilities in their AOS-CX Devices.

Carestream Advisory - Carestream published an advisory discussing the PrintNightmare vulnerabilities.

CODESYS Advisory - CODESYS published an advisory describing six vulnerabilities in their V2 web servers.

Hitachi-ABB Advisory - Hitachi-ABB published an advisory describing a password autocomplete vulnerability in their eSOMS web application.

Philips Advisory - Philips published an advisory discussing the latest SolarWinds vulnerability.

PulseSecure #1 - PulseSecure published an advisory discussing three OpenSSL vulnerabilities.

PulseSecure #2 - PulseSecure published an advisory discussing two OpenSSL vulnerabilities.

SonicWall #1 - SonicWall published an advisory discussing two OpenSSL vulnerabilities.

SonicWall #2 - SonicWall published an advisory describing an SQL injection vulnerability in their end-of-life Secure Remote Access (SRA) products.

Advantech Reports - Talos published four vulnerability reports for six vulnerabilities in the Advantech R-SeeNet product.

Rockwell Reports - Kaspersky published five reports on vulnerabilities in the Rockwell Automation ISaGRAF Runtime product.

Schneider Report - Tenable published a report describing an authentication bypass vulnerability in the Schneider Modicon M340/M580 PLC.

VMware Exploit - Wvu published a Metasploit module for an input validation vulnerability in the VMware vCenter Server.

Aruba Exploit #1 - Aleph Security published an exploit for eight vulnerabilities in the Aruba Instant (IAP) product.

Aruba Exploit #2 - GR33NH4T published an exploit for an arbitrary file write vulnerability in the Aruba Instant (IAP) product.

For more details about the advisories see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-ab4 - subscription required.

Saturday, July 3, 2021

Review Public ICS Disclosures – Week of 6-26-21

This week we have twelve vendor disclosures from Aruba, Carestream, Hitachi, WAGO, HMS, Philips, QNAP (5), and Tanzu. We have vendor updates from CODESYS and GE Healthcare. We have five researcher reports for products from Bosch. Finally, I would like to report that the bad links to Johnson Controls advisories that I noted (here and here) have been corrected.

Aruba Advisory - Aruba published an advisory describing thirteen vulnerabilities in their ClearPass Policy Manager.

Carestream Advisory - Carestream published an advisory [.PDF download link] discussing a third-party (Microsoft) HTTP Protocol Stack Remote Code Execution Vulnerability.

Hitachi Advisory - Hitachi published an advisory describing an OS command injection vulnerability in their Virtual File Platform.

WAGO Advisory - CERT-VDE published an advisory describing four vulnerabilities in the WAGO I/O-Check Service.

HMS Advisory - HMS published an advisory discussing the FragAttacks WiFi vulnerabilities.

Philips Advisory - Philips published an advisory discussing the PrintNightmare vulnerabilities.

QNAP Advisory #1 - QNAP published an advisory discussing the DNSpooq vulnerabilities.

QNAP Advisory #2 - QNAP published an advisory describing an XSS vulnerability in QTS and QuTS hero products.

QNAP Advisory #3 - QNAP published an advisory describing a Stored XSS vulnerability in Q'center product.

QNAP Advisory #4 - QNAP published an advisory describing a Stored XSS vulnerability in QuLog Center product.

QNAP Advisory #5 - QNAP published an advisory describing two command injection vulnerabilities in their QTS and QuTS hero products.

CODESYS Update - CODESYS published an update [.PDF download link] for their V2 web server advisory that was originally published on May 11th, 2021.

GE Healthcare Update - GE Healthcare published an update for the PACS vulnerability advisory that was originally published on December 18th, 2020.

Bosch Reports - Kaspersky published five reports for vulnerabilities in the Bosch CPP HD/MP cameras.

For more detailed information, see my article on CFSN Detailed analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-a1b  - subscription required.

Wednesday, June 9, 2021

Review - 10 Updates Published – 6-8-21

Yesterday CISA’s NCCIC-ICS published updates for ten control system security advisories for products from Rockwell and Siemens (9).

Rockwell Update

This update provides additional information on an advisory that was originally published on October 10th, 2020. This was originally published on the restricted HSIN site, so in effect this is the original public posting for this advisory. This update describes five vulnerabilities in the Rockwell ISaGRAF5 Runtime product.

Siemens Updates

• PROFINET Update #1 - This update provides additional information on an advisory that was originally published on May 9th, 2017 and most recently updated on March 9th, 2021.

• Industrial Products Update #1 - This update provides additional information on an advisory that was originally published on December 5th, 2017 and most recently updated on March 9th, 2021.

• PROFINET Update #2 - This update provides additional information on an advisory that was originally published on October 10th, 2019 and most recently updated on September 9th, 2020.

• SIMATIC Update #1 - This update provides additional information on an advisory that was originally published on September 8th, 2021.

• Industrial Products Update #2 - This update provides additional information on an advisory that was originally published on September 8th, 2020 and most recently updated on April 13th, 2021.

• SIMATIC Update #2 - This update provides additional information on an advisory that was originally published on July 9th, 2020 and most recently updated on March 9th, 2021.

• SINAMICS Update - This update provides additional information on an advisory that was originally published on April 13th, 2021.

• Linux Based Products Update - This update provides additional information on an advisory that was originally published on May 11th, 2021.

NOTE: Siemens published two additional updates that I will discuss in my ICS Public Disclosures post this weekend.

For a more detailed look at these updates see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/10-updates-published-6-8-21.  Subscription required.


Saturday, May 22, 2021

Public ICS Disclosures – Week of 5-15-21

This week we have seven vendor disclosures from Bosch, CODESYS (2), WAGO, ENDRESS+HAUSER, Siemens, and VMware. We have two vendor updates from Siemens. Finally, we have a researcher report for products from Advantech.

Bosch Advisory

Bosch published an advisory discussing an input validation vulnerability in their IndraMotion MTX, MLC and MLD and the ctrlX CORE PLC application products. This is a third-party (CODESYS) vulnerability. An update for the ctrlX CORE PLC APP is pending. Generic mitigation measures are provided.

CODESYS Advisories

CODESYS published an advisory describing an improper input validation vulnerability in their CODESYS V3 products. The vulnerability was reported by  Alexander Nochvay from Kaspersky Lab ICS CERT. CODESYS has software updates available to mitigate the vulnerability. There is no indication that Nochvay has been provided an opportunity to verify the efficacy of the fix.

CODESYS published an advisory describing a NULL pointer dereference vulnerability in their CODESYS V3 products. The vulnerability was reported by Uri Katz of Claroty. CODESYS has new versions available that mitigate the vulnerability. There is no indication that Katz has been provided an opportunity to verify the efficacy of the fix.

WAGO Advisory

CERT-VDE published an advisory discussing twelve vulnerabilities in the WAGO PLCs. These are third-party (CODESYS) vulnerabilities that were reported by JSC Positive Technologies. WAGO has new firmware versions available that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The twelve reported vulnerabilities are:

• Allocation of resources without limit or throttling - CVE-2021-21000,

• Path traversal - CVE-2021-21001,

• Heap-based buffer overflow - CVE-2021-30186,

• Stack-based buffer overflow (2) - CVE-2021-30188, CVE-2021-30189,

• Improper input validation - CVE-2021-30195,

• Improper access control - CVE-2021-30190,

• Buffer copy without checking size of input - CVE-2021-30191,

• Improperly implemented security check - CVE-2021-30192,

• Out-of-bounds write - CVE-2021-30193,

• Out-of-bounds read - CVE-2021-30194,

• Improper neutralization of special elements used in an OS command - CVE-2021-30187

NOTE: The first two vulnerabilities have apparently not yet been addressed by CODESYS and have been given CERT-VDE CPE numbers.

ENDRESS+HAUSER Advisory

CERT-VDE published an advisory discussing the KRACK attacks vulnerabilities in the ENDRESS+HAUSER Proline portfolio flow meter products. ENDRESS+HAUSER has firmware updates that mitigate the vulnerabilities.

Siemens Advisory

Siemens published an advisory describing five vulnerabilities in their n JT2Go and Teamcenter Visualization products. The vulnerabilities were reported by the Zero Day Initiative and Carsten Eiram from Risk Based Security. Siemens has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

Untrusted pointer dereference - CVE-2020-26991,

Out-of-bounds read (3) - CVE-2020-26998, CVE-2020-26999, and CVE-2020-27002, and

Stack-buffer overflow - CVE-2020-27001

NOTE: Apparently, none of the above vulnerabilities are the 0-day vulnerability that ZDI published for this product on April 28th.

VMWare Advisory

VMWare published an advisory describing three out-of-bounds read vulnerabilities in their VMware Workstation and Horizon Client for Windows. This is a third-party (Cortado ThinPrint) vulnerability. The vulnerabilities were published by Anonymous at ZDI and Hou JingYi of Qihoo 360. VMware has new versions that mitigate the vulnerabilities. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

NOTE: The Cortado web site make the following claim about ThinPrint, so these vulnerabilities may exist in other ICS products.

“Thanks to numerous OEM partnerships, ThinPrint technology components are integrated in a variety of terminals, print boxes and thin client of leading hardware manufacturers.”

Siemens Updates

Siemens published an update for their JT2Go and Teamcenter Visualization advisory that was originally published on January 12th, 2021 and most recently updated on February 9th, 2021. The new information includes:

• Moving vulnerabilities CVE-2020-26989, CVE-2020-26990, and CVE-2020-28383

to advisory SSA-663999 (see below), and

• Moving vulnerabilities d CVE-2020-26991 to SSA-695540 (see new advisory above).

NOTE: NCCIC-ICS should be updating their advisory, ICSA-21-012-03, this coming week.

Siemens published an update for their JT2Go and Teamcenter Visualization advisory that was originally published on February 9th, 2021. The new information includes:

• Removing vulnerabilities CVE-2020-26991, CVE-2020-26998, CVE-2020-26999, CVE-2020-27001, and CVE-2020-27002, and

• Adding vulnerabilities CVE-2020-28383, CVE2021-31784 (from update above).

NOTE: NCCIC-ICS should be updating their advisory, ICSA-21-040-06, this coming week.

Advantech Report

ZDI published a report describing a use of hard-coded credentials vulnerability in the Advantech BB-ESWGP506-2SFP-T industrial switches. ZDI coordinated the disclosure with NCCIC-ICS.

Sunday, May 16, 2021

Public ICS Disclosures – Week of 5-8-21, Part 2

This week we have five additional vendor notifications from QNAP (2), VMware, and Siemens (2). We also have two vendor updates from Siemens. We also have nine researcher reports for products from Moxa (4), and Siemens (5). Finally, we have three exploits for ScadaBR (2) and OpenPLC.

The sharp-eyed reader will have noted that I have not mentioned Schneider at all in yesterday’s or today’s posts. Schneider published seven new advisories and six updates on Tuesday. I am going to have to do a ‘Part 3’ to my Public ICS Disclosures post this week. I will try to get it out later today.

QNAP Advisories

QNAP published an advisory describing a command injection vulnerability in their NAS running Malware Remover 4.x. The vulnerability was reported by polict of Shielder via the Zero Day Initiative. QNAP has an update that mitigates the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

QNAP published an advisory discussing eCh0raix Ransomware. QNAP is taking the unusual step of noting that the eCh0raix ransomware has been reported to affect QNAP NAS devices. There is no mention of a particular vulnerability being used, but they do recommend (among other generic mitigation measures) not using ports 443 or 8080.

VMware Advisory

VMware published an advisory describing a cross-site scripting vulnerability in their Workspace ONE UEM console. The vulnerability was reported by Mr. Lauritz Holtmann and Mr. Leif Enders of usd AG. VMware has patches that mitigate the vulnerability. There is no indication that Holtmann has been provided an opportunity to verify the efficacy of the fix.

Siemens Advisories

Siemens published an advisory describing 13 vulnerabilities in their SINAMICS medium voltage products. Siemens has new versions for some of the products that mitigate the vulnerabilities.

The 13 reported vulnerabilities are:

• Improper restriction of operations within the bounds of a memory buffer (2) - CVE-2021-27383 and CVE-2021-27385,

• Access memory location after the end of buffer (2) - CVE-2021-27384 and CVE-2019-8280,

• Uncontrolled resource allocation - CVE-2021-27385,

• Improper initialization (4) - CVE-2019-8259, CVE-2019-8264,  CVE-2019-8265, andCVE-2019-8277,

• Out-of-bounds read (2) - CVE-2019-8260 and CVE-2019-8261,

• Heap-based buffer overflow - CVE-2019-8262,

• Stack-based buffer overflow - CVE-2019-8263,

• Improper Null termination - CVE-2019-8275,

NOTE 1: The CVE’s above with links were previously discussed by Kaspersky Labs in a report on VNC vulnerabilities.

NOTE 2: Many of these vulnerabilities were also reported earlier this week by NCCIC-ICS in the Siemens SIMATIC HMIs/WinCC Products and in the Siemens SINUMERIK products back in June of 2020

COMMENT: Siemens has been aware of these VNC problems for quite some time. I am surprised that they are just now getting around to reporting/fixing these problems in the two product lines being reported this week. I suspect that this is a problem that may have been prevented by use of a good software bill of materials.

Siemens published an advisory discussing four vulnerabilities in their Industrial PCs and CNC devices. These are third-party (Intel) vulnerabilities. Siemens is recommending updating the Bios on some of the affected products.

The four reported vulnerabilities are:

• Improper isolation of shared resources in System-on-a-chip - CVE-2020-8698,

• Improper privilege management - CVE-2020-8745,

• Improper authentication - CVE-2020-8694, and

• Improper input validation - CVE-2020-0590

Siemens Updates

Siemens published an update for their GNU/Linux subsystem advisory that was was originally published in 2018 and most recently updated on March 13th, 2021. The new information includes:

Adding the following CVEs:

CVE-2020-13529,

CVE-2020-36312,

CVE-2021-20305, and

Clarifying that the list of vulnerabilities is no longer maintained for versions below V2.8.4.

Siemens published an update for their DNSpooq – Dnsmasq advisory that was originally published on January 19th, 2021 and most recently updated on March 13th, 2021. The new information includes clarifying that a solution for SCALANCE W1750D is not expected.

NOTE: NCCIC-ICS does not update their DNSSpooq advisory for changes in vendor advisories since the NCCIC-ICS advisory links to the latest version of the vendor advisory.

Moxa Reports

Kaspersky published four reports for vulnerabilities in the Moxa NPort IA5000A Series. Moxa reported on these vulnerabilities on April 28th, 2021. The CVEs covered in the Kaspersky reports are:

CVE-2020-27149,

CVE-2020-27184,

CVE-2020-27150, and

CVE-2020-27185

NOTE: Links are to the respective Kaspersky reports.

Siemens Reports

ZDI published five reports of vulnerabilities in the Siemens Solid Edge Viewer. The vulnerabilities were reported by rgod. The vulnerabilities have been coordinated thru NCCIC-ICS with Siemens, but Siemens has not yet published an advisory for these issues. It has, however, provided CVE numbers for the vulnerabilities. The reported vulnerabilities in the ZDI reports are:

• Improper restriction of XML External Entity - CVE-2021-27492,

• Improper validation of user supplied data - CVE-2021-27490,

• Untrusted pointer dereference - CVE-2021-27496,

• Stack-based buffer overflow - CVE-2021-27494, and

• Out-of-bounds write - CVE-2021-27488

NOTE: Links are to the respective ZDI report.

ScadaBR Exploits

Fellipe Oliveira published two different exploits for a vulnerability in ScadaBr. There is a CVE number (CVE-2021-26828) provided but there is no information on that CVE in either the Mitre or NIST databases. These may be 0-day exploits. The exploits employ separate techniques:

Authenticated arbitrary file upload, and

Linux shell upload

NOTE: Links are to the exploit reports.

OpenPLC Exploit

Fellipe Oliveira published an exploit for a remote code execution vulnerability in the OpenPLC WebServer. There is no CVE number or reference to vendor notification. This may be a 0-day exploit.

Wednesday, May 12, 2021

6 Updates Published – 5-11-21

Yesterday CISA’s NCCIC-ICS published six updates for control system security advisories for products from Siemens (5) and Mitsubishi

Industrial Products Update

This update provides additional information on an advisory that was originally published on September 10th, 2019 [Corrected link and date - 7-14-21 7:33 EDT] and most recently updated on April 13th, 2021. The new information includes adding the following new affected products:

• TIM 3V-IE,

• TIM 3V-IE Advanced,

• TIM 3V-IE DNP3,

• TIM 4R-IE, and

• TIM 4R-IE DNP3

TightVNC Update

This update provides additional information on an advisory that was originally published on December 8th, 2020. Siemens revoked their underlying advisory; NCCIC-ICS update removes all of the affected products from their advisory. The original Kaspersky report did not mention Siemens products.

SIMARIS Update

This update provides additional information on an advisory that was originally published on February 9th, 2021. The new information includes:

• Updating affected product versions, and

• Providing mitigation measures.

SCALALNCE Update  

This update provides additional information on an advisory that was originally published on March 9th, 2021. The new information includes adding SIMATIC CP343-1 Advanced (incl. SIPLUS variants) to the list of affected products.

NOTE: NCCIC-ICS has still not added a reference/link to the current Siemens advisory (SSA-936080) for this vulnerability.

TCP/IP Stack Update

This update provides additional information on an advisory that was originally published on March 9th, 2021. The new information includes adding link of update version for SENTRON PAC3220.

Mitsubishi Update

This update provides additional information on an advisory that was originally published on December 8th, 2020. The new information includes:

• Adding re-boot information to ‘Risk Evaluation’,

• Updating affected version information,

• Adding mitigation information.

NOTE: NCCIC-ICS provided an incorrect date for the original version.

Other Updates

Siemens published to additional updates yesterday that NCCIC-ICS will not specifically address. I will discuss them this weekend.

Thursday, February 25, 2021

4 Advisories Published – 2-25-21

Today the CISA NCCIC-ICS published four control system security advisories for products from ProSoft Technology, Rockwell Automation, Fatek, and PerFact.

ProSoft Advisory

This advisory describes a permissions, privileges, and access controls vulnerability in the ProSoft industrial cellular gateways. The vulnerability was reported by Maxim Rupp. ProSoft has a new firmware version that mitigates the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to change the current user’s password and alter device configurations.

Note: Interesting Twitversation about this advisory today.

Rockwell Advisory

This advisory describes an insufficiently protected credentials vulnerability in the Rockwell  Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers.  The vulnerability was independently reported by Lab. of Information Systems Security Assurance, Kaspersky, and Claroty. Rockwell describes compensating controls to mitigate the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a remote unauthenticated attacker to bypass the verification mechanism and connect with Logix controllers. Additionally, this vulnerability could enable an unauthorized third-party tool to alter the controller’s configuration and/or application code.

Fatek Advisory

This advisory describes five vulnerabilities in the Fatek FvDesigner software tool. The vulnerabilities were reported by Francis Provencher and rgod via the Zero Day Initiative. Fatek is working on mitigation measures.

The five reported vulnerabilities are:

• Use after free - CVE-2021-22662,

• Access of uninitialized pointer - CVE-2021-22670,

• Stack-based buffer overflow - CVE-2021-22666,

• Out-of-bounds write - CVE-2021-22683, and

• Out-of-bounds read - CVE-2021-22638

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to read/modify information, execute arbitrary, and/or crash the application.

PerFact Advisory

This advisory describes an external control of system or configuration setting vulnerability in the PerFact OpenVPN-Client. The vulnerability was reported by Sharon Brizinov of Claroty. PerFact has a new version that mitigates the vulnerability. There is no indication that Sharon has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow for local privilege escalation or remote code execution through a malicious webpage.

Tuesday, August 25, 2020

3 Advisories Published – 8-25-20


Today the CISA NCCIC-ICS published three control system security advisories for products from WECON, Emerson, and Advantech.

WECON Advisory


This advisory describes a stack-based buffer overflow vulnerability in the WECON LeviStudioU. The vulnerabilities (see note below) were reported by Natnael Samson via the Zero Day Initiative. WECONis working on mitigation measures.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow an attacker to execute code under the privileges of the application.

NOTE: As I noted last Saturday, Samson reported 22 separate (ZDI-20-1055 thru ZDI-20-1076) stack-based buffer overflow vulnerabilities in this product. NCCIC-ICS lumped the ‘multiple buffer overflow vulnerabilities’ into a single CVE CVE-2019-16243. Samson’s ZDI reports provide the name of each of the affected modules of the program. The ZDI advisories also note that in order to exploit the vulnerabilities an authenticated user must “visit a malicious page or open a malicious file”, presumably this would require a social engineering attack.

Emerson Advisory


This advisory describes an inadequate encryption strength vulnerability in the Emerson OpenEnterprise SCADA Software. The vulnerability was reported by Roman Lozko of Kaspersky. Emerson has a new service pack that mitigates the vulnerability. There is no indication that Lozko has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker access to credentials held by OpenEnterprise used for accessing field devices and external systems.

Advantech Advisory


This advisory describes a path traversal vulnerability in the Advantech iView device management application. The vulnerability was reported by KPC via ZDI. Advantech has a new version that mitigates the vulnerability. There is no indication that KPC has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to read/modify information, execute arbitrary code, limit system availability, and/or crash the application.

Tuesday, June 9, 2020

6 Advisories and 4 Updates Published


Today the CISA NCCIC-ICS published six control system security advisories for products from Siemens (4), Mitsubishi Electric and Advantech. They also updated four advisories for products from Philips, Siemens (2) and OSIsoft.

SINUMERIK Advisory


This advisory describes 22 vulnerabilities in the Siemens SINUMERIK products. The vulnerabilities are self-reported. Siemens has updates that mitigate the vulnerabilities.

The 22 reported vulnerabilities are:

• Buffer underflow - CVE-2018-15361,
• Heap-based buffer overflow (5) - CVE-2019-8258, CVE-2019-8262, CVE-2019-8271, CVE-2019-8273, and CVE-2019-8274,
• Improper initialization - CVE-2019-8259,
• Out-of-bounds read (3) - CVE-2019-8260, CVE-2019-8267, and CVE-2019-8270,
• Stack-based buffer overflow (3) - CVE-2019-8263, CVE-2019-8269, and CVE-2019-8276,
• Access of memory location after ends of buffer (4) - CVE-2019-8264, CVE-2019-8265, CVE-2019-8266, and CVE-2019-8280,
• Off-by-one error (2) - CVE-2019-8268, and CVE-2019-8272,
• Improper null determination - CVE-2019-8275,
• Improper initialization - CVE-2019-8277,

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow remote code execution, information disclosure, and denial-of-service attacks under certain conditions.

Note: according to the Siemens advisory these are third-party vulnerabilities (in this case, UltraVNC, a remote access system) – that were reported by Kaspersky. A number of other VNC systems were included in that report.

SIMATIC Advisory #1


This advisory describes two vulnerabilities in the Siemens SIMATIC and SINAMICS products. The vulnerabilities were reported by Nadav Erez of Claroty. Siemens has new versions that mitigate the vulnerabilities. There is no indication that Erez has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Uncontrolled search path - CVE-2020-7585, and
• Heap-based buffer overflow - CVE-2020-7586

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to affect the availability of the devices under certain conditions.

NOTE: According to the Siemens advisory the vulnerabilities were reported by Uri Katz of Claroty.

SIMATIC Advisory #2


This advisory describes an unquoted search path or element vulnerability in the Siemens SIMATIC, SINAMICS, SINEC, SINEMA and SINUMERIK products. This vulnerability was reported by Ander Martinez of Titanium Industrial Security via INCIBE. Siemens has some updates that mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with authorized local access could exploit the vulnerability to execute custom code with SYSTEM level privileges.

LOGO! Advisory


This advisory describes a missing authentication for critical function vulnerability in the Siemens LOGO! Product. The vulnerability was reported by Alexander Perez-Palma of Cisco Talos and Emanuel Almeida of Cisco Systems. Siemens has provided generic mitigation measures for this vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to read and modify device configurations and obtain project files from affected devices.

NOTE: The Siemens advisory says that an attacker would have to have access to port 135/tcp to exploit this vulnerability.

Mitsubishi Advisory


This advisory describes a resource exhaustion vulnerability in the Mitsubishi MELSEC iQ-R series modules. The vulnerability was reported by Yossi Reuven of SCADAfence. Mitsubishi has provided generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause the Ethernet port to enter a denial-of-service condition.

Advantech Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Advantech WebAccess Node. The vulnerability was reported by Z0mb1E via the Zero Day Initiative. Advantech has a patch that mitigates the vulnerability. There is no indication that Z0mb1E has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to crash the application being accessed; a buffer overflow condition may allow remote code execution.

Philips Update


This update provides additional information on an advisory that was originally published on August 16th, 2018. The new information includes:

• Extending the expected update publication from mid-2019 to 3rd Quarter 2020, and
• Change mitigation instructions for PageWriter TC50 and TC70,

SIMATIC Update


This update provides additional information on an advisory that was was originally published on December 10th, 2019 and most recently updated on March 10th, 2020. The new information includes:

• Revised version and mitigation information for  SIMOCODE pro V PN, and
• Clarified update version information for SINAMICS G130/G150/S150 and SINAMICS S120

Industrial Products Update


This update provides additional information on an advisory that was originally published on September 10th, 2019 and most recently updated April 14th, 2020. The new information includes:

• Added products SIMATIC NET CP 443-1 OPC UA, CP 443-1 RNA, CP 442-1 RNA, CP 443-1, CP 443-1 Advanced and CP 343-1 Advanced,
• Included additional information to CP 1623 and CP 1628 regarding affected CVE,
• Added new vulnerability: Excessive data query operations in large data table - CVE-2019-8460

Other Siemens Update


There was one other Siemens update that was published today. I will cover it this weekend.

OSIsoft Update


This update provides additional information on an advisory that was originally published on May 12th, 2010. The new information includes:

• Four new affected products:
PI Connector for IEC 60870-5-104,
PI Connector for OPC-UA,
PI Connector for Siemens Simatic PCS 7, and
PI Connector for UFL
• Major change to mitigation measures

Tuesday, May 19, 2020

2 Advisories Published – 5-19-20


Today the CISA NCCIC-ICS published two control system security advisories for products from Rockwell Automation and Emerson.

Rockwell Advisory


This advisory describes two vulnerabilities in the Rockwell EDS Subsystem. The vulnerabilities were reported by Sharon Brizinov and Amir Preminger (VP Research) of Claroty. Rockwell has a patch available to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper restriction of operations within the bounds of a memory buffer - CVE-2020-12038, and
• SQL injection - CVE-2020-12034

NCCIC-ICS reported that a relatively low-skilled attacker on an adjacent network could exploit the vulnerabilities to  lead to a denial-of-service condition.

Emerson Advisory


This advisory describes three vulnerabilities in the Emerson OpenEnterprise SCADA Software. The vulnerabilities were reported by Roman Lozko of Kaspersky. Emerson has an upgrade that mitigates the vulnerabilities. There is no indication that Lozko has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Missing authentication for critical function - CVE-2020-10640,
• Improper ownership management - CVE-2020-10632, and
• Inadequate encryption strength - CVE-2020-10636

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker access to OpenEnterprise configuration services or access passwords for OpenEnterprise user accounts.

Tuesday, November 19, 2019

1 Advisory Published – 11-19-19


Today the CISA NCCIC-ICS published a control system security advisory for products from Flexera.

Flexera Advisory

This advisory describes four vulnerabilities in the Flexera FlexNet Publisher software license manager. The vulnerabilities were reported by Sergey Temnikov of Kaspersky. Flexera has a new version that mitigates the vulnerability. There is no indication that Temnikov has been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Improper input validation (3) - CVE-2018-20031, CVE-2018-20032 and CVE-2018-20034; and
• Memory corruption - CVE-2018-20033

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to deny the acquisition of a valid license for legal use of the product. The memory corruption vulnerability could allow remote code execution.

Previously Reported


These same four CVE#s were reported by Schneider in their Floating License Manager back in May 14th, 2019 followed by an NCCIC-ICS advisory on July 11th, 2019. NIST reported the CVE#s as being in the FlexNet Publisher on March 25th, 2019 with the following link to the Flexera advisory (registration required).

The FlexNet Publisher is fairly obviously being used by Schneider. We have seen this sort of vulnerability pairing between the two products on multiple occasions. I suspect that other vendors are also using FlexNet Publisher in their products. Should we be seeing more vulnerabilities on these 4 CVE’s? Apparently only if other researchers like Temnikov check other license managers to see if they can see the same problem.

Thursday, July 13, 2017

S 1519 Introduced – FY 2018 NDAA

Earlier this week Sen. McCain (R,AZ) introduced S 1519, the National Defense Authorization Act for Fiscal Year 2018. The bill has already been marked up in the Senate Armed Services Committee. The House version of this bill is currently being considered on the floor of the House. The bill includes a number of cyber provisions.

Those provisions include:

§510. Service credit for cyberspace experience or advanced education upon original appointment as a commissioned officer.
§1042. Department of Defense integration of information operations and cyber-enabled information operations.
§1621. Policy of the United States on cyberspace, cybersecurity, and cyber warfare.
§1622. Cyber posture review.
§1623. Modification and clarification of requirements and authorities relating to establishment of unified combatant command for cyber operations.
§1624. Annual assessment of cyber resiliency of nuclear command and control system.
§1625. Strategic Cybersecurity Program.
§1626. Evaluation of agile acquisition of cyber tools and applications.
§1627. Report on cost implications of terminating dual-hat arrangement for Commander of United States Cyber Command.
§1628. Modification of Information Assurance Scholarship Program.
§1629. Measuring compliance of components of Department of Defense with cybersecurity requirements for securing industrial control systems.
§1630. Exercise on assessing cybersecurity support to election systems of States.
§1630A. Report on various approaches to cyber deterrence.
§1630B. Prohibition on use of software platforms developed by Kaspersky Lab.

Only one of these provisions (§1629) specifically addresses industrial control system operations.

ICS Compliance


Section 1629 requires DOD to modify its Cyber Scorecard (part of the DOD Cybersecurity Discipline Implementation Plan) to specifically address securing “the industrial control systems of the Department against cyber threats, including supervisory control and data acquisition systems (SCADA), distributed control systems (DCS), programmable logic controllers (PLC), and platform information technology (PIT)” {§1629(a)}.

Kaspersky Lab


Section 1630B is the much-publicized prohibition of DOD use or continued use products from the Kaspersky Lab. There is nothing in the language of §1630B (or in the Committee Report on the bill) that explains the reason for the prohibition.

Moving Forward


This bill is one of the ‘required’ bills that will be passed each year. The bill will be taken up by the Senate, probably before the summer recess starts in August. The process will include a substantial number of amendments to be considered. Once the bill passes in the Senate, a conference committee will take up the differences between the House version (HR 2810) and this bill.

Commentary


If the §1629 provisions make it into the final bill, DOD will have to substantially re-write their Cybersecurity Discipline Implementation Plan. The current document is IT-centric with no mention of control systems or their unique security issues.


The Kaspersky provision is pure political theater; anti-Russian posturing at its worst. Interestingly, the ‘immediately’ provisions of the section do not become effective until October 1st, 2018 {§1630B(c)}, theoretically one year after this bill becomes effective. I suspect that this unusual provision was added to allow calmer heads to remove this requirement after the political capital is harvested.
 
/* Use this with templates/template-twocol.html */