Showing posts with label Kirill Nesterov. Show all posts
Showing posts with label Kirill Nesterov. Show all posts

Tuesday, November 26, 2019

2 Advisories Published – 11-26-19

Today the CISA NCCIC-ICS published two control system security advisories for products from ABB.

ABB Advisory #1


This advisory describes a path traversal vulnerability in the ABB Relion 670 series. The vulnerability was reported by Kirill Nesterov of Kaspersky Lab. ABB has new versions that mitigate the vulnerability. There is no indication that Nesterov has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to read and delete files on the device.

ABB Advisory #2


This advisory describes an improper input validation vulnerability in the ABB  Relion 650 and 670 Series. The vulnerability was reported by Ilya Karpov, Evgeniy Druzhinin, and Victor Nikitin of ScadaX. ABB has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to reboot the device, causing a denial of service.

NOTE: I briefly reported on both of these vulnerabilities and a third that was also reported by ABB on the same day back in October. The third advisory dealt with OpenSSL vulnerabilities.

Saturday, October 26, 2019

Public ICS Disclosures – Week of 10-19-19


This week we have three vendor disclosures from ABB and two vendor updates from 3S and Yokogawa. There is also an exploit report for previously reported vulnerabilities in products from Moxa.

ABB Advisories


Relion® 670 series

ABB published an advisory describing a path traversal vulnerability in the MMS server included in their Relion 670 series protection and control IEDs. The vulnerability was reported by Kirill Nesterov of Kaspersky Lab. ABB has new versions that mitigate the vulnerability. There is no indication that Nesterov has been provided an opportunity to verify the efficacy of the fix.

Relion® 650 series and Relion® 670 series
ABB published an advisory describing a terminal reboot vulnerability in the SPA protocol over TCP/IP included in their Relion 650 and 670 series protection and control IEDs. The vulnerability was reported by Ilya Karpov, Evgeniy Druzhinin, Damir Zainullin of Positive Technologies and Victor Nikitin of i-Grids. ABB has updates that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Relion® 650 series and Relion® 670 series

ABB published an advisory describing four known OpenSSL vulnerabilities (CVE-2017-3737, CVE-2018-0739, CVE-2018-0737, CVE-2018-0732) in their Relion 650 and 670 series protection and control IEDs. These vulnerabilities are self-reported. ABB has updates that mitigate the vulnerabilities.

3S Update


3S published an update an advisory that was originally published on September 12th, 2019. The new information includes:

Revised affected version numbers;
Added CVE number for vulnerability; and
Revised version number for mitigation

Yokogawa Update


Yokogawa published an update for an advisory that was originally published on September 27th, 2019 and most recently updated on October 11th, 2019. The new information includes a link to the patch for the Exaquantum product.

Moxa Exploit


RANDORISEC published exploit code for two vulnerabilities in the Moxa Moxa EDR-810 Series Secure Routers. One of these vulnerabilities was addressed in an NCCIC-ICS advisory published on October 1st, 2019. The second vulnerability was reported in a Moxa advisory published on October 2nd, 2019.

Wednesday, December 12, 2018

Two Advisories and Three Updates Published – 12-11-18


Yesterday the DHS NCCIC-ICS published two control system security advisories and updates to two previously published control system advisories; all for products from Siemens. They also published a medical device security advisory for products from Philips.

SINUMERIK Advisory


This advisory describes ten vulnerabilities in the Siemens SINUMERIK Controllers. The vulnerabilities were reported by Anton Kalinin, Danila Parnishchev, Dmitry Sklyar, Gleb Gritsai, Kirill Nesterov, Radu Motspan, and Sergey Sidorov from Kaspersky Lab. Siemens has updates for several of the products and provides work arounds for the others. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The ten reported vulnerabilities are:

• Heap-based buffer overflow - CVE-2018-11457;
• Integer overflow or wraparound - CVE-2018-11458;
• Protection mechanism failure (2) - CVE-2018-11459 and CVE-2018-11460;
• Permission, privileges and access control (2) - CVE-2018-11461 and CVE-2018-11462;
• Stack-based buffer overflow - CVE-2018-11463; and
Uncaught exception (3) - CVE-2018-11464, CVE-2018-11465 and CVE-2018-11466

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to cause denial-of-service conditions, privilege escalation, or allow remote code execution.

SINAMICS Advisory


This advisory describes an improper access control vulnerability in the Siemens SINAMICS PERFECT HARMONY GH180 (based upon a 3rd party vulnerability – McAffee Application and Change Control). The vulnerability was reported by McAffee. Siemens recommends installing a McAffee update to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with physical access could exploit the vulnerability to compromise the HMI, and by extension, the drive system.

PROFINET Update


This update provides new information on an advisory that This update provides additional information on an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th,  November 28th, 2017January 18th, 2018, January 25th, 2018, January 27th, 2018, March 6th, 2018, May 3rd, 2018 and most recently on November 13th, 2018. The update provides new affected version information and mitigation measures for:

• SIMATIC ET 200MP IM155-5 PN HF; and
• SIRIUS ACT 3SU1 interface module PROFINET

Industrial Products Update


This update provides new information on an advisory that This update provides additional information on an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th, November 28th, February 27th, 2018, May 3rd, 2018 May 15th, 2018, September 11th, 2018, October 9th, 2018 and most recently on November 13th, 2018. This update provides new mitigation information for SIMATIC ET 200MP IM155-5 PN HF.

Philips Update


This update provides new information on an advisory that was originally published on March 27th, 2018. This update slips the new version expected date from ‘December 2018’ to ‘Q1 of 2019’.

Other Siemens Updates


Yesterday Siemens published a total of three new advisories and seven updates. We may see more from NCCIC-ICS later this week, but some will not be specifically addressed by NCCIC-ICS. I will have further information on the remainder on Saturday.

Thursday, March 1, 2018

ICS-CERT Published 3 Advisories and Update the Meltdown Alert


Today the DHS ICS-CERT published three new control system security advisories for products from Delta Industrial Automation, Moxa and Siemens. They also updated the previously published alert for the Meltdown and Spectre chip vulnerabilities.

Delta Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Delta DOPSoft human machine interface. The vulnerability was reported by Ghirmay Desta via the Zero Day Initiative. Delta has a new version that mitigates the vulnerability. There is no indication that Desta has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause the device the attacker is accessing to crash; a buffer overflow condition may allow remote code execution.

Moxa Advisory


This advisory describes three vulnerabilities in the Moxa OnCell high-speed industrial-grade IP gateway. The vulnerabilities were reported by Kirill Nesterov, Eugenie Potseluevskaya, and Radu Motspan of Kaspersky Labs. Moxa has released a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Reliance on cookies without validation and integrity checking - CVE-2018-5455;
• Improper handling of length parameter inconsistency - CVE-2018-5453; and
Null pointer dereference - CVE-2018-5449

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability  to remotely execute code on the device.

Siemens Advisory


This advisory describes multiple vulnerabilities in the Siemens SIMATIC, SIMOTION, and SINUMERIK industrial computers. These vulnerabilities were self-reported by Siemens. The Siemens security advisory reports that these are 3rd party vulnerabilities in the Intel Management Engine (ME), Intel Server Platform Services (SPS), and Intel Trusted Execution Engine (TXE)

The eight reported vulnerabilities are:

• Stack-based buffer overflow (5) - CVE-2017-5705, CVE-2017-5706, CVE-2017-5707, CVE-2017-5712, and CVE-2017-5711; and
• Permissions, privileges, and access controls (3) - CVE-2017-5708, CVE-2017-5709, and CVE-2017-5710

ICS-CERT reports that a relatively low-skilled attacker could remotely (some of the vulnerabilities require local access) to execute arbitrary code or gain unauthenticated access to sensitive data.

NOTE: Again, with 3rd party vulnerabilities one has to wonder what other systems will be affected. But, since Intel is such a small company (right) it is unlikely that any other vendors will use this vulnerable code (pardon the sarcasm).

Meltdown Update


This update provides additional information on an alert that was originally published on January 11th, 2018 and updated on January 16th, 2018, January 17th, 2018, January 30th, 2018, February 20th, 2018, and again on February 22nd, 2018.

The advisory provides links to new vendor reports on the vulnerabilities:

Dräger;
Pepperl+Fuchs; and

Thursday, February 15, 2018

ICS-CERT Publishes 4 Advisories and One ABB Update


Today the DHS ICS-CERT published four new control system security advisories for products from Schneider Electric (2), GE and Nortek. Additionally, they provided an update for a previously published advisory for products from ABB.

StructureOn Advisory


This advisory describes an unrestricted upload of file with dangerous type vulnerability in the Schneider StruxureOn Gateway software management program. The vulnerability is being self-reported.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to upload a malicious file to any directory on the device, which could lead to remote code execution. The Schneider security advisory reports that the file must be a .zip file with specifically modified metadata for this vulnerability to be exploited.

IGSS Mobile Advisory


This advisory describes two vulnerabilities in the Schneider IGSS Mobile application (iOS and Android). The vulnerabilities were reported by Alexander Bolshev (IOActive) and Ivan Yushkevich (Embedi). Schneider has produced updates for both versions. There is no indication that either researcher has been provided an opportunity to verify the efficacy of the fix.



The two reported vulnerabilities are:

• Improper certificate validation - CVE-2017-9968; and
Plaintext storage of password - CVE-2017-9969

ICS-CERT reports that a relatively low-skilled attacker with local access (okay they, actually said: “Locally exploitable”; that may not mean ‘local access’) could exploit the vulnerability to execute a man-in-the-middle attack. In addition, passwords can be accessed by unauthorized users.

NOTE: Marc Ayala pointed out to me that anyone can download these apps from the appropriate (iOs/Android) app store. This means that it would be easy to exploit a compromised mobile password. All the attacker needs to do is to get access to the IGSS configuration file on an oh so secure smart phone to compromise the password.

GE Advisory


This advisory describes two vulnerabilities in the GE D60 Line Distance Relay. The vulnerabilities were reported by Kirill Nesterov of Kaspersky Labs. GE has released new firmware that mitigates the vulnerability. There is no indication that Nesterov was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-5475; and
• Improper restriction of operations within bounds of memory buffer - CVE-2018-5473

ICS-CERT reports that relatively low-skilled attacker could remotely exploit the vulnerability to execute arbitrary code on the device.

Nortek Advisory


This advisory describes a command injection vulnerability in the Nortek Linear eMerge E3 Series access control interface. The vulnerability was reported by Evgeny Ermakov and Sergey Gordeychik. Nortek recommends upgrading the system using established procedures. There is no indication that either researcher was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability  to execute malicious code on the system with elevated privileges, allowing for full control of the server.

ABB Update


This update provides additional information on an advisory that was originally published on November 14th, 2017. The update reports that the new update of Mesh OS mitigates the KRACK vulnerability in these devices.

NOTE: The updated ABB security advisory that forms the basis for this ICS-CERT update was published on January 11th, 2018.

Thursday, January 25, 2018

ICS-CERT Publishes 3 Advisories and 5 Siemens Updates

Today the DHS ICS-CERT published two control system security advisories for products from Siemens and Nari as well as a medical control system security advisory for products from Philips. They also updated five control system security advisories from Siemens.

Philips Advisory


This advisory describes an insufficient session expiration advisory for the Philips IntelliSpace Cardiovascular cardiac image and information management systems. According to the Philips product security page this vulnerability was identified based upon a customer submitted complaint. Philips plans on releasing an updated version to mitigate the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker with local access could exploit the vulnerability  to gain unauthorized access to sensitive information stored on the system and modify this information.

NOTE: This vulnerability was not reported on the FDA medical device safety communications page, probably because an exploit would only reveal personally identifiable information making this more of a HIPAA problem. Unfortunately, I cannot find (after an admittedly brief search) a software vulnerability reporting page on the HHS HIPAA site.

Siemens Advisory


This advisory describes an improper authentication vulnerability in the Siemens Desigo PXC. The vulnerability was reported by Can Demirel and Melih Berk Eksioglu from Biznet Bilisim. Siemens has provided an updated version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability to  allow unauthenticated remote attackers to upload malicious firmware without prior authentication.

BTW: Siemens tweeted this morning about another new advisory that they have just published. That will probably show up next week on the ICS-CERT site.

Nari Advisory


This advisory describes an improper input validation vulnerability in the Nari PCS-9611 relay, a control and monitoring unit. The vulnerability was reported by Kirill Nesterov and Alexey Osipov from Kaspersky Labs. Nari has not responded to ICS-CERT about this reported vulnerability.

ICS-CERT reports that a relatively low-skilled attacker could use a publicly available exploit to remotely exploit the vulnerability to gain arbitrary read/write abilities on the system.

Industrial Products (older advisory) Update



• SINEMA Remote Connect Client: All versions prior to V1.0 SP3;

NOTE: The revised Siemens security notice also changed the temporary mitigation measures for SIMATIC PCS 7 V8.1, but that was not mentioned in the ICS-CERT update.

S7-300 Update


This update provides new information for an advisory that was originally published on December 13th, 2016 and then updated on May 9th, 2017, July 25th, 2017, and again on November 28th, 2017. The new information includes the addition of two new affected products along with mitigation links:

• SIMATIC S7-400 V7 CPU family; and
• SIMATIC S7-410 V8 CPU family
NOTE: The revised Siemens security notice reports that the S7-410 V8 CPU family is only affected by the inadequate encryption strength vulnerability.

PROFINET Update


This update provides new information for an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th,  November 28th, 2017, and most recently January 18th, 2018. The new information includes new affected version data and mitigation links for:

• S7-400 PN/DP V7 Incl. F: All versions prior to V7.0.2
• SINAMICS DCP w. PN: All versions prior to V1.2 HF 1

SCALANCE Update


This update provides new information for an advisory that was originally published on November 14th, 2017 and updated on December 5th, 2017, and again on December 19th, 2017. The new information includes new affected version data and mitigation links for:


• SCALANCE WLC711: All versions prior to V9.21.19.003; and
• SCALANCE WLC712: All versions prior to V9.21.19.003


Industrial Products (newer advisory) Update


This update provides new information for an advisory that was originally published on December 5th, 2017 and updated on December 19th, 2017 and again on January 23rd, 2018. The new information includes new affected version data and mitigation links for:


• SIMATIC S7-400 PN/DP V7: All versions prior to V7.0.2; and
• SIMATIC ET 200MP: All versions prior to V4.0.2

Commentary


Even if Siemens does not issue any more multiple product advisories in the near future (not likely, they have obviously shared a bunch of code across product lines over the years) we will continue to see large numbers of these advisory updates over the next year or so. Unfortunately, while vulnerable code is relatively easy to share, fixes cannot be cut and pasted so easily; too many dependencies, loops, etc. to check and modify as necessary. These time and resource-consuming exercises being undertaken by Siemens are a good example of why secure coding practices are so important; it really is easier over the life of the product to do it right the first time.


It would really be a good cybersecurity grad-student project to look at the costs that Siemens is expending to go back and correct mistakes that should have been caught before they ever made it to market.

Tuesday, September 6, 2016

ICS-CERT Publishes Siemens SIPROTEC Advisory

Today the DHS ICS-CERT published a control-system security advisory for three vulnerabilities in the EN100 Ethernet module used in the Siemens SIPROTEC 4 and SIPROTEC Compact devices. The vulnerabilities were reported by Kirill Nesterov and Anatoly Katushin from Kaspersky Lab. Siemens has produced a firmware update. There is no indication that the researchers have been provided the opportunity to verify the efficacy of the fix.

The two vulnerabilities are:

• Authentication bypass issues - CVE-2016-7112 and CVE-2016-7114; and
• Resource exhaustion - CVE-2016-7113


ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to circumvent authentication and perform administrative operations. The SiemensCERT advisory notes that all three vulnerabilities require network access to the device’s web interface (port 80/tcp).

Tuesday, October 20, 2015

ICS-CERT Publishes 3 Advisories

This afternoon the DHS ICS-CERT published three control system security advisories. Two of them were for products from IniNet Solutions and the third was from 3S.

CODESYS Advisory

This advisory describes another null pointer exception vulnerability in a CODESYS product, this time the Gateway Server. The vulnerability was reported by Ashish Kamble of Qualys, Inc. 3S has produced a new version that mitigates the vulnerability and Kamble has validated the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to crash the server.

This is the same type vulnerability that was reported last week by ICS-CERT in the CODESYS Runtime Tool Kit.

IniNet Solutions SCADA Web Server Advisory

This advisory describes three vulnerabilities in the IniNet Solutions GmbH’s SCADA Web Server. The vulnerabilities were reported by Kirill Nesterov and Aleksandr Timorin of Positive Technologies. IniNet Solutions has produced a new version that mitigates these vulnerabilities, but there is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The three vulnerabilities are:

• Stack-based buffer overflow, CVE-2015-1001;
• Improper handling of URL encoding, CVE-2015-1002; and
• Path traversal; CVE-2015-1003

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to manipulate and delete files, execute arbitrary code, and initiate a denial of service condition.

ICS-CERT also reports that the affected web server is known to be used in a variety of Beckhoff Embedded PCs. Beckhoff is apparently not accepting any responsibility for the vulnerable application.

IniNet Solution embeddedWebServer Advisory

This advisory describes a password cleartext storage vulnerability in the IniNet Solution eWebServer. The vulnerability was reported by Aleksandr Timorin of Positive Technologies. IniNet Solutions has produced a new version that mitigates the vulnerability, but there is no indication that Timorin was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker with local access could exploit this vulnerability to obtain logon information.


ICS-CERT also reports that the affected web server is known to be used in a variety of BaumĂ¼ller PCs and Beckhoff Embedded PCs. BaumĂ¼ller does not plan on updating their affected PCs because they are being retired in December. Beckhoff is apparently not accepting any responsibility for the vulnerable application.

Saturday, May 24, 2014

ICS-CERT Publishes Emersion Advisory

Note: It’s been a busy week at my real job, so some stuff is being posted much later than normal.

On Thursday DHS ICS-CERT published an advisory for two vulnerabilities in the DeltaV product from Emerson. The vulnerabilities were reported to Emerson in a coordinated disclosure by a team (Kirill Nesterov, Alexander Tlyapov, Dmitry Nagibin, Alexey Osipov, and Timur Yunusov) from Positive Technologies. Emerson has produced a patch to mitigate the vulnerabilities, but there is no indication in the advisory if Positive Technologies has had a chance to validate the efficacy of the patch.

The two vulnerabilities are:

• Improper authorization - CVE-2014-2349;
• Hard-coded credentials - CVE-2014-2350.


ICS-CERT reports that a relatively unskilled attacker with local access and a successful social engineering attack could exploit these vulnerabilities to conduct a denial of service attack or read/replace configuration files, or log into accounts.

Emerson only releases their advisories to customers so no other information on this vulnerability is publicly available.

Tuesday, February 4, 2014

ICS-CERT Publishes Two Advisories

This afternoon the DHS ICS-CERT published advisories for control systems from two major vendors, Siemens and Rockwell. Both advisories were based upon vulnerabilities discovered by outside researchers that were revealed in coordinated disclosures.

Siemens Advisory

This advisory is based upon information disclosed in a Siemens ProductCERT advisory released Monday morning for SIMATIC WinCC OA. The multiple vulnerabilities covered in these advisories were discovered by Gleb Gritsai, Ilya Karpov, and Kirill Nesterov of Positive Technologies. The vulnerabilities were:

• Improper control of generation of code, CVE-2014-1697;
• Relative path traversal, CVE-2014-1698;
• Improper input validation, CVE-2014-1699; and
• Use of password hash with insufficient computational effort, CVE-2014-1696
NOTE: The CVE links have not yet become active.

Both advisories note that a moderately skilled attacker could remotely exploit the vulnerabilities to escalate their privileges, perform remote code execution, traverse through file systems, or cause a denial of service. Siemens does note that an attacker would have to have network access to exploit these vulnerabilities.

Siemens has produced software updates for systems affected by these vulnerabilities. Neither advisory mentions if the vulnerability discoverers have had a chance to verify the efficacy of the updates.

Rockwell Advisory

This advisory is based upon a vulnerability reported by Stephen Dunlap in a coordinated disclosure. Dunlap reported an insufficiently protected credential vulnerability in the RSLogix 5000 software. This advisory was previously posted to the US-CERT protected portal to allow system owners a chance to upgrade their systems before the vulnerability became public.

The vulnerability could allow an attacker to access and tamper with information in controller configuration programs. Not mentioned in the advisory is the fact that these files would provide invaluable information for an attacker to develop an exploit based upon some other access to the system.

ICS-CERT notes that a moderately skilled attacker could exploit the vulnerability through local access to the system when an authorized user accesses their password.


Rockwell has produced new versions of the RSLogix 5000 software that addresses these vulnerabilities. There is no mention of whether or not Dunlap has been provided an opportunity to verify the efficacy of the update software versions. Project files modified with the newer versions of the software cannot be opened by earlier versions. This means that an organization would have to upgrade all of their systems operating on the RSLogix 5000 software.
 
/* Use this with templates/template-twocol.html */