Showing posts with label LCDS. Show all posts
Showing posts with label LCDS. Show all posts

Thursday, October 17, 2024

Review – 5 Advisories and 2 Updates Published – 10-17-24

Today, CISA’s NCCIC-ICS published five control system security advisories for products from Kieback&Peter, HMS, Mitsubishi Electric, LCDS, and Elvaco. They also published updates for products from goTenna.

Advisories

Kieback&Peter Advisory - This advisory describes three vulnerabilities in the Kieback&Peter DDC4000 series building automation controllers.

HMS Advisory - This advisory describes an insufficiently protected credentials vulnerability in the HMS WON FLEXY 202 industrial modular gateway.

Mitsubishi Advisory - This advisory describes an improper validation of specified quantity in input vulnerability in the Mitsubishi CNC products.

LCDS Advisory - This advisory describes a cross-site scripting vulnerability in the LCDS LAquis SCADA HMI program.

Elvaco Advisory - This advisory describes four vulnerabilities in the Elvaco CMe3100 metering gateway.

Updates

GoTenna Update #1 - This update provides additional information on the Pro ATAK Plugin advisory that was originally published on September 26th, 2024.

GoTenna Update #2 - This update provides additional information on the Pro X and Pro X2 advisory that was originally published on September 26th, 2024.

 

For more information on these advisories see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-2-updates-published-bb1 - subscription required.

Tuesday, May 21, 2024

Review – 1 Advisory Published – 5-21-24

Today, CISA’s NCCIC-ICS published a control system security advisory for products from LCDS. They also published an alert about a new cybersecurity initiative from Rockwell Automatio 

Advisories

LCDS Advisory - This advisory describes a path traversal vulnerability in the LCDS LAquis SCADA product.

Rockwell Initiative - This alert notes that: “Rockwell Automation has released guidance encouraging users to remove connectivity on all Industrial Control Systems (ICS) devices connected to the public-facing internet to reduce exposure to unauthorized or malicious cyber activity.”

 

For more information about the advisory and alert, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-advisory-published-5-21-24 - subscription required.

Tuesday, October 13, 2020

6 Advisories Published – 10-13-20

Today the CISA NCCIC-ICS published six control system security advisories for products from Siemens (2), Fieldcomm Group, Flexera, LCDS, and Moxa.

SIPORT Advisory

This advisory describes a use of client-side authentication vulnerability in the Siemens SIPORT MP access control system. The vulnerability is self-reported. Siemens has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an authenticated attacker to impersonate other users of the system and perform (potentially administrative) actions on behalf of those users if the single sign-on feature (“Allow logon without password”) is enabled.

Desigo Advisory

This advisory describes three vulnerabilities in the Siemens Desigo Insight product. The vulnerabilities were reported by Davide De Rubeis, Damiano Proietti, Matteo Brutti, Stefano Scipioni, and Massimiliano Brolli from TIM Security Red Team Research. Siemens has a ‘hotfix’ available to mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• SQL injection - CVE-2020-15792,

• Improper restriction of rendered UI layers or frames - CVE-2020-15793, and

• Exposure of sensitive information to an unauthorized actor - CVE-2020-15794

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to retrieve or modify data and gain access to sensitive information.

Fieldcomm Group Advisory

This advisory describes a stack-based buffer overflow vulnerability in the Fieldcom HARP-IP Developer kit. The vulnerability was reported by Reid Wightman from Dragos, Inc. Fieldcomm has a new version for one of the affected products that mitigates the vulnerability. There is no indication that Wightman has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to  crash the device being accessed; a buffer overflow condition may allow remote code execution.

Flexera Advisory

This advisory describes an untrusted search path vulnerability in the Flexera InstallShield product. The vulnerability was reported by an anonymous researcher. Flexera will only provide mitigation measures and work arounds to registered owners.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow execution of a malicious DLL.

NOTE: This vulnerability was reported by Flexera in 2016, so why is NCCIC-ICS reporting this now? Both IBM (Tivoli Storage Manager) and Tenable (Nessus Network Monitor) have issued advisories covering this as a third-party vulnerability in 2016 and 2019 respectively. I suspect that there are other vendors that also use InstallShield that may be unaware of the vulnerability or may not have addressed it.

LCDS Advisory

This advisory describes an out-of-bounds read vulnerability in the LCDS LAquis SCADA. The vulnerability was reported by an anonymous researcher via the Zero Day Initiative. LCDS has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow an attacker to execute code under the privileges of the application.

Moxa Advisory

This advisory describes six vulnerabilities in the Moxa NPort IAW5000A-I/O Series integrated serial device server. The vulnerabilities were reported by Evgeniy Druzhinin and Ilya Karpov of Rostelecom-Solar. Moxa has an updated firmware version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Session fixation - CVE-2020-25198,

• Improper privilege management - CVE-2020-25194,

Weak password requirements - CVE-2020-25153,

• Cleartext transmission of sensitive information - CVE-2020-25190,

• Improper restriction of excessive authorization attempts - CVE-2020-25196, and

• Exposure of sensitive information to unauthorized actor - CVE-2020-25192

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to gain access to and hijack a session; allow an attacker with user privileges to perform requests with administrative privileges; allow the use of weak passwords; allow credentials of third-party services to be transmitted in cleartext; allow the use of brute force to bypass authentication on an SSH/Telnet session; or allow access to sensitive information without proper authorization.

NOTE: I briefly described these vulnerabilities back in August. Moxa has updated their advisory to list the CVE numbers assigned by NCCIC-ICS.

Siemens Updates

NCCIC-ICS also published four Siemens updates today. I will cover them in a post tomorrow.

Tuesday, April 28, 2020

1 Advisory Published – 4-28-20


Today the CISA NCCIC-ICS published a control system security advisory for products from LCDS.

LCDS Advisory


This advisory describes two vulnerabilities in the LCDS LAquis SCADA. The vulnerabilities were reported by Natnael Samson via the Zero Day Initiative. LCDS has a new version that mitigates the vulnerabilities. There is no indication that Samson was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Exposure of sensitive data to an unauthorized actor - CVE-2020-10618; and
• Improper input validation - CVE-2020-10622.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow unauthorized attackers to view sensitive information and create files in arbitrary locations.

Friday, August 2, 2019

6 Advisories Published – 08-01-19


Yesterday the DHS NCCIC-ICS published six control system advisories for products from Leão Consultoria e Desenvolvimento de Sistemas (LCDS), Rockwell, 3S (2), Fuji Electric and Advantech.

LCDS Advisory


This advisory describes two vulnerabilities in the LCDS LAquis SCADA software. The vulnerabilities were reported by Francis Provencher (PRL) via the Zero Day Initiative. LCDS has an update available that mitigates the vulnerability. There is no indication that Provencher has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Out-of-bounds read - CVE-2019-10994; and
• Type confusion - CVE-2019-10980


NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to obtain confidential information or execute remote code.

Rockwell Advisory


This advisory describes two vulnerabilities in the Rockwell Arena Simulation Software. The vulnerabilities were reported by kimiya of 9SG Security Team via ZDI. Rockwell has a new version that mitigates the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

• Use after free - CVE-2019-13510; and
• Information exposure - CVE-2019-13511

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to cause a current Arena session to fault or enter a denial-of-service (DoS) state, allowing the attacker to run arbitrary code.

First CODESYS Advisory


This advisory describes an insufficiently protected credentials vulnerability in the CmpUserMgr component of 3S CODESYS products. The vulnerability was reported by JunYoung Park. 3S will correct this vulnerability in a new version to be released in February. The 3S advisory strongly recommends activating and using encryption of online communication whenever possible.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow for an attacker with access to PLC traffic to obtain user credentials.

NOTE: Is it just me or is this advisory just a seven-month zero-day announcement?

Second CODESYS Advisory


This advisory describes two vulnerabilities in the CmpGateway component of the 3S CODESYS products. These vulnerabilities are self-reported. 3S has a new version that mitigates the vulenrabilities.

The two reported vulnerabilities are:

• Unverified ownership - CVE-2019-9010; and
• Uncontrolled memory allocation - CVE-2019-9012 

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow a remote attacker to close existing communication channels or to take over an already established user session to send crafted packets to a PLC.

NOTE 1: There were six other advisories published by 3S at the same time as the two referenced in these two NCCIC-ICS advisories. I will address them this weekend.

NOTE 2: A reminder that the CODESYS operating system is used in a wide variety of devices and systems. These vulnerabilities will have widespread application. Few vendors are expected to publish updates referencing these vulnerabilities.

Fuji Advisory


This advisory describes and out-of-bounds read vulnerability in the Fuji  FRENIC Loader. The vulnerability was reported by kimiya of 9SG Security Team via ZDI. Fuji has a new version that mitigates the vulnerability. There is no indication that the kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow information disclosure.

Advantech Advisory


This advisory describes an out-of-bounds write vulnerability in the Advantech WebAccess HMI Designer. The vulnerability was reported by Mat Powell via ZDI. Advantech has a new version that mitigates the vulnerability. There is no indication that Powell has been provided an opportunity to verify the efficacy of the fix.

Thursday, March 14, 2019

3 Advisories Published – 03-14-19


Today the DHS NCCIC-ICS published three control system security advisories for products from PEPPERL+FUCHS, Gemalto and Leão Consultoria e Desenvolvimento de Sistemas Ltda (LCDS).

PEPPERL+FUCHS Advisory


This advisory describes a path traversal vulnerability in the PEPPERL+FUCHS WirelessHART-Gateways. The vulnerability was publicly reported (with exploit) by Hamit CİBO. PEPPERL+FUCHS has firmware upgrades to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could use publicly available code to remotely exploit this vulnerability to allow access to files and restricted directories stored on the device through the manipulation of file parameters.

NOTE: I briefly reported on this vulnerability last Saturday.

Gemalto Advisory


This advisory describes an uncontrolled search path element in the Gemalto Sentinel UltraPro. The vulnerability was reported by ADLab of Venustech. Gemalto has a software update to mitigate the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to load and execute a malicious file from the ux32w.dll in Sentinel UltraPro.

NOTE: Gemalto issued an early warning to upgrade the UltraPro software back on January 19th, 2019 with a restricted link to their advisory on this product. I do not know what information was included in that advisory.

LCDS Advisory


This advisory describes an out-of-bounds write vulnerability in the LCDS LAquis SCADA. The vulnerability was reported by Mat Powel via the Zero Day Infitiative. LCDS has a new version that mitigates the vulnerability. There is no indication that Powel was provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow remote code execution.

Tuesday, January 15, 2019

One Advisory and One Update Published – 01-15-19


Today the DHS NCCIC-ICS published a control system security advisory for products from Leão Consultoria e Desenvolvimento de Sistemas Ltda (LCDS) and updated an advisory for products from Schneider Electric.

LCDS Advisory


This advisory describes eleven vulnerabilities in the LCDS LAquis SCADA. The vulnerabilities were reported by Esteban Ruiz (mr me) via the Zero Day Initiative. LCDS has a new version that mitigates the vulnerabilities. There is no indication that Ruiz has been provided an opportunity to verify the efficacy of the fix.

The eleven reported vulnerabilities are:

• Improper input validation - CVE-2018-18988;
• Out-of-bounds read (2) - CVE-2018-19004 and CVE-2018-18994;
• Code injection - CVE-2018-19002;
• Untrusted pointer dereference - CVE-2018-19029;
• Out-of-bounds write - CVE-2018-18986;
• Relative path traversal - CVE-2018-18990;
• Injection (2) - CVE-2018-18992 and CVE-2018-18996;
• Use of hard-coded credential - CVE-2018-18998; and
• Authentication bypass using alternative path or channel - CVE-2018-19000

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow remote code execution, data exfiltration, or cause a system crash.

Schneider Update


This update provides additional information on an advisory that was originally published on January 8th, 2019. The new information includes an additional vulnerability, cryptographic issues.

Wednesday, October 17, 2018

Advisory for LCDS Products


Yesterday the DHS NCCIC-ICS published a control system advisory for products from Leão Consultoria e Desenvolvimento de Sistemas Ltda (LCDS). The advisory describes six vulnerabilities in the LAquis SCADA software. The vulnerabilities were reported by Mat Powell, rgod of 9SG Security Team, Esteban Ruiz (mr_me) of Source Incite, b0nd @garage4hackers, and Ashraf Alharbi (Ha5ha5hin) via the Zero Day Initiative. LCDS has a new version that mitigates the vulnerability. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Untrusted pointer dereference - CVE-2018-17893;
• Out-of-bounds read - CVE-2018-17895;
• Integer overflow to buffer overflow - CVE-2018-17897;
• Path traversal - CVE-2018-17899;
• Out-of-bounds write - CVE-2018-17901 and
• Stack-based buffer overflow - CVE-2018-17911

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to execute arbitrary code, crash the system, or write controlled content to the target system.

Thursday, April 5, 2018

ICS-CERT Publishes 3 Advisories and 2 Siemens Updates


Today the DHS ICS-CERT published three control system security updates for products from Leão Consultoria e Desenvolvimento de Sistemas (LCDS), Moxa, and Rockwell. They also updated two previously published control system security advisories for products from Siemens.

LCDS Advisory


This advisory describes an improper check of handling of exceptional conditions vulnerability in the LCDS LAquis SCADA. The vulnerability was reported by Karn Ganeshen. LCDS has a new version that mitigates the vulnerability. There is no indication that Ganeshen has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a highly-skilled attacker with local access could exploit this vulnerability to cause the device an attacker is accessing to crash, resulting in a structured exception handler overflow condition, which may allow code execution.

Moxa Advisory


This advisory describes an information exposure vulnerability in the Moxa MXview, network management software. The vulnerability was reported by Michael DePlante of Leahy Center for Digital Investigation at Champlain College. Moxa developed a new version to mitigate the vulnerability. There is no indication that DePlante has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability to read the private key of the web server, which may allow a remote attacker to decrypt encrypted information.

Rockwell Advisory


This advisory describes six vulnerabilities in the Rockwell MicroLogix Controller. The vulnerabilities were reported by Jared Rittle and Patrick DeSantis of Cisco. Rockwell has provided mitigation strategies in their customer notification (registration required). There is no indication that the researchers were provided an opportunity to verify the efficacy of the fixes.

The six reported vulnerabilities (according to ICS-CERT) are:

• Improper authentication (6) - CVE-2017-12088, CVE-2017-12089, CVE-2017-12090, CVE-2017-12092, and CVE-2017-12093

NOTE: Rockwell does not use the ‘improper authentication’ description for any of the six (actually 17) vulnerabilities. Instead they report (using the same CVE numbers):

• Denial of service via ethernet functionality - CVE-2017-12088;
• Denial of service via download functionality - CVE-2017-12089;
• Denial of service – SNMP-set request - CVE-2017-12090;
• Access control vulnerabilities (12) - CVE-2017-14462 thru CVE-2017-14473;
• File-write vulnerability in memory module - CVE-2017-1209; and
• Malicious register session packets lead to communication loss - CVE-2017-12093

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to cause denial of service, disclosure of sensitive information, communication loss, and modification of settings or ladder logic.

SCALANCE Update


This update provides additional details on an advisory that was originally published on November 28th, 2017. The new version provides updated mitigation information for the SCALANCE W1750D.

Building Technologies Products Update


This update provides additional details on an advisory that was originally published on April 3rd, 2017. The new information provides a link to the updated LMS. I mentioned this new information in my earlier post.

Thursday, March 23, 2017

ICS-CERT Publishes 2 Advisories

Today the DHS ICS-CERT published two control system security advisories for products from Becton, Dickinson and Company (BD) and Leão Consultoria e Desenvolvimento de Sistemas LTDA ME (LCDS).

BD Advisory


This advisory describes a hard-coded password vulnerability in the BD Kiestra PerformA and KLA Journal Service (laboratory information management systems) applications. The vulnerability is apparently self-reported. BD has will be providing updates to the two applications and the Kiestra Database to “reduce the risk [emphasis added] of exploitation of the hard-coded passwords vulnerability”.

ICS-CERT reported that a relatively low skilled attacker could remotely exploit this vulnerability to access the BD Kiestra Database, which could be leveraged to compromise the confidentiality of limited patient health information and personally identifiable information stored in the BD Kiestra Database.

The BD Security Advisory paints a more complicated picture of the vulnerability situation, but it also provides work arounds to be used pending the updates that will be provided later this year. It describes three vulnerabilities instead of one:

• A legacy application (SMB1 protcol);
• Hard-coded password in the two applications;
• Third-party default password in the Database.

LCDS Advisory


This advisory describes a path traversal vulnerability in the LCDS LAquis SCADA software. The vulnerability was reported by Karn Ganeshen via the Zero Day Initiative. LCDS has produced a new firmware version to mitigate the vulnerability. There is no indication that Ganeshen has been provided an opportunity to verify the efficacy of the fix.


ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to allow an unprivileged, malicious attacker to access files remotely.

Thursday, March 16, 2017

ICS-CERT Publishes LCDS Advisory

Today the DHS ICS-CERT published a control system security advisory for the Leão Consultoria e Desenvolvimento de Sistemas (LCDS) LAquis SCADA software. They also published the draft agenda for the Spring 2017 meeting of the ICSJWG in Minneapolis, Minnesota, on April 11-13, 2017.

LCDS Advisory


This advisory describes an improper access control vulnerability in the LAquis SCADA software. The vulnerability was reported by Karn Ganeshen. LCDS has produced a new version to mitigate the vulnerability. ICS-CERT reports that Ganeshen has verified the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker, presumably with local access, could exploit the vulnerability to escalate their privileges and modify or replace application files.

ICSJWG Agenda


ICS-CERT has provided a link to the draft agenda for the ICSJWG Spring 2016 Meeting. It looks like there will be a number of interesting presentations from familiar names and organizations.


There appears to be an increasing interest in the interface of safety and security in process engineering. With the recent congressional interest in cyber informed engineering (see S 79 in the 115th Congress and S 2943 in the last session) Virginia Wright of the Idaho National Labs will be doing a presentation on the INL work on the topic (see here).
 
/* Use this with templates/template-twocol.html */