Showing posts with label Leahy Center for Digital Investigation. Show all posts
Showing posts with label Leahy Center for Digital Investigation. Show all posts

Thursday, April 26, 2018

ICS-CERT Publishes 2 Alerts and Updates Meltdown Alert


Today the DHS ICS-CERT published two control system security advisories for products from WECON Technology and Delta Electronics. They also updated their control system security alert for the Meltdown/Spectre vulnerabilities.

WECON Advisory


This advisory describes a stack-based buffer overflow vulnerability in the WECON LEVI Studio HMI Editor and PI Studio HMI Project Programmer. The vulnerability was reported by Sergey Zelenyuk of RVRT and Michael DePlante of Leahy Center for Digital Investigation via the Zero Day Initiative (ZDI). WECON has a new version that mitigates the vulnerability. There is no indication that either researcher was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow remote code execution.

Delta Advisory


This advisory describes multiple stack-based buffer overflows (on a single CVE) in the Delta PMSoft, a software development tool for motion controllers. The vulnerabilities were reported by Ghirmay Desta via ZDI. Delta has a new version available that mitigates the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to cause the application to crash; stack-based buffer overflow conditions may allow arbitrary code execution.

Meltdown Update


This update provides new information on an alert that was originally published on January 11th, 2018 and updated on January 16th, 2018, January 17th, 2018, January 30th, 2018, February 20th, 2018, February 22nd, 2018 and again on March 1st, 2018. The update provides a link to a new vendor report from:


Not specifically mentioned in the update, but the current links also provide access to updated information from:

Siemens (which I mentioned Saturday); and

Thursday, April 5, 2018

ICS-CERT Publishes 3 Advisories and 2 Siemens Updates


Today the DHS ICS-CERT published three control system security updates for products from Leão Consultoria e Desenvolvimento de Sistemas (LCDS), Moxa, and Rockwell. They also updated two previously published control system security advisories for products from Siemens.

LCDS Advisory


This advisory describes an improper check of handling of exceptional conditions vulnerability in the LCDS LAquis SCADA. The vulnerability was reported by Karn Ganeshen. LCDS has a new version that mitigates the vulnerability. There is no indication that Ganeshen has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a highly-skilled attacker with local access could exploit this vulnerability to cause the device an attacker is accessing to crash, resulting in a structured exception handler overflow condition, which may allow code execution.

Moxa Advisory


This advisory describes an information exposure vulnerability in the Moxa MXview, network management software. The vulnerability was reported by Michael DePlante of Leahy Center for Digital Investigation at Champlain College. Moxa developed a new version to mitigate the vulnerability. There is no indication that DePlante has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability to read the private key of the web server, which may allow a remote attacker to decrypt encrypted information.

Rockwell Advisory


This advisory describes six vulnerabilities in the Rockwell MicroLogix Controller. The vulnerabilities were reported by Jared Rittle and Patrick DeSantis of Cisco. Rockwell has provided mitigation strategies in their customer notification (registration required). There is no indication that the researchers were provided an opportunity to verify the efficacy of the fixes.

The six reported vulnerabilities (according to ICS-CERT) are:

Improper authentication (6) - CVE-2017-12088, CVE-2017-12089, CVE-2017-12090, CVE-2017-12092, and CVE-2017-12093

NOTE: Rockwell does not use the ‘improper authentication’ description for any of the six (actually 17) vulnerabilities. Instead they report (using the same CVE numbers):

• Denial of service via ethernet functionality - CVE-2017-12088;
• Denial of service via download functionality - CVE-2017-12089;
• Denial of service – SNMP-set request - CVE-2017-12090;
• Access control vulnerabilities (12) - CVE-2017-14462 thru CVE-2017-14473;
• File-write vulnerability in memory module - CVE-2017-1209; and
• Malicious register session packets lead to communication loss - CVE-2017-12093

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to cause denial of service, disclosure of sensitive information, communication loss, and modification of settings or ladder logic.

SCALANCE Update


This update provides additional details on an advisory that was originally published on November 28th, 2017. The new version provides updated mitigation information for the SCALANCE W1750D.

Building Technologies Products Update


This update provides additional details on an advisory that was originally published on April 3rd, 2017. The new information provides a link to the updated LMS. I mentioned this new information in my earlier post.

 
/* Use this with templates/template-twocol.html */