Showing posts with label Linux. Show all posts
Showing posts with label Linux. Show all posts

Saturday, February 27, 2021

Public ICS Disclosures – Week of 2-20-21

This week we have six vendor disclosures from Advantech, Aruba Networks (2), Bosch, Carestream, and VMware. We have researcher a report for products from Secomea (and B&R automation). Finally, there are two remote access exploits for products from ASUS and

Advantech Advisory

Advantech published an advisory discussing the DNSpooq vulnerabilities in their industrial cellular routers. Advantech notes that their routers are only vulnerable to the three ‘cache poisoning’ vulnerabilities. Advantech has new firmware that mitigates the vulnerabilities.

Aruba Advisories

Aruba published an advisory discussing the DNSpooq vulnerabilities in their products. Aruba reports that their products are only vulnerable to the three ‘cache poisoning’ vulnerabilities. Aruba will update the dnsmasq in “future routine maintenance patches”.

 

Aruba published an advisory describing twelve vulnerabilities in their AirWave Management Platform. The vulnerabilities were reported by multiple researchers via the BugCrowd platform. Aruba has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The twelve reported vulnerabilities are:

• Cross-site request forgery (2) - CVE-2021-29960 and CVE-2021-29961,

• Command injection (2) - CVE-2021-29962 and CVE-2021-29963,

• Improper access control - CVE-2021-29964,

• SQL injection (2) - CVE-2021-29965 and CVE-2021-29966,

• Reflected cross-site scripting - CVE-2021-29967,

• Authenticated stored cross-site scripting - CVE-2021-29968,

• Authenticated XML external entity - CVE-2021-29969, and

• Authenticated remote command injection (2) - (CVE-2021-29970 and CVE-2021-29971

Bosch Advisory

Bosch published an advisory describing three vulnerabilities in their ctrlX CORE and the IoT Gateway. These are third-party (Linux kernel and sudo) vulnerabilities. Bosch reports that the next updates for the affected products would include updates for both the kernel and sudo.

The three reported vulnerabilities are:

• Improper locking and use after free - CVE-2020-29661,

• Out-of-bounds write - CVE-2021-3156 (multiple exploits publicly available), and

• Use after free - CVE-2021-3347 (exploit publicly available)

Carestream Advisory

Carestream published an advisory [.PDF download link] describing a heap-based buffer overflow vulnerability in a number of their products. This is a third-party (Chrome) vulnerability. Carestream reports that Chrome will be updated with the next software release for most of the affected products. This vulnerability has been exploited in the wild, but not yet in Carestream products.

VMware Advisory

VMware published an advisory describing three vulnerabilities in their VMware ESXi and vCenter Server. The vulnerabilities were reported by Mikhail Klyuchnikov of Positive Technologies, and Lucas Leong via the Zero Day Initiative. VMware has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Remote code execution - CVE-2021-21972,

• Heap-based buffer overflow - CVE-2021-21974,

• Server-side request forgery - CVE-2021-21973

Tenable has published a report on the vulnerabilities noting that these vulnerabilities have been exploited in the wild. NebulabdSec has published proof-of-concept code for the RCE vulnerability.

Secomea Report

Tenable published a report (including proof-of-concept code) describing three vulnerabilities in the Secomea GateManager (also applies to B&R GateManager). The report was coordinated with both Secomea and B&R; Secomea has a new version that mitigates the vulnerability. B&R’s response is pending.

The three reported vulnerabilities include:

• Reflected cross-site scripting - CVE-2020-29028,

• Authentication token exposed in URL path - CVE-2020-29030, and

• Authenticated malicious firmware upload - CVE-2020-29029

NOTE: This is likely to be a third-party vulnerability in products from vendors other than B&R.

Remote Access Exploits

H4rk3nz0 published an exploit for a remote code execution vulnerability in the ASUS Remote Link. There is no CVE# listed and no indication that ASUS had been contacted. This may be a 0-day exploit.

MATTHEW DUNN published a Metasploit module for an authentication timing vulnerability for Remote Desktop Web Access. The is no CVE# and no indication that Microsoft has been contacted. This may be a 0-day exploit.

Saturday, April 27, 2019

ICS Public Disclosures – Week of 04-27-19


This week we have exploit code published for a possible zero-day vulnerability in products from Siemens.

Google Security Research published exploit code for a race condition vulnerability in Siemens R3964 line discipline code, a Linux driver that allows synchronous communication with devices using the Siemens R3964 packet protocol. The Google report notes that this vulnerability is fixed, but according to the Linux folks that fix is simply marking the code as ‘broken’. The Linux researcher notes that:

The n_r3964 line discipline driver was written in a different time, when SMP machines were rare, and users were trusted to do the right thing. Since then, the world has moved on but not this code, it has stayed rooted in the past with its lovely hand-crafted list structures and loads of "interesting" race conditions all over the place.

After attempting to clean up most of the issues, I just gave up and am now marking the driver as BROKEN so that hopefully someone who has this hardware will show up out of the woodwork (I know you are out there!) and will help with debugging a raft of changes that I had laying around for the code, but was too afraid to commit as odds are they would break things.

I am a tad bit over my head here technically, but this looks like a GNU library issue; part of the larger issue that Siemens is dealing with. The CVE for this vulnerability (CVE-2019-11486) was not included in the most recent Siemens advisory for the GNU library issues, but that is hardly surprising since the CVE was issued after the latest update to the Siemens advisory. These issues have still not been addressed by NCCIC-ICS.

Saturday, December 1, 2018

Public ICS Disclosure – Week of 11-24-18


This week we have three vendor disclosures from Schneider Electric, ABB and Siemens, exploit code for a previously disclosed vulnerability and a disclosure from a researcher which is probably been coordinated with Moxa. And there is a special non-disclosure disclosure at the end of the post.

Schneider Advisory


This advisory describes five vulnerabilities in the Schneider Embedded Web Servers for Modicon V1.1 PLC’s. The vulnerabilities were reported by Tenable. Schneider has provided generic fixes to mitigate the vulnerability. There is no indication that Tenable has been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Unverified password change (2) - CVE-2018-7811 and CVE-2018-7809;
• Cross-site scripting - CVE-2018-7810;
• Basic XSS - CVE-2018-7831; and
HTTP response splitting - CVE-2018-7830

ABB Advisory


This advisory describes an improper input validation vulnerability in the ABB CP400 Panel Builder TextEditor 2.0. The vulnerability was reported by Ivan Sanchez from Nullcode Team. ABB has an updated version of the affected products to mitigate the vulnerability. ABB reports that Sanchez has verified the efficacy of the fix.

Siemens Advisory


This advisory describes 21 vulnerabilities in GNU/Linux subsystem of
the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP. The vulnerabilities were reported by an unidentified ‘external source’. Siemens reports that the vulnerabilities will be corrected in the next firmware version and currently provides generic mitigation advice.

The advisory provides links to 21 CVE’s without a description of the associated vulnerability or risk evaluation of the vulnerability in the affected system. I have clicked through on a couple of these links to the Debian.org reports on the vulnerabilities and there are a wide variety of vulnerabilities involved here with reports of public exploits for many of them. Those exploits are not specifically for the Siemens implementation of these processes, but a reasonably competent hacker could probably use them to craft a Siemens specific exploit.

NOTE: Insert standard blurb about 3rd party vulnerabilities potentially being found in products from other vendors. Fortunately (sarcasm warning) Linux is a rather obscure OS and is seldom seen in real operations. (SIGH)

Schneider Exploit


PHOTUBIAS published an exploit for a session calculation authentication bypass vulnerability in the Schneider Modicon PLCs. This vulnerability was previously reported by ICS-CERT.

NOTE: Exploit-DB.com has ‘updated’ the layout of their site. Larger print in headers, more colorful, but unfortunately harder to read. Too bad.

Moxa Vulnerabilities


Maxim Khazov reports two OS command injection vulnerabilities in the Moxa NPort W2x50A wireless device servers. The report includes proof of concept exploit instructions. Khazov reports that Moxa has fixed these vulnerabilities in a newer version, but it is not clear if this is a coordinated disclosure.

Bonus Non-Disclosure Disclosure


This week OSIsoft released a new version of PI Integrator for Business Analytics. In the release notes (pg 12) OSIsoft notes that:

“For this release of the PI Integrator for Business Analytics, one security vulnerability was identified and fixed. The resolved issue was rated using the Common Vulnerability Scoring System (CVSS).”

The only other information provided was that the CVSS score was rated as low (0.1 to 3.9).

Now I have a lot of respect for OSIsoft’s commitment to security and I am a big fan of their PI Processbook application, but the way OSIsoft has handled this non-disclosure is disappointing. It is great that they have fixed this unidentified, low-risk security vulnerability, but they have provided no security incentive to owners of this product to upgrade to this new version. The other fixes enumerated in the release notes may provide adequate incentive to upgrade, but if folks have not had problems with those listed issues, a defined security problem might make a difference.

BTW: I really hate it when people set security on .PDF documents so that they will not allow cutting and pasting from the documents. Really? I like to make sure that when I quote a document, I do it accurately. Cutting and pasting is the easiest, most efficient way of doing that. Re-typing just sets me up for making errors. And, the quote is still there.

 
/* Use this with templates/template-twocol.html */