Showing posts with label Mandar Jadhav. Show all posts
Showing posts with label Mandar Jadhav. Show all posts

Thursday, October 26, 2017

ICS-CERT Publishes 2 Advisories

Today the DHS ICS-CERT published two control system security advisories for products from Korenix and Rockwell.

Rockwell Advisory


This advisory describes a reusing a nonce, key pair in encryption vulnerability in the Rockwell Stratix 5100 Wireless Access Point. This is the ‘KRACK’ (Key Reinstallation Attack) vulnerability that has been in the news lately (see here for example). The advisory reports that the vulnerability was discovered by Mathy Vanhoef; this attribution is for the KRACK vulnerability generally, not necessarily the specific instance of the vulnerability in this device. Rockwell will produce a new firmware version that mitigates the vulnerability in this device.

ICS-CERT reports that an uncharacterized attacker presumably with access to a wi-fi signal could exploit the vulnerability with a publicly available exploit to operate as a “man-in-the-middle” between the device and the wireless network.

NOTE: The advisory only claims CVE-2017-13082. This is just one of the 10 CVE’s associated with the KRACK vulnerability. It is not clear if this is just an oversight or if this is the only part of the vulnerability found in this particular implementation of the WPA2 standard. I suspect that it is the former.

Korenix Advisory


This advisory describes two vulnerabilities in the Korenix JetNet ethernet switch. The vulnerabilities were reported by Mandar Jadhav of the Qualys Vulnerability Signature/Research Team. Korenix has produced new firmware that mitigates the two vulnerabilities. There is no indication that Jadhav was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability  to gain remote access to the device to run arbitrary code and perform man-in-the-middle attacks.

Commentary


It is odd that ICS-CERT published the Rockwell Advisory without publishing a general alert about the KRACK vulnerability. Any control system devices that provide for wi-fi access while using the WPA2 security protocol are most likely affected by KRACK.

Fixing just one side of the communications link could still possibly leave the network vulnerable to this vulnerability, particularly since this is potentially 10 separate vulnerabilities. This is addressed in the advisory; noting that:

“Rockwell Automation recommends that all users patch the clients that connect to the Stratix 5100 WAP/WGB, and recommends contacting your supplier to get the most updated patch that is compatible with your client devices. However, patching the client only protects the connection formed by that specific client.”

ICS-CERT certainly needs to address this vulnerability since it potentially affects a wide-swath of the wi-fi capable control system devices; a quickly-growing number of devices if vendor ads are any indication.

Thursday, August 24, 2017

ICS-CERT Publishes Two Advisories

Today the DHS ICS-CERT published two control system security advisories for products from Rockwell and Westermo. The Rockwell advisory was originally published on the NCCIC Portal on July 27, 2017.

Rockwell Advisory


This advisory describes an SNMP remote code execution vulnerability in the Rockwell Allen-Bradley Stratix and ArmoStratix. The vulnerability was originally reported by Cisco and subsequently self-reported by Rockwell as affecting their switches. Rockwell has produced a newer version of one of the affected product families that mitigates the vulnerability. Rockwell has produced compensating controls for the remainder of the affected products pending further updates.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to execute code on an affected system or cause an affected system to crash and reload.

As always when these types of vulnerabilities from third party systems are reported, we have to ask what other vendors have also been using the same system and thus have the same vulnerabilities?

Westermo Advisory


This advisory describes three vulnerabilities in the Westermo MRD-305-DIN, MRD-315, MRD-355, and MRD-455 routers. The vulnerabilities were originally reported by Mandar Jadhav from Qualys Security. Westermo has produced a new firmware to mitigate the vulnerabilities. There are no indications that Jadhav was provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Cross-site request forgery - CVE-2017-12703;
• Hard-coded credentials - CVE-2017-12709; and
• Use of hard-coded cryptographic key - CVE-2017-5816

Westermo reports in their security advisory [.PDF Download] that a fourth vulnerability was reported by the researcher, but the default user account identified is not interactive and is not accepted in the existing management interfaces and is therefore not an immediate attack vector. It has, however, been removed from the updated firmware.


ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerabilities to obtain hard-coded cryptographic keys, hard-coded credentials, or trick a user into submitting a malicious request, resulting in the attacker gaining unauthorized access to the device and running arbitrary code.
 
/* Use this with templates/template-twocol.html */