Showing posts with label Marc Ruef. Show all posts
Showing posts with label Marc Ruef. Show all posts

Tuesday, February 18, 2020

4 Advisories and 1 Update Published – 2-18-20


Today the CISA NCCIC-ICS published two control system security advisories for products from Emerson and Honeywell, two medical device security advisories for products from GE and Spacelabs, and 1 update for products from Interpeak.

Emerson Advisory


This advisory describes a heap-based buffer overflow vulnerability in the Emerson OpenEnterprise SCADA Server. The vulnerability was reported by Roman Lozko of Kaspersky ICS CERT. Emerson has an upgrade that mitigates the vulnerability. There is no indication that Lozko has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit this vulnerability to allow an attacker to execute code on an OpenEnterprise SCADA Server.

Honeywell Advisory


This advisory describes a clear-text storage of sensitive information vulnerability in the Honeywell INNCOM INNControl 3 energy management platform. The vulnerability is self-reported. Honeywell has an upgrade available to mitigate the vulnerability.

NCCIC reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to escalate user privileges within the INNControl application.

GE Advisory


This advisory describes a protection measure failure vulnerability in the GE Ultrasound Products. The vulnerability was reported by Marc Ruef and Rocco Gagliardi of scip AG. GE has provided generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with local access could exploit the vulnerability to allow an attacker to gain access to the operating system of affected devices.

Spacelabs Advisory


This advisory describes the BlueKeep vulnerability in the Spacelabs Xhibit Telemetry Receiver. Spacelabs has an updated version that mitigates the vulnerability.

NOTE: A number of other vendors in both the control system and medical device realms issued advisories on this vulnerability (see my blog post here for example) beginning in May of last year. This is the first acknowledgement of vendor actions on this vulnerability from NCCIC-ICS though there was an obscure advisory on the vulnerability published by NCCIC-ICS.

Interpeak Update


This update provides additional information on the Urgent/11 advisory that was originally published on October 1st, 2019 and most recently updated on December 10th, 2019. The new information includes a link to a vendor advisory from Mitsubishi.

Wednesday, April 24, 2019

Two Advisories Published – 04-23-19


Yesterday the DHS NCCIC-ICS published a control system security advisory for products from Rockwell and a medical device security advisory for products from Fujifilm.

Rockwell Advisory


This advisory describes an open redirect vulnerability in the Rockwell MicroLogix 1400 and CompactLogix 5370 Controllers. The vulnerability was reported by Josiah Bryan and Geancarlo Palavicini. Rockwell has new versions or updates to mitigate the vulnerabilities in most devices. There is no indication that the researchers have verified the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to input a malicious link redirecting users to a malicious website.

Fujifilm Advisory


This advisory describes two vulnerabilities in the Fujifilm FCR Capsula X/Carbon X. The vulnerability was reported by Marc Ruef and Rocco Gagliardi of Scip AG. Fujifilm has provided generic mitigation measures. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Uncontrolled resource consumption - CVE-2019-10948; and
Improper access control - CVE-2019-10950.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to effect a denial-of-service condition in affected cassette reader units, causing potential image loss or device unavailability. Attackers could gain unauthorized access to the underlying operating system, allowing arbitrary code execution.

Tuesday, January 22, 2019

Two Advisories Published – 01-22-19


Today the DHS NCCIC-ICS published a control system security advisory for products from Johnson Controls and a medical device security advisory for products from Drager.

Johnson Controls Advisory


This advisory describes two vulnerabilities in the Johnson Controls Facility Explorer. The vulnerabilities were reported by Tridium. Johnson Controls has new versions that mitigate the vulnerabilities. There is no indication that Tridium has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Path traversal - CVE-2017-16744; and
Improper authentication - CVE-2017-16748

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit these vulnerabilities to allow an attacker to read, write, and delete sensitive files to gain administrator privileges in the Facility Explorer system.

Drager Advisory


This advisory describes three vulnerabilities in the Drager Infinity Delta patient monitoring devices. The vulnerabilities were reported by Marc Ruef and Rocco Gagliardi, of scip AG. Drager has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Improper input validation - CVE-2018-19010;
• Information exposure through log files - CVE-2018-19014; and
• Improper privilege management - CVE-2018-19012

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to cause information disclosure of device logs, denial of service through device reboots of the patient monitors, and privilege escalation.

NOTE: The Drager security advisory adds an additional vulnerability for one of the affected products; “Several 3rd party components were found outdated and vulnerable to several published security vulnerabilities.”

 
/* Use this with templates/template-twocol.html */