Showing posts with label Mark Cross. Show all posts
Showing posts with label Mark Cross. Show all posts

Thursday, June 25, 2020

4 Advisories Published – 6-25-20


Today the CISA NCIC-ICS published three control system security advisories for products from Rockwell Automation (2) and ENTTEC. They also published a medical device security advisory for products from Philips.

FactoryTalk Advisory


This advisory describes two vulnerabilities in the Rockwell FactoryTalk View SE. The vulnerabilities were reported by Ilya Karpov and Evgeny Druzhinin of ScadaX Security. Rockwell has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Cleartext transmission of sensitive information - CVE-2020-14480, and
Weak encoding for passwords - CVE-2020-14481

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to lead to unauthorized access to server data.


FactoryTalk Services Advisory


This advisory describes an improper restriction of XML external entity reference vulnerability in the Rockwell FactoryTalk Services Platform. The vulnerability was reported by Applied Risk. Rockwell has a patch that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to lead to a denial-of-service condition and to the arbitrary reading of any local file via system level services.

NOTE: NCCIC-ICS did not publish a link to the Rockwell advisory.

ENTTEC Advisory


This advisory describes four vulnerabilities in the ENTTEC Datagate Mk2, Storm 24, Pixelator, E-Streamer Mk2 lighting control products. The vulnerabilities were reported (report includes proof-of-concept exploit code) by Mark Cross. ENTTEC has not yet offered mitigation measures for these vulnerabilities.

The four reported vulnerabilities are:

• Hard-coded cryptographic key - CVE-2019-12776,
• Cross-site scripting - CVE-2019-12774,
• Improper access control - CVE-2019-12775, and
• Improper permission assignment for critical resource - CVE-2019-12777

NCCIC-ICS reports that a relatively low-skilled attacker with remote access could use publicly available code to remotely exploit the vulnerability to allow an attacker to gain unauthorized SSH/SCP access to devices, inject malicious code, run commands with root privileges, and read, write, and execute files in system directories as any user.

Philips Advisory


This advisory describes an authentication bypass using alternate path or channel vulnerability in the Philips Ultrasound Systems. The vulnerability is self-reported. Philips has a new version that mitigates the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerability to allow a non-authenticated attacker to view or modify information. The Phillips advisory reports that it would take a relatively high-skilled attacker with local access to exploit the vulnerability.

Tuesday, August 13, 2019

1 Alert, 3 Advisories and 4 Updates Published – 08-13-19


Today the DHS NCCIC-ICS published a control system security alert for products from Mitsubishi Electric; three control system security advisories for products from Siemens, OSIsoft, and Delta Industrial; and four control system advisory updates for products from Siemens.

Mitsubishi Alert


This alert describes a report of seven vulnerabilities in the Mitsubishi smartRTU and INEA ME-RTU. The vulnerabilities were reported (with exploit code) by Mark Cross (@xerubus) (NCCIC-ICS did provide the link to the report, a first). Cross disclosed the vulnerabilities to CISA and published the public disclosure under the 45-day disclosure policy.

The seven reported vulnerabilities are:

OS command injection - CVE-2019-14931;
Unauthenticated download of configuration file - CVE-2019-14927;
Stored cross-site script - CVE-2019-14928;
Use of hard-coded cryptographic keys - CVE-2019-14926;
Hard-coded user passwords - CVE-2019-14930;
Plaintext password storage - CVE-2019-14929; and
Incorrect default permissions - CVE-2019-14925


Siemens Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the Siemens SCALANCE X switches. The vulnerability was reported by Younes Dragoni from Nozomi Networks. Siemens has provided generic workarounds. There is no indication that Dragoni has been provided an opportunity to verity the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial-of-service condition.

OSIsoft Advisory


This advisory describes two vulnerabilities in the OSIsoft PI Web API. The vulnerabilities are self-reported. OSIsoft has an update to mitigate the vulnerability.

The two reported vulnerabilities are:

Inclusion of sensitive information in log files - CVE-2019-13515; and
Protection mechanism failure.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerabilities to allow direct attacks against the product and disclose sensitive information.

Delta Advisory


This advisory describes two vulnerabilities in the Delta DOPSoft Human Machine Interface (HMI) editing software. The vulnerability was reported by kimiya of 9SG Security Team via the Zero Day Initiative. Delta has a new version that mitigates the vulnerabilities. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Out-of-bounds read - CVE-2019-13513; and
Use after free - CVE-2019-13514

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow information disclosure, remote code execution, or crash of the application.

SIMATIC WinCC Update


This update provides additional information on an advisory that was originally reported on July 11th, 2019. The update provides new affected version information and mitigation links for:

SIMATIC WinCC V7.3;
SIMATIC PCS 7 V8.1, and
SIMATIC WinCC Runtime Professional V14

Spectrum Power Update


This update provides additional information on an advisory that was originally reported on July 9th, 2019. The update provides corrected version information for Spectrum Power 5.

SIPROTEC Update


This update provides additional information on an advisory that was originally reported on July 9th, 2019. The update provides additional mitigation information.

SIMATIC PCS7 Update


This update provides additional information on an advisory that was originally reported on July 9th, 2019. The update provides corrected version information and mitigation links for:

SIMATIC WinCC V7.3; and
SIMATIC PCS 7 V8.1
NOTE: Siemens published an additional two advisories and two updates today that were not reported by NCCIC-ICS. They may be reported on Thursday, if not, I will report on them on Saturday.

Friday, November 10, 2017

ICS-CERT Publishes Two Advisories

Yesterday the DHS ICS-CERT published two control system security advisories for products from Schneider and AutomationDirect.

Schneider Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Schneider InduSoft Web Studio and InTouch Machine Edition. The vulnerabilities were reported by Aaron Portnoy, formerly of Exodus Intelligence. Schneider has produced new versions that mitigate the vulnerability. There is no indication that Portnoy has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could use a publicly available exploit to remotely exploit this vulnerability to remotely execute code with high privileges. The Schneider security bulletin notes that the vulnerability exists during tag subscription.

AutomationDirect Advisory


This advisory describes and uncontrolled search path element vulnerability in a number of AutomationDirect products. The vulnerability was reported by Mark Cross of RIoT Solutions. Newer software versions are available from AutomationDirect that mitigate the problem. There is no indication that Cross has been provided an opportunity to verify the efficacy of the fix.


ICS-CERT reports that an uncharacterized attacker with uncharacterized access to execute arbitrary code on the system.

Tuesday, October 31, 2017

ICS-CERT Publishes Two Advisories

Today the DHS ICS-CERT published two control system security advisories for products from Trihedral Engineering and ABB. The ABB advisory addresses a vulnerability that I addressed ten days ago.

Trihedral Advisory


This advisory describes two vulnerabilities in the Trihedral VTScada. The vulnerabilities were independently reported by Karn Ganeshen and Mark Cross. Trihedral has a new version that mitigates the vulnerabilities. There is no indication that either researcher has been provided the opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper access control - CVE-2017-14031;
• Uncontrolled search path element - CVE-2017-14029

ICS-CERT reports that a relatively low skilled attacker with uncharacterized access could exploit the vulnerability to allow execution of arbitrary code.

NOTE: If one were to look for one possible explanation about why owner/operators are slow to update their ICS software, one would need to look no further than the Trihedral upgrade notes for moving from v11.2 to the current version. Lots of work and lots of tools do not carry over to the newest version.

ABB Advisory


This advisory describes an improper input validation vulnerability in the ABB FOX515T. The vulnerability was reported by Ketan Bali. ABB reports that the device has been phased out and is no longer being supported. The ABB cybersecurity advisory reports that there are no work around available for this vulnerability.

ICS-CERT reports that a relatively low skilled attacker with uncharacterized access could exploit this vulnerability to craft a malicious script that would enable retrieval of any file on the server.

Commentary


Two security researchers independently detecting and reporting the same vulnerabilities is not real common, but I suspect that is more due to the reporting component of that statement rather than the detection component. This is an important concept for security researchers and vendors to remember when they decide whether or not to communicate vulnerabilities.

For vendors trying to determine whether or not to report an in-house detected vulnerability they first have to determine if they are going to (or can) patch/upgrade to mitigate the vulnerability. If they do not patch, they are risking having an independent researcher/team discover the vulnerability and either misuse it or selling it to somewhere.


If the vendor fixes the vulnerability the question arises of whether or not to report the underlying vulnerability or letting the update stand on routine improvements to the device/system. As I have mentioned before, ICS owners are slow to update for any number of reasons; the risk of a security vulnerability un-fixed may be the incentive needed to upgrade to a newer version.

Thursday, September 7, 2017

ICS-CERT Publishes 4 Advisories

Today the DHS ICS-CERT published two medical device security advisories for products from Smiths Medical and i-SENS. They also published to control system security advisories for products from PHOENIX CONTACT and SpiderControl.

Smiths Medical Advisory


This advisory describes eight vulnerabilities in the Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump. The vulnerabilities were reported by Scott Gayou. Smiths Medical is developing a new product version to mitigate the vulnerabilities; compensating controls have been developed.

The eight reported vulnerabilities are:

• Buffer copy without checking size of input - CVE-2017-12718;
• Out-of-bounds read - CVE-2017-12722;
• Use of hard-coded credentials - CVE-2017-12725, CVE-2017-12724;
• Improper access control - CVE-2017-12720;
• Use of hard-coded password - CVE-2017-12726;
• Improper certificate validation - CVE-2017-12721; and
• Password in configuration file - CVE-2017-12723

ICS-CERT reports that an uncharacterized attacker could remotely exploit the vulnerabilities to gain unauthorized access and impact the intended operation of the pump. Despite the segmented design, it may be possible for an attacker to compromise the communications module and the therapeutic module of the pump.

No FDA safety communication has been released on these vulnerabilities.

i-SENS Advisory


This advisory describes an uncontrolled search path element vulnerability in the i-SENS SmartLog Diabetes Management Software. The vulnerability was reported by Mark Cross. i-SENS has produced a new version that mitigates the vulnerability. ICS-CERT reports that Cross has been provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that an authorized user with local access could exploit the vulnerability to execute arbitrary code on the target system.

PHOENIX CONTACT Advisory


This advisory describes a null pointer deference vulnerability in the PHOENIX CONTACT mGuard firmware. This vulnerability was self-reported. PHOENIX CONTACT has produced a firmware version that mitigates the vulnerability.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to cause a remote denial of service and force a restart of all IPSec connections.

SpiderControl Advisory


This advisory describes an improper privilege management vulnerability in the SpiderControl SCADA Web Server. The vulnerability was reported by Karn Ganeshen. SpiderControl has produced a new version that mitigates the vulnerability. There is no indication that Ganeshen has been provided an opportunity to verify the efficacy of the fix.


ICS-CERT reports that a relatively low skilled attacker with authorized access could exploit the vulnerability to escalate their privileges under certain conditions.

Thursday, February 23, 2017

ICS-CERT Publishes Three Advisories

Today the DHS ICS-CERT published three control system security advisories for products from Schneider Electric, Red Lion Controls and VIPA Controls.

Schneider Advisory


This advisory describes a resource exhaustion vulnerability in the Schneider Electric Modicon M340 PLC. The vulnerability was reported by Luis Francisco Martin Liras. Schneider has released a new firmware version that mitigates the vulnerability. There is no indication that Liras has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to render the device unresponsive requiring a physical reset of the PLC.

Red Lion Controls Advisory


This advisory describes a hard-coded cryptographic key vulnerability in the Red Lion Controls Sixnet-Managed Industrial Switches and the AutomationDirect STRIDE-Managed Ethernet Switch models. The vulnerability was reported by Mark Cross of RIoT Solutions. New firmware versions have been made available for both sets of devices. There is no indication that Cross has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to effect the loss of data confidentiality, integrity, and availability.

VIPA Controls Advisory


This advisory describes a stack-based buffer overflow vulnerability in the VIPA Controls WinPLC7. The vulnerability was reported by Ariele Caltabiano (kimiya) through ZDI. VIPA Controls has developed a patch to mitigate the vulnerability. There is no indication that kimiya has been provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to crash the device; a buffer overflow condition may allow remote code execution.


NOTE: Yesterday Siemens announced on TWITTER® the publication of two security notification updates (here and here) and the publication of a new security notification (here). I had almost expected ICS-CERT to publish their updates and advisory today; maybe tomorrow.
 
/* Use this with templates/template-twocol.html */