Showing posts with label Martem. Show all posts
Showing posts with label Martem. Show all posts

Friday, August 31, 2018

ICS-CERT Publishes Advisory and 2 Updates


Yesterday the DHS ICS-CERT published a control system security advisory for products from Philips. They also published updates for previous published advisory; one for control system products from Martem and one for medical device products from Philips.

Philips Advisory


This advisory describes 9 vulnerabilities in the Philips e-Alert Unit. The vulnerability is self-reported. Phillips has a version available that mitigates some of the vulnerabilities. A new version dealing with the remainder will be published by the end of the year.

The nine reported vulnerabilities are:

• Improper input validation - CVE-2018-8850;
• Improper neutralization of input during web page generation - CVE-2018-8846;
• Information exposure - CVE-2018-14803;
• Incorrect default permission - CVE-2018-8848;
• Cleartext transmission of sensitive information - CVE-2018-8842;
• Cross-site request forgery - CVE-2018-8844;
• Session fixation - CVE-2018-8852;
• Uncontrolled resource consumption - CVE-2018-8854; and
Use of hard-coded credentials - CVE-2018-8856

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit some of the vulnerabilities to allow attackers to provide unexpected input into the application, execute arbitrary code, display unit information, or potentially cause e-Alert to crash. The other vulnerabilities could only be exploited from the same subnet.

Martem Update


This update provides new information on an advisory that was previously published on May 22nd, 2018 and updated on May 24th, 2018. The new information includes:

• An additional vulnerability (incorrect default permissions);
• An additional risk consequence (full control over RTU);
• Updated affected version information; and
• Mitigation information for new vulnerability


Philips Update


This update provides new information on an advisory that was originally published on August 21st, 2018. The new information removes the ‘remotely exploitable’ language and notes that the “vulnerability is exploitable from within the same local device subnet”.

Thursday, May 24, 2018

ICS-CERT Publishes 2 Advisories and 3 Updates

Today the DHS ICS-CERT published a control system security advisory for products from Schneider Electric and a medical device security advisory for products from BeaconMedaes. They also published updates to previously published advisories for products from Rockwell, Siemens, and Martem.

Schneider Advisory


This advisory describes three vulnerabilities in the Schneider Floating License Manager. The vulnerabilities are being self-reported. Schneider has new versions available to mitigate the vulnerabilities.

The three reported vulnerabilities are:

• Heap-based buffer overflow - CVE-2016-2177;
• Improper restriction of operations within bounds of a memory buffer - CVE-2016-10395; and
• URL redirection to an untrusted site - CVE-2017-5571

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to cause a denial of service, allow arbitrary execution of code with system level privileges, or send users to arbitrary websites.

BeaconMedaes Advisory


This advisory describes three vulnerabilities in the BeaconMedaes TotalAlert Scroll Medical Air Systems web application. These vulnerabilities were reported by Maxim Rupp. BeaconMedaes has a new version that mitigates the vulnerability, There is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Improper access control - CVE-2018-7526;
• Insufficiently protected credential - CVE-2018-7518; and
• Unprotected storage of credentials - CVE-2018-7515;

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities  to view and potentially modify some device information and web application setup information, which does not include access to patient health information.

NOTE: These vulnerabilities were not reported on the FDA Medical Device Safety Communication site.

Rockwell Update


This update provides new information on an advisory that was originally published on May 10th, 2018. The new information is supposed to be a link to the Rockwell security advisory [log-in required]. Unfortunately, that link is to the Rockwell Arena advisory (the ICS-CERT advisory for that was publicly published on the same day as the Factory Talk advisory that is currently being updated here. The correct link is https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1073133.


Siemens Update


This update provides new information on an advisory that was originally published on May 8th, 2018. The new information is a revision to the instructions as to how owner/operators should go about getting the updated version. It removed the original link to the ‘hotfix’ and substitutes the instruction to “Obtain the update via the local Siemens representative”.

Martem Update



This update provides new information on an advisory that was originally published on May 22nd, 2018. The new information is links to the Martem advisories for vulnerability CVE-2018-10603 and CVE-2018-10607. A link to the Martem advisory for the third vulnerability was already included in the initial ICS-CERT advisory.

Tuesday, May 22, 2018

ICS-CERT Publishes 2 Advisories


Today the DHS ICS-CERT published a control system security advisory for products from Martem. They also published a medical device security advisory for products from Becton, Dickinson and Company (BD).

Martem Advisory


This advisory describes three vulnerabilities in the Martem TELEM-GW6/GWM products. The vulnerabilities were reported by Bernhards Blumbergs and Arturs Danilevics of CERT.LV, Latvia. Martem has described work arounds to mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Missing authentication for critical function - CVE-2018-10603;
• Uncontrolled resource consumption - CVE-2018-10607; and
Cross-site scripting - CVE-2018-10609

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to allow execution of unauthorized industrial process control commands, denial of service, or client-side code execution.

BD Advisory


This advisory describes three separate SQL related vulnerabilities in the BD BD Kiestra and InoqulA systems. These vulnerabilities are being self-reported. BD intends to have mitigations in place by July. In the mean-time BD has described workarounds to mitigate the vulnerabilities.

The following applications in the affected products fail to warn users of unsafe actions:

• Database (DB) Manager;
• ReadA Overview; and
• PerformA

ICS-CERT reports that an uncharacterized attacker with access to an adjacent network could exploit the vulnerabilities which may lead to loss or corruption of data.

NOTE: These vulnerabilities have not been reported on the FDA Medical Device Safety Communications site.

 
/* Use this with templates/template-twocol.html */