Showing posts with label Martin Jartelius. Show all posts
Showing posts with label Martin Jartelius. Show all posts

Tuesday, February 2, 2016

ICS-CERT Updates Siemens Advisory and Publishes Two New Advisories

Today the DHS ICS-CERT published an update for a Siemens advisory that was originally published on December 1st, 2015. Two new advisories were also published for vulnerabilities in control system components from GE and Sauter.

Siemens Update

This update updates the vulnerable device list to provide limiting version numbers. It also announces that firmware updates are now available for SIMATIC TIM 3V-IE, TIM 4R-IE, and CP 443-1 / CP 443-1 Advanced modules. Siemens is still working on updates for a number of other affected devices. Both of the recent updates to the Siemens Security Advisory are covered in today’s update.

As has become usual for ICS-CERT advisory updates, this updated was not listed on the ICS-CERT landing page, but it was reported on TWITTER®.

GE Advisory

This advisory describes twin vulnerabilities in the GE SNMP/Web Interface adapter. The vulnerabilities were reported by Karn Ganeshen. GE has produced a firmware update to fix the vulnerability in newer versions. There is no indication that Ganeshen has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Command injection - CVE-2016-0861; and
• Cleartext storage of sensitive information - CVE-2016-0862

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to execute arbitrary system commands.

The GE Product Security Advisory notes that these adapters are used with uninterruptable power supplies.

Sauter Advisory 

This advisory describes three vulnerabilities in the Sauter moduWeb Vision application. The vulnerabilities were reported by Martin Jartelius and John Stock of Outpost24. Sauter has produced a firmware update to fix the vulnerabilities. ICS-CERT reports that the researchers have validated the efficacy of the fix.

The vulnerabilities include:

• Insecure credential storage - CVE-2015-7914;
• Insecure transmission of credentials - CVE-2015-7915; and
• Cross-site scripting - CVE-2015-7916

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to gain system access and escalate privileges. 

Tuesday, July 22, 2014

ICS-CERT Obscures Publication of Two Advisories

This afternoon the DHS ICS-CERT published two control system advisories on their web site. For some reason, probably an oversight, they did not list the two advisories on the landing page of their web site. They were reported on TWITTER® (here and here) and are listed on the Advisories page of their web site. The advisories report multiple vulnerabilities in systems from Omron and Honeywell.

Omron Advisory

This advisory describes vulnerabilities reported by Joel Sevilleja Febrer of S2 Grupo with Omron’s NS series HMI terminals. ICS-CERT reports that Omron has produced an update that mitigates the vulnerabilities, but there are no indications that Sevilleja has had the opportunity to verify the efficacy of the effort.

The twin vulnerabilities are:

• Cross-site request forgery - CVE-2014-2369; and
• Cross-site scripting - CVE-2014-2370.

ICS-CERT reports that it would take a moderately to highly skilled attacker to remotely exploit these vulnerabilities. The advisory provides separate links to the new versions of each affected system. Interestingly, I can find no mention of the updated versions or the security issues requiring the update at the links provided.

Honeywell Advisory

This advisory describes vulnerabilities reported by Martin Jartelius of Outpost24 and Juan Francisco Bolivar in the Honeywell Falcon XLWeb controller. ICS-CERT reports that Honeywell has produced an update that deals with both vulnerabilities, but there is no indication that the researchers have been given the opportunity to verify the efficacy of the fix.

The twin vulnerabilities are:

• File accessible to external parties - CVE-2014-2717; and
• Cross-site scripting - CVE-2014-3110.

ICS-CERT reports that a moderately skilled attacker could remotely exploit these vulnerabilities. Honeywell’s report on these vulnerabilities is only available to registered owners.


NOTE: This advisory was previously posted to the US-CERT Secure Portal. Once again, I urge all control system owner, integrators and security researchers to register for access to this portal for valuable advance notice of advisories like this.
 
/* Use this with templates/template-twocol.html */