Showing posts with label Mat Powell. Show all posts
Showing posts with label Mat Powell. Show all posts

Tuesday, September 17, 2019

3 Advisories Published – 09-17-19


Today the DHS NCCIC-ICS published three control system security advisories for products from Honeywell, Siemens and Advantech.

Honeywell Advisory


The advisory describes an information exposure vulnerability in the Honeywell  Performance IP Series cameras and Performance Series NVRs are affected. The vulnerability was reported by Ismail Bulbil. Honeywell has an update that mitigates the vulnerability. There is no indication that Bulbil has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to view device configuration information.

NOTE 1: The Honeywell advisory for this vulnerability was published on April 30th, 2019. Two additional advisories were published last Friday. I will discuss these on Saturday unless NCCIC-ICS publishes their advisories later this week.

NOTE 2: The link to the Honeywell advisory in this advisory does not work.

Siemens Advisory


The advisory describes four vulnerability in the Siemens SINEMA Remote Connect Server. The vulnerabilities were reported by Hendrik Derre and Tijl Deneut from HOWEST. Siemens has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

Improper restriction of excessive authentication attempts - CVE-2019-13918;
Information exposure - CVE-2019-34623;
Cross-site request forgery - CVE-2019-13920; and
Use of password hash with insufficient computational effort - CVE-2019-13922

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerabilities to allow an attacker unauthorized access to the web interface, improper access to privileged user and device information, and may allow successful CSRF attacks.

NOTE: I briefly reported on these vulnerabilities last Saturday.

Advantech Advisory


The advisory describes four vulnerabilities in the Advantech WebAccess HMI platform. The vulnerabilities were reported by Peter Cheng of Elextec Security Tech. Co., and Mat Powell of the Zero Day Initiative. Advantech has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported advisories are:

Code injection (2) - CVE-2019-13558, and CVE-2019-13552;
Stack-based buffer overflow - CVE-2019-13556; and
Improper authorization - CVE-2019-13550

Friday, August 2, 2019

6 Advisories Published – 08-01-19


Yesterday the DHS NCCIC-ICS published six control system advisories for products from Leão Consultoria e Desenvolvimento de Sistemas (LCDS), Rockwell, 3S (2), Fuji Electric and Advantech.

LCDS Advisory


This advisory describes two vulnerabilities in the LCDS LAquis SCADA software. The vulnerabilities were reported by Francis Provencher (PRL) via the Zero Day Initiative. LCDS has an update available that mitigates the vulnerability. There is no indication that Provencher has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Out-of-bounds read - CVE-2019-10994; and
Type confusion - CVE-2019-10980


NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to obtain confidential information or execute remote code.

Rockwell Advisory


This advisory describes two vulnerabilities in the Rockwell Arena Simulation Software. The vulnerabilities were reported by kimiya of 9SG Security Team via ZDI. Rockwell has a new version that mitigates the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

Use after free - CVE-2019-13510; and
Information exposure - CVE-2019-13511

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to cause a current Arena session to fault or enter a denial-of-service (DoS) state, allowing the attacker to run arbitrary code.

First CODESYS Advisory


This advisory describes an insufficiently protected credentials vulnerability in the CmpUserMgr component of 3S CODESYS products. The vulnerability was reported by JunYoung Park. 3S will correct this vulnerability in a new version to be released in February. The 3S advisory strongly recommends activating and using encryption of online communication whenever possible.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow for an attacker with access to PLC traffic to obtain user credentials.

NOTE: Is it just me or is this advisory just a seven-month zero-day announcement?

Second CODESYS Advisory


This advisory describes two vulnerabilities in the CmpGateway component of the 3S CODESYS products. These vulnerabilities are self-reported. 3S has a new version that mitigates the vulenrabilities.

The two reported vulnerabilities are:

Unverified ownership - CVE-2019-9010; and
Uncontrolled memory allocation - CVE-2019-9012 

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow a remote attacker to close existing communication channels or to take over an already established user session to send crafted packets to a PLC.

NOTE 1: There were six other advisories published by 3S at the same time as the two referenced in these two NCCIC-ICS advisories. I will address them this weekend.

NOTE 2: A reminder that the CODESYS operating system is used in a wide variety of devices and systems. These vulnerabilities will have widespread application. Few vendors are expected to publish updates referencing these vulnerabilities.

Fuji Advisory


This advisory describes and out-of-bounds read vulnerability in the Fuji  FRENIC Loader. The vulnerability was reported by kimiya of 9SG Security Team via ZDI. Fuji has a new version that mitigates the vulnerability. There is no indication that the kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow information disclosure.

Advantech Advisory


This advisory describes an out-of-bounds write vulnerability in the Advantech WebAccess HMI Designer. The vulnerability was reported by Mat Powell via ZDI. Advantech has a new version that mitigates the vulnerability. There is no indication that Powell has been provided an opportunity to verify the efficacy of the fix.

Friday, June 28, 2019

6 Advisories Published – 06-27-19


Yesterday the DHS NCCIC-ICS published five control system security advisories for products from Advantech, SICK AG, and ABB (3). They also published a medical device security advisory for products from Medtronic.

Advantech Advisory


This advisory describes six vulnerabilities in the Advantech WebAccess/SCADA software platform. The vulnerabilities were reported by Mat Powell, Natnael Samson (@NattiSamson) and EljahLG via the Zero Day Initiative. Advantech has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

Path traversal - CVE-2019-10985;
Stack-based buffer overflow - CVE-2019-10991;
Heap-based buffer overflow - CVE-2019-10989;
Out-of-bounds read - CVE-2019-10983;
Out-of-bounds write - CVE-2019-10987; and
Untrusted pointer dereference - CVE-2019-10993

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow information disclosure, deletion of files, and remote code execution.

SICK Advisory


This advisory describes a use of hard-coded credentials vulnerability in the SICK MSC800 PLC. The vulnerability was reported by Tri Quach of Amazon’s Customer Fulfillment Technology Security (CFTS) group. SICK has new firmware that mitigates the vulnerability. There is no indication that Quach has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow a low-skilled remote attacker to reconfigure settings and/or disrupt the functionality of the device.

CP 635 Advisory


This advisory describes a use of hard-coded credentials vulnerability in the ABB CP620 and CP635 HMI products. The vulnerability is self-reported. ABB has an update available that mitigates the vulnerability.

The ABB advisory describes two other vulnerabilities with these products and reports that the vulnerabilities were reported by Xen1thLabs. The individual vulnerability reports from Xen1thLabs (see links below) include proof of concept exploits.

The three reported vulnerabilities are:

Out-dated software components – multiple OpenSSL CVE;
Hard-coded credentials - CVE-2019-7225; and
Absence of signature verification - CVE-2019-7229

NCCIC-ICS reports that a relatively low-skilled attacker on an adjacent network could exploit the (single reported?) vulnerability to allow an attacker to prevent legitimate access to an affected system node, remotely cause an affected system node to stop, take control of an affected system node, or insert and run arbitrary code in an affected system node.

CP 651 Advisory


This advisory describes a use of hard-coded credentials vulnerability in the ABB CP651, CP665 and CP676 HMI products. The vulnerability is self-reported. ABB has an update available that mitigates the vulnerability.

The ABB advisory describes the same two other vulnerabilities with these products and reports that the vulnerabilities were discovered based upon the work of Xen1thLabs on the CP 635 vulnerabilities reported above.

NCCIC-ICS reports that a relatively low-skilled attacker on an adjacent network could exploit the (single reported?) vulnerability to allow an attacker to prevent legitimate access to an affected system node, remotely cause an affected system node to stop, take control of an affected system node, or insert and run arbitrary code in an affected system node.

Panel Builder Advisory


This advisory describes seven vulnerabilities in the ABB PB610 Panel Builder 600 engineering tool. The vulnerability was reported by Xen1thLabs. ABB has new versions available that mitigate the vulnerabilities. There is no indication that Xen1thLabs has been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities (with links to the Xen1thLabs reports; reports which contain proof of concept exploit code) are:

Use of hard-coded credentials - CVE-2019-7225;
Improper authentication - CVE-2019-7226;
Relative path traversal - CVE-2019-7227;
Improper input validation (2) - CVE-2019-7228 and CVE-2019-7230; and
Stack-based buffer overflow - CVE-2019-7231

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to prevent legitimate access to an affected system node, remotely cause an affected system node to stop, take control of an affected system node, or insert and run arbitrary code in an affected system node.

Medtronic Advisory


This advisory describes an improper access control vulnerability in the Medtronic MiniMed 508 and Paradigm Series Insulin Pumps. The vulnerability is self-reported, but NCCIC-ICS notes that the internal investigation by Medtronic was guided by previous work from outside researchers on other Medtronic products. Medtronic suggests upgrading to a newer product. The FDA advisory on this product notes that Medtronic is recalling the affected insulin pumps.

NCCIC-ICS reports that an uncharacterized attacker with adjacent access (radio frequency access according to the Medtronic advisory) could exploit this vulnerability to intercept, modify, or interfere with the wireless RF (radio frequency) communications to or from the product. This may allow attackers to read sensitive data, change pump settings, or control insulin delivery.

Wednesday, February 6, 2019

5 Advisories and 6 Updates Published – 02-05-19


Yesterday the DHS NCCIC-ICS published five control system advisories for products from Kunbus, Siemens, WECON, Rockwell and AVEVA. They also updated five previously published advisories for products from Siemens and updated a medical device security advisory for products from BD.

Kunbus Advisory 


This advisory describes three vulnerabilities in the Kunbus PR100088 Modbus gateway. The vulnerabilities were reported by Nicolas Merle of Applied Risk. Kunbus has a new version that mitigates the vulnerability. There is no indication that Merle has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Improper authentication - CVE-2019-6527;
• Missing authentication for critical function - CVE-2019-6533; and
Improper input validation - CVE-2019-6529

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to achieve remote code execution and/or cause a denial-of-service condition.

Siemens Advisory 


This advisory describes two improper input validation vulnerabilities in the Siemens SIMATIC S7-1500 CPU. The vulnerabilities were reported by Georgy Zaytsev, Dmitry Sklyarov, Druzhinin Evgeny, Ilya Karpov, and Maxim Goryachy of Positive Technologies. Siemens has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a denial of service condition of the device.

WECON Advisory 


This advisory describes three vulnerabilities in the WECON LeviStudioU product. The vulnerabilities were reported by Mat Powell, Ziad Badawi, and Natnael Samson via the Zero Day Initiative. WECON has an updated version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Heap-based buffer overflow - CVE-2019-6539;
• Stack-based buffer overflow - CVE-2019-6537; and
• Memory corruption - CVE-2019-6541

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to allow attackers to execute arbitrary code.

Rockwell Advisory 


This advisory describes an improper input validation vulnerability in the Rockwell EtherNet/IP Web Server Modules. The vulnerability was reported by Tenable. Rockwell has provided generic mitigations for the vulnerability. There is no indication that Tenable has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow a remote attacker to deny communication with Simple Network Management Protocol (SNMP) service.

AVEVA Advisory


This advisory describes two vulnerabilities in the AVEVA InduSoft Web Studio and InTouch Edge HMI products. The vulnerabilities were reported by Tenable. AVEVA has a new version that mitigates the vulnerability. AVEVA reports that Tenable has verified the efficacy of the fix.

The two reported vulnerabilities are:

• Missing authentication for critical function - CVE-2019-6543; and
• Resource injection - CVE-2019-6545

NCCIC-ICS reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to allow a remote attacker to execute an arbitrary process using a specially crafted database connection configuration file.

SIMATIC PCS7 Update 


This update provides additional information on an advisory that was originally published on March 29th, 2018 and updated on April 24th, 2018, June 12th, 2018, November 14th, 2018 and again on December 13th, 2018. This update provides corrected version numbers and patch links for WinCC 7.2 and 7.4.

NOTE: I briefly discussed this update on January 12th.

SIMATIC Update


This update provides additional information on an advisory that was originally published on March 20th, 2018 and updated on October 9th, 2018. This update provides corrected version numbers and patch links for SIMATIC S7-300 incl. F and T.

NOTE: I briefly discussed this update on January 12th.


Industrial Products Update


This update provides additional information on an advisory that was that This update provides additional information on an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th, November 28th, February 27th, 2018, May 3rd, 2018 May 15th, 2018, September 11th, 2018, October 9th, 2018, November 13th, 2018 and most recently on December 11th, 2018. This update provides a link to an updated solution for SIMATIC S7-300.

NOTE: I briefly discussed this update on January 12th.

Discovery Service Update 


This update provides additional information on an advisory that was originally published on 8-31-17 and updated on October 3rd, 2017 and again on November 30th, 2017. This update provides updated version information and provides a link to the fix for SIMATIC NET PC Software.

NOTE: I briefly discussed this update on January 12th.

PROFINET Update


This update provides additional information on an advisory that was was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th,  November 28th, 2017January 18th, 2018, January 25th, 2018, January 27th, 2018, March 6th, 2018, May 3rd, 2018, November 13th, 2018 and most recently on December 11th, 2018. This update provides corrected information for CP 1243-1.

NOTE: I briefly discussed this update on January 12th.

BD Update


This update provides additional information on an advisory that was originally published on January 29th, 2019. In the vulnerability overview section of the advisory this update changes the words “The application…” to “The system…”.

Commentary


On January 12th, 2019 I reported on the five advisories and seven updates published by Siemens on December 8th. To date NCCIC-ICS has only reported on one of the advisories and six of the updates. I do not expect to see an update on the final Siemens update as it is for the generic GNU/Linux vulnerabilities that is covered by an NCCIC-ICS alert. I am beginning to suspect that NCCIC-ICS will not be reporting on the remaining Siemens advisories. This may be because the vulnerability reports were not coordinated through NCCIC-ICS. Or it may be that NCCIC-ICS was understaffed during the recent Federal Funding Fiasco and has not yet had time to catch up with all of the vulnerability reporting that occurred during that time.

As I gradually expand the list of web sites that I scan weekly for my ‘Public ICS Disclosures’ blog post, it is becoming rather obvious that NCCIC-ICS is not a central clearing house for ICS vulnerability disclosures. That means that there is no central agency that is tracking (and more importantly reporting on) vulnerabilities in the ICS sphere. With the major ICS vendors this is probably not a major issue since they have relatively robust reporting systems of their own. But for the second and third tier of vendors, this is going to become a serious problem.

If/when Congress ever gets around to looking at the subject on control system security, one of the issues that they are going to have to look at (and hopefully rationally deal with) is the issue of vulnerability coordination and disclosure. When/if they do that, I would hope that they would consider codifying and expanding the role of NCCIC-ICS in that process. And, I believe, that part of that expansion should be establishing NCCIC-ICS as the public clearing house for vulnerability disclosure in the control system arena.

Thursday, October 25, 2018

Two Advisories Published


Today the DHS NCCIC-ICS published two control system security advisories for products from Advantech and GEOVAP.

Advantech Advisory


This advisory describes two vulnerabilities in the Advantech WebAccess application. The vulnerability was reported by Mat Powell via the Zero Day Initiative. Advantech has a new version (the same version that mitigated Tuesday’s vulnerabilities) that mitigates the vulnerabilities. There is no indication that Powell has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper Access Control - CVE-2018-17908; and
Stack-based buffer overflow - CVE-2018-17910

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow for arbitrary remote code execution.

NOTE: It is interesting that Matt has two Advantech advisories this week where he is the security researcher. Looking at the CVE numbers it looks like there was at least some delay between the reporting of the two sets of vulnerabilities. Not surprising that Advantech would fix all five vulnerabilities in the same version; finding vulnerabilities almost certainly takes less time than fixing them.

GEOVAP Advisory


This advisory describes a cross-site scripting vulnerability in the GEOVAP Reliance 4 SCADA/HMI. The vulnerability was reported by Ismail Mert AY AK. GEOVAP has a new version that mitigates the vulnerability. There is no indication that Ismail has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an unauthenticated attacker to use HTTP proxy to inject arbitrary Javascript in a specially crafted HTTP request that may reflect it back in the HTTP response.

Thursday, October 18, 2018

Omron Advisory Published


Yesterday the DHS NCCIC-ICS published a control system security advisory for products from Omron. The advisory describes four vulnerabilities in the Omron CX-Supervisor. The vulnerabilities were reported by Mat Powell, Ariele Caltabiano (kimiya) of 9SG Security Team, and b0nd @garage4hackers via the Zero Day Initiative. Omron has a new version that mitigates the vulnerabilities. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Improper restriction of operations within the bounds of a memory buffer - CVE-2018-17905;
• Out-of-bounds read - CVE-2018-17907;
• Use after free - CVE-2018-17909; and
Incorrect type version or cast - CVE-2018-17913

NCCIC-ICS reports that an uncharacterized hacker with uncharacterized access could exploit these vulnerabilities to execute code under the context of the application, corrupt objects, and force the application to read a value outside of an array.

Wednesday, October 17, 2018

Advisory for LCDS Products


Yesterday the DHS NCCIC-ICS published a control system advisory for products from Leão Consultoria e Desenvolvimento de Sistemas Ltda (LCDS). The advisory describes six vulnerabilities in the LAquis SCADA software. The vulnerabilities were reported by Mat Powell, rgod of 9SG Security Team, Esteban Ruiz (mr_me) of Source Incite, b0nd @garage4hackers, and Ashraf Alharbi (Ha5ha5hin) via the Zero Day Initiative. LCDS has a new version that mitigates the vulnerability. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Untrusted pointer dereference - CVE-2018-17893;
• Out-of-bounds read - CVE-2018-17895;
• Integer overflow to buffer overflow - CVE-2018-17897;
• Path traversal - CVE-2018-17899;
• Out-of-bounds write - CVE-2018-17901 and
Stack-based buffer overflow - CVE-2018-17911

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to execute arbitrary code, crash the system, or write controlled content to the target system.

Friday, October 5, 2018

ICS Advisory and 2 Medical Device Advisories


Yesterday the DHS NCCIC-ICS published a controls system security advisory for products from WECON and two medical device security advisories for products from Change Healthcare and Carestream.

WECON Advisory


This advisory describes four vulnerabilities in the WECON PI Studio, a HMI project programmer. The vulnerabilities were reported by Mat Powell and Natnael Samson (Natti) via the Zero Day Initiative. WECON is working on mitigation measures.

The four reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-14818;
• Out-of-bounds write - CVE-2018-14810;
• Information exposure through XML external entity reference - CVE-2018-17889; and
Out-of-bounds read - CVE-2018-14814

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow remote code execution, execution of code in the context of an administrator, read past the end of an allocated object or allow an attacker to disclose sensitive information under the context of administrator.

Change Healthcare Advisory


This advisory describes an information exposure through error message vulnerability in the Change Healthcare PeerVue Web Server. The vulnerability was reported by Dan Regalado of Zingbox. Change Healthcare has a patch available to mitigate the vulnerability. There is no indication that Regalado has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker on an adjacent network could exploit the vulnerability to allow an attacker to obtain technical information about the PeerVue Web Server, allowing an attacker to target a system for attack.

Carestream Advisory


This advisory describes an information exposure through an error message vulnerability in the Carestream Vue RIS, a web-based radiology information system. The vulnerability was reported by Dan Regalado of Zingbox. Carestream has a new version that mitigates the vulnerability and has provided workarounds. There is no indication that Regalado has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker with access to the network can exploit the vulnerability to passively read traffic.

NOTE: It is always interesting to see a researcher who has found an unusual vulnerability in one system to then look for the same type vulnerability in other related systems. It makes me wonder if developers reading these advisories (and of course they do, right?) ask themselves if their systems have the same vulnerability.

Friday, September 28, 2018

4 ICS Advisories


Yesterday the DHS NCCIC-ICS (okay, I finally gave in; ICS-CERT is gone; please clean up the web site) published four control system security advisories for products from Delta Electronics, Fuji Electric (2) and Emerson.

Delta Advisory

This advisory describes an out-of-bounds read vulnerability in the Delta Industrial Automation PMSoft software development tool. The vulnerability was reported by Mat Powell via ZDI. Delta has an update available that mitigates the vulnerability. There is no indication that Powell has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to read confidential information.

FRENIC Advisory


This advisory describes three vulnerabilities in the Fuji FRENIC HVAC drive devices. The vulnerability was reported by Michael Flanders and Ghirmay Desta via ZDI. Fuji is working on mitigation measures.

The three reported vulnerabilities are:

• Buffer over-read - CVE-2018-14790;
• Out-of-bounds read - CVE-2018-14798; and
Stack-based buffer overflow - CVE-2018-14802

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow for arbitrary remote code execution affecting the availability of the device.

Alpha5 Advisory


This advisory describes two buffer-overflow vulnerabilities in the Fuji Alpha5 Smart Loader servo drive. The vulnerability was reported by Michael Flanders via ZDI. Fuji is working on mitigation measures.

The two reported vulnerabilities are:

• Classic buffer overflow - CVE-2018-14788; and
• Heap-based buffer overflow - CVE-2018-14794

NCCIC-ICS reports that a relatively low-skilled attacker could remotely use publicly available exploits to allow for arbitrary remote code execution on the device.

NOTE: It is disappointing that Fuji was not even able to provide workaround security measures for these two product lines. Does anyone know if NCCIC-ICS is still giving the 45-day grace period before publishing their advisories?

Emerson Advisory


This advisory describes two vulnerabilities in the Emerson AMS Device Manager. The vulnerabilities were reported by Sergey Temnikov of Kaspersky Lab and Emerson. Emerson has patches available to mitigate the vulnerabilities. There is no indication that Temnikov has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper access control - CVE-2018-14804; and
• Improper privilege management - CVE-2018-14808

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to

Tuesday, August 7, 2018

ICS-CERT Publishes 3 Advisories


Today the DHS ICS-CERT published one control system security advisory for products from Delta Electronics and two medical device security advisories for products from Medtronic.

Delta Advisory


This advisory describes two vulnerabilities in the Delta CNCSoft and ScreenEditor products. The vulnerability was reported by Mat Powell via the Zero Day Initiative. Delta has an updated version of CNCSoft that mitigates the vulnerabilities. There is no indication that Powell was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-10636; and
Out-of-bounds read - CVE-2018-10598

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to gain remote code execution with administrator privileges.

MiniMed Advisory


This advisory describes two vulnerabilities in the Medtronic MiniMed 508 Insulin Pump. The vulnerabilities were reported by Billy Rios, Jesse Young, and Jonathan Butts of Whitescope LLC. Medtronic does not intend to develop a mitigation for these vulnerabilities (see note below).

The two reported vulnerabilities are:

• Cleartext transmission of sensitive information - CVE-2018-10634; and
• Authentication bypass by capture replay - CVE-2018-14781

ICS-CERT reports that an uncharacterized attacker could remotely exploit these vulnerabilities to allow an attacker to replay captured wireless communications and cause an insulin (bolus) delivery.

NOTE: The Medtronic security advisory reports that the following must occur for these vulnerabilities to be exploited:

1. The remote option for the pump would need to be enabled. This is not a factory-delivered default, and a user must choose this option.
2. The user’s remote controller ID needs to be registered to the pump.
3. The easy bolus option would need to be turned on and easy bolus step size programmed in the pump.
4. An unauthorized individual would need to be within close proximity to the user, with
necessary equipment to copy the RF signals activated, when the user is delivering a bolus
using the remote controller.
5. The unauthorized individual would need to be within the vicinity of the userto play back the RF signals to deliver a malicious remote bolus.
6. The user would need to ignore the pump alerts, which indicates that a remote bolus is being delivered.

MyCareLink Advisory


This advisory describes two vulnerabilities in the Medtronic MyCareLink Patient Monitor. The vulnerabilities were reported by Billy Rios, Jesse Young, and Jonathan Butts of Whitescope LLC. Medtronic is making (has made for one of the vulnerabilities) server side updates to mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Insufficient verification of data authenticity - CVE-2018-10626; and
• Storing passwords in a recoverable format - CVE-2018-10622

ICS-CERT reports that an uncharacterized attacker with physical access to the device could exploit the vulnerabilities to obtain per-product credentials that are utilized to authenticate data uploads and encrypt data at rest. Additionally, an attacker with access to a set of these credentials and additional identifiers can upload invalid data to the Medtronic CareLink network.

Tuesday, July 31, 2018

ICS-CERT Publishes 5 Advisories


Today the DHS ICS-CERT published five control system security advisories for products from AVEVA (2), WECON, Johnson Controls and Davolink.

Wonderware Advisory


This advisory describes an improper restriction in operations within the bounds of a memory buffer vulnerability in the AVEVA Wonderware License Server; the vulnerability is in the 3rd party  Flexera FlexNet Publisher software. The vulnerability was reported to AVEVA by an anonymous researcher. AVEVA has an update that mitigates the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability to effect remote code execution with administrative privileges.

NOTE: This vulnerability was also reported in the Rockwell Factory Talk Activation Manager earlier this year. There is an interesting blog post from 2016 about this vulnerability over at Security Mumblings.

InTouch Advisory


This advisory describes a cross-site scripting vulnerability in the AVEVA InTouch Access Anywhere product. The vulnerability was reported by Google’s Security Team. AVEVA has an update that mitigates the vulnerability. The AVEVA security advisory indicates that the researchers have verified the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability to obtain sensitive information and/or execute Javascript or HTML code.

WECON Advisory


This advisory describes two buffer overflow vulnerabilities in the WECON LeviStudioU. The vulnerabilities were reported by NSFOCUS security team, Ghirmay Desta and Mat Powell via the Zero Day Initiative.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-10602; and
Heap-based buffer overflow - CVE-2018-10606

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to execute remote code.

NOTE: Reading between the lines of the advisory, it looks like ICS-CERT did not get much cooperation from WECON on these vulnerabilities.

Johnson Controls Advisory


This advisory describes an information exposure through an error message vulnerability in the Johnson Controls Metasys and BCPro products. The vulnerability was reported by Dan Regalado of Zingbox. Newer versions mitigate the vulnerability. There is no indication that Regalado was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker on an adjacent network could exploit the vulnerability to obtain technical information about the Metasys or BCPro server, allowing an attacker to target a system for attack.

Davolink Advisory


This advisory describes a use of password hash with insufficient computational effort vulnerability in the Davolink DVW-3200N network switch. The vulnerability was reported by Ankit Anubhav of NewSky Security. There is new firmware for the device that mitigates the vulnerability. There is no indication that Anubhav was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to obtain the password to the device.

Tuesday, May 15, 2018

ICS-CERT Publishes Advantech Advisory and Updates Siemens Advisory


Today the DHS ICS-CERT published a control system security advisory for products from Advantech. They also updated a previously issued advisory for products from Siemens.

Advantech Advisory


This advisory describes eleven vulnerabilities in the Advantech WebAccess products. The vulnerabilities were reported by Mat Powell and rgod, working with ZDI; Steven Seeley of Offensive Security, working with ZDI; and Donato Onofri and Simone Onofri of Business Integration Partners S.p.A. Advantech released a new version that mitigates the vulnerabilities. There is no indication that any of the researchers were provided an opportunity to verify the efficacy of the fix.

The eleven reported vulnerabilities are:

• SQL injection - CVE-2018-7501;
• Information exposure through directory listing - CVE-2018-10590;
• Improper authorization - CVE-2018-7505;
• Path traversal (2) - CVE-2018-7503, and CVE-2018-10589;
• Stack-based buffer overflow - CVE-2018-7499;
• Heap-based buffer overflow - CVE-2018-8845;
• Untrusted pointer dereference - CVE-2018-7497;
• External control of file name or path - CVE-2018-7495;
• Origin validation error - CVE-2018-10591; and
Improper privilege management - CVE-2018-8841

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilitie to disclose sensitive information from the host and/or target, execute arbitrary code, or delete files.

Siemens Update


This update provides additional information for an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th, November 28th, February 27th, 2018 and most recently on May 3rd, 2018. The new information includes links to new versions for version 4.7 of:

• SINAMICS G130;
• SINAMICS G150;
• SINAMICS S120; and
• SINAMICS S150

The Siemens security advisory provided undated version information for the same products, but that was not reported in the ICS-CERT advisory

NOTE: Siemens also reported two other updated advisories (here and here) and a new advisory (here) today when they reported this update. Hopefully ICS-CERT will publish their versions later this week.

 
/* Use this with templates/template-twocol.html */