Showing posts with label Matthias Niedermaier. Show all posts
Showing posts with label Matthias Niedermaier. Show all posts

Wednesday, April 17, 2019

Three Advisories Published – 04-16-19


Yesterday the DHS NCCIC-ICS published two control system security advisories for products from WAGO and Delta Industrial Automation, and one for PLC products from multiple vendors.

PLC Advisory


This advisory describes an uncontrolled resource consumption vulnerability in specific PLC products from ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO. The vulnerability was reported by Matthias Niedermaier (Hochschule Augsburg), Jan-Ole Malchow (Freie Universität Berlin), and Florian Fischer (Hochschule Augsburg). The responses range from a firmware update from Schneider, to ‘its not really a vulnerability but here are generic workarounds’, to ‘its not a vulnerability’ from Siemens. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fixes.

NCCIC-ICS reports that a relatively low-skilled attacker could use a publicly available exploit to emotely influence configured cycle times.

NOTE: The Schneider advisory referenced in this advisory was released in February and listed a 2018 CVE number for the reported vulnerability. Neither CVE number is currently available.

WAGO Advisory


This advisory describes a hard-coded credential vulnerability in the WAGO Series 750-88x and 750-87x PLCs. The vulnerability was reported by Jörn Schneeweisz of Recurity Labs. WAGO has new firmware that mitigates the vulnerability. There is no indication that Schneeweisz has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to change the settings or alter the programming of the device.

NOTE: I briefly mentioned this vulnerability last Saturday.

Delta Advisory


This advisory describes three vulnerabilities in the Delta Industrial Automation CNCSoft screen editor software. The vulnerabilities were reported by Natnael Samson and an anonymous researcher via the Zero Day Initiative. Delta has an updated version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

Stack-based buffer overflow - CVE-2019-10947;
Heap-based buffer overflow - CVE-2019-10951; and
Out-of-bounds read - CVE-2019-10949

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to cause buffer overflow conditions that may allow information disclosure, remote code execution, or crash the application.

Saturday, February 16, 2019

Public ICS Disclosures – Week of 02-09-19


This week we have five vendor disclosures for products from Kunbus, Schneider (3) and Rockwell; five vendor updates from Siemens; one coordinated disclosure for products from Resource Data Management and one exploit for a previously disclosed vulnerability for products from AVEVA.

Kunbus Advisory


Kunbus published an advisory for five vulnerabilities in its KUNBUS-GW Modbus TCP PR100088 product. The vulnerabilities were reported by Nicolas Merle of Applied Risk. Kunbus is working on an update to mitigate the vulnerabilities.

The five reported vulnerabilities are:

• Conditional authentication bypass;
• Missing authentication for critical function;
• Denial of service;
• Publication of information by parameter data in an HTTP GET request; and
Plain text storage of passwords

Schneider Advisories


Schneider has published an advisory describing six vulnerabilities in its Sarix Enhanced and Spectra Enhanced cameras. The vulnerabilities were reported by Deng Yongkai (NSFOCUS) and Gjoko Krstic (Zero Science). Schneider has a new firmware version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• A permissions, privileges, and access control vulnerability - CVE-2018-7816;
• A command injection vulnerability (2) - CVE-2018-7825 and CVE-2018-7826;
• A cross-site scripting (XSS) vulnerability (2) - CVE-2018-7827 and CVE-2018-7828; and
• An improper neutralization of special elements in query vulnerability - CVE-2018-7829


Schneider has published an advisory describing a buffer error vulnerability in its Vijeo Designer Lite software. The vulnerability is self-reported. Schneider has provided generic mitigations as the product has reached end-of-life status.


Schneider has published an advisory describing three vulnerabilities in its  Modicon M221 and
SoMachine Basic products. The vulnerabilities were reported by Matthias Niedermaier (Hochschule Augsburg), Jan-Ole Malchow (Freie Universität Berlin), Florian Fischer (Hochschule Augsburg) and Reid Wightman (Dragos Inc.). Schneider has updates available to mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• An environment vulnerability (2) - CVE-2018-7821 and CVE-2018-7823; and
• An incorrect default permissions vulnerability - CVE-2018-7822

Rockwell Advisory


Rockwell has published an advisory describing two vulnerabilities in its PowerMonitor 1000 monitor that were publicly reported (with exploits) in December (here and here) by Luca Chiou. Rockwell has provided generic mitigation measures pending development of updates. It also provides a link to intrusion prevention system (by CheckPoint) rules to detect the cross-site scripting vulnerability.

The two reported vulnerabilities are:

• Cross-site scripting - CVE-2019-19615; and
• Authentication bypass - CVE-2019-19616

 Siemens Updates


Siemens published an update for their advisory on Spectre and Meltdown Vulnerabilities in Industrial Products. They added updated affected version data and provided links to mitigations for:

• SIMATIC ET 200 SP Open Controller; and
• SIMATIC IPC547E

NOTE: NCCIC-ICS updated their alert (ICS-ALERT-18-011-01) for this vulnerability when Siemens added a new advisory. That technically included this update since the link provided in the alert goes to the latest version of the Siemens advisory.


Siemens published an update for their advisory on Spectre-NG (Variants 3a and 4) Vulnerabilities in Industrial Products. They added updated version data and provided links to mitigations for:

• SIMATIC ET 200 SP Open Controller:
• SIMATIC ET 200 SP Open Controller (F);
• SIMATIC S7-1500 Software Controller;
• SIMATIC IPC547E;
• SIMATIC ITP1000;
• SIMATIC IPC3000 SMART V2;
• SIMATIC IPC347E;
• SIMATIC HMI Basic; and
• Panels 2nd Generation:

They also removed the following unaffected products from the advisory:

• SIMATIC IPC227E;
• SIMATIC IPC277E;
• SIMATIC IPC327E; and
• SIMATIC IPC377E

NOTE: NCCIC-ICS is expected to update their advisory.


Siemens published an update for their advisory on Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP. They added two additional vulnerabilities to the list for these products:

• CVE-2018-1000876; and
• CVE-2018-16862
NOTE: NCCIC-ICS has not published an advisory/alert on these vulnerabilities.

Siemens has published an update for their advisory on Denial-of-Service in SICAM A8000 Series. They updated the CVSS vector due to known exploit.


Siemens has published an update for their advisory on Foreshadow / L1 Terminal Fault Vulnerabilities in Industrial Products. They updated the affected version data and provided links to the mitigation measures for:

• SIMATIC IPC547E;
• SIMATIC IPC547G;
• SIMATIC ITP1000;
• SIMATIC IPC3000 SMART V2; and
• SIMATIC IPC347E

They also removed the following unaffected products from the advisory:

• SIMATIC IPC227E;
• SIMATIC IPC277E;
• SIMATIC IPC327E; and
• SIMATIC IPC377E
NOTE: NCCIC-ICS has not published an advisory/alert on these vulnerabilities.

Resource Data Management


Safety Detective published an article describing default credential vulnerabilities for commercial refrigeration systems from Resource Data Management. The article describes how the researchers were able to locate vulnerable systems, change settings, and manipulate controls in systems in hospitals and stores.

AVEVA Exploit


Jacob Baines published an exploit for vulnerabilities in the AVEVA InduSoft Web Studio. The vulnerabilities were reported by NCCIC-ICS earlier this month.

Saturday, August 18, 2018

Public ICS Disclosures – Week of 08-11-18


This week we have three vendor disclosures from Yokogawa (2), and Belden and an advisory update from Siemens. There are also two disclosures from vdeCERT for products from Phoenix Contact and WAGO. Both of those disclosures pointed to an interesting research paper on “Measuring PLC Cycle Times under Attacks”.

Vnet/IP Network Switches Advisory


Yokogawa reports a debug vulnerability in their Vnet/IP network switches. The vulnerability is due to a third-party software issue (see Belden below). Yokogawa reports a work around since there “is no provision of firmware’s which are countermeasures against this vulnerability”.

License Management Advisory


Yokogawa reports a buffer overflow vulnerability in the license management function in a number of their products. Yokogawa has an update that mitigates the vulnerability. The advisory notes that ICS-CERT has been notified so there is a strong chance that this will be reported by ICS-CERT in the coming week.

Belden Advisory


Belden reports (.PDF Download) 16 separate vulnerabilities in the TCPdump functionality of their OWL industrial routers and HiOS ethernet switches. Belden provides a work around and notes that the TCPdump functionality is inactive by default.

NOTE: This advisory is actually dated July 27th, 2018 (and outside of this week’s window), but because of its relation to the Yokogawa advisory it is being included here because of the potential for other vendors being affected. Also note that the CVE’s for the vulnerabilities date back to 2016 and 2017. That indicates that either it took a long time to figure out the minor workaround, or Belden was not really concerned about these vulnerabilities.

Siemens Update


Siemens updated their general customer advisory for the Spectre/Meltdown vulnerabilities. The advisory was last updated on July 17th, 2018.This update adds information on the L1 Terminal Fault / Foreshadow versions of the vulnerabilities.

NOTE: The latest version (update H) of the ICS-CERT alert on Spectre/Meltdown still does not mention the newer variants of the vulnerabilities reported in this Siemens advisory.

Phoenix Contact Advisory


VDE-CERT reports an uncontrolled resource consumption vulnerability in the Phoenix Contact ILC 1x1 ETH. The vulnerability was reported by Matthias Niedermaier (Hochschule Augsburg), Jan-Ole Malchow (Freie Universität Berlin) and Florian Fischer (Hochschule Augsburg). A generic workaround has been provided.

WAGO Advisory


VDE-CERT reports an uncontrolled resource consumption vulnerability in the WAGO 750-8xx Controllers. he vulnerability was reported by Matthias Niedermaier (Hochschule Augsburg), Jan-Ole Malchow (Freie Universität Berlin) and Florian Fischer (Hochschule Augsburg). A generic workaround has been provided.

Measuring PLC Cycle Times under Attacks


The research paper that pointed out the Phoenix Contact and WAGO vulnerabilities discussed above provides an interesting look at the possibility of detecting on-going control-system attacks by monitoring PLC cycle times. As an academic look at this potential attack detection technique, this paper is well worth reading. From a process chemist’s point of view this points out a specific, unintended process problem, that these attacks might pose that also provide an indication of an on-going cyber-attack.

One of the problems that a process engineer/chemist has to deal with in designing a control system scheme in the chemical industry (and that is probably true for other industries as well) is the lag time between when a process indicator (sensor) notes that a process state needs to be changed and when the process actuator (valve for example) can complete its action to effect that change. A great deal of effort goes into ‘tuning’ the system to minimize the potential adverse impacts caused by that time lag.

This paper notes that a variety of attacks can affect the lag time within the PLC. Normally, this portion of the total lag time is small and nearly constant, so it is essentially ignored in the tuning process. This paper notes that in some attacks the lag time can be increased by up to several seconds (this can be an eternity in critical portions of many chemical reactions). To make things even more interesting it appears that TCPdump attacks (like those discussed in the Yokogawa and Belden advisories above) can actually speed-up the PLC processing and decrease the overall lag time, creating a whole new set of process problems.

This means that certain types of process upsets can be an indication of on-going cyber-attacks on control systems. To say the least, this complicates the job of the process overseers (another root cause possibility that needs to be examined), but it could provide control systems engineers with a warning to check their systems for other signs of attacks.

Friday, September 22, 2017

ICS-CERT Publishes 5 Advisories

Yesterday the DHS ICS-CERT published five control system security advisories for products from Schneider, Ctek, Digium, iniNet Solutions, and Saia Burgess Controls. The advisory for the products from Saia Burgess Controls was originally posted to the NCCIC Portal on August 22, 2017.

Saia Burgess Controls Advisory


This advisory describes an information exposure vulnerability in the Saia Burgess Controls PCD Controllers. The vulnerability was reported by Davide Fauri of Eindhoven University of Technology. The latest version of the firmware mitigates the vulnerability. There is no indication that Fauri has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to to obtain information in memory.

The SBC upgrade notes also report that the current version makes the following security changes:

• Protective functions are activated by default;
• Improved password protection associated with the role-based user management;
• Access filter using "white" and "black" lists;
• Removed hardcoded password [NOT mentioned in ICS-CERT advisory].

Similar changes were also apparently made to the SBC PG5 Controls Suite.

iniNet Solutions Advisory


This advisory describes an improper authentication vulnerability in the iniNet Solutions SCADA Webserver. The vulnerability was reported by Matthias Niedermaier and Florian Fischer, both of Augsburg University of Applied Sciences. iniNet has released a new version that allows users to implement basic authentication. There is no indication that the researchers were afforded an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability  to access human-machine interface (HMI) pages or to modify programmable logic controller (PLC) variables without authentication.

Digium Advisory


This advisory describes an OS command injection vulnerability in the Digium Asterisk GUI. The vulnerability was reported by Davy Douhine of RandoriSec. Asterisk GUI is no longer maintained and should not be used. Digium recommends affected users to migrate to Digium’s SwitchVox product.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability  to execute arbitrary code on the device.

Interesting Questions: Would owners of a control system that uses an HMI configured with Digium’s Asterix GUI even know that it had been used, particularly if the system had been designed by a contractor or vendor? Would it take a complete system redesign to change out the GUI for an HMI?

Ctek Advisory


This advisory describes an improper authentication vulnerability in the Ctek SkyRouter. The vulnerability was reported by Maxim Rupp. The latest firmware version mitigates this and “additional security requirements”. NOTE: “Ctek, Inc., reports that due to industry demand, wireless carriers are rapidly eliminating 2G and 3G CDMA service and they will not be creating any additional update releases for those products.” There is no indication that Rupp was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to view and edit settings without authenticating.

Schneider Advisory


This advisory describes a missing authentication for critical function vulnerability in the Schneider InduSoft Web Studio products. The vulnerability was reported by Aaron Portnoy, formerly of Exodus Intelligence. Schneider has created a patch to mitigate the vulnerability. There is no indication that Portnoy was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability  to remotely execute arbitrary commands with high privileges.


NOTE: The Schneider security bulletin was published last Friday. Maybe Dale Peterson was right, it looks like ICS-CERT is doing ‘ICS-vuln Thursday’.

Wednesday, November 9, 2016

ICS-CERT Publishes 3 Advisories and Latest Monitor

Yesterday the DHS ICS-CERT published three control system security advisories for products from OSIsoft, Siemens and Phoenix Contact. Earlier this week they also published the September – October 2016 Monitor.

ICS-CERT Monitor

The latest issue of the ICS-CERT Monitor reports on activities of the DHS ICS-CERT for September and October of 2016. No real valuable information in this issue of the Monitor with ICS-CERT returning to the glossy corporate quarterly report format for this issue. The main articles include:

• ICS-CERT Vulnerability Coordination;
• Cybersecurity Crawl, Walk, Run;
• DHS Moving US-CERT Portal to HSIN, Rebranding as NCCIC Portal;
• ICSJWG Fall 2016 Meeting Recap;
• ICS-CERT Hosts Regional Training in Lisbon, Portugal;
• ICS-CERT Releases Defense-in-Depth and Annual Vulnerability Coordination Reports; and
• What is a CSET Assessment?

OSIsoft Advisory


The advisory describes an incomplete model of endpoint features vulnerability in the OSIsoft PI System software. This is apparently a self-reported vulnerability. OSIsoft has produced a new version that mitigates the vulnerability.

ICS-CERT reports that a relatively unskilled attacker with local access could effect a DOS attack to cause a shutdown of the PI Data Archive or connected applications. The OSIsoft Security Update, on the other hand reports that an exploit of the session management issue could “result in remote shutdown of the PI Data Archive or connected applications”.

Siemens Advisory


The advisory describes a privilege escalation vulnerability that affects several of industrial products from Siemens (18 products listed in advisory). The vulnerability was reported by WATERSURE and KIANDRA IT. Siemens has produced updates for six of the products and temporary fixes for the remaining products pending the production of new updates.

ICS-CERT reports that it would be difficult to effect a working exploit of the vulnerability and would require local authenticated access to the product. Interestingly the Siemens Security Advisory notes that:

“If the affected products are installed under their default path (“C:\Program Files\*” or the localized equivalent) and the default file system access permissions for drive C:\ were not modified, the security vulnerability is not exploitable.”

Phoenix Contact Advisory


The advisory describes multiple authentication vulnerabilities in the Phoenix Contact ILC (inline controller) PLCs. The vulnerabilities were reported by Matthias Niedermaier and Michael Kapfer of HSASec Hochschule Augsburg. Phoenix Contact has produced an update and recommended security practices to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The vulnerabilities include:

• Cleartext storage of sensitive information - CVE-2016-8366;
• Authentication bypass issues - CVE-2016-8371; and
• Access to critical private variable via public method - CVE-2016-8380.


ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to access human-machine interface (HMI) pages and to modify programmable logic controller (PLC) variables. ICS-CERT explains that the new version only corrects the plaintext password storage issue.
 
/* Use this with templates/template-twocol.html */