Showing posts with label Maxim Rupp. Show all posts
Showing posts with label Maxim Rupp. Show all posts

Saturday, October 3, 2020

Public ICS Disclosures – Week of 9-26-20

This week we have ten vendor disclosures for products from WAGO (3), IBM, Bosch, B&R Automation (2), Moxa, BD, and Philips.

WAGO Advisories

CERT-VDE published an advisory describing an improper authentication and authorization vulnerability in the WAGO 750-8XX series PLCs. The vulnerability was reported by Maxim Rupp. WAGO has new firmware versions that mitigate the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

CERT-VDE published an advisory describing an improper authentication and access control vulnerability in the WAGO 750-36X and WAGO 750-8XX series PLCs. The vulnerability was reported by Maxim Rupp. WAGO has new firmware versions that mitigate the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

CERT-VDE published an advisory describing an improper neutralization of input during web page generation vulnerability in the Web-UI for WAGO 750-88X and WAGO 750-89X series PLCs. This vulnerability was reported by Secuninja. WAGO has new firmware versions that mitigate the vulnerability. There is no indication that Secuninja has been provided an opportunity to verify the efficacy of the fix.

IBM Advisory

IBM published an advisory describing an authentication bypass vulnerability in their Maximo Asset Management product. The vulnerability is being self-reported. IBM has updates that mitigate the vulnerability.

Bosch Advisory

Bosch published an advisory describing three vulnerabilities in their PRAESIDEO Network Controller and the PRAESENSA System Controller products. The vulnerabilities were reported by Gjoko Krstic of Applied Risk. Bosch has software updates for the supported products that mitigate the vulnerabilities. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Cross-site scripting - CVE-2020-6777,

• Cross-site request forgery - CVE-2020-6776, and

• Nonce reuse attack - CVE-2020-15688

NOTE: The last is a third-party vulnerability (GoAhead web server).

B&R Advisories

B&R published an advisory describing four vulnerabilities in their GateManager product. These vulnerabilities were reported by NCCIC-ICS on July 28th as being for the Secomea GateManager.

B&R published an advisory describing six vulnerabilities in their SiteManager and GateManager procucts. These vulnerabilities were reported by NCCIC-ICS last Tuesday, but the B&R advisory was not available when I published my blog post. It is not clear if the Secomea versions of these products are also affected by these vulnerabilities.

Moxa Advisory

Moxa published an advisory describing a device information leak vulnerability in their EDR-810 Series Industrial Secure Routers. The vulnerability was reported by the National Security Agency (yep, that is what the advisory says). Moxa has provided generic workarounds to mitigate the vulnerability.

BD Advisory

BD published an advisory describing a remote code execution vulnerability (CVE-2020-1147) in a third-party component (Microsoft) of a long list of their products. BD is working on testing and validation of the Microsoft patch.

Philips Advisory

Philips published an advisory describing a privilege elevation vulnerability (CVE-220-1472) in a third-party component (Microsoft) of an undisclosed number of Philips products. No mitigation information has been provided.

Saturday, April 4, 2020

Public ICS Disclosures – Week of 3-28-20


This week we have eight vendor disclosures for products from PEPPERL+FUCHS, ABB (4), B&R Automation, GE Digital and BD and updates for two previous vendor disclosures from 3S.

PEPPERL+FUCHS Advisory


VDE CERT published an advisory describing a time-of-check time-of-use race condition vulnerability in the PEPPERL+FUCHS Tab-Ex 02 mobile device. This is the third party 'Kr00k' vulnerability affecting encrypted WiFi traffic and PEPPERL+FUCHS reports that this is the only device of theirs that is vulnerable. PEPPERL+FUCHS plans on releasing an update to mitigate this vulnerability in May 2020.

NOTE: This vulnerability affects a variety of Broadcom and Cypress chipsets.

ABB Advisories


ABB published an advisory describing two weak file permission vulnerabilities in their System 800xA. The vulnerabilities were reported by William Knowles at Applied Risk. ABB has new versions that mitigate the vulnerability. There is no indication that Knowles has been provided an opportunity to verify the efficacy of the fix.


ABB published an advisory describing four vulnerabilities in their Telephone Gateway. The vulnerabilities were reported by Maxim Rupp. The product was phased out in 2015 and there are no plans to mitigate the vulnerability.

The four reported vulnerabilities are:

• Improper authentication and access control - CVE-2019-19104;
• Unprotected storage of credentials - CVE-2019-19105;
• Permissions, privileges and access control - CVE-2019-19106; and
• Information exposure - CVE-2019-19107


ABB published an advisory describing a remote code execution vulnerability in their System 800xA information manager. The vulnerability was reported by William Knowles at Applied Risk. An update to mitigate this vulnerability will be included in the next product release.


ABB published an advisory describing a weak registries permission vulnerability in their System 800xA. The vulnerability was reported by William Knowles at Applied Risk. ABB has a new version that mitigates the vulnerability. There is no indication that Knowles has been provided an opportunity to verify the efficacy of the fix.

B&R Advisory


B&R published an advisory describing a race condition vulnerability in a variety of their products. This is the third-party vulnerability, the Intel TPM Fail. B&R has bios patches available to mitigate the vulnerability.

GE Advisory


GE published an advisory describing a privilege escalation vulnerability in their CIMPLICITY HMI/SCADA product. The vulnerability was reported by Claroty. GE has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

BD Advisory


BD published an advisory describing three remote code execution vulnerabilities on a variety of BD products. These are third-party Microsoft vulnerabilities in the Remote Desktop services. BD reports that it is currently working to test and validate the Microsoft patch for their products.

The three reported vulnerabilities (links are to MS reports on the vulnerability) are:

CVE-2020-0610; and

3S Updates


3S published an update [.PDF download link] for an advisory that was originally published on March 25th, 2020. The new information includes reporting the availability of publicly available proof-of-concept exploit code that I reported last week.


3S published an update [.PDF download link] for an advisory that was originally published on March 25th, 2020. The new information includes reporting the availability of publicly available proof-of-concept exploit code that I reported last week.

Commentary


There are a lot of ‘third-party’ vulnerabilities being reported this week; all in systems that are likely to be found in products from other vendors. This is especially true when the ‘third-party’ is a major player like Intel or Microsoft.

Wednesday, February 12, 2020

13 Advisories and 5 Updates Published – 2-11-20

Today the CISA NCCIC-ICS published 13 control system security advisories for products from Synergy Systems and Solutions, Digi International and Siemens (11). They also updated five control system security advisories for products from Siemens.

Synergy Systems Advisory


This advisory describes two vulnerabilities in the SSS HUSKY RTU. The vulnerabilities were reported by VAPT Team, C3i Center. SSS has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper authentication - CVE-2019-20046; and
• Improper input validation - CVE-2019-20045

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to read sensitive information, execute arbitrary code, or cause a denial-of-service condition.

Digi Advisory


This advisory describes two vulnerabilities in the Digi ConnectPort LTS 32 MEI. The vulnerabilities were reported by Murat Aydemir and Fatih Kayran of Biznet Bilisim. Digi has a new release that mitigates the vulnerabilities. There is no indication that the researchers have been provided with an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Unrestricted upload of file with dangerous type - CVE-2020-6975; and
• Cross-site scripting - CVE-2020-6973

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to limit system availability.

SIPROTEC Advisory


This advisory describes an improper input validation vulnerability in the Siemens SIPROTEC 4 and SIPROTEC Compact. The vulnerability was reported by Tal Keren from Claroty. Siemens has provided generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to conduct a denial-of-service attack over the network.

SIMATIC S7-1500 Advisory


This advisory describes a resource exhaustion vulnerability in the Siemens SIMATIC S7-1500 CPU family. The vulnerability is self-reported. Siemens has provided generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to conduct denial-of-service attacks.

SCALANCE S-600 Advisory


This advisory describes three vulnerabilities in the Siemens SCALANCE S-600 Firewall. One of the vulnerabilities was reported by Melih Berk Ekşioğlu. Siemens has provided generic workarounds to mitigate the vulnerability.

The three reported vulnerabilities are:

• Cross-site scripting - CVE-2019-6585; and
• Uncontrolled resource consumption (2) - CVE-2019-13925 and CVE-2019-13926

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to conduct denial-of-service or cross-site scripting attacks. User interaction is required for a successful exploitation of the cross-site-scripting attack.

OZW Web Server Advisory


This advisory describes and information disclosure vulnerability in the Siemens OZW web server. The vulnerability was reported by Maxim Rupp. Siemens has a new version that mitigates the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow unauthenticated users to access project files.

SIPORT Advisory


This advisory describes an insufficient logging vulnerability in the Siemens SIPORT MP. The vulnerability is self-reported. Siemens has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow the attacker to create special accounts with administrative privileges.

SCALANCE Advisory


This advisory describes a protection mechanism failure vulnerability in the Siemens SCALANCE X switches. The vulnerability is self-reported. Siemens has updates that mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to perform administrative actions.

SIMATIC PCS 7 Advisory


This advisory describes an incorrect calculation of buffer size vulnerability in the Siemens SIMATIC PCS 7, SIMATIC WinCC, SIMATIC NET PC products. The vulnerability was reported by Nicholas Miles from Tenable. Siemens has new versions that mitigate the vulnerability. There is no indication that Miles has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker with network access to cause a denial-of-service condition.

SIMATIC S7 Advisory


This advisory describes a resource exhaustion vulnerability in the Siemens SIMATIC S7 devices. The vulnerability was reported by China Industrial Control Systems Cyber Emergency Response Team. Siemens has a new version that mitigates the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow remote attackers to perform a denial-of-service attack by sending a specially crafted HTTP request to the web server of an affected device.

PROFINET Advisory


This advisory describes a resource exhaustion vulnerability in the Siemens PROFINET-IO Stack. The vulnerability was reported by Yuval Ardon and Matan Dobrushin of OTORIO. Siemens has updates that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to lead to a denial-of-service condition.

NOTE: OTORIO reports that this same vulnerability is found in multiple vendor products including the Moxa EDS Ethernet Switches.

SIMATIC CP Advisory


This advisory describes two vulnerabilities in the Siemens SIMATIC CP 1543-1. The vulnerabilities are self-reported. Siemens has a new version that mitigates the vulnerabilities.

The two reported vulnerabilities are:

• Improper access control - CVE-2019-12815; and
• Loop with unreachable exit condition - CVE-2019-18217

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow for remote code execution and information disclosure without authentication, or unauthenticated denial of service.

Industrial Products Advisory


This advisory describes two vulnerabilities in the Siemens SCALANCE, SIMATIC, SIPLUS products. The vulnerabilities were reported by Artem Zinenko of Kaspersky Lab. Siemens has new versions that mitigate the vulnerabilities. There is no indication that Zinenko has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Data processing errors - CVE-2015-5621; and
• Null pointer dereference - CVE-2018-18065

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow remote attackers to conduct a denial-of-service attack by sending specially crafted packets to Port 161/UDP (SNMP).

SIMOCODE Update


This update provides additional information on an advisory that was originally published on March 9th, 2019 and most recently updated on January 14th, 2020. The new information includes the addition of two affected products:

• SITOP PSU8600; and
• TIM 1531 IRC

Industrial Products w/OPC UA Update


This update provides additional information on an advisory that was originally published on April 9th, 2019 and most recently updated on January 14th, 2020. The new information includes updated affected version data and mitigation links for SIMATIC NET PC Software.

PROFINET Update


This update provides additional information on an advisory that was originally published on October 10th, 2019 and most recently updated on January 14th, 2020. The new information includes updated affected version data and mitigation links for SINAMICS DCP.

Industrial Real Time Devices Update


This update provides additional information on an advisory that was originally published on October 10th, 2019 and most recently updated on January 14th, 2020. The new information includes updated affected version data and mitigation links for SINAMICS DCP.

SIMATIC Update


This update provides additional information on an advisory that was originally published on December 10th, 2019. The new information includes updated affected version data and mitigation links for:

• TIM 1531 IRC;
• SIMATIC NET PC Software

Other Siemens Advisories and Updates


Siemens also published two additional advisories and 3 updates yesterday that have not yet been addressed by NCCIC-ICS.

Additionally, on Monday Siemens published updates of 58 previously published advisories. All of these updates were adding references to the SIPLUS device variants as affected products. Siemens has been adding references to this as they have been updating advisories for the last couple of months, so it looks like they are just doing the final house cleaning on the issue. I do not expect NCCIC-ICS to update all of their applicable advisories.

Saturday, October 19, 2019

Public ICS Disclosures – Week of 10-12-19


This week we have four vendor disclosures for products from Phoenix Contact, ABB, Gemalto and Eaton. We also have an updated disclosure from Schneider and a report of a cyberattack from Pilz.

Phoenix Contact Advisory


Phoenix Contact published an advisory [.PDF download link] for an out-of-bounds read vulnerability in their Automationworx Suite. The vulnerability was reported by the 9sg Security Team via the Zero Day Initiative. Phoenix Contact has provided generic workarounds pending publication of a new version.

NOTE: The vulnerability was reportedly coordinate through NCCIC-ICS so an advisory from them should be forthcoming.

ABB Advisory


ABB published an advisory describing an improper authentication vulnerability in their UnoDM. The vulnerability was reported by Maxim Rupp. ABB has updates that mitigate the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

Gemalto Advisory


Gemalto announced that they have published an advisory (customer registration required for access) for a vulnerability in their Sentinel LDK License Manager when installed as a service.

NOTE: I suspect that owners of systems from other vendors that use the LDK License Manager will have to wait for notification from those vendors before they will be able to learn about this vulnerability and fixes available for it.

Eaton Advisory


Eaton published an advisory describing an undisclosed vulnerability in their CGLine+ when connected to CGVision. The vulnerability is self-reported. Eaton has a new version that mitigates the vulnerability.

Schneider Update


Schneider published an update of their URGENT/11 advisory. The new information includes updated version information and mitigation links for:

SCADAPack 57x RTUs; and
SAGE RTU

Pilz Cyberattack


Pilz is currently reporting that: “Since Sunday, October 13, 2019, all server and PC workstations including the communication network of the automation company have been affected worldwide. The website is currently only partially functional.”

They also note that: “Data sent to us by partners and customers have not been lost or misappropriated by third parties. At the current time, however, we cannot completely exclude this.”

NOTE: Both quotes are Google Translations from German.

Saturday, June 8, 2019

Public ICS Disclosures – Week of 06-01-19


This week we have five vendor disclosures for products from Gemalto, ABB (3), and TECSON/GOK. There is also one new Windows® RDP advisory from a vendor.

RDP Vulnerability Disclosures



Gemalto Advisory


Gemalto published an advisory describing a DLL vulnerability in the Gemalto Sentinel SuperPro, Sentinel Hardware Keys and Sentinel UltraPro Products. Details are only available to registered customers.

ABB Advisories


1. ABB has published an advisory describing multiple vulnerabilities in the ABB CP635
HMI. The vulnerabilities were reported by Xen1thLabs. ABB has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

Outdated software components;
Hard-coded credentials; and
Absence of signature verification

2. ABB has published an advisory describing multiple vulnerabilities in the ABB PB610. The vulnerabilities were reported by Xen1thLabs. ABB has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

Hidden administrative accounts;
HTTP server authentication bypass;
FTP server path traversal;
HTTP server uncontrolled format string;
FTP server uncontrolled format string; and
HTTP server stack-based buffer overflow

3. ABB has published an advisory for multiple vulnerabilities in the ABB CP651 HMI. The vulnerabilities were reported by Xen1thLabs. ABB has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

Outdated software components;
Hard-coded credentials; and
Absence of signature verification.

TESCON/GOK Advisory


CERT VDE published an advisory describing an improper access control vulnerability in the TESCON/GOK type LX-Net, LX-Q-Net, e-litro net, SmartBox4 LAN and SmartBox4 pro LAN devices. The vulnerabilities were reported by Maxim Rupp. TESCON/GOK has a new firmware version that mitigates the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

Tuesday, June 4, 2019

Three Advisories Published – 06-04-19


Today the DHS NCCIC-ICS published thee control system security advisories for products from Geutebruck and Phoenix Contact (2).

Geutebruck Advisory


This advisory describes three vulnerabilities in the Geutebruck Encoder and E2 Series Cameras. The vulnerabilities were reported by Romain Luyer and Guillaume Gronnier from CEIS, and Davy Douhine from RandoriSec. Geutebruck reports that the latest version of the firmware mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

Cross-site scripting - CVE-2019-10957; and
OS command injection (2) - CVE-2019-10956 and CVE-2019-10958

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow remote code execution as root and remote code execution in the browser of the IP camera operator.

FL NAT Advisory


This advisory describes an improper access control vulnerability in the Phoenix Contact FL NAT SMx industrial Ethernet switches. The vulnerability was reported by Maxim Rupp via CERT VDE. Phoenix Contact has provided generic mitigation measures for the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow unauthorized users full access to the device configuration.

PLCNext Advisory


This advisory describes four vulnerabilities in the Phoenix Contact PLCNext AXC F 2152 products. The vulnerabilities were reported by Zahra Khani of Firmalyzer and the OPC Foundation. Phoenix Contact reports that later versions of the firmware mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

Key management errors - CVE-2018-7559;
Improper access control - CVE-2019-10998;
Man-in-the-middle - CVE-2019-10997; and
Using components with known vulnerabilities

NOTE: the CERT VDE advisory lists 43 separate Linux vulnerability CVE’s for the fourth vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to decrypt passwords, bypass authentication, and deny service to the device. In addition, these vulnerabilities could interact with third-party vulnerabilities to cause other impacts to integrity, confidentiality, and availability.

Saturday, May 25, 2019

Public ICS Disclosure – Week of 05-18-19


This week we have three vendor disclosures from Eaton, Bosch and Miele. There is also one exploit report for products from Anvis. I also found more vendor information on the Microsoft® RDP  vulnerability.

Microsoft RDP Vulnerability

While the NCCIC-ICS has only released a very generic notice on the Microsoft® RDP vulnerability (CVE-2019-0708), a number of control system vendors this week have released their own outlook on the vulnerability in their products. The vendors include:

Rockwell;
Philips (update); and
Siemens Healthineers:

With the number of medical device manufacturers reporting on the RDP vulnerability and the healthcare industry’s history of problems with WannaCry you would think that the FDA would have issued at least a generic warning on the issue; but no, there is nothing on the medical device safety page.

Eaton Advisory


Eaton published an advisory reporting an undescribed vulnerability in the Eaton easySoft V6. Eaton is working on a new version to mitigate the vulnerability and offers generic workarounds in the mean time.

NOTE: This has to be the worst corporate vulnerability disclosure ever. Oh well, at least an advisory was published.

Bosch Advisory


Bosch has published an advisory describing an unauthenticated certificate access vulnerability in the Bosch Video Recording Manager (VRM) software. Bosch has firmware updates that mitigate the vulnerability.

Miele Advisory


CERT-VDE has published an advisory describing two vulnerabilities in the Miele XGW 3000 ZigBee Gateway. The vulnerability was reported by Maxim Rupp. Miele has a new version that mitigates the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Improper authorization; and
Cross-site request forgery

Anvis Exploit


Wizlab-IT published an exploit for security issues with the Anvis M3 RFID Access Control product. This was a coordinated disclosure and Anvis has a new version of the device that mitigates the vulnerability.

NOTE: So all of the vulnerable devices will be replaced?????

Saturday, March 30, 2019

Public ICS Disclosures – Week of 03-23-19


This week we have one vendor notification from Phoenix Contact and an update of an earlier vendor notification from Rockwell Automation.

Phoenix Contact Advisory


VDE-CERT published an advisory for an improper access control vulnerability in the Phoenix Contact FL NAT SMx web UI. The vulnerability was reported by Maxim Rupp. Phoenix Contact provides generic control measures to mitigate this vulnerability. There is no indication that Rupp was provided an opportunity to verify the efficacy of the fix.

Rockwell Update


Rockwell provided an update to their advisory published earlier this week. The update provides links to:

• The Applied Risk report on the vulnerability; and
The ICS-CERT advisory

Tuesday, March 26, 2019

3 Advisories Published – 03-26-19


Today the DHS NCCIC-ICS published three control system security advisories for products from ENTTEC, Phoenix Contact and Siemens.

ENTTEC Advisory


This advisory describes a missing authentication for critical function vulnerability in the ENTTEC Datagate MK2, Storm 24, Pixelator industrial lighting control products. The vulnerability was reported by Ankit Anubhav of NewSky Security. ENTTEC has updated firmware that mitigate the vulnerability. There is no indication that Anubhav has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to reboot this device allowing a continual denial of service condition.

Phoenix Contact Advisory


This advisory describes a command injection vulnerability in the Phoenix Contact RAD-80211-XD radio modules. The vulnerability was reported by Maxim Rupp. The affected products are no longer supported.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to  allow an attacker to execute system level commands with administrative privileges.

Siemens Advisory


This advisory describes an expected behavior violation vulnerability in the Siemens SCALANCE X switches. The vulnerability is being self-reported. Siemens has a new version that mitigates the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow an attacker to feed data over a mirror port and into the mirrored network.

NOTE: I briefly reported on this vulnerability earlier this month.

Saturday, January 26, 2019

Public ICS Disclosures – Week of 01-19-19


This week we have vendor notifications from Bosch, AVEVA, Drager, Yokogawa and BD. We also have an exploit of a previously disclosed set of vulnerabilities for products from NUUO.

Bosch Advisory


Bosch has published an advisory for two vulnerabilities in their DIVAR 400 & 600 digital recorders. The vulnerabilities were reported by Maxim Rupp. Bosch has provided generic workarounds to mitigate the vulnerability. There is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper access control; and
Unprotected credentials

AVEVA Advisory


AVEVA has published an advisory for three vulnerabilities in their Wonderware System Platform. The vulnerabilities were reported by Vladimir Dashchennko from Kaspersky Lab. AVEVA has a new update that mitigates the vulnerabilities. There is no indication that Daschennko has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Insufficiently protected credentials;
• Execution with unnecessary privilege; and
• Missing authorization

These vulnerabilities were coordinated through ‘ICS-CERT’ so I expect that we will see an advisory from NCCIC-ICS next week (though they may have a backlog to work through now that the Federal Funding Fiasco is at least temporarily over).

Drager Advisory


Drager published an advisory that is not technically for a control system vulnerability. They are advising customers of a number of reported fraudulent emails from apparent Drager email addresses that have been part of schemes to have companies make payments to non-Drager accounts.

Yokogawa Advisory


Yokogawa has published an advisory for an access control vulnerability in their License Manager Service. The vulnerability was reported by Kaspersky Lab. Yokogawa has patches that mitigate the vulnerability. There is no indication that Kaspersky Lab has been provided an opportunity to verify the efficacy of the fix.

BD Advisory


BD has published an advisory  (actually an update for an advisory that was issued last summer) for a Microsoft Windows vulnerability in the task scheduler that affects a number of BD products. BD will patch the software during the next patch cycle.

NUOO Exploit


Pedro Ribeiro published a set of exploits for the NUOO CMS software management platform. The vulnerabilities were reported by NCCIC-ICS in an advisory published on October 12th, 2018 and updated on November 20th, 2018. Ribeiro was the one who originally reported the NUOO vulnerabilities to NCCIC-ICS.

In addition to publishing four Metasploit modules as part of his exploit report, Ribeiro reports that one of the vulnerabilities reported through NCCIC-ICS (Use of hard-coded credentials - CVE-2018-17894) has not actually been fixed as was reported in the NCCIC-ICS advisory.

Reading the exploit report from Ribeiro provides an interesting look into the coordinated disclosure process where the vendor is less than cooperative. Pedro has all sorts of nice things to say about the folks he worked with at ‘ICS-CERT’ during the two-year process but suffice to say he is disappointed with NUOO.

Wednesday, December 19, 2018

7 Advisories and One Update Published - 12-18-18


Yesterday the DHS NCCIC-ICS published seven control system security advisories for products from ABB (3), Advantech, 3S and Siemens. They also published an update of a previously issued advisory for products from Schneider.

M2M Ethernet Advisory


This advisory describes an improper authentication vulnerability in the ABB M2M ETHERNET, network analyzer. It was reported by Maxim Rupp. ABB has provided generic workarounds for this vulnerability. There is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker on an adjacent network could exploit the vulnerability to upload a malicious language file.

NOTE: I briefly discussed the ABB advisory for this vulnerability in early November.


CMS-770 Advisory


This advisory describes an improper authentication vulnerability in the ABB CMS-770. This vulnerability was reported by Maxim Rupp. ABB has provided generic workarounds to mitigate the vulnerability. There is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS has reported that a relatively low-skilled attacker on an adjacent network could exploit the vulnerability to read sensitive configuration files that may lead to code execution on the device.

NOTE: I briefly discussed the ABB advisory for this vulnerability in early November.

Siemens Advisory


This advisory describes a missing authentication for critical function vulnerability in the Siemens TIM 1531 IRC. Siemens is self-reporting this vulnerability. Siemens has a firmware update to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to perform arbitrary administrative operations.

NOTE: I briefly discussed the Siemens advisory and first update for this vulnerability last Saturday. The first update noted that the originally provided firmware update had been withdrawn and left just a workaround available to mitigate the vulnerability. This NCCIC-ICS advisory is based upon the second Siemens update of their advisory.

CODESYS V3 Advisory 1


This advisory describes two vulnerabilities in the S3 CODESYS V3 products. The vulnerabilities were reported by Alexander Nochvay from Kaspersky Lab. S3 has a new version that mitigates the vulnerabilities. There is no indication that Nochvay has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Use of insufficiently random values - CVE-2018-20025; and
Improper restrictions of communication channel to intended endpoint - CVE-2018-20026

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to  allow a remote attacker to disguise the source of malicious communication packets and also exploit a random values weakness affecting confidentiality and integrity of data stored on the device.

NOTE: There are two S3 advisories that support this NCCIC-ICS advisory (here and here).

CODESYS V3 Advisory 2


This advisory describes an improper access control vulnerability in the S3 CODESYS Control V3 products. The vulnerability was reported by Yury Serdyuk of Kaspersky Lab. S3 has a new version and recommends activating the CODESYS Control online user management and encryption of the online communication. There is no indication that Serdyuk has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow unauthorized access and exfiltration of sensitive data including user credentials.

NOTE: S3 published five other advisories last week when they published the three supporting these two NCCIC-ICS advisories. Interestingly, none of the others have CVE numbers. More on these on Saturday.

Advantech Advisory


This advisory describes an improper input validation vulnerability in the AdvantechWebAccess/SCADA product. The vulnerability was reported by Jacob Baines of Tenable Network Security. Advantech has a new version that mitigates the vulnerability. There is no indication that Baines has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to cause the overflow of a buffer on the stack.

Gate E-2 Advisory


This advisory describes two vulnerabilities in the ABB GATE-E2 Pluto ethernet gateway. The vulnerabilities were reported by Nelson Berg of Applied Risk. ABB is only providing generic workarounds as this product is no longer supported. There is no indication that Berg has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Missing authentication of a critical function - CVE-2018-18995; and
• Cross-site scripting - CVE-2018-18997

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow unrestricted access to the administrative telnet/web interface of the device, enabling attackers to compromise the availability of the device, read or modify registers and settings, or change the device configuration.

NOTE: I briefly discussed the two ABB advisories supporting this NCCIC-ICS advisory last Saturday.

Schneider Update


This update provides additional information on an advisory that was originally published on April 17th, 2018, and updated on May 3rd, 2018. The new information included in the update includes:

• Links to a rewritten Schneider advisory;
• Announcement of a new version that further mitigates the HatMan vulnerabilities;
• The announcement that as of February 19th, 2019, “Schneider Electric will require customers to have a support contract in place to engage with the HatMan malware detection service.”

Saturday, November 3, 2018

Public ICS Disclosure – Week of 10-27-18


This week we have two vendor disclosures from ABB and two exploits for products from Modbus Tools.

CMS-770 Advisory


ABB published an advisory for a configuration file vulnerability in the CMS-770 control unit. The vulnerability was reported by Maxim Rupp. ABB has updated the manual for this product to outline additional security measures that mitigate the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

ABB reports that successful exploitation of this vulnerability could cause the product to reveal the credentials allowing to take over the entire control of the product.

M2M Ethernet Network Analyzer Advisory


ABB published an advisory for a language file vulnerability in the M2M Ethernet Network Analyzer. The vulnerability was reported by Maxim Rupp. ABB has updated the manual for this product to outline additional security measures that mitigate the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

ABB reports that successful exploitation of this vulnerability could allow an attacker to upload a language file to the product without being requested to authenticate himself.

Modbus Tools Exploits


Kağan Çapar published an exploit for a buffer overflow vulnerability in the Modbus Tools Modbus Slave programming tool. No CVE number is provided so this may be a 0-day vulnerability.

Ihsan Sencan published an exploit for a denial of service vulnerability in the Modbus Tools Modbus Slave programming tool. A new (no details available) CVE number was provided so there is a possibility that the vendor has been contacted about this vulnerability.

Thursday, September 6, 2018

ICS-CERT Publishes Ice Qube Advisory


Today the DHS ICS-CERT published a control system security advisory for products from Ice Qube. The advisory describes two vulnerabilities in the Thermal Management Center. The vulnerabilities were reported by Maxim Rupp. Ice Qube has a new version available that mitigates the vulnerabilities. There is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper authentication - CVE-2017-14026; and
Unprotected storage of credentials - CVE-2017-16714

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to gain unauthorized access to configuration files or obtain sensitive information.

Saturday, July 21, 2018

Public ICS Disclosures – Week of 07-14-18


This week we have two vendor updates (Rockwell and Siemens), two coordinated disclosures with POC (Sony), and proof-of-concept code (POC) for a recently disclosed vulnerability in Echelon products. There is also an announcement about an update to a security tool from OSIsoft.

Rockwell Update


Rockwell updated their FactoryTalk® Activation Manager advisory (previous update). The new version notes that: “Cisco has released several Snort Rules [Snort Rule 38246Snort Rule 38247, Snort Rule 39910] to addressing the Flexera software vulnerability.”

NOTE 1: Since at least one other vendor (Schneider) apparently uses the same third-party software these Cisco snort rules may be more widely applicable in the control system community.

NOTE 2: This was published on Friday so there is a good chance that we will see the ICS-CERT version of this advisory updated in the coming week.

Siemens Update


Siemens published an update of their general advisory on the Spectre/Meltdown vulnerabilities. Siemens continues to expand their coverage of the newer versions of this problem; this time adding information on the Lazy FP State Restore and Spectre V1.1 vulnerabilities. While the latest version of the ICS-CERT Spectre/Meltdown alert does provide a link to this advisory, there is no mention of the newer versions of this continuing problem in that alert.

Sony Vulnerabilities


Talos Intelligence published two vulnerability reports (here and here) for coordinated disclosures of vulnerabilities in the Sony IPELA E Series Camera. According to the reports Sony has a patch available to mitigate the vulnerabilities, but there is no indication that they have had the opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Command injection - CVE-2018-3937; and
Stack-based buffer overflow - CVE-2018-3938

NOTE: This was reported Friday, so there is always a chance that ICS-CERT will report this in the coming week. They have reported on IP camera vulnerabilities before, but do not necessarily report on all such vulnerabilities.

Echelon Exploit


Maxim Rupp published proof-of-concept exploit code on TWITTER for one of the Echelon vulnerabilities reported this week by ICS-CERT. Maxim has reportedly known about this vulnerability for about a year now; no word on why he has not reported it.

OSIsoft Security Audit Tool


OSIsoft announced that they have a new version of their PI Security Audit Tools (v. 2.2.0.3) available. They note that: “This tool is a PowerShell module that performs validation checks for the machine, PI Data Archive, PI AF Server, SQL Server, and PI Vision, indicating areas where the security configuration is out of compliance with best practices, and providing actionable information to address the issue.”

Tuesday, June 5, 2018

ICS-CERT Publishes 2 Advisories and 1 Update


Today the DHS ICS-CERT published a control system security advisory for products from ABB and a medical device security advisory for products from Philips. They also updated a medical device security advisory for products from Silex.

ABB Advisory


This advisory describes three vulnerabilities in the ABB IP Gateway. The vulnerabilities were reported by Maxim Rupp. ABB has a new version that mitigates the vulnerabilities. There is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Improper authentication - CVE-2017-7931;
• Cross-site request forgery - CVE-2017-7906; and
Unprotected storage of credentials - CVE-2017-7933

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to perform actions using administrative privileges.

NOTE: I reported these vulnerabilities nearly three weeks ago when ABB published their advisory.

Philips Advisory


This advisory describes three vulnerabilities in the Philips IntelliVue Patient Monitors and Avalon Fetal/Maternal Monitors. These vulnerabilities were reported by Oran Avraham of Medigate. Philips has provided mitigation suggestions to use until an update becomes available. There is no indication that Avraham has been provided an opportunity to verify the efficacy of the interim measures.

The three reported vulnerabilities are:

• Improper authentication - CVE-2018-10597;
• Information exposure - CVE-2018-10599; and
• Stack-based buffer overflow - CVE-2018-10601

ICS-CERT reports that a highly-skilled attacker on the same local device subnet could exploit these vulnerabilities to read/write memory, and/or induce a denial of service through a system restart, thus potentially leading to a delay in diagnosis and treatment of patients.

NOTE: These vulnerabilities have not been reported on the FDA Medical Device Safety Communications page.

Silex Update


This update provides new information on an advisory that was originally reported on May 8th, 2018 and updated on May 31st, 2018. The update provides a link to a firmware update for SD-320AN (separate from GEH-SD-320AN) and a link to GE security information about the vulnerability.

Thursday, May 24, 2018

ICS-CERT Publishes 2 Advisories and 3 Updates

Today the DHS ICS-CERT published a control system security advisory for products from Schneider Electric and a medical device security advisory for products from BeaconMedaes. They also published updates to previously published advisories for products from Rockwell, Siemens, and Martem.

Schneider Advisory


This advisory describes three vulnerabilities in the Schneider Floating License Manager. The vulnerabilities are being self-reported. Schneider has new versions available to mitigate the vulnerabilities.

The three reported vulnerabilities are:

• Heap-based buffer overflow - CVE-2016-2177;
• Improper restriction of operations within bounds of a memory buffer - CVE-2016-10395; and
• URL redirection to an untrusted site - CVE-2017-5571

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to cause a denial of service, allow arbitrary execution of code with system level privileges, or send users to arbitrary websites.

BeaconMedaes Advisory


This advisory describes three vulnerabilities in the BeaconMedaes TotalAlert Scroll Medical Air Systems web application. These vulnerabilities were reported by Maxim Rupp. BeaconMedaes has a new version that mitigates the vulnerability, There is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Improper access control - CVE-2018-7526;
• Insufficiently protected credential - CVE-2018-7518; and
• Unprotected storage of credentials - CVE-2018-7515;

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities  to view and potentially modify some device information and web application setup information, which does not include access to patient health information.

NOTE: These vulnerabilities were not reported on the FDA Medical Device Safety Communication site.

Rockwell Update


This update provides new information on an advisory that was originally published on May 10th, 2018. The new information is supposed to be a link to the Rockwell security advisory [log-in required]. Unfortunately, that link is to the Rockwell Arena advisory (the ICS-CERT advisory for that was publicly published on the same day as the Factory Talk advisory that is currently being updated here. The correct link is https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1073133.


Siemens Update


This update provides new information on an advisory that was originally published on May 8th, 2018. The new information is a revision to the instructions as to how owner/operators should go about getting the updated version. It removed the original link to the ‘hotfix’ and substitutes the instruction to “Obtain the update via the local Siemens representative”.

Martem Update



This update provides new information on an advisory that was originally published on May 22nd, 2018. The new information is links to the Martem advisories for vulnerability CVE-2018-10603 and CVE-2018-10607. A link to the Martem advisory for the third vulnerability was already included in the initial ICS-CERT advisory.

Thursday, December 7, 2017

ICS-CERT Publishes 3 Advisories and 1 Alert

Today the DHS ICS-CERT published three control system security advisories for products from Phoenix Contact, Rockwell and Xiongmai Technology. The also published a control system security alert for a WAGO programable logic controller (PLC).

Phoenix Contact Advisory


This advisory describes a cross-site scripting vulnerability in the Phoenix Contact FL COMSERVER, FL COM SERVER, and PSI-MODEM/ETH industrial networking equipment. The vulnerability was reported by Maxim Rupp. Phoenix Contact has released new firmware versions to mitigate the vulnerabilities. There is no indication that Rupp was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to change configuration variables on the device. The VDE-CERT advisory notes that network access is required to exploit the vulnerability.

Rockwell Advisory


This advisory describes an improper input validation vulnerability in the Rockwell FactoryTalk Alarms and Events component of the Factory Talk Services Platform. The vulnerability was reported by an unnamed major oil and gas company. ICS-CERT reports that newer versions or existing patches mitigate the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial of service condition in the in the history archiver service running on FactoryTalk Alarms and Events.

QUESTIONS: Does it seem odd to anyone else that a ‘major oil and gas company’ would be using an out-of-date version of this product? Or is this a problem that is endemic to the ICS user community? Did Rockwell notify their customers (or even just their major customers) when they discovered and fixed this vulnerability? (It does not sound like it.)

Xiongmai Technology Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Xiongmai IP Cameras and DVRs. The vulnerability was reported by Clinton Mielke. ICS-CERT reports that has not responded to requests to coordinate with NCCIC/ICS-CERT.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause the device to reboot and return to a more vulnerable state in which Telnet is accessible.

WAGO Alert


This alert describes an unconfirmed improper authentication vulnerability in the WAGO PFC200 PLC. This is the vulnerability that I discussed almost a week ago. SEC Consult reported that they had coordinated with CODESYS and that the vendor was planning on issuing a patch next month.

I am not sure why ICS-CERT issued an alert for the WAGO vulnerability and an advisory for the Xiongmai vulnerability. It would seem to me that those reporting formats probably should have been reversed.


NOTE: There is still no word on the Hikvision vulnerability that I reported in the same blog post as this WAGO vulnerability.

Thursday, October 12, 2017

ICS-CERT Publishes 5 Advisories and 1 Update

Today the DHS publishes five control system security updates for products from ProMinent, WECON, Envitech, NXP Semiconductor, and Siemens. They also updated a previously published control system security advisory for products from Marel Food Processing Systems.

Siemens Advisory


This advisory describes two vulnerabilities in the Siemens BACnet Field Panels. The vulnerabilities are self-reported. Siemens has developed a new firmware version that mitigates the vulnerabilities.

The two reported vulnerabilities are:

• Authentication bypass using an alternate path or channel - CVE-2017-9946; and
• Path traversal - CVE-2017-9947

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to allow unauthenticated attackers with access to the integrated webserver to download sensitive information. The Siemens security advisory notes that the first vulnerability requires network access to exploit.

NXP Advisory


This advisory describes two vulnerabilities in the NXP MQX real time operating system (RTOS). The vulnerability was reported by Scott Gayou. ICS-CERT reports that NXP intends to issue a new version in January to mitigate the vulnerabilities. NXP provides a work around for the first vulnerability in the latest version (the second does not exist in that version) and recommends that users upgrade to that newer version pending the January update.

The two reported vulnerabilities are:

• Classic buffer overflow – CVE-2017-12718; and
• Out-of-bounds read – CVE-2017-12722

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerabilities to cause a buffer overflow condition that may, in turn, cause remote code execution or out-of-bounds read conditions, resulting in a denial of service.

Envitech Advisory


This advisory describes an improper authentication vulnerability in the Envitech EnviDAS Ultimate web application. The vulnerability was reported by Can Demirel and Deniz Çevik of Biznet Bilisim. Envitech has a new version that mitigates the vulnerability. ICS-CERT reports that the researchers have verified the efficacy of the fix.

ICS-CERT reports that relatively low skilled attacker could remotely exploit the vulnerability  to view and edit settings without authenticating and execute code remotely.

WECON Advisory


This advisory describes a stack-based buffer overflow vulnerability in the WECON LeviStudio HMI Editor. The vulnerability was reported by Andrea “rgod” Micalizzi, working with iDefense Labs. WECON has developed a new version that mitigates the vulnerability. There is no indication that Micalizzi was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to effect a denial of service and arbitrary code execution.

ProMinent Advisory


This advisory describes multiple vulnerabilities in the ProMinent MultiFLEX M10a Controller. The vulnerabilities were reported by Maxim Rupp. ICS-CERT reports that ProMinent has not mitigated the vulnerabilities.

The reported vulnerabilities are:

• Client-side enforcement of server-side security - CVE-2017-14013l;
• Insufficient session expiration - CVE-2017-14007;
• Cross-site request forgery - CVE-2017-14011;
• Information exposure - CVE-2017-14009; and
• Unverified password change - CVE-2017-14005

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerabilities  to bypass protection mechanisms, assume the identity of authenticated users, and change the device configuration.

Marel Update


This update provides additional information on an advisory originally published on April 4th, 2017 and updated on August 17th. This update provides information on the firewall update for the Pluto platform that Marel has released.


The advisory still states that “Marel has created an update for Pluto-based applications, which was scheduled for release in October, 2017. This update will restrict remote access by implementing SSH authentication”.
 
/* Use this with templates/template-twocol.html */