Showing posts with label MedSec. Show all posts
Showing posts with label MedSec. Show all posts

Tuesday, August 29, 2017

ICS-CERT Publishes Three Advisories

Today the DHS ICS-CERT published two control system security advisories for products from Advantech and AzeoTech. They also published a medical device advisory for products from Abbott Laboratories.

Advantech Advisory


This advisory describes nine vulnerabilities in the Advantech WebAccess HMI platform. The vulnerabilities were reported by  Fritz Sands, independent researcher rgod, Tenable Network Security, and an anonymous researcher (all via Zero Day Initiative), and Haojun Hou and DongWang from ADLab of Venustech. Advantech has released a new version to mitigate the vulnerabilities. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The nine reported vulnerabilities are:

• Improper neutralization of special elements used in an SQL command - CVE-2017-12710;
• Improper restriction of operations within the bounds of a memory buffer - CVE-2017-12708;
• Stack-based buffer overflow -CVE-2017-12706;
• Heap-based buffer overflow - CVE-2017-12704;
• Use of externally-controlled format string - CVE-2017-12702;
• Improper authentication - CVE-2017-12698;
• Incorrect permission assignment for critical resource - CVE-2017-12713;
• Incorrect privilege assignment - CVE-2017-12711; and
• Uncontrolled search path element - CVE-2017-12711

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to allow remote code execution or unauthorized access and could cause the device that the attacker is accessing to crash.

NOTE: Earlier this month I mentioned that there were  a large number of ‘pending’ vulnerability reports on Advantech products currently listed on the ZDI web site. These are not those vulnerabilities; those are still apparently being resolved.

AzeoTech Advisory


This advisory describes two vulnerabilities in the AzeoTech DAQFactory HMI. The vulnerabilities were reported by Karn Ganeshen. AzeoTech has produced a new version that mitigates the vulnerabilities. There is no indication that Ganeshen was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Incorrect default permissions - CVE-2017-12699; and
• Uncontrolled search path element - CVE-2017-5147

ICS-CERT reports that an authenticated user with local access could exploit the vulnerabilities to escalate their privileges and modify or replace application files.

Abbott Labs Advisory


This advisory describes three vulnerabilities in the Abbot Labs (formerly St. Jude Medical) pacemakers. The vulnerabilities were reported by MedSec. Abbott has produced a firmware update that mitigates the vulnerability. ICS-CERT reports that an unidentified third-party has verified the efficacy of the fix. The FDA Safety Communication notes that the firmware update must be applied during “an in-person patient visit with a health care provider”.

The three reported vulnerabilities are:

• Improper authentication - CVE-2017-12712;
• Improper restriction of power consumption - CVE-2017-12714; and
• Missing encryption of sensitive data - CVE-2017-12716


ICS-CERT reports that an uncharacterized attacker near the patient could exploit the vulnerabilities to gain unauthorized access to a pacemaker and issue commands, change settings, or otherwise interfere with the intended function of the pacemaker.

Wednesday, August 16, 2017

ICS-CERT Publishes Two Advisories

Yesterday the DHS ICS-CERT published a medical device security advisory for products from BMC Medical and 3B Medical (one advisory). They also published a control system security advisory for products from Advantech

BMC Medical Advisory


This advisory describes an improper input validation vulnerability in the Luna continuous positive airway pressure (CPAP) therapy machine produced jointly by BMC Medical and 3B Medical. The vulnerability was reported by MedSec. Newer versions (after July 2017) have had the problem corrected; ICS-CERT reports that the company’s do not plan on providing mitigation measures for ‘older’ (before July 2017) machines.

ICS-CERT reports that a relatively low skilled attacker with adjacent network access could exploit the vulnerability to cause a crash of the device’s Wi-Fi module resulting in a denial-of-service condition affecting the Wi-Fi module chipset. This does not affect the device’s ability to deliver therapy.

NOTE: Buyers of CPAP devices should take careful note of the lack of post-production cybersecurity support demonstrated for this brand of devices.

Advantech Advisory


This advisory describes a heap-based buffer overflow vulnerability in the Advantech WebOP operator panels. The vulnerability was reported by Ariele Caltabiano (kimiya) via the Zero Day Initiative. ICS-CERT reports that Advantech was unable to verify the validity of this vulnerability. (NOTE: this obviously means that no mitigation measures appear to be forthcoming.)

ICS-CERT reports that a relatively low skilled attacker with uncharacterized access could use publicly available exploits to exploit this vulnerability to cause the target device to crash and may allow arbitrary code execution.


NOTE: There are a large number of ‘pending’ vulnerability reports on Advantech products currently listed on the ZDI web site.
 
/* Use this with templates/template-twocol.html */