Showing posts with label NCCIC-ICS. Show all posts
Showing posts with label NCCIC-ICS. Show all posts

Tuesday, June 15, 2021

Is something going on with ZOLL Defibrillators?

Okay, this probably does not mean anything, but something odd is going on with the recent advisory about the vulnerabilities in the ZOLL Defibrillator Dashboard. As I reported last week CISA’s NCCIC-ICS published a medical device security advisory describing five vulnerabilities in the Defibrillator Dashboard from ZOLL.

According to the advisory from NCCIC-ICS, ZOLL has new versions available to mitigate the vulnerability. On the surface the only odd thing about the advisory was that the vulnerabilities were reported to CISA by an anonymous researcher. One could speculate about why the researcher wanted to remain anonymous, but at this point it would be just speculation. In any case, NCCIC-ICS reported the vulnerabilities to ZOLL, ZOLL corrected the problems, NCCIC-ICS published the advisory. Nothing unusual here.

Then, yesterday, CISA published an advisory about the same vulnerabilities, pointing at the NCCIC-ICS advisory. No new information, just the point and a recommendation that:

“CISA encourages users and administrators to review the ICS Medical Advisory ICSMA-21-161-01 and apply the recommended mitigations.”

I thought that that was a little bit odd, CISA issuing an advisory pointing at an earlier CISA advisory with no new information, but I did not really start to get curious until I saw the following TWEET® from @ICS-CERT this morning:

“ICYMI

@CISAgov recently released an #ICS Medical Advisory on multiple vulnerabilities in the ZOLL Defibrillator Dashboard. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.

#VulnerabilityManagement #OT #IoT #Healthcare”

Obviously, someone at CISA thinks that these vulnerabilities are unusually important. So, maybe there are exploits in the wild? I search both cve.mitre.org and nvd.nist.gov for the six reported CVEs and get nothing; the CVE has been reserved, but no data has been given to either organization yet. This is not really unusual, it may take as much as a week from the time NCCIC-ICS publishes an advisory for the CVE information to make it into the National Vulnerability Database.

Okay, so next I do a Google® search for the ZOLL Defibrillator Dashboard to see if there are any news articles about problems. No problems found there. But I did see almost nine pages of reference to unrelated articles on Homeland Security Today, dating back to January. Why? Because each article currently has the same ‘You Might Be Interested’ text box at the bottom:

“JUNE 14, 2021

CISA Releases Advisory on ZOLL Defibrillator Dashboard

“CISA has released an Industrial Controls Systems (ICS) Medical Advisory on multiple vulnerabilities in the ZOLL Defibrillator Dashboard. A remote…”

That text box refers back to the short article on the site that refers back to yesterday’s CISA advisory. Except that most of those pages no longer have that text box; Homeland Security Today keeps changing what boxes show up on the bottom of their pages to keep people flowing back to their web site. Good internal SEO work.

Oh, nothing on the FDA’s medical device cybersecurity page, but they have not reported on a vulnerability since 2019, so nothing new there (in both ways of looking at that phrase). And nothing on the ZOLL webpages, but lots of companies ignore their cyber vulnerabilities, so nothing too unusual with that.

In any case, I still cannot tell why CISA is so concerned about the ZOLL Defibrillator Dashboard…. If you have one, just update it, please.

Friday, August 16, 2019

4 Advisories Published – 08-15-19


Yesterday the DHS NCCIC-ICS published four control system security advisories for products from Siemens (2), Fuji Electric, and Johnson Controls.

SINAMICS Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the web server of the Siemens SINAMICS control units. The vulnerability is self-reported. Siemens has updates available to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to perform a denial-of-service attack.

SCALANCE Advisory


This advisory describes two instances of an improper adherence to coding standards vulnerability in the Siemens SCALANCE products. The vulnerability is self-reported. Siemens has an update available that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to  lead to a denial of service or could allow an authenticated local user with physical access to the device to execute arbitrary commands on the device.

NOTE: There are still two advisories and an update that were published by Siemens earlier this week that have not been addressed by NCCIC-ICS. I will report further on them tomorrow.

Fuji Advisory


This advisory describes a stack-based buffer overflow in the Fuji Alpha5 Smart Loader servo  drive. The vulnerability was reported by Natnael Samson (@NattiSamson) via the Zero Day Initiative. Fuji has a new version that mitigates the vulnerability. There is no indication that Samson has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to execute code under the privileges of the application.

Johnson Controls Advisory


This advisory describes two vulnerabilities in the Johnson Controls Metasys building automation system. The vulnerability was reported by harpocrates.ghost. Johnson Controls has a new version that mitigates the vulnerabilities. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Reusing a nonce, key-pair in an encryption - CVE-2019-7593; and
Use of hard-coded cryptographic key - CVE-2019-7594

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit these vulnerabilities to decrypt captured network traffic.

Friday, August 2, 2019

6 Advisories Published – 08-01-19


Yesterday the DHS NCCIC-ICS published six control system advisories for products from Leão Consultoria e Desenvolvimento de Sistemas (LCDS), Rockwell, 3S (2), Fuji Electric and Advantech.

LCDS Advisory


This advisory describes two vulnerabilities in the LCDS LAquis SCADA software. The vulnerabilities were reported by Francis Provencher (PRL) via the Zero Day Initiative. LCDS has an update available that mitigates the vulnerability. There is no indication that Provencher has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Out-of-bounds read - CVE-2019-10994; and
Type confusion - CVE-2019-10980


NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to obtain confidential information or execute remote code.

Rockwell Advisory


This advisory describes two vulnerabilities in the Rockwell Arena Simulation Software. The vulnerabilities were reported by kimiya of 9SG Security Team via ZDI. Rockwell has a new version that mitigates the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

Use after free - CVE-2019-13510; and
Information exposure - CVE-2019-13511

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to cause a current Arena session to fault or enter a denial-of-service (DoS) state, allowing the attacker to run arbitrary code.

First CODESYS Advisory


This advisory describes an insufficiently protected credentials vulnerability in the CmpUserMgr component of 3S CODESYS products. The vulnerability was reported by JunYoung Park. 3S will correct this vulnerability in a new version to be released in February. The 3S advisory strongly recommends activating and using encryption of online communication whenever possible.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow for an attacker with access to PLC traffic to obtain user credentials.

NOTE: Is it just me or is this advisory just a seven-month zero-day announcement?

Second CODESYS Advisory


This advisory describes two vulnerabilities in the CmpGateway component of the 3S CODESYS products. These vulnerabilities are self-reported. 3S has a new version that mitigates the vulenrabilities.

The two reported vulnerabilities are:

Unverified ownership - CVE-2019-9010; and
Uncontrolled memory allocation - CVE-2019-9012 

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow a remote attacker to close existing communication channels or to take over an already established user session to send crafted packets to a PLC.

NOTE 1: There were six other advisories published by 3S at the same time as the two referenced in these two NCCIC-ICS advisories. I will address them this weekend.

NOTE 2: A reminder that the CODESYS operating system is used in a wide variety of devices and systems. These vulnerabilities will have widespread application. Few vendors are expected to publish updates referencing these vulnerabilities.

Fuji Advisory


This advisory describes and out-of-bounds read vulnerability in the Fuji  FRENIC Loader. The vulnerability was reported by kimiya of 9SG Security Team via ZDI. Fuji has a new version that mitigates the vulnerability. There is no indication that the kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow information disclosure.

Advantech Advisory


This advisory describes an out-of-bounds write vulnerability in the Advantech WebAccess HMI Designer. The vulnerability was reported by Mat Powell via ZDI. Advantech has a new version that mitigates the vulnerability. There is no indication that Powell has been provided an opportunity to verify the efficacy of the fix.

Wednesday, July 3, 2019

2 Advisories Published – 07-02-19


Yesterday the DHS NCCIC published two control system security advisories for products from Quest and Schneider Electric.

Quest Advisory


This advisory describes an improper input validation vulnerability in the Quest KACE Systems Management Appliance. The vulnerability was reported by Juan Pablo Lopez Yacubian. Quest reports that newer versions mitigate the vulnerability. There is no indication that Yacubian has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an administrative user unintentional access to the underlying operating system of the device.

Schneider Advisory


This advisory describes an improper check for unusual or exceptional conditions vulnerability in the Schneider Modicon Controllers. The vulnerability was reported by Zhang Xiaoming, Zhang Jiawei, Sun Zhonghao and Luo bing of CNCERT/CC. Schneider has new firmware versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to cause a denial-of-service condition.

Thursday, March 14, 2019

3 Advisories Published – 03-14-19


Today the DHS NCCIC-ICS published three control system security advisories for products from PEPPERL+FUCHS, Gemalto and Leão Consultoria e Desenvolvimento de Sistemas Ltda (LCDS).

PEPPERL+FUCHS Advisory


This advisory describes a path traversal vulnerability in the PEPPERL+FUCHS WirelessHART-Gateways. The vulnerability was publicly reported (with exploit) by Hamit CİBO. PEPPERL+FUCHS has firmware upgrades to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could use publicly available code to remotely exploit this vulnerability to allow access to files and restricted directories stored on the device through the manipulation of file parameters.

NOTE: I briefly reported on this vulnerability last Saturday.

Gemalto Advisory


This advisory describes an uncontrolled search path element in the Gemalto Sentinel UltraPro. The vulnerability was reported by ADLab of Venustech. Gemalto has a software update to mitigate the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to load and execute a malicious file from the ux32w.dll in Sentinel UltraPro.

NOTE: Gemalto issued an early warning to upgrade the UltraPro software back on January 19th, 2019 with a restricted link to their advisory on this product. I do not know what information was included in that advisory.

LCDS Advisory


This advisory describes an out-of-bounds write vulnerability in the LCDS LAquis SCADA. The vulnerability was reported by Mat Powel via the Zero Day Infitiative. LCDS has a new version that mitigates the vulnerability. There is no indication that Powel was provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow remote code execution.

Tuesday, March 12, 2019

1 Advisory and 6 Updates Published – 03-12-19


Today the DHS NCCIC-ICS published on control system security advisory for products from WIBU Systems and six updates for previously published advisories for products from Siemens.

WIBU Advisory 


This advisory describes three vulnerabilities in the WibuKey Digital Rights Management tool. NCCIC-ICS reports that the vulnerabilities were reported to it by Siemens, but the vulnerabilities were originally reported by Talos (here, here and here) with exploits. Wibu has an updated software version that mitigates the vulnerability. There is no indication that Talos has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Information exposure - CVE-2018-3989;
• Out-of-bounds write - CVE-2018-3990; and
Heap-based buffer overflow - CVE-2018-3991

NCCIC-ICS reports that a relatively low-skilled attacker could use a publicly available exploit to remotely exploit the vulnerabilities to allow information disclosure, privilege escalation, or remote code execution.

NOTE: This advisory originally published on February 12th, 2019 by NCCIC-ICS and updated on February 14th, 2019 as a third-party software problem only affecting the Siemens SICAM 230. This advisory was renamed today as a Wibu Systems problem affecting Siemens (2 product lines, the second reported here on March 2nd, 2019) and three other vendors; COPA-DATA, SPRECHER Automation, and Phoenix Contact (reported here last Saturday). As with other third-party software issues, there may be other vendors added to this revised advisory in the future.

Industrial Products Update


This update provides additional information on an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th, November 28th, February 27th, 2018, May 3rd, 2018 May 15th, 2018, September 11th, 2018, October 9th, 2018, November 13th, 2018, December 11th, 2018, February 5th, 2019 and most recently on February 12th, 2019. The update provides additional affected version information and links for mitigation measures for SINUMERIK 840D sl.

Desigo PXC Update


This update provides additional information on an advisory that was originally published on January 25th, 2018, February 6th, and updated on March 22nd, 2018. Added links to mitigation measures for products before v 6.00.

SIPROTEC 4 Update


This update provides additional information on an advisory that was originally published on March 8th, 2018, April 19th, 2018, and updated on May 17th, 2018. The update provides additional affected version information and links for mitigation measures for:

• 7SJ61;
• 7SJ62;
• 7SJ64; and
• Contacts for mitigation measures for products without solution.

SIMATIC PCS 7 Update


This update provides additional information on an advisory that was originally published on March 29th, 2018 and updated on April 24th, 2018, June 12th, 2018, and again on November 13th, 2018. The update corrected the data for fixed version for the WinCC 7.4.

NOTE: This should be “Update E” not “Update G”.

SIMATIC S7 Update


This update provides additional information on an advisory that was originally published on November 13th, 2018. The update provides additional affected version information and links for mitigation measures for SIMATIC S7-1200.

SINUMERIK Update


This update provides additional information on an advisory that was originally published on December 11th, 2018. The update provides additional affected version information and links for mitigation measures for SINUMERIK 808D.

Siemens Advisory Day


The six Siemens updates published today by NCCIC-ICS were all published by Siemens today on their monthly release of vulnerabilities and updates. There was also one new advisory published today by Siemens and three other updates.

Tuesday, March 5, 2019

One Advisory and One Update Published – 03-05-19


Today the DHS NCCIC-ICS published a control-system security advisory for products from Rockwell and updated a previously published advisory for products from IDenticard.

Rockwell Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Rockwell RSLinx Classic PLC communications software. The vulnerability was reported by Tenable. Rockwell has patches that mitigate the vulnerability. There is no indication that Tenable has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow a remote attacker to execute arbitrary code on the target device.

IDenticard Update


This update provides additional information on an advisory that was originally published on January 31st, 2019. The new information includes:

• A revision to the affected version data;
• A report that the hard-coded credential vulnerability was corrected in an earlier version;
New information about applying the latest update; and
• A link to the IDenticard advisory

Friday, March 1, 2019

HatMan Update Published – 03-01-19


Today the DHS NCCIC-ICS published an update to their malware analysis report (MAR) for HatMan; the safety system malware. The MAR was originally published on December 18th, 2017 and previously updated on April 10th, 2018. The update includes an updated YARA signature to identify a custom, Windows-based remote deployment tool that threat actors may have used.

NOTE: A number of minor formatting changes and a few inconsequential wording changes were also made in the document.

Thursday, February 28, 2019

One Advisory and One Update Published – 02-28-19


Today the DHS NCCIC-ICS published a control system security advisory for products from PSI GridConnect and an update for a previously published advisory for products from Kunbus.

PSI Advisory


This advisory describes a cross-site scripting vulnerability in the PSI Telecontrol Gateway, Smart Telecontrol Unit family,  and IEC104 Security Proxy. The vulnerability was reported by M. Can Kurnaz. PSI has a version that mitigates the vulnerability. There is no indication that Kurnaz has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to execute dynamic scripts in the context of the application, which could allow cross-site scripting attacks.

Kunbus Update


This update provides additional information on an advisory that was originally published on February 5th, 2019 and updated on February 7th, 2019. The update provides a link to a new version that mitigates the vulnerabilities. There is no indication that the researcher involved was provided an opportunity to verify the efficacy of the fix.

Tuesday, February 26, 2019

One Advisory Published – 02-26-19


Today the DHS NCCIC-ICS published a control system security advisory for products from Moxa. The advisory describes ten vulnerabilities in the Moxa IKS and EDS industrial switches. The vulnerabilities were reported by Ivan B, Sergey Fedonin, and Vyacheslav Moskvin of Positive Technologies Security. Moxa has a firmware patch that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The ten reported vulnerabilities are:

• Classic buffer overflow - CVE-2019-6557;
• Cross-site request forgery - CVE-2019-6561;
• Cross-site scripting - CVE-2019-6565;
• Improper access control - CVE-2019-6520;
• Improper restriction of excessive authentication request - CVE-2019-6524;
• Missing encryption of sensitive data - CVE-2019-6526;
• Out-of-bounds read - CVE-2019-6522;
• Unprotected storage of credentials - CVE-2019-6518;
• Predictable from observable state - CVE-2019-6563; and
Uncontrolled resource consumption - CVE-2019-6559

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow the reading of sensitive information, remote code execution, arbitrary configuration changes, authentication bypass, sensitive data capture, reboot of the device, device crash, or full compromise of the device.

Thursday, February 21, 2019

One Update Published – 02-21-19

NCCIC-ICS published an update of a control system security advisory for products from Wind River. The advisory was originally published on April 1st, 2013. The updated information includes:

• Adds GE D20MX as an affected product;
• Changes characterization of CVE-2013-0715 from ‘Command Injection’ to ‘Improper Input Validation’; and
• Provides GE mitigation measures for vulnerabilities.

There must be an interesting story here, just do not know what it is.

Tuesday, February 19, 2019

Four advisories Published – 02-19-19


Today the DHS NCCIC published four control system security advisories for products from Rockwell Automation, Horner Automation, Delta Industrial and Intel.

Rockwell Advisory


This advisory describes two vulnerabilities in the Rockwell Allen-Bradley PowerMonitor 1000. This vulnerability was reported by Luca Chiou of ACSI. Rockwell is working on mitigation measures. CheckPoint Software Technologies has released IPS rules to detect attempts to exploit CVE-2019-19615.

The two reported vulnerabilities are:

• Cross-site scripting - CVE-2019-19615; and
Authentication bypass using alternate path or channel - CVE-2019-19616

NCCIC-ICS reports that a relatively low-skilled attacker could use a publicly available exploits (here and here) to remotely exploit these vulnerabilities to allow a remote attacker to affect the confidentiality, integrity, and availability of the device.

NOTE: I discussed these vulnerabilities last Saturday.

Horner Advisory


This advisory describes an improper input validation vulnerability in the Horner Cscape control system application programming software. The vulnerability was reported by ‘anonymous’ via the Zero Day Initiative (ZDI). Horner has a new version that mitigates the vulnerability. There is no indication that anonymous has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to crash the device being accessed, which may allow the attacker to read confidential information and remotely execute arbitrary code.

Delta Advisory


This advisory describes an out-of-bounds read vulnerability in the Delta Industrial Automation CNCSoft. The vulnerability was reported by Natnael Samson (@NattiSamson) via ZDI. Delta has an updated version that mitigates the vulnerability. There is no indication that Samson was provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to cause a buffer overflow condition that may allow information disclosure or crash the application.

Intel Advisory


This advisory describes eleven vulnerabilities in the Intel Data Center Manager SDK. The vulnerability was reported by Intel’s Product Security Incident Response Team. Intel has a new version that mitigates the vulnerability.

The eleven reported vulnerabilities are:

• Improper authentication - CVE-2019-0102;
• Protection mechanism failure (4) - CVE-2019-0103, CVE-2019-0104, CVE-2019-0106, and CVE-2019-0107,
• Permission issues (4) - CVE-2019-0105, CVE-2019-0108, CVE-2019-0109, and CVE-2019-0111;
• Key management issues - CVE-2019-0110;
• Insufficient control flow management - CVE-2019-0112

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow escalation of privilege, denial of service, or information disclosure.

Thursday, February 14, 2019

Two Advisories and Three Updates Published – 02-14-19


Today the DHS NCCIC-ICS published two control system security advisories for products from gpsd Open Source Project and Pangea. They also updated three previously published advisories for products from Fuji and Siemens (2). The gpsd advisory was originally published on the HSIN ICS-CERT library on November 6, 2018.

gpsd Advisory


This advisory describes a stack-based buffer overflow vulnerability in the gpsd, an open-source GPS framework. The vulnerability was reported by GE Digital Cyber Security Services, working with GE-PSIRT. A new version is available that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit this vulnerability to allow remote code execution, data exfiltration, or denial-of service via device crash.

Note: This advisory is a ‘third-party vendor’ vulnerability report. NCCIC-ICS reports that gpsd can be found in many mobile embedded systems such as Android phones, drones, robot submarines, driverless cars, manned aircraft, marine navigation systems, and military vehicles.

Pangea Advisory


This advisory describes an authentication bypass using an alternate path or channel vulnerability in the Pangea Internet FAX Analog Telephone Adapter (ATA). The vulnerability was reported by Ankit Anubhav of NewSky Security. Pangea has a patch deployed that mitigates the vulnerability. There is no indication that Anubhav has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could use a publicly available exploit to remotely exploit the vulnerability to cause the device to reboot and create a continual denial-of-service condition.

Fuji Update


This update provides additional information on an advisory that was originally published on September 27th, 2018. The update announces the availability of a new firmware version that mitigates the vulnerabilities.

Licensing Software Update


This update provides additional information on an advisory that was originally published on February 12th, 2019. The update makes a number of editorial corrections in the data presentation on the vulnerabilities reported. I missed identifying these inconsistencies as I reported on the vulnerabilities based upon the Talos reports. The update still does not mention that there are publicly available exploits for these vulnerabilities from those reports.

PROFINET Update


This update provides additional information on an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, 2017, November 14th, 2017, January 23rd, 2018, February 27th, 2018, and most recently on June 21st, 2018. The update provides updated affected version information and mitigation links for SINAUT ST7CC.

Wednesday, February 13, 2019

6 Advisories and 7 Updates Published – 02-12-19


Yesterday the DHS NCCIC-ICS published six control system security advisories for products from Siemens (5) and OSIsoft. They also updated seven previously published advisories for products from Siemens.

CP1604 Advisory


This advisory describes three vulnerabilities in the Siemens CP1604 and CP1616 products. These vulnerabilities were self-reported. Siemens has a new version that mitigates the vulnerabilities.

The three reported vulnerabilities are:

• Clear-text transmission of sensitive information - CVE-2018-13808;
• Cross-site scripting - CVE-2018-13809; and
Cross-site request forgery - CVE-2018-13810

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow a denial-of-service condition and information exposure. An attacker could inject arbitrary JavaScript in a specially crafted URL request to execute on unsuspecting user’s systems, allowing an attacker to trigger actions via the web interface that a legitimate user is allowed to perform.

NOTE: I briefly discussed this advisory on January 12th.

Intel Active Management Advisory


This advisory describes three vulnerabilities in the Intel Active Management Technology (AMT) of Siemens SIMATIC IPCs. The vulnerabilities are self-reported. These vulnerabilities exist in third-party (Intel) firmware on the affected PCs. Siemens has firmware updates that mitigate the vulnerabilities.

The three reported vulnerabilities are:

• Cryptographic issues - CVE-2018-3616;
• Improper restrictions of operations within the bounds of a memory buffer - CVE-2018-3657; and
• Resource management errors - CVE-2018-3658

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow arbitrary code execution, a partial denial-of-service condition, or information disclosure. The Siemens advisory reports that:

“The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction.”

NOTE: These vulnerabilities could be found on a large number of industrial PC’s not related to the Siemens products in this advisory.

SIMATIC Advisory


This advisory describes an improper input validation vulnerability in the Siemens SIMATIC S7-300 CPU. The vulnerability was reported by the China Industrial Control Systems Cyber Emergency Response Team (CIC). Siemens has a firmware update that mitigates the vulnerability. There is no indication that CIC has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to all the attacker to  crash the device being accessed, resulting in a denial-of-service condition.

NOTE: I briefly discussed this advisory on January 12th.

Licensing Software Advisory


This advisory describes three vulnerabilities in the Siemens WibuKey Digital Rights Management (DRM) used with SICAM 230. These vulnerabilities are self-reported. Siemens has provided links to a third-party update to mitigate the vulnerabilities. These vulnerabilities were originally reported in the WibuKey product in December by Talos; see the links on the CVE numbers for the Talos reports.

The three reported vulnerabilities are:

• Input validation (3) - CVE-2018-3989, CVE-2018-3990, and CVE-2018-3991.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow information disclosure, privilege escalation, or remote code execution. NOTE: The Talos reports provide proof of concept exploit code.

Again, as with any third-party vulnerability, these problems could be seen in systems from other vendors that also use the WibuKey DRM.

EN100 Ethernet Communications Module Advisory


This advisory describes an improper input validation vulnerability in the Siemens EN100 Ethernet Communication Module and SIPROTEC 5 Relays. The vulnerability was reported by Lars Lengersdorf from Amprion GmbH. Siemens has updates for some of the affected products. There is no indication that Lengersdorf has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to conduct a denial-of-service attack over the network.

OSIsoft Advisory


This advisory describes a cross-site scripting vulnerability in the OSIsoft PI Vision application. The vulnerability is self-reported. OSIsoft has a new version that mitigates this vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow an attacker to read and modify the contents of the PI Vision web page and data related to the PI Vision application in the victim’s browser.

NOTE: I briefly discussed this vulnerability on December 18th, 2018.

Meltdown Spectre Update


This update provides additional information on an advisory that was originally published on January 11th, 2018 and updated on January 16th, 2018, January 17th, 2018, January 30th, 2018, February 20th, 2018, February 22nd, 2018, March 1st, 2018, July 10th, 2018, and most recently on September 11th, 2018.. The new information includes a link to a new Meltdown/Spectre advisory from Siemens for their SIMATIC Industrial Thin Clients.

EN100 Ethernet Communications Module Update


This update provides additional information on an advisory that was originally published on December 13th, 2018. The new information includes updated version data and mitigation links for or firmware variant IEC104 for EN100 Ethernet modules.

SIMATIC S7-1500 Update


This update provides additional information on an advisory that was originally published on October 9th, 2018. The new information includes updated version data and mitigation links for:

• SIMATIC ET 200 SP Open Controller; and
• SIMATIC S7-1500 Software Controller

Open SSL Update


This update provides additional information on an advisory that was originally published on August 14th, 2018 and updated on September 11th, 2018, October 9th, 2018, and again on November 13th, 2018. The update provides new affected version and mitigation information for:

• SIMATIC S7-1500 Software Controller; and
• SIMATIC ET 200SP Open Controller CPU 1515SP PC

SIPROTEC 4 Update


This update provides additional information on an advisory that was originally published on March 8th, 2018 and updated on April 18th, 2018. The update provides new affected version and mitigation information for IEC 104 variant of EN100 module.

Industrial Products Update #1

This update provides additional information on an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th, November 28th, February 27th, 2018, May 3rd, 2018 May 15th, 2018, September 11th, 2018, October 9th, 2018, November 13th, 2018, December 11th, 2018, and most recently on February 5th, 2019. The update provides new affected version and mitigation information for SIMATIC ET 200SP IM155-6 PN HA.

Industrial Products Update #2


This update provides additional information on an advisory that was originally published on January 12th, 2018. The update provides new affected version and mitigation information for SIMATIC CP 1626.

Siemens Advisory Update


Yesterday’s publications by ICS-CERT is really rather remarkable since most of the Siemens advisories covered were published yesterday. NCCIC-ICS has now reported on all of the original advisories from Siemens from January and all but one of the updates (the GNU/Linux vulnerabilities that have not been reported by NCCIC-ICS).

Of the four advisories and 12 updates published yesterday by Siemens only 8 updates have not been directly covered by NCCIC-ICS in yesterday’s reporting. Unless those are reported by NCCIC-ICS on Thursday, I will have more details this weekend.

Thursday, January 31, 2019

Two Advisories and Two Updates Published – 01-31-19


Today the DHS NCCIC-ICS published two control system security advisories for products from Schneider and IDenticard. They also updated two previously published advisories for products from Omron and Siemens

Schneider Advisory


This advisory describes three vulnerabilities in the Schneider EVLink Parking product. The vulnerabilities were reported by Vladimir Kononovich and Vyacheslav Moskvin of Positive Technologies. Schneider has an update available that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Use of hardcoded credentials - CVE-2018-7800;
• Code injection - CVE-2018-7801; and
SQL injection - CVE-2018-7802

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to stop the device and prevent charging, execute arbitrary commands, and access the web interface with full privileges.

NOTE: I briefly discussed these vulnerabilities in December just as the Federal Funding Fiasco started.

IDenticard Advisory


This advisory describes three vulnerabilities in the IDenticard PremiSys WCF Service access control system. The vulnerabilities were reported by Jimi Sebree working with Tenable. IDenticard has a software update that mitigates two of the three vulnerabilities. There is no indication that Sebree has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Hard-coded credentials - CVE-2019-3906;
• Inadequate encryption strength - CVE-2019-3907; and
• Use of hard-coded password - CVE-2019-3908

NCCIC-ICS reports that a relatively low-skilled attacker could use a publicly available information to exploit the vulnerability to view sensitive information via backups, obtain access to credentials, and/or obtain full access to the system with admin privileges.

NOTE: The Tenable report on these vulnerabilities add a four vulnerability; default database credentials - CVE-2019-3909.

Omron Update


This update provides additional information on an advisory that was originally published on October 18th, 2018. The update added Esteban Ruiz (mr_me) of Source Incite as one of the researchers reporting the vulnerabilities.

Siemens Update


This update provides additional information on an advisory that was originally published on June 14th, 2018. The update added affected version information and provided a mitigation link for RUGGEDCOM WiMAX.

NOTE: I briefly discussed this update (and six other Siemens updates published on the same day) earlier this month.

Thursday, January 24, 2019

Two Advisories Published – 01-24-19


Today the DHS NCCIC-ICS published two control system security advisories for products from Phoenix Contact and Advantech.

Phoenix Contact Advisory


This advisory describes six vulnerabilities in the Phoenix Contact FL SWITCH. The vulnerabilities were reported by Evgeniy Druzhinin, Ilya Karpov, and Georgy Zaytsev of Positive Technologies via CERT@VDE. Phoenix Contact reports that newer firmware versions mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Cross-site request forgery - CVE-2018-13993;
• Improper restriction of excessive authentication attempts - CVE-2018-13990;
• Cleartext transmission of sensitive information - CVE-2018-13992;
• Resource exhaustion - CVE-2018-13994;
• Insecure storage of sensitive information - CVE-2018-13991; and
Memory corruption - CVE-2017-3735

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow attackers to have user privileges, gain access to the switch, read user credentials, deny access to the switch, or perform man-in-the-middle attacks.

NOTE: The CERT@VDE advisory notes that CVE-2018-13992 has not been fixed in the newer firmware versions available. A generic fix for that vulnerability has been recommended.

Advantech Advisory


This advisory describes three vulnerabilities in the Advantech WebAccess/SCADA platform.
The vulnerabilities were reported by Devesh Logendran of Attila Cybertech. Advantech has a new version that mitigates the vulnerabilities. There is no indication that Logendran has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Improper authentication - CVE-2019-6519:
• Authentication bypass using an alternate path or channel - CVE-2019-6521; and
• SQL injection - CVE-2019-6523

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to access and manipulate sensitive data.

Tuesday, January 15, 2019

One Advisory and One Update Published – 01-15-19


Today the DHS NCCIC-ICS published a control system security advisory for products from Leão Consultoria e Desenvolvimento de Sistemas Ltda (LCDS) and updated an advisory for products from Schneider Electric.

LCDS Advisory


This advisory describes eleven vulnerabilities in the LCDS LAquis SCADA. The vulnerabilities were reported by Esteban Ruiz (mr me) via the Zero Day Initiative. LCDS has a new version that mitigates the vulnerabilities. There is no indication that Ruiz has been provided an opportunity to verify the efficacy of the fix.

The eleven reported vulnerabilities are:

• Improper input validation - CVE-2018-18988;
• Out-of-bounds read (2) - CVE-2018-19004 and CVE-2018-18994;
• Code injection - CVE-2018-19002;
• Untrusted pointer dereference - CVE-2018-19029;
• Out-of-bounds write - CVE-2018-18986;
• Relative path traversal - CVE-2018-18990;
• Injection (2) - CVE-2018-18992 and CVE-2018-18996;
• Use of hard-coded credential - CVE-2018-18998; and
Authentication bypass using alternative path or channel - CVE-2018-19000

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow remote code execution, data exfiltration, or cause a system crash.

Schneider Update


This update provides additional information on an advisory that was originally published on January 8th, 2019. The new information includes an additional vulnerability, cryptographic issues.

Thursday, January 3, 2019

Three Advisories Published – 01-03-19


Today the DHS NCCIC-ICS proved that they were not currently furloughed (though still not being paid for their service) by publishing three control system security advisories for products from Hetronic, Yokogawa, and Schneider Electric.

Hetronic Advisory


This advisory describes a authentication bypass by capture-replay vulnerability in the Hetronic Nova-M family of remote control transmitters and receivers. The vulnerability was reported by Jonathan Andersson, Philippe Z Lin, Akira Urano, Marco Balduzzi, Federico Maggi, Stephen Hilt, and Rainer Vosseler via the Zero Day Initiative. Hetronic has new firmware versions that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow unauthorized users to view commands, replay commands, control the device, or stop the device from running.

Yokogawa Advisory


This advisory describes a resource management error vulnerability in the Yokogawa Vnet/IP Open Communication Driver. The vulnerability was self-reported. Yokogawa has new versions that mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to cause Vnet/IP network communications to controlled devices to become unavailable.

NOTE: I briefly discussed this vulnerability almost two weeks ago.

Schneider Advisory


This advisory describes an improper input validation vulnerability in the Schneider Pro-face GP-Pro EX devices. The vulnerability was reported by Yu Quiang of Venustech’s ADLab. Schneider has a new version that mitigates the vulnerability. There is no indication that Yu has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to modify code to launch an arbitrary executable upon launch of the program.

NOTE: I briefly discussed this vulnerability almost two weeks ago.

Commentary


I am really glad to see that NCCIC-ICS is publishing advisories during the Federal Funding Fiasco. The people doing the writing, editing, reviewing and posting of these advisories are currently working without pay though they may (probably will) be paid once the FFF is fixed, but that does not make their day-to-day life outside of the office any easier. Please remember them in your thoughts and prayers, and most importantly in your letters to your congresscritters.


Friday, December 21, 2018

Three Advisories and One Update Published – 12-20-18


Yesterday the DHS NCCIC-ICS published three control system security advisories for products from Rockwell Automation, Schneider Electric and Horner Automation. The also published an update for a previously published advisory for products from OMRON. The Rockwell advisory was originally posted to the HSIN ICS-CERT library on November 27, 2018.

Rockwell Advisory


This advisory describes an heap-based buffer overflow vulnerability on the Rockwell FactoryTalk Services Platform. The vulnerability was reported by Andrey Zhukov. Rockwell has a new version that mitigates the vulnerability. There is no indication that Zhukov has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to diminish communications or cause a complete denial of service to the device.

Schneider Advisory


This advisory describes an open redirect vulnerability in the Schneider EcoStruxure. The vulnerability was reported by Donato Onofri of Business Integration Partners S.p.A. Schneider has new versions that mitigate the vulnerability. There is no indication that Onofri has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability  allow an attacker to use this device as a platform to conduct a phishing attack.

Horner Advisory


This advisory describes an improper input validation vulnerability in the Horner Cscape programming software. The vulnerability was reported by rgod and mdm of 9SG Security Team via the Zero Day Initiative. Horner has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to crash the device being accessed, allow the attacker to read confidential information, and may allow an attacker to remotely execute arbitrary code.

OMRON Update


This update provides new information on an advisory that was originally published on March 13th, 2018. The new information includes:

• Revision of advisory format;
• Added Esteban Ruiz (mr_me) of Source Incite as an additional vulnerability reporting source; and
Added new affected versions.

Wednesday, December 19, 2018

7 Advisories and One Update Published - 12-18-18


Yesterday the DHS NCCIC-ICS published seven control system security advisories for products from ABB (3), Advantech, 3S and Siemens. They also published an update of a previously issued advisory for products from Schneider.

M2M Ethernet Advisory


This advisory describes an improper authentication vulnerability in the ABB M2M ETHERNET, network analyzer. It was reported by Maxim Rupp. ABB has provided generic workarounds for this vulnerability. There is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker on an adjacent network could exploit the vulnerability to upload a malicious language file.

NOTE: I briefly discussed the ABB advisory for this vulnerability in early November.


CMS-770 Advisory


This advisory describes an improper authentication vulnerability in the ABB CMS-770. This vulnerability was reported by Maxim Rupp. ABB has provided generic workarounds to mitigate the vulnerability. There is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS has reported that a relatively low-skilled attacker on an adjacent network could exploit the vulnerability to read sensitive configuration files that may lead to code execution on the device.

NOTE: I briefly discussed the ABB advisory for this vulnerability in early November.

Siemens Advisory


This advisory describes a missing authentication for critical function vulnerability in the Siemens TIM 1531 IRC. Siemens is self-reporting this vulnerability. Siemens has a firmware update to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to perform arbitrary administrative operations.

NOTE: I briefly discussed the Siemens advisory and first update for this vulnerability last Saturday. The first update noted that the originally provided firmware update had been withdrawn and left just a workaround available to mitigate the vulnerability. This NCCIC-ICS advisory is based upon the second Siemens update of their advisory.

CODESYS V3 Advisory 1


This advisory describes two vulnerabilities in the S3 CODESYS V3 products. The vulnerabilities were reported by Alexander Nochvay from Kaspersky Lab. S3 has a new version that mitigates the vulnerabilities. There is no indication that Nochvay has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Use of insufficiently random values - CVE-2018-20025; and
Improper restrictions of communication channel to intended endpoint - CVE-2018-20026

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to  allow a remote attacker to disguise the source of malicious communication packets and also exploit a random values weakness affecting confidentiality and integrity of data stored on the device.

NOTE: There are two S3 advisories that support this NCCIC-ICS advisory (here and here).

CODESYS V3 Advisory 2


This advisory describes an improper access control vulnerability in the S3 CODESYS Control V3 products. The vulnerability was reported by Yury Serdyuk of Kaspersky Lab. S3 has a new version and recommends activating the CODESYS Control online user management and encryption of the online communication. There is no indication that Serdyuk has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow unauthorized access and exfiltration of sensitive data including user credentials.

NOTE: S3 published five other advisories last week when they published the three supporting these two NCCIC-ICS advisories. Interestingly, none of the others have CVE numbers. More on these on Saturday.

Advantech Advisory


This advisory describes an improper input validation vulnerability in the AdvantechWebAccess/SCADA product. The vulnerability was reported by Jacob Baines of Tenable Network Security. Advantech has a new version that mitigates the vulnerability. There is no indication that Baines has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to cause the overflow of a buffer on the stack.

Gate E-2 Advisory


This advisory describes two vulnerabilities in the ABB GATE-E2 Pluto ethernet gateway. The vulnerabilities were reported by Nelson Berg of Applied Risk. ABB is only providing generic workarounds as this product is no longer supported. There is no indication that Berg has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Missing authentication of a critical function - CVE-2018-18995; and
• Cross-site scripting - CVE-2018-18997

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow unrestricted access to the administrative telnet/web interface of the device, enabling attackers to compromise the availability of the device, read or modify registers and settings, or change the device configuration.

NOTE: I briefly discussed the two ABB advisories supporting this NCCIC-ICS advisory last Saturday.

Schneider Update


This update provides additional information on an advisory that was originally published on April 17th, 2018, and updated on May 3rd, 2018. The new information included in the update includes:

• Links to a rewritten Schneider advisory;
• Announcement of a new version that further mitigates the HatMan vulnerabilities;
• The announcement that as of February 19th, 2019, “Schneider Electric will require customers to have a support contract in place to engage with the HatMan malware detection service.”

 
/* Use this with templates/template-twocol.html */