Showing posts with label NSA. Show all posts
Showing posts with label NSA. Show all posts

Tuesday, April 28, 2026

Review – 1 Advisory Published – 4-28-26

 Today CISA’s NCCIC-ICS published one control system security advisory for products from NSA. 

Advisories  

NSA Advisory This advisory describes an improper restriction of XML external entity reference vulnerability in the NSA GRASSMARLIN passive network mapping tool. 


For more information on this advisory, including a brief down-the-rabbit-hole look at GRASSMARLIN, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-advisory-published-4-28-26 - subscription required. 

Saturday, October 3, 2020

Public ICS Disclosures – Week of 9-26-20

This week we have ten vendor disclosures for products from WAGO (3), IBM, Bosch, B&R Automation (2), Moxa, BD, and Philips.

WAGO Advisories

CERT-VDE published an advisory describing an improper authentication and authorization vulnerability in the WAGO 750-8XX series PLCs. The vulnerability was reported by Maxim Rupp. WAGO has new firmware versions that mitigate the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

CERT-VDE published an advisory describing an improper authentication and access control vulnerability in the WAGO 750-36X and WAGO 750-8XX series PLCs. The vulnerability was reported by Maxim Rupp. WAGO has new firmware versions that mitigate the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

CERT-VDE published an advisory describing an improper neutralization of input during web page generation vulnerability in the Web-UI for WAGO 750-88X and WAGO 750-89X series PLCs. This vulnerability was reported by Secuninja. WAGO has new firmware versions that mitigate the vulnerability. There is no indication that Secuninja has been provided an opportunity to verify the efficacy of the fix.

IBM Advisory

IBM published an advisory describing an authentication bypass vulnerability in their Maximo Asset Management product. The vulnerability is being self-reported. IBM has updates that mitigate the vulnerability.

Bosch Advisory

Bosch published an advisory describing three vulnerabilities in their PRAESIDEO Network Controller and the PRAESENSA System Controller products. The vulnerabilities were reported by Gjoko Krstic of Applied Risk. Bosch has software updates for the supported products that mitigate the vulnerabilities. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Cross-site scripting - CVE-2020-6777,

• Cross-site request forgery - CVE-2020-6776, and

• Nonce reuse attack - CVE-2020-15688

NOTE: The last is a third-party vulnerability (GoAhead web server).

B&R Advisories

B&R published an advisory describing four vulnerabilities in their GateManager product. These vulnerabilities were reported by NCCIC-ICS on July 28th as being for the Secomea GateManager.

B&R published an advisory describing six vulnerabilities in their SiteManager and GateManager procucts. These vulnerabilities were reported by NCCIC-ICS last Tuesday, but the B&R advisory was not available when I published my blog post. It is not clear if the Secomea versions of these products are also affected by these vulnerabilities.

Moxa Advisory

Moxa published an advisory describing a device information leak vulnerability in their EDR-810 Series Industrial Secure Routers. The vulnerability was reported by the National Security Agency (yep, that is what the advisory says). Moxa has provided generic workarounds to mitigate the vulnerability.

BD Advisory

BD published an advisory describing a remote code execution vulnerability (CVE-2020-1147) in a third-party component (Microsoft) of a long list of their products. BD is working on testing and validation of the Microsoft patch.

Philips Advisory

Philips published an advisory describing a privilege elevation vulnerability (CVE-220-1472) in a third-party component (Microsoft) of an undisclosed number of Philips products. No mitigation information has been provided.

Tuesday, July 12, 2016

House Passes HR 5639, NIST Improvement

Yesterday as expected the House passed HR 5639, the National Institute of Standards and Technology Improvement Act of 2016 by a voice vote. There was only eleven minutes ‘debate’ on the bill before the vote was taken, but there were no words spoken in opposition to the bill.

As I mentioned in my earlier post there is only one cybersecurity provision in the bill, but it is more of a face-saving slap at the NSA than an effective legislative provision.


The bill, if it reaches the floor of the Senate before the end of the session, will almost certainly be considered under their unanimous consent provisions where it will be passed with no debate and no vote.

Wednesday, February 18, 2015

HR 726 Introduced – NSA Backdoors

As I mentioned earlier Rep. Lofgren (D,CA) introduced HR 726, the Secure Data Act of 2015. While the bill does not specifically mention the National Security Agency (NSA) it was obviously written in response to revelations that the NSA obtained backdoor access to various computer systems and software. Similar bills (HR 5800 and S 2981) were introduced last year during the close of the 113th Congress without any subsequent action.

The bill’s requirements are fairly straightforward. It states that no government agency “may mandate or request that a manufacturer, developer, or seller of covered products design or alter the security functions in its product or service to allow the surveillance of any user of such product or service, or to allow the physical search of such product, by any agency” {§2(a)}.

The one loop hole in this bill that I identified in my discussion of the bills introduced last year remains in the definition of ‘covered products’. That term is defined as “any computer hardware, computer software, or electronic device that is made available to the general public[emphasis added]”  {§2(c)(2)}. It could certainly be argued that servers and the software for many internet based services are not ‘available to the general public’.

The bill is careful to ensure that the language does not interfere with court ordered access to digital communications as authorized under 47 USC 1001 et seq. Even those provisions prohibit law enforcement agencies from requiring “any specific design of equipment, facilities, services, features, or system configurations to be adopted by any provider of a wire or electronic communication service, any manufacturer of telecommunications equipment, or any provider of telecommunications support services” {47 USC 1002(b)(1)(A)}.


I suspect that if this bill were to make it to the floor of the House that it would pass with substantial bipartisan support. The question is if Lofgren has the political connections to get this bill considered in either of the two committees to which it has been referred. She is a member of the Judiciary Committee so I would expect that this would be the first committee to see any action on this bill.

Tuesday, July 15, 2014

House Did Not Consider HR 5035

According to the House Floor Summary for today, the House did not consider HR 5035, the NIST reauthorization bill that I described this weekend. It is still listed on the Majority Leader’s web site for consideration on Monday, July 14th so there is no official reason given for why the bill was not addressed today. I suspect that there was enough concern about the NIST-NSA relationship that was not adequately addressed in this bill to make this slightly more controversial than the Leadership was willing to risk on considering the bill under suspension of the rules.


There is an outside chance that the bill could get added to tomorrow’s session. I suspect that, if I am right about why the bill was not considered today, it will be considered next week under a rule with limited amendments.

Saturday, July 12, 2014

HR 5035 Introduced – NIST Authorization

As I mentioned earlier Rep. Bucshon (R,IN) the Chair of the Subcommittee on Research and Technology of the House Science, Space and Technology Committee, introduced HR 5035, the NIST Reauthorization Act of 2014. This is the two-year re-authorization of the National Institute of Standards and Technology.

Cybersecurity

There is only one place in this bill where cybersecurity activities are specifically addressed. Section 12 of the bill would amend 15 USC 278g-3, the Computer Standards Program. This section of the USC provides for NIST being responsible for setting standards for the security of government computer systems (not including ‘national security systems) and the information within those systems.

The only change made to this section is the removal of the words “the National Security Agency” from §278g-3(c)(1). This section currently requires the Director to “consult with other agencies and offices (including, but not limited to, the Director of the Office of Management and Budget, the Departments of Defense and Energy, the National Security Agency, the Government Accountability Office, and the Secretary of Homeland Security) to assure” that proper appropriate information security policies, procedures, and techniques are used by government agencies.

Apparently this revision was put into place because of Snowden revelations that NIST recommended less than adequate encryption standards under recommendations of NSA. If this is the reason, the crafters of this language are taking very limited action against the NSA because section only applies to the security of government systems and not NIST standards that would be used by the private sector.

Even with government IT security, this amendment to §278g-3 only deals with lower security standards associated with government IT systems not associated with national security systems. Paragraph (b) of the section still requires NIST to coordinate with NSA to establish guidelines “for identifying an information system as a national security system consistent with applicable requirements for national security systems” {§278g-3(b)(3)}.

There are almost certainly other mentions of working with NSA in 15 USC Chapter 7 {for example §278g-4(a)(3)} that could have also been addressed if Congress was serious about severing ties between NIST and NSA. So this amendment is a symbolic congressional wrist slap of the NSA with no real consequences.

Moving Forward


According to the Majority Leader’s web site, HR 5035 will be considered by the House on Monday under suspension of the rules. Barring some unforeseen circumstance, this should mean that the bill will pass with a minimum of fuss and bother, very little debate and no amendments. It is likely to get equally swift and cursory attention in the Senate.
 
/* Use this with templates/template-twocol.html */