Showing posts with label NSFOCUS. Show all posts
Showing posts with label NSFOCUS. Show all posts

Sunday, December 13, 2020

Public ICS Disclosures – Week of 12-5-20, Part II

This week we have nine disclosures for products from Schneider. We also have eight vendor updates for products from Siemens (5) and Schneider (3). Finally, we have two researcher reports about vulnerabilities in products from Schneider.

Schneider Advisories

Schneider published an advisory describing a write-what-where condition vulnerability in their EcoStruxure™ Control Expert. The vulnerability was reported by Jared Rittle of Cisco Talos; the report contains proof-of-concept code. Schneider provides generic workarounds pending development of remediation measures.

 

Schneider published an advisory describing an insufficiently protected credentials vulnerability in their EcoStruxure Geo SCADA Expert. The vulnerability is being self-reported. Schneider has updates available that mitigate the vulnerability.

 

Schneider published an advisory describing two vulnerabilities in their Web Server on Modicon M340 communication modules. The vulnerabilities were reported by DongJian Security Lab and the Russian BDU FSTEC (report here). Schneider has new firmware versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Forced browsing - CVE-2020-7541, and

• Improper check for unusual or exceptional conditions - CVE-2020-7539

 

Schneider published an advisory describing a missing authentication for critical function vulnerability in their Web Server on Modicon M340 communications modules. The vulnerability was reported by DongJian Security Lab. Schneider has new firmware versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

 

Schneider published an advisory describing a path traversal vulnerability on the Web Server on Modicon M340 communications modules. The vulnerability was reported by Zheng Qiang. Schneider has new firmware versions that mitigate the vulnerability. There is no indication that the researcher have been provided an opportunity to verify the efficacy of the fix.

 

Schneider published an advisory describing an improper check for unusual or exceptional conditions vulnerability in their Web Server on Modicon M340 communications modules. The vulnerability is being self-reported.

 

Schneider published an advisory describing an improper check for unusual or exceptional conditions vulnerability in their Modicon M340 CPU’s. The vulnerability was reported by the VAPT Team from C3i IITK, India. Schneider has new firmware versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

 

Schneider published an advisory describing three separate improper check for unusual or exceptional conditions vulnerabilities in their Modicon M580 controllers. The vulnerabilities were reported by Gao Jian of NSFOCUS, Daniel Lubel of OTORIO, Armis Security, Victor Fidalgo Villar of INCIBE-CERT, and Gideon Guo. Schneider has firmware updates that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

 

Schneider published an advisory describing an improper restriction of operations within the bounds of a memory buffer vulnerability in their M258 Logic Controllers and SoMachine/SoMachine Motion software. The vulnerability was reported by Kai Feng. Schneider has new versions that mitigate the vulnerability. There is no indication that Kai has been provided an opportunity to verify the efficacy of the fix.

Siemens Updates

Siemens published an update for their SegmentSmack advisory that was originally published on April 14th, 2020 and most recently updated on September 8th, 2020. The new information include updating information regarding successor products for SIMATIC RF180C and RF182C.

NOTE: NCCIC-ICS updated their advisory for this vulnerability back in September but has not updated for this Siemens update.

 

Siemens published an update for their GNU/Linux subsystem advisory that was originally published in 2018 and most recently updated on November 10th, 2020. The new information includes adding the following new vulnerabilities:

• CVE-2020-25284,

• CVE-2020-25668,

• CVE-2020-25705,

• CVE-2020-27618, and

• CVE-2020-27777

 

Siemens published an update for their Industrial Products advisory that was originally published on December 10th, 2019 and most recently updated on September 8th, 2020. The new information includes updating d information regarding successor products for SIMATIC RF182C and RFID 181EIP.

NOTE: NCCIC-ICS last updated their advisory for this product back in August.

 

Siemens published an update for their advisory that was originally published on September 9th, 2020 and most recently updated on October 13th, 2020. The new information includes adding patch links for:

• SIMATIC HMI Basic (2nd generation),

• Comfort (including SIPLUS variants), and

• Mobile Panels

NOTE: NCCIC-ICS published their advisory for these vulnerabilities back in September but has not updated it since.

 

Siemens published an update for their ZombieLoad advisory that was originally published on July 9th, 2019 and most recently updated on March 10th, 2020. The new information includes:

• Correcting mitigations for SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP and

• Providing updates for SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP

Schneider Updates

Schneider published an update for their Ripple20 advisory that was originally published on June 23, 2020 and most recently updated on November 10th, 2020. The new information includes adding remediation for:

• SCADAPack 32 RTU,

• XUPH001 OsSense communication module,

• XGCS850C201 OsiSense RFID compact smart antenna,

• ATV340E Altivar Machine Drives,

• ATV630/650/660/680/6A0/6B0 Altivar Process Drives,

• ATV930/950/960/980/9A0/9B0 Altivar Process Drives,

• VW3A3720, VW3A3721 Altivar Process Communication Modules,

• ACE850 Sepam communication interface,

• PowerLogic EGX300 Ethernet Gateway,

• PowerLogic EGX100 Ethernet Gateway, and

• Acti9 Smartlink IP

 

Schneider published an update for their CodeMeter advisory that was originally published on October 13th, 2020. The new information includes reporting that the CodeMeter V7.10a fix qualification is confirmed for EcoStruxure Machine SCADA Expert.

 

Schneider published an update for their Modicon controllers advisory that was originally published on May 14th, 2019 and most recently updated on October 18th, 2020. The new information includes adding a fix for additional attack scenario is available on M340 V3.30 for CVE-2018-7857.

Schneider Reports

Claroty published a report discussing the Modicon M221 PLC vulnerabilities reported Tuesday by Schneider.

Trustwave published a report discussing one of the Modicon M221 PLC vulnerabilities reported Tuesday by Schneider. This report contains proof-of-concept code for the one-way hash vulnerability.

Saturday, April 18, 2020

Public ICS Disclosures – Week of 04-11-20


This week we have five vendor disclosures for products from Schneider (4) and OPC Foundation. We also have nine updated advisories for products from Schneider (4) and Siemens (5).

Schneider Advisories


Schneider published an advisory describing an injection vulnerability in their Modicon M100/M200/M221 controllers, SoMachine Basic and EcoStruxure Machine Expert - Basic products. The vulnerability was reported by Seok Min Lim and Johnny Pan of Trustwave. Schneider has updated software and firmware that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.


Schneider published an advisory describing two vulnerabilities in their Modicon M218/M241/M251/M258 Logic Controllers, SoMachine & SoMachine Motion, and EcoStruxure Machine Expert products. The vulnerabilities were reported by Rongkuan Ma, Shunkai Zhu and Peng Cheng of 307Lab. Schneider has new versions to mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Insufficient verification of data authenticity - CVE-2020-7487; and
• Clear-text transmission of sensitive data - CVE-2020-7488



Schneider published an advisory describing an untrusted search path vulnerability in their Vijeo Designer and Vijeo Designer Basic Software products. The vulnerability was reported by Yongjun Liu of nsfocus. Schneider has a new version that mitigates the vulnerability. There is no indication that Yongjun has been provided an opportunity to verify the efficacy of the fix.


Schneider published an advisory describing four vulnerabilities in their legacy Triconex product. These vulnerabilities are self-reported. Schneider reports that newer versions corrected the vulnerabilities.

The four reported vulnerabilities are:

• Password vulnerability (2) - CVE-2020-7483 and CVE-2020-7484;
• Improper access - CVE-2020-7485; and
• Denial of service - CVE-2020-7486

OPC Foundation Advisory


OPC published an advisory describing an malformed message vulnerability in their UA .NET Standard Stack. The vulnerability was reported by Steven Seeley (mr_me) and Chris Anastasio (muffin) via the Zero Day Initiative. OPC has updates available that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Schneider Updates


Schneider has published an update for their Urgent/11 advisory that was originally published on August 2nd, 2019 and most recently updated on March 11th, 2020. The new information includes updated mitigation information for:

• ION7400 MID; and
• PM8000 MID


Schneider has published an update for their Modicon Controllers advisory that was originally published on November 12th, 2019. The new information includes the addition of a new hard-coded credentials vulnerability - CVE-2019-6859.


Schneider has published an update for their Andover Continuum advisory that was originally published on March 10th, 2020. The updated information includes an explanation that the code injection vulnerability is a third-party MS-XML library vulnerability.


Schneider has published an update for their Modicon Controllers advisory that was originally published on December 10th, 2019. The updated information includes:

• Adding Modicon M340 and M580 to affected product list;
• Adding a hotfix link and adding further details to the mitigation measures;
• Adding updated firmware links; and
• Adding Enrique Murias Fernández of Tecdesoft Automation to the acknowledgements.

Siemens Updates


Siemens published an update for an advisory for Intel CPUs that was originally published on February 11th, 2020 and most recently updated on March 10th, 2020. The new information includes updated version information and mitigation links for SIMATIC ET 200SP Open Controller CPU 1515SP PC2.


Siemens published an update for an advisory for Industrial Products that was originally published on January 14th, 2020. The new information includes explicitly mentioning old versions of SIMATIC NET.


Siemens published an update for their GNU/Linux subsystem vulnerabilities advisory that was originally published on November 27th, 2018 and most recently updated on February 11th, 2020. The new information includes adding the following new vulnerabilities:

• CVE-2015-5895;
• CVE-2019-19447;
• CVE-2019-19603;
• CVE-2019-19645,
• CVE-2019-19646;
• CVE-2019-19880;
• CVE-2019-19923;
• CVE-2019-19924;
• CVE-2019-19925;
• CVE-2019-19926;
• CVE-2019-19959;
• CVE-2019-20218;
• CVE-2020-8428;
• CVE-2020-8492;
• CVE-2020-9327;
• CVE-2020-10029; and
• CVE-2020-10942


Siemens published an update for their SIMATIC advisory that was originally published on July 30th, 2012. The new information includes adding SIPLUS devices to the list of affected devices.

NOTE: ICS-CERT published advisory ICSA-12-212-02 covering this vulnerability, but has not yet updated (and may not update) that advisory.


Siemens published an update for their SIMATIC advisory that was originally published on July 30th, 2012. The new information includes adding SIPLUS devices to the list of affected devices.

NOTE: This advisory was lumped into the ICS-CERT advisory described above.

Sunday, March 15, 2020

Public ICS Disclosures – Week of 3-7-20 Part II


In addition to the vendor disclosures I discussed yesterday, we have four vendor disclosures from Schneider and three updated disclosures from Schneider and Siemens (2).

Schneider Advisories


Schneider published an advisory describing two vulnerabilities in the Schneider Interactive Graphical SCADA System (IGSS). The vulnerabilities were reported by an anonymous researcher via the Zero Day Initiative. Schneider has a new version that mitigates the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper limitation of a path name to a restricted directory - CVE-2020-7478; and
• Missing authentication for a critical function - CVE-2020-7479


Schneider published an advisory describing an improper check for unusual or exceptional conditions vulnerability in the Schneider Modicon Quantum Ethernet Network module and Quantum / Premium COPRO. The vulnerability was reported by China Information Technology Security Evaluation Centre (CNITSEC). Schneider has a new version for the Quantum Ethernet Network module that mitigates the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.


Schneider published an advisory describing an untrusted search path vulnerability in the Schneider ZigBee Installation Toolkit. The vulnerability was reported by Yongjun Liu of nsfocus. Schneider has a new version that mitigates the vulnerability. There is no indication that Liu has been provided an opportunity to verify the efficacy of the fix.


Schneider published an advisory describing three vulnerabilities in the Schneider Andover Continuum Line of Controllers. The vulnerabilities were reported by Niv Levy. Schneider provided generic mitigation measures for this product that is no longer under service support.

Schneider Update


Schneider has published an update for their Urgent/11 advisory that was originally published on August 2nd, 2019 and most recently updated on February 11th, 2020. The new information includes mitigation measures for:

• HMIGXU;
• Easergy MiCOM P30;
• Tricon Communication Modules; and
• Trident Communication Integration Module

Siemens Updates


Siemens published an update for an advisory for Intel CPUs that was originally published on February 11th, 2020. The new information includes updated version and mitigation data for:

• SIMATIC IPC127El;
• SIMATIC IPC627E;
• SIMATIC IPC647E;
• SIMATIC IPC677E; and
• SIMATIC IPC847E


Siemens published an update for an advisory for their ZombieLoad advisory that was originally published on July 9th, 2019 and most recently updated on February 11th, 2020. The new information includes updated version and mitigation data for:

• SIMATIC IPC127E; and
• SIMATIC IPC527G

Saturday, February 15, 2020

Public ICS Disclosure – Week of 2-7-20


This week we have eight vendor disclosures for products from Siemens (2), Schneider Electric, Phoenix Contact, HMS, ABB (2) and Moxa. We also have three advisory updates from Siemens and one from Schneider.

Siemens Advisories


Siemens published an advisory describing three vulnerabilities found in Intel chips used in Siemens products. The vulnerabilities were identified and reported (advisory links below) by Intel. Siemens has provided generic workarounds to mitigate the vulnerabilities.

The three reported vulnerabilities are:

• Insufficient memory protection (2) - CVE-2019-0151 and CVE-2019-0152; and
• Heap-based buffer overflow - CVE-2019-0169

Siemens published an advisory describing a resource allocation vulnerability in their Profinet-IO stack. The vulnerability was reported by Yuval Ardon and Matan Dobrushin from OTORIO. Siemens has updates that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Schneider Advisory


Schneider Published an advisory describing an uncontrolled search path element vulnerability in their ProSoft Configurator. The vulnerability was reported by Yongjun Liu from nsfocus. Schneider has a new version that mitigates the vulnerability. There is no indication that Yongiun has been provided an opportunity to verify the efficacy of the fix.

Phoenix Contact Advisory


Phoenix Contact has published an advisory [.PDF download link] describing a remote configuration vulnerability in their Emalytics Controllers. The vulnerability was reported by Anil Parmar. Phoenix Contact has a new firmware version that mitigates the vulnerability. There is no indication that Parmar has been provided an opportunity to verify the efficacy of the fix.

HMS Advisory


HMS has published an advisory describing a cross-site scripting vulnerability in their Flexy and Cosy products. The vulnerability was reported by Ander Martínez from Titanium Industrial Security. HMS has a new firmware version that mitigates the vulnerability. There is no indication that Martinez has been provided an opportunity to verify the efficacy of the fix.

ABB Advisories


ABB published an advisory describing a direct object reference vulnerability in their Asset Suite product. The vulnerability is self-reported. ABB has a new version that mitigates the vulnerability.

ABB published an advisory describing 14 vulnerabilities in their eSOMS product. The vulnerabilities are self-reported. ABB has a new version that mitigates the vulnerabilities.

Moxa Advisory


Moxa published an advisory describing 8 vulnerabilities in their OnCell cellular gateway. The vulnerabilities were reported by Alexander Zaytsev from Kaspersky Lab. Moxa has new firmware versions that mitigate the vulnerabilities. There is no indication that Zaytsey has been provided an opportunity to verify the efficacy of the fix.

Siemens Updates


Siemens published an update to their  Linux TCP SACK PANIC advisory for Industrial Products that was originally published on September 10th, 2019 and most recently updated on November 14th, 2019. The new information includes revised version data and mitigation links for:

• TIM 1531 IRC;
• SIMATIC CP 1242-7, CP 1243-7 LTE (EU andUS versions), CP 1243-1, CP 1243-8 IRC, CP 1543-1, CP 1542SP-1, CP 1542SP1 IRC, CP 1543SP-1; and
• SCALANCE W1700.

NOTE: NCCIC-ICS updated their advisory on February 11th, but did not list it on their web site.

Siemens published an update for their ZombieLoad advisory that was originally published on July 9th, 2019 and most recently updated on December 10th, 2019. The new information includes updated version data and mitigation links for:

• SIMATIC IPC547E;
• SIMATIC IPC347E; and
• SIMATIC IPC3000 SMART V2
Siemens published an update for their GNU/Linux subsystem vulnerabilities advisory that was originally published on November 27th, 2018 and most recently updated on January 14th, 2020. The new information includes adding the following new vulnerabilities;

• CVE-2019-5188;
• CVE-2019-11190;
• CVE-2019-19956;
• CVE-2019-20054,
• CVE-2019-20079;
• CVE-2019-20388; and
• CVE-2020-7595

Schneider Update


Schneider published an update for their U.motion Builder advisory that was originally published on April 5th, 2018. The new information includes an updated remediation section.

Saturday, December 21, 2019

Public ICS Disclosures – Week of 12-14-19


This week we have five vendor disclosures for products from WAGO, ABB, 3S, BD and Symantech. There is also an updated advisory from 3S.

WAGO Advisory


CERT-VDE published an advisory describing 9 vulnerabilities in the WAGO Series PFC100 and Series PFC200 devices. The vulnerabilities were reported (CVE links to individual reports) by Kelly Leuschner of Cisco Talos. WAGO has a specific workaround and firmware updates to mitigate the vulnerabilities. There is no indication that Leuschner has been provided an opportunity to verify the efficacy of the fix.

The nine reported vulnerabilities are:

• Information exposure through sent data - CVE-2019-5073;
• Buffer access with incorrect length value (2) - CVE-2019-5074 and CVE-2019-5075;
• Missing authentication for critical function (3) - CVE-2019-5077, CVE-2019-5078 and CVE-2019-5080; and
Classic buffer overflow (3) - CVE-2019-5079, CVE-2019-5081 and CVE-2019-5082

NOTE1: The following Talos reports include exploit code: CVE-2019-5073; CVE-2019-5074; CVE-2019-5075; CVE-2019-5079; CVE-2019-5081; CVE-2019-5082

NOTE2: Talos reports that some of these vulnerabilities are in third-party components from 3S.

ABB Advisory


ABB published an advisory that describes four vulnerabilities in their PB610 Panel Builder 600. The vulnerabilities were reported by NSFOCUS. ABB has a new version that mitigates the vulnerabilities. There is no indication that NSFOCUS was provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• PB610 HMIStudio crashes after launching an empty *.JPR application file;
• PB610 HMISimulator does not check content-length of the HTTP request;
• PB610 HMIStudio accepts malicious DLL file in an application; and
• PB610 HMISimulator provides interface with access to arbitrary files

3S Advisory


3S published an advisory [.PDF download link] describing a null pointer dereference vulnerability in their CODESYS V2 runtime systems. The vulnerability was reported by Chen Jie from NSFOCUS. 3S has new versions that mitigate the vulnerability. There is no indication that Chen has been provided an opportunity to verify the efficacy of the fix.

3S Update


3S published an update [.PDF download link] of an advisory that was originally published on November 20th, 2019. The new data includes updated exploit information.

BD Advisory


BD has published an advisory describing the impact of the Internet Explorer® Scripting Engine Memory Corruption Vulnerability in their products. The vulnerability is self-reported. BD is working to test and validate the Microsoft patch for BD products that use the affected third-party components.

Symantec Advisory


Symantec has published an advisory describing an improper authentication vulnerability in their Industrial Control System Protection product. The vulnerability was reported by Tyler Holland at Horne Cyber Solutions. Symantec has an update that mitigates the vulnerability. There is no indication that Holland has been provided an opportunity to verify the efficacy of the fix.

Tuesday, October 22, 2019

1 Advisory Published – 10-22-19


Today he CISA NCCIC-ICS published a control system security advisory for products from Schneider

Schneider Advisory


This advisory describes three vulnerabilities in the Schneider ProClima building and automation control products. The vulnerabilities were reported by Haojun Hou, Kushal Arvind Shah, Fortinet, Yongjun Liu, NSFOCUS, and Telus. Schneider has released a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

Code injection - CVE-2019-6823;
Improper restriction of operations within the bounds of a memory buffer - CVE-2019-6824; and
Uncontrolled search path element - CVE-2019-6825

NCCIC-ICS reported that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system.

NOTE: According to the Schneider advisory these vulnerabilities were reported on June 11th, and I briefly reported on them on June 15th. What NCCIC-ICS is actually addressing is an update to the original advisory that adjusted the CVSS Base Score and Vector for CVE2019-6823 and CVE-2019-6824.

Saturday, October 12, 2019

Public ICS Disclosures – Week of 09-05-19


This week we have URGENT/11 updates from three ICS vendors; seven new vendor disclosures from Siemens, Schneider (4), Beckhoff (2) and Drager; six updates of previously issued advisories from Siemens (2), Schneider (3) and Yokogawa, and one exploit of a previously reported vulnerability for products from SMA Solar Technology.

URGENT/11 Updates



Siemens Advisory


Siemens published an advisory describing twelve vulnerabilities in the Siemens SIMATIC WinAC
RTX (F) 2010. These vulnerabilities are known as Spectre, Meltdown, Spectre-NG, Foreshadow, L1 Terminal Fault (L1TF), ZombieLoad, and Microarchitectural Data Sampling (MDS). These vulnerabilities were reported by various researchers. Siemens has an update that mitigates the vulnerabilities.

Schneider Advisories


Modicon Controllers Advisory #1

Schneider published an advisory describing a file and directory information disclosure vulnerability in the Schneider Modicon brand of programmable logic controllers. The vulnerability was reported by Jared Rittle (Cisco Talos); the report includes proof-of-concept (POC) code. Schneider provides generic workarounds to mitigate the vulnerability.

Modicon Controllers Advisory #2

Schneider published an advisory describing six vulnerabilities in the Schneider Modicon brand of programmable logic controllers. The vulnerabilities were reported by Jared Rittle and Patrick DeSantis (Cisco Talos) (the CVE links below are to the individual reports which contain POC code). Schneider provides generic workarounds to mitigate the vulnerability.

The six reported vulnerabilities are:

Uncaught exception (5) - CVE-2019-6841, CVE-2019-6842, CVE-2019-6843, CVE-2019-6844 and CVE-2019-6847; and
Clear-text transmission of sensitive information - CVE-2019-6846;

Modicon Controllers Advisory #3

Schneider published an advisory describing a clear-text transmission of sensitive information vulnerability in the Schneider Modicon brand of programmable logic controllers. The vulnerability was reported by Jared Rittle (Cisco Talos). Schneider provides generic workarounds to mitigate the vulnerability.

Modicon Controllers Advisory #4

Schneider published an advisory describing three vulnerabilities in the Schneider Modicon brand of programmable logic controllers. The vulnerabilities were reported by Jared Rittle (Cisco Talos) (the CVE links below are to the individual reports which contain POC code). Schneider provides generic workarounds to mitigate the vulnerability.

The three reported vulnerabilities are:

Uncaught exception vulnerability - CVE-2019-6848; and
Information exposure (2) - CVE-2019-6849 and CVE-2019-6850

Beckhoff Advisories


TwinCat Advisory

VDE-CERT published an advisory describing a divide by zero vulnerability in the Beckhoff TwinCAT real-time controller. The vulnerability was reported by Andreas Galauner from Rapid7. The Beckhoff advisory on this vulnerability reports that they are working on an update to mitigate the vulnerability.

CE Remote Display Advisory

Beckhoff published an advisory describing an incorrect login response vulnerability in the Beckhoff CE Remote Display. The vulnerability was reported by Chen Jie from NSFOCUS and Tijl Deneut from University Howest. Beckhoff has updates that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Drager Advisory


Drager has published an advisory describing three vulnerabilities in the Drager Infinity® M300 patient monitor. Drager is self-reporting the vulnerabilities. Drager will be releasing a new version to mitigate the vulnerabilities in March 2020.

The three reported vulnerabilities are:

Network DDOS attack;
Repeated DDOS attacks; and
Information exposure

Siemens Updates


Industrial Products Update

Siemens published an update for an advisory that was originally published in May of 2017 and most recently updated on February 14th, 2019. The new information includes:

• Merged WinAC RTX 2010 SP2 and WinAC RTX F 2010 SP2 to SIMATIC WinAC RTX (F) 2010; and
• Added mitigation information for SIMATIC WinAC RTX (F) 2010

NOTE: I expect NCCIC-ICS to update their advisory this week.

SIMATIC S7 Update

Siemens published an update for an advisory that was originally reported in November 2018 and most recently updated on August 13th, 2019. The new information includes:

• Added CVE-2019-1125, CVE-2019-15666 and CVE-2019-15903; and
• Removed CVE2018-19591 from the list of fixed vulnerabilities

NOTE: NCCIC-ICS has not addressed these Linux vulnerabilities.

Schneider Updates


Floating License Manager Update

Schneider published an update for an advisory that was originally published in May 2019 and most recently updated on September 10th, 2019. The new information is updated remediations for EcoStruxure Power
Monitoring Expert.

NOTE: NCCIC-ICS may update their advisory, but they did not update for the last Schneider update.

SoMachine Update

Schneider published an update for an advisory that was originally published on August 13th, 2019. The new information is adding SoMove FDT to the list of affected products.

NOTE: NCCIC-ICS did not address this vulnerability.

Embedded Web Server Update

Schneider published an update for an advisory that was originally published in November 2018 and most recently updated on June 11th, 2019. The new information includes mitigation information for the M340 controller.

 NOTE: NCCIC-ICS did not address these vulnerabilities.

Yokogawa Update


Yokogawa published an update for an advisory that was originally published on September 27th, 2019. The new information includes updated affected version data and mitigation measures for Exaquantum.

NOTE: NCCIC-ICS will probably update their advisory this week.

SMA Exploit


Borja Merino published an exploit for a cross-site forgery vulnerability in the SMA Sunny WebBox. An advisory for the vulnerability was published on October 8th, 2019.

Saturday, September 14, 2019

Public ICS Disclosures – Week of 09-07-19


This week we have 11 vendor disclosures for products from Siemens (3), Schneider (3), Bosch (2), 3S, Eaton, and Draeger. We also have 3 vendor updates from Schneider (2) and Siemens.

Siemens Advisories


DejaBlue Advisory

Siemens published an advisory describing the Microsoft Windows® DejaBlue vulnerabilities in the Siemens Healthineers Products. In most of the affected products Siemens is recommending applying the appropriate MS patches.

Siemens repeatedly makes the following observation: “The compatibility of Microsoft security patches with products from Siemens Healthineers that are beyond their End of Support date cannot be guaranteed.”

RUGGEDCOM URGENT/11 Advisory

Siemens published an advisory describing the Wind River URGENT/11 vulnerabilities in the Siemens RUGGEDCOM Win base stations. Siemens provides generic workarounds for the vulnerabilities.

SINEMA Advisory

Siemens published an advisory describing four vulnerabilities in the Siemens r SINEMA Remote Connect Server. The vulnerabilities were reported by Hendrik Derre and Tijl Deneut from HOWEST. Siemens has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

Password guessing - CVE-2019-13918;
Privilege escalation - CVE-2019-13919;
Cross-site request forgery - CVE-2019-13920; and
Password hash - CVE-2019-13922

Siemens Update


Siemens published an update for an advisory that was originally published on June 9th, 2019. This update provides corrected version information and mitigation information for:

FieldPG M4;
FieldPG M5; and
ITP1000

Schneider Advisories


U.Motion Server Advisory

Schneider published an advisory describing six vulnerabilities in the Schneider U.motion din rail and touch panel servers. The vulnerabilities were reported by Zhu Jiaqi and Constantin-Cosmin Craciun. Schneider has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

Cross-site scripting - CVE-2019-6835;
Improper access control (3) - CVE-2019-6836, CVE-2019-6838 and CVE-2019-6839;
Server-side request forgery - CVE-2019-6837; and
Format string - CVE-2019-6840

Modicon Quantum Advisory

Schneider published an advisory describing an improper check for unusual or exceptional conditions vulnerability for the Schneider Modicon Quantum 140 NOE771x1 controllers. The vulnerability is self-reported. Schneider has a new version that mitigates the vulnerability.

TwidoSuite Advisory

Schneider published an advisory describing two vulnerabilities in the Schneider TwidoSuite product. The vulnerability is self-reported. This product is no longer supported.

The two reported vulnerabilities are:

Untrusted search path;
Input validation

Schneider Updates


BlueKeep Update

Schneider published an update for an advisory that was originally published on July 12, 2019. The update includes:

Exploit information; and
Updated affected product versions

 Floating License Manager Update

Schneider published an update for an advisory that was originally published on May 14th, 2019. The update provides updated affected product information.

Bosch Advisories


Bosch published two advisories (here and here) describing vulnerabilities in the Access Professional access control system. The vulnerabilities were reported by Oleksii Orekhov. Bosch has a new version that mitigates the vulnerabilities. There is no indication that Orekhov has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Hard-coded credentials - CVE-2019-11898; and
Improper access control - CVE-2019-11899

3S Advisory


3s published an advisory describing a stack-based buffer overflow vulnerability in the CODESYS V2.3 ENI servers. This vulnerability was reported by Chen Jie from NSFOCUS. 3S has an update that mitigates the vulnerability. There is no indication that Chen has been provided an opportunity to verify the efficacy of the fix.

Eaton Advisory


Eaton published an advisory describing multiple undisclosed vulnerabilities in the Eaton Intelligent Power Protector. The vulnerabilities are apparently self-reported. Eaton has a new version that mitigates the vulnerabilities.

NOTE: Eaton continues to publish unusable security advisories.

Drager Advisory


Drager published an advisory describing the Microsoft Windows® DejaBlue vulnerabilities in Drager products.

Saturday, June 15, 2019

Public ICS Disclosure – Week of 06-08-19


This week we have two new vendor notifications from Schneider and 18 researcher reports from Talos of vulnerabilities in products from Schneider. We also have four updated notifications from Schneider (2) and Siemens (2). Additionally, we have two vendor updates for advisories about the Microsoft® RDP vulnerability from Philips and Drager.

Schneider Advisories


1. Schneider published an advisory for a credential exposure vulnerability in the Schneider PowerSCADA Expert product (NOTE: According to Schneider this also affects the AVEVA CitecSCADA, but no AVEVA advisory has yet been published). This vulnerability is apparently self-reported. Schneider has a new version that mitigates the vulnerability.

2. Schneider published an advisory for three vulnerabilities in the Schneider ProClima product. The vulnerabilities were reported by Kushal Arvind Shah (Fortinet), Telus, and Haojun Hou and
Yongjun Liu (NSFOCUS). Schneider has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

Code injection - CVE-2019-6823;
Buffer errors - CVE-2019-6824; and
Uncontrolled search path element - CVE-2019-6825

Talos Reports on Schneider Vulnerabilities


Talos has provided reports with exploits on 18 vulnerabilities in two products from Schneider; Modicon 580 UMAS and UnityPro PLC. These are coordinated disclosures, but Schneider has not yet published advisories for these vulnerabilities. Because of the volume I am not going to attempt to go into details.

Modicon 580 UMAS

Information disclosure - CVE-2018-7845;
Denial of service - CVE-2018-7854;
Denial of service - CVE-2018-7853;
Denial of service - CVE-2018-7849;
Improper authentication - CVE-2018-7842;
Unauthenticated file write - CVE-2018-7847;
Denial of service - CVE-2018-7855;
Denial of service - CVE-2019-6807;
Denial of service - CVE-2018-7856;
Information disclosure - CVE-2018-7844;
Information disclosure - CVE-2019-6806;
Information disclosure - CVE-2018-7848;
Denial of service - CVE-2018-7852;
Denial of service - CVE-2018-7846;
Denial of service - CVE-2018-7857; and
Denial of service - CVE-2018-7843

UnityPro

Remote code execution - CVE-2019-6808;
Untrusted inputs - CVE-2018-7850;

NOTE: There are still 10 reports pending on Schneider vulnerabilities on the Talos Zeroday Reports web page. Someone has been spending a great deal of time testing Schneider equipment.

Schneider Updates


1. Schneider updated an advisory for the Schneider Embedded Web Servers for Modicon V2 (Note: this has not been reported by NCCIC-ICS). The new information is the addition of researcher acknowledgements.

2. Schneider updated an advisory for the Schneider – U.motion Builder software (Note: this has not been reported by NCCIC-ICS). Schneider is reporting that this vulnerability has been exploited by Mirai malware. Schneider is making an unusual recommendation: “It is imperative customers cease using U.motion Builder software and remove it from their systems immediately.”

Siemens Updates


1. Siemens updated an advisory for Foreshadow/L1 terminal fault vulnerabilities in Industrial Products (Note: this has not been reported by NCCIC-ICS). The new information is added mitigation measures for:

SIMATIC S7-1500 Software Controller;
SIMATIC ET 200 SP Open Controller; and
SIMATIC ET 200 SP Open Controller (F)

2. Siemens updated an advisory for Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU. The update adds information for new firmware V2.6.1

RDP Vulnerability


Two vendor advisories were updated this week:

Philips; and
Drager

 
/* Use this with templates/template-twocol.html */