Showing posts with label NUMBER:JACK. Show all posts
Showing posts with label NUMBER:JACK. Show all posts

Tuesday, March 9, 2021

10 Advisories Published – 3-9-21

Today the CISA NCCIC-ICS published ten control system security advisories for products from Siemens.

SCALANCE Advisory #1

This advisory describes an out-of-bounds read vulnerability in Siemens SCALANCE and SIMATIC products. This is a third-party (curl) vulnerability in libcurl. The vulnerability is self-reported. Siemens has a new version for one of the affected products that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to cause a denial-of-service condition on the affected devices.

NOTE 1: There are reported exploits (here and here) for the underlying vulnerability.

NOTE 2: NCCIC-ICS does not provide a link to the Siemens advisory. The Siemens link in the advisory is to an update of an earlier advisory about the same vulnerability in another product line.

Solid Edge Advisory

This advisory describes four vulnerabilities in the Siemens Solid Edge portfolio of software tools. The vulnerabilities were reported by Francis Provencher and rgod via the Zero Day Initiative. Siemens has updates that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Out-of-bounds write (2) - CVE-2020-28385 and CVE-2021-27380,

• Improper restriction of XML external entity reference - CVE-2020-28387, and

• Out-of-bounds read - CVE-2021-27381

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to lead to a denial-of-service condition, and could lead to arbitrary code execution or data extraction on the target host system.

PLUSCONTROL Advisory

This advisory describes a predictable exact value from previous values vulnerability in the Siemens PLUSCONTROL product. The vulnerability is self-reported. Siemens has provided generic mitigations for this vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to affect integrity of TCP connections.

NOTE: This vulnerability was reported in the NCCIC-ICS TCP/IP Stacks Advisory for the NUMBER:JACK vulnerabilities and the Siemens advisory should probably have been reported in an update to ICSA-21-042-01.

TCP Stack Advisory

This advisory describes two vulnerabilities in the Siemens SIMATIC MV400 family. The vulnerability is self-reported. Siemens has a new version that mitigates the vulnerabilities.

The two reported vulnerabilities are:

• Improper validation of specified index, position, or offset in input - CVE-2020-25241, and

• Use of insufficiently random values - CVE-2020-27632

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial-of-service condition or affect the integrity of TCP connections.

NOTE: The second vulnerability was reported in the NUMBER:JACK paper (and the NCCIC-ICS advisory in the Note above) in the NDKTCPIP TCP/IP stack. This means that it is likely that the first vulnerability listed above would also affect other products using the same versions of that stack.

SENTRON Advisory

This advisory describes two vulnerabilities in the Siemens SENTRON products. These are third-party (Amnesia:33) vulnerabilities that have previously been reported by NCCIC-ICS. Siemens has upgrades that mitigate the vulnerabilities in some of the affected products.

The two reported vulnerabilities are:

• Out-of-bounds read - CVE-2020-13987, and

• Out-of-bounds write - CVE-2020-17437

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to cause a denial-of-service condition.

NOTE: NCCIC-ICS probably should have added a link to the Siemens advisory to ICSA-20-343-01, their AMNESIA:33 advisory.

LOGO! Advisory

This advisory describes an improper handling of exceptional conditions vulnerability in the Siemens LOGO! 8 programmable logic controller. The vulnerability was reported by Max Bäumler. Siemens has provided generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to cause a denial-of-service condition if a user is tricked into loading a malicious project file.

SINEMA Advisory

This advisory describes an incorrect authorization vulnerability in the Siemens SINEMA Remote Connect Server. The vulnerability is self-reported. Siemens has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow authenticated unprivileged user accounts to access unauthorized functionality.

SCALANCE Advisory #2

This advisory describes a stack-based buffer overflow in the Siemens SCALANCE and RUGGEDCOM Devices. The vulnerability is self-reported. Siemens has updates available to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to cause a reboot. Under specific circumstances, an attacker could also achieve remote code execution of the affected devices.

SCALANCE Advisory #3

This advisory describes an improper restriction of excessive authentication attempts vulnerability in the Siemens SCALANCE and RUGGEDCOM Devices. The vulnerability is self-reported. Siemens has an update available for one of the affected products.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to cause a denial-of-service under certain conditions.

SIMATIC Advisory

This advisory describes three vulnerabilities to the Siemens SIMATIC S7-PLCSIM. This vulnerability is self-reported. Siemens has provided generic workarounds to mitigate the vulenrabilities.

The three reported vulnerabilities are:

• Infinite loop - CVE-2021-25673,

• Null pointer dereference - CVE-2021-25674, and

• Divide by zero - CVE-2021-25675

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker with local access to craft special project files that may lead to denial-of-service attacks.

Other Siemens Advisories

Siemens published two additional advisories today that have not yet been addressed by NCCIC-ICS. If they are not covered this week, I will discuss them this weekend.

Thursday, February 11, 2021

2 Advisories and 1 Update Published – 2-11-21

Today CISA’s NCCIC-ICS published two control system security advisories for products from Rockwell and multiple embedded TCP/IP stacks.

Rockwell Advisory

This advisory describes an uncontrolled search path element vulnerability in the Rockwell DriveTools SP and Drives AOP. The vulnerability was reported by Claroty and Cognite, Rockwell has an update that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker with local access could exploit the vulnerability resulting in privilege escalation and complete control of the system.

TCP/IP Stacks Advisory

This advisory describes nine separate use of insufficiently random values vulnerabilities in multiple open-source and proprietary TCP/IP stacks. The vulnerabilities (nicknamed NUMBER:JACK) were reported by Daniel dos Santos, Stanislav Dashevskyi, Jos Wetzels, and Amine Amri of Forescout Research Labs. Some the affected vendors have new versions that mitigate the vulnerability in their TCP/IP stack.

The nine reported CVE’s (each generally associated with a separate TCP/IP stack vendor) are:

• CVE-2020-27213 - Nut/Net 5.1 - Patch in progress

• CVE-2020-27630 - uC/TCP-IP 3.6.0 - Patched in the latest version of Micrium OS (successor project),

• CVE-2020-27631 - CycloneTCP 1.9.6 - Patched in version 2.0.0,

• CVE-2020-27632 - NDKTCPIP 2.25 - Patched in version 7.02 of Processor SDK,

• CVE-2020-27633 - FNET 4.6.3 - Documentation updated to warn users and recommend implementing their own PRNG [pseudorandom number generator],

• CVE-2020-27634 - uIP 1.0 Contiki-OS 3.0 Contiki-NG 4.5 - No response from maintainers,

• CVE-2020-27635 - PicoTCP 1.7.0 PicoTCP-NG - Version 2.1 removes the default (vulnerable) implementation and recommends users implement their own PRNG,

• CVE-2020-27636 - MPLAB Net 3.6.- Patched in version 3.6.4.

• CVE-2020-28388 Nucleus NET 4.3 -Patched in Nucleus NET 5.2 and Nucleus ReadyStart v2012.12.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to hijack or spoof TCP connections, cause denial-of-service conditions, inject malicious data, or bypass authentication.

NOTE: The “NUMBER:JACK” report explains that “Forescout Research Labs has released an open source script that uses active fingerprinting to detect which stack a target device is running.” {pg 6}.

Commentary: Oh this is going to be a fun one. I foresee lots of equipment vendor advisories in the works as everyone scrambles to try to fix this mess. BTW, the Report notes that an attack on this type of vulnerability in the old IT world was known as a Mitnick Attack.

CodeMeter Update

This update provides new information on an advisory that was originally published on September 8th, 2020 and most recently updated on December 3rd, 2020. The new information includes adding links to the vendor alert from Drager.

 
/* Use this with templates/template-twocol.html */