Showing posts with label NUOO. Show all posts
Showing posts with label NUOO. Show all posts

Saturday, February 23, 2019

Public ICS Disclosures – Week of 02-16-19


This week we have one vendor disclosure for products from CODESYS and two exploits for previously disclosed vulnerabilities for products from NUOO.

CODESYS Advisory


CODESYS has published an advisory that describes a directory traversal vulnerability in their runtime system. This vulnerability was reported by Ivan Cheyrezy of Schneider Electric. 3S has released a new version that mitigates the vulnerability. There is no indication that Cheyrezy has been provided an opportunity to verify the efficacy of the fix.

NOTE: Somehow, I suspect that Schneider identified this vulnerability in one of their products and traced it back to CODESYS code in that product. We may be seeing a Schneider advisory for this vulnerability in the near future.

NUOO Exploits


Pedro Ribeiro published two Metasploit modules for two vulnerabilities (here and here) that he had previously disclosed through NCCIC-ICS for vulnerabilities in the NUOO Central Management Software platform.

The two vulnerabilities for which the Metasploit modules were published are:

• Unrestricted upload of file of dangerous type; and
SQL injection


Saturday, January 26, 2019

Public ICS Disclosures – Week of 01-19-19


This week we have vendor notifications from Bosch, AVEVA, Drager, Yokogawa and BD. We also have an exploit of a previously disclosed set of vulnerabilities for products from NUUO.

Bosch Advisory


Bosch has published an advisory for two vulnerabilities in their DIVAR 400 & 600 digital recorders. The vulnerabilities were reported by Maxim Rupp. Bosch has provided generic workarounds to mitigate the vulnerability. There is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper access control; and
Unprotected credentials

AVEVA Advisory


AVEVA has published an advisory for three vulnerabilities in their Wonderware System Platform. The vulnerabilities were reported by Vladimir Dashchennko from Kaspersky Lab. AVEVA has a new update that mitigates the vulnerabilities. There is no indication that Daschennko has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Insufficiently protected credentials;
• Execution with unnecessary privilege; and
• Missing authorization

These vulnerabilities were coordinated through ‘ICS-CERT’ so I expect that we will see an advisory from NCCIC-ICS next week (though they may have a backlog to work through now that the Federal Funding Fiasco is at least temporarily over).

Drager Advisory


Drager published an advisory that is not technically for a control system vulnerability. They are advising customers of a number of reported fraudulent emails from apparent Drager email addresses that have been part of schemes to have companies make payments to non-Drager accounts.

Yokogawa Advisory


Yokogawa has published an advisory for an access control vulnerability in their License Manager Service. The vulnerability was reported by Kaspersky Lab. Yokogawa has patches that mitigate the vulnerability. There is no indication that Kaspersky Lab has been provided an opportunity to verify the efficacy of the fix.

BD Advisory


BD has published an advisory  (actually an update for an advisory that was issued last summer) for a Microsoft Windows vulnerability in the task scheduler that affects a number of BD products. BD will patch the software during the next patch cycle.

NUOO Exploit


Pedro Ribeiro published a set of exploits for the NUOO CMS software management platform. The vulnerabilities were reported by NCCIC-ICS in an advisory published on October 12th, 2018 and updated on November 20th, 2018. Ribeiro was the one who originally reported the NUOO vulnerabilities to NCCIC-ICS.

In addition to publishing four Metasploit modules as part of his exploit report, Ribeiro reports that one of the vulnerabilities reported through NCCIC-ICS (Use of hard-coded credentials - CVE-2018-17894) has not actually been fixed as was reported in the NCCIC-ICS advisory.

Reading the exploit report from Ribeiro provides an interesting look into the coordinated disclosure process where the vendor is less than cooperative. Pedro has all sorts of nice things to say about the folks he worked with at ‘ICS-CERT’ during the two-year process but suffice to say he is disappointed with NUOO.

Tuesday, November 20, 2018

Two Advisories and One Update Published – 11-20-18


Today the DHS NCCIC-ICS published two control system security advisories for products from Schneider Electric and Teledyne DALSA. They also published an update for a previously published advisory for products from NUOO.

Schneider Advisory


This advisory describes an insufficient verification of data authenticity vulnerability in the Schneider Modicon M221 PLC. The vulnerability was reported by Eran Goldstein of CRITIFENCE. Schneider has provided workarounds to mitigate the vulnerability. There is no indication that Goldstein has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a change of IPv4 configuration (IP address, mask, and gateway) when remotely connected to the device.

Teledyne Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Teledyne Sherlock machine vision software interface. The vulnerability was reported by Robert Hawes. Teledyne reports that newer versions mitigate the vulnerability. There is no indication that Hawes has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to crash the device being accessed; a buffer overflow condition may allow remote code execution.

NUOO Update


This update provides additional information on an advisory that was originally reported on October 11th, 2018. The update adds additional affected version information and three new vulnerabilities:

• Path traversal - CVE-2018-17934;
• Unrestricted upload of file of dangerous type - CVE-2018-17936; and
SQL injection - CVE-2018-18982

 
/* Use this with templates/template-twocol.html */