Showing posts with label Nadia Heninger. Show all posts
Showing posts with label Nadia Heninger. Show all posts

Wednesday, December 21, 2016

Siemens Desigo PX Web modules

Yesterday the DHS ICS-CERT published a control system security advisory for an insufficient entropy vulnerability in the Siemens Desigo PX Web modules. The vulnerability was reported by Marcella Hastings, Joshua Fried, and Nadia Heninger from the University of Pennsylvania. Siemens has produced a firmware update to mitigate the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that while the vulnerability is remotely exploitable, that an exploit would be difficult to craft. A successful exploit could allow an attacker to recover private keys used for HTTPS in the integrated web server.

Siemens reported this vulnerability in a tweet last Friday. The Siemens security advisory notes that the Desigo PX Web modules are used in building automation systems


NOTE: Over the last year there has been an increasing number of exploit reports from university programs. It would seem that there is an increase in the number of academic programs looking at control system security issues. This is certainly a plus for the community; both in the terms of vulnerability reports, but also in the number of people explicitly being trained in control system security issues.

Monday, August 5, 2013

ICS-CERT Publishes Moxa Cellular Vulnerability

This afternoon the DHS ICS-CERT published an advisory for an insufficient entropy vulnerability in Moxa’s OnCell Gateways, cellular IP gateways. The vulnerability was reported by  Nadia Heninger (UCSD) and  Zakir Durumeric, Eric Wustrow, and J. Alex Halderman (UM) in a coordinated disclosure.

ICS-CERT reports that a highly skilled attacker could remotely exploit this vulnerability to gain unauthorized access to the system. Moxa has produced a firmware upgrade that mitigates the vulnerability, though there is no indication in the Advisory that anyone outside of Moxa has verified the efficacy of the upgrade. Actually Moxa released the upgrade in early April, 2013 and has been notifying their customers of the situation.


ICS-CERT provides their standard tactics for protecting control systems (avoiding internet exposure, locate devices behind firewalls, use VPNs for remote access etc). What is missing is any mention of dealing with cellular access, particularly important when the vulnerable system is used for connecting devices to a cellular network.
 
/* Use this with templates/template-twocol.html */