Showing posts with label Neil Smith. Show all posts
Showing posts with label Neil Smith. Show all posts

Thursday, May 26, 2016

ICS-CERT Publishes Three Advisories

This morning the DHS ICS-CERT published three control system security advisories for products from Black Box, Sixnet and Environmental Systems Corporation.

Black Box Advisory


This advisory describes a credential management vulnerability in the Black Box AlertWerks ServSensor devices. The vulnerability was reported by Lee Ryman. Black Box has produced a new firmware version to mitigate the vulnerability and Ryman has verified the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to gain access system passwords.

Sixnet Advisory


This advisory describes a hard-coded credential vulnerability in the Sixnet BT series routers. The vulnerability was reported by Neil Smith. Sixnet has produced a new firmware version and updates to mitigate the vulnerability. There is no indication that Smith has been provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could use publicly available exploits to remotely exploit the vulnerability to gain full access to the affected device.

The Sixnet web site does not yet (as of 22:00 EDT, 5-26-16) have the new version of the BT firmware listed.

Environmental Systems Corporation Advisory


This advisory describes twin vulnerabilities in the ESC 8832 Data Controller. The vulnerabilities were independently reported by Maxim Rupp and Balazs Makany. ESC reports that there is no code space for a firmware update so it has designed compensating controls to mitigate the vulnerabilities. There is no indication that either Rupp or Makany have been provided an opportunity to verify the efficacy of the fix.

The two vulnerabilities are:

• Authentication bypass - CVE-2016-4501; and
• Privilege management - CVE-2016-4502

ICS-CERT reports that a relatively unskilled attacker could use publicly available information to remotely exploit the vulnerability to perform administrative operations over the network without authentication.


ESC recommends replacing the device or blocking Port 80 with a firewall.

Thursday, January 28, 2016

ICS-CERT Publishes Advisory and ICSJWG Notice

This afternoon the DHS ICS-CERT published an advisory for Westermo switches. They also announced registration and request for papers for the Spring 2016 ISJWG meeting.

Westermo Advisory

This advisory describes a hard-coded certificate vulnerability in Westermo Ethernet switches. The vulnerability was reported by Neil Smith. ICS-CERT reports that Westermo has produced a firmware update that mitigates the vulnerability. Smith have verified the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability after conducting a successful man-in-the-middle attack to obtain authenticated access to the device.

Later in the advisory ICS-CERT reports that: “Westermo is working on an update to automate the changing of the key, which will be published on its web site as soon as it is ready.” The advisory then provides a work around for changing the hard-coded SSL certificate. There is nothing about this vulnerability on the public portion of the Westermo web site. The latest version of the WeOS on that website is 4.18.0 (released this month) which according to the advisory is an affected version. So, apparently the fix that Smith validated is the workaround.

ICSJWG Spring Meeting

I reported in an earlier blog post that the date for the Spring 2016 ICSJWG meeting had been set for May 3rd thru 5th. Today ICS-CERT announced that the registration for that meeting was now open. You can register on-line here and there is still no cost to attend the meeting. Registrations should be completed by April 28th, 2016.

ICS-CERT also published a call for abstracts for that meeting. They are looking for four types of presentations:

• Presentation;
• Panel;
• Demonstration;
• Lightning round

Thursday, November 5, 2015

ICS-CERT Updates VxWorks Advisory and Publishes New Advantech Advisory

Today the DHS ICS-CERT updated a control system advisory for Wind River VxWorks that was originally published in June. It also published a new advisory for Advantech’s EKI-122X series products.

Wind River Update

This update provides updated information on the systems affected by the vulnerability and the mitigation measures available for Wind River devices. There is no mention of any changes in mitigation measures for Schneider products and there are no new vendors added to the list using the vulnerable VxWorks embedded software.

Three versions of VxWorks Cert have been added to the list of affected products. The Schneider Electric Sage 2300 RTU and SAGE LANDAC2 Upgrade Kit have also been added. The Schneider advisory on this vulnerability is not currently available on-line.

Patches are now available for more of the affected products, but Wind River is recommending that owners upgrade to newer versions that are not affected by the vulnerability.

VxWorks Commentary

It seems a bit odd to me that ICS-CERT has not yet identified any other vendors that are using the vulnerable VxWorks firmware. I suppose that they may know of some, but are waiting for word that a patch is available.

It sure would be nice if there were some simple test that could be performed by an owner to see if their RTU’s were subject to the TCP predictability vulnerability. Of course, since a facility may have a large number of RTU’s, the test would have to be very quick for anyone to use it in practice.

BTW: I learned of this update via a twitfication from @ICSCERT.

Advantech Advisory

This advisory describes a hard-coded SSH key vulnerability in the Advantech EKI-122X series products. The vulnerability was first reported by Neil Smith. Advantech has produced a new firmware version that mitigates the vulnerability, but there is no indication that Smith has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability to intercept communications to and from the device.

Tuesday, June 9, 2015

ICS-CERT Publishes Two Advisories

Today the DHS ICS-CERT published two new control system advisories for systems from Sinapsi and N-Tron.

Sinapsi Advisory

This advisory describes a plain text password vulnerability in the Sinapsi eSolar Light application. The vulnerability was disclosed by Maxim Rupp. Sinapsi had produced a new version that mitigates the vulnerability but there is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker with local system access could exploit this vulnerability to gain system passwords.

ICS-CERT reports that the updated version is available by contacting Sinapsi on their web site. ICS-CERT does not provide a link to the web site.

Interestingly an earlier ICS-CERT alert for separate Sinapsi eSolar Light vulnerabilities indicates that this product had also been sold under the names Enerpoint eSolar Light, Schneider Electric Ezylog Photovoltaic Management Server, Gavazzi Eos-Box, and Astrid Green Power Guardian. I suspect that at least some versions of those products might be affected by this vulnerability as well.

N-Tron Advisory

This advisory describes a hard-coded encryption key vulnerability in the N-Tron 702-W Industrial Wireless Access Point device. The vulnerability was reported to ICS-CERT by Neil Smith of ZeroFox. ICS-CERT reports that:


“N-Tron has been notified of this reported vulnerability, and NCCIC/ICS‑CERT has not been able to successfully coordinate this issue with N-Tron or Red Lion because of the vendor’s unresponsiveness. ICS-CERT is unaware of any fix, patch, or update by N-Tron that mitigates this vulnerability. This advisory is being published to inform critical infrastructure asset owners of the risk of using this equipment and for them to increase compensating measures if possible.”

Tuesday, February 12, 2013

ICS-CERT Publishes Moxa Communications Advisory


Yesterday the DHS ICS-CERT published an advisory for the Moxa EDR-G903 Series Routers. The advisory identifies two communications vulnerabilities identified by Neil Smith in a coordinated disclosure. The vulnerabilities are a hardcoded user account and an insufficient entropy vulnerability.

The Advisory

According to ICS-CERT the first vulnerability is a minimal issue because the access provided is limited and does not allow changing of settings or traversing the network. The second is more of a problem because it could allow a relatively skilled attacker to gain remote access to the system and compromise data integrity and system availability.

Moxa has provided an update notice on their web site and an updated version that was tested by Smith, who verified that it corrected the vulnerabilities. Not noted in the ICS-CERT advisory: Moxa also included in this update support for using special characters in the login password, this could increase system security if properly utilized.

Other Moxa Vulnerabilities

A Tweet® by Patrick C Miller yesterday pointed me at an article about hard-coded credentials on control system applications. That post is by NJ Ouchn. Moxa had four separate listings in the article:

• Series Railway Remote I/O (ioLogik E12xx and E15xx) – two default passwords
• Cellular Micro RTU Controller (ioLogik W53xx) – two default passwords
• IA240/241 Embedded Computer – four default passwords
• ioPac 8020-C – four (I think, it’s not real clear in the article) default passwords

Since the article was published on Sunday, I would like to think that ICS-CERT will have an alert out for these vulnerabilities today or tomorrow. It is possible, of course, that these have already been addressed by ICS-CERT, but they don’t have a searchable database to check.

BTW: The article also lists hard-coded credential issues in Siemens, and westermo products.
 
/* Use this with templates/template-twocol.html */