Showing posts with label Nelson Berg. Show all posts
Showing posts with label Nelson Berg. Show all posts

Wednesday, December 19, 2018

7 Advisories and One Update Published - 12-18-18


Yesterday the DHS NCCIC-ICS published seven control system security advisories for products from ABB (3), Advantech, 3S and Siemens. They also published an update of a previously issued advisory for products from Schneider.

M2M Ethernet Advisory


This advisory describes an improper authentication vulnerability in the ABB M2M ETHERNET, network analyzer. It was reported by Maxim Rupp. ABB has provided generic workarounds for this vulnerability. There is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker on an adjacent network could exploit the vulnerability to upload a malicious language file.

NOTE: I briefly discussed the ABB advisory for this vulnerability in early November.


CMS-770 Advisory


This advisory describes an improper authentication vulnerability in the ABB CMS-770. This vulnerability was reported by Maxim Rupp. ABB has provided generic workarounds to mitigate the vulnerability. There is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS has reported that a relatively low-skilled attacker on an adjacent network could exploit the vulnerability to read sensitive configuration files that may lead to code execution on the device.

NOTE: I briefly discussed the ABB advisory for this vulnerability in early November.

Siemens Advisory


This advisory describes a missing authentication for critical function vulnerability in the Siemens TIM 1531 IRC. Siemens is self-reporting this vulnerability. Siemens has a firmware update to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to perform arbitrary administrative operations.

NOTE: I briefly discussed the Siemens advisory and first update for this vulnerability last Saturday. The first update noted that the originally provided firmware update had been withdrawn and left just a workaround available to mitigate the vulnerability. This NCCIC-ICS advisory is based upon the second Siemens update of their advisory.

CODESYS V3 Advisory 1


This advisory describes two vulnerabilities in the S3 CODESYS V3 products. The vulnerabilities were reported by Alexander Nochvay from Kaspersky Lab. S3 has a new version that mitigates the vulnerabilities. There is no indication that Nochvay has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Use of insufficiently random values - CVE-2018-20025; and
• Improper restrictions of communication channel to intended endpoint - CVE-2018-20026

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to  allow a remote attacker to disguise the source of malicious communication packets and also exploit a random values weakness affecting confidentiality and integrity of data stored on the device.

NOTE: There are two S3 advisories that support this NCCIC-ICS advisory (here and here).

CODESYS V3 Advisory 2


This advisory describes an improper access control vulnerability in the S3 CODESYS Control V3 products. The vulnerability was reported by Yury Serdyuk of Kaspersky Lab. S3 has a new version and recommends activating the CODESYS Control online user management and encryption of the online communication. There is no indication that Serdyuk has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow unauthorized access and exfiltration of sensitive data including user credentials.

NOTE: S3 published five other advisories last week when they published the three supporting these two NCCIC-ICS advisories. Interestingly, none of the others have CVE numbers. More on these on Saturday.

Advantech Advisory


This advisory describes an improper input validation vulnerability in the AdvantechWebAccess/SCADA product. The vulnerability was reported by Jacob Baines of Tenable Network Security. Advantech has a new version that mitigates the vulnerability. There is no indication that Baines has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to cause the overflow of a buffer on the stack.

Gate E-2 Advisory


This advisory describes two vulnerabilities in the ABB GATE-E2 Pluto ethernet gateway. The vulnerabilities were reported by Nelson Berg of Applied Risk. ABB is only providing generic workarounds as this product is no longer supported. There is no indication that Berg has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Missing authentication of a critical function - CVE-2018-18995; and
• Cross-site scripting - CVE-2018-18997

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow unrestricted access to the administrative telnet/web interface of the device, enabling attackers to compromise the availability of the device, read or modify registers and settings, or change the device configuration.

NOTE: I briefly discussed the two ABB advisories supporting this NCCIC-ICS advisory last Saturday.

Schneider Update


This update provides additional information on an advisory that was originally published on April 17th, 2018, and updated on May 3rd, 2018. The new information included in the update includes:

• Links to a rewritten Schneider advisory;
• Announcement of a new version that further mitigates the HatMan vulnerabilities;
• The announcement that as of February 19th, 2019, “Schneider Electric will require customers to have a support contract in place to engage with the HatMan malware detection service.”

Saturday, December 15, 2018

Public ICS Disclosures – Week of 12-08-18


This week we have five vendor notifications for products from ABB (2), OSIsoft, Eaton and Siemens and seven vendor updates of previously issued notifications from Siemens. It has been a busy week.

ABB Advisories


ABB published two advisories (here and here) for their Pluto E2-Gate, ethernet gateway. The two vulnerabilities were reported by Nelson Berg (Applied Risk). ABB has provided generic workarounds for these vulnerabilities. There is no indication that Berg has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• No access control - CVE-2018-18995; and
• Cross-site scripting - CVE-2018-18997

OSIsoft Advisory


OSIsoft published an advisory for a cross-site scripting vulnerability in their PI Vision 2017. This vulnerability was self-reported. OSIsoft has a new version that mitigates the vulnerability.

Eaton Advisory


Eaton published an advisory for undisclosed vulnerabilities in their XP 503 Panel PC. These vulnerabilities are related to the use of Windows Embedded Standard 7 as the operating system. Eaton provides generic workarounds to mitigate the vulnerabilities.

Siemens Advisory


Siemens published an advisory for a missing authentication vulnerability in their TIM 1531 IRC Modules. This vulnerability is self-reported. Siemens provides specific workarounds to mitigate the vulnerability.

Siemens Updates


As part of the swath of 14 advisories and updates issued by Siemens this week there were three updates that were not covered by NCCIC-ICS updates. These were for vulnerabilities addressed in ICS-CERT generic alerts; NCCIC-ICS does not update these alerts for new information from the existing vendor list on the alert, the links on those alerts already take interested parties to this latest information.

• SSA-254686, v 1.2 - Foreshadow / L1 Terminal Fault Vulnerabilities in Industrial Products - Added solution for SIMATIC IPC627D, SIMATIC IPC677D, SIMATIC IPC827D;
• SSB-439005, v 1.1 - Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP - Added CVE-13053 and CVE-2018-19591;
• SSA-268644, v 1.3 - Spectre-NG (Variants 3a and 4) Vulnerabilities in Industrial Products - Added solution for SIMATIC IPC547G, SIMATIC IPC627D, SIMATIC IPC677D, SIMATIC IPC827D, SINUMERIK PCU 50.5;

There were three additional updates that I suspect that NCCIC-ICS could still pick-up in the coming week, or maybe not since the latest version of  each of these advisories essentially negated the correction made in the previous version.

• SSA-181018, v 1.1 and v 1.2 – NCCIC-ICS originally published their advisory for this vulnerability on June 14th, 2018 – v 1.1: Added solution for RUGGEDCOM WiMAX; v 1.2: Update for RUGGEDCOM WiMAX not available, see mitigations; and
• SSA-293562, v 2.5 – NCCIC-ICS published their last update on these vulnerabilities (ICSA-17-129-02) on December 11th, 2018 - Corrected download links, update for CP 1243-1 not available, see mitigations; and

Commentary


It is disconcerting to see that only one of the five original vendor notifications listed here this week (OISsoft) contains an actual mitigation for the reported vulnerabilities and only one of the workarounds (Siemens) provided for the other four provides specific actionable information (the port to be blocked). And the ‘advisory’ from Eaton is so generic and lacking in any specific information that it might not as well have been published. And then Siemens was forced to withdraw (without explanation) previously published mitigation measures for three of their advisories/updates. It was a sad week for public ICS disclosures.

Wednesday, November 14, 2018

8 Advisories and 5 Updates (all Siemens) Published


Yesterday the DHS NCCIC-ICS published eight control system security advisories and updated five previously published advisories; all for products from Siemens.

SIMATIC Panels Advisory


This advisory describes two vulnerabilities in the Siemens SIMATIC HMI and WinCC. The vulnerabilities were reported by Hosni Tounsi from Carthage Red Team. Siemens has newer versions that mitigate the vulnerability. There is no indication that Tounsi has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Path traversal - CVE-2018-13812; and
• Open redirect - CVE-2018-13813

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow download of arbitrary files from the device, or allow URL redirections to untrusted websites.

SIMATIC IT Advisory


This advisory describes an improper authentication vulnerability in the Siemens SIMATIC IT Production Suite. The vulnerability is self-reported. Siemens has updated to mitigate the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow an attacker to compromise confidentiality, integrity and availability of the system.

SIMATIC Step 7 Advisory


This advisory describes an unprotected storage of credential in the Siemens SIMATIC STEP 7 (TIA Portal). This vulnerability is self-reported. Siemens has updates available that mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to reconstruct passwords.

SIMATIC S7 Advisory


This advisory describes a resource exhaustion vulnerability in the Siemens SIMATIC S7. The vulnerability was reported by Younes Dragoni of Nozomi Networks. Siemens has a new version for the S7-1500 that mitigates the vulnerability. There is no indication that Dragoni was provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial-of-service condition that could result in a loss of availability of the affected device.

SCALANCE S Advisory


This advisory describes a cross-site scripting vulnerability in the Siemens SCALANCE S firewalls. The vulnerability was reported by Nelson Berg of Applied Risk. Siemens has a new version that mitigates the vulnerability. There is no indication that Berg has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker using social engineering could remotely exploit this vulnerability to allow arbitrary script injection (XSS).

SIMATIC WinCC Advisory


This advisory describes a code injection vulnerability in the Siemens SIMATIC Panels and SIMATIC WinCC (TIA Portal). The vulnerability is self-reported. Siemens has updates available for all but one of the affected devices.

NCCIC reports that a relatively low-skilled attacker with network access could exploit the vulnerability to perform a HTTP header injection attack.

S7-400 Advisory


This advisory describes two improper input validation vulnerabilities in the Siemens S7-400 CPUs. The vulnerability was reported by CNCERT/CC. Siemens has provided specific workarounds to mitigate the vulnerabilities.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to crash the device being accessed which may require a manual reboot or firmware re-image to bring the system back to normal operation.

IEC 61850 Advisory


This advisory describes an improper access control vulnerability in the Siemens IEC 61850 system configurator, DIGSI 5, DIGSI 4, SICAM PAS/PQS, SICAM PQ Analyzer, and SICAM SCC. The vulnerability is self-reported. Siemens has updates to mitigate the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to exfiltrate limited data from the system or execute code with operating system user permissions.

Industrial Products Update


This update provides additional information on an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th, November 28th, February 27th, 2018, May 3rd, 2018 May 15th, 2018, September 11th, 2018 and most recently on October 9th, 2018. The update provides new affected version and mitigation information for:

• SINAMICS S120;
• PN/PN Coupler;
• SIMATIC ET200 SP;
• SIMATIC S7-400 V; and
• SIMOCODE pro V PROFINET

SCALANCE Update


This update provides additional information on an advisory that was originally published on November 14th, 2017 and updated on December 5th, 2017, December 19th, 2017, January 25th, 2018 and again on April 24th, 2018. The update changed the update information for SCALANCE W-700 (IEEE 802.11n).

PROFINET Update


This update provides additional information on an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th,  November 28th, 2017, January 18th, 2018, January 25th, 2018, January 27th, 2018, March 6th, 2018 and most recently on May 3rd, 2018. The update provides new affected version and mitigation information for:

• SINAMICS S120;
• SIMATIC ET 200SP (except IM155-6 PN ST); and
• SIMATIC Panels

OpenSSL Update


This update provides additional information on an advisory that was originally published on August 14th, 2018 and updated on September 11th, 2018 and again on October 9th, 2018. The update provides new affected version and mitigation information for:

• SIMATIC HMI WinCC Flexible; and
• SIMATIC IPC DiagMonitor

SIMATIC S7 Update


This update provides additional information on an advisory that was originally published on March 29th, 2018 and updated on April 24th, 2018, and again on June 12th, 2018. The update provides new affected version and migitagion information for:

• SIMATIC BATCH V8.2;
• OpenPCS 7 V8.2; and
• SIMATIC Route Control V8.2

NOTE: I will address the other four updates that Siemens published on Saturday.

 
/* Use this with templates/template-twocol.html */