Showing posts with label Nordex. Show all posts
Showing posts with label Nordex. Show all posts

Wednesday, July 8, 2026

Looking Back – 11-2-13, Nordex Alert

Nearly every morning I start my computer time by looking at information from Google about what happened in my blog in the previous 24 hours. Google, and blogspot.com is a Google service, provides interesting pieces of analytical data about my blog readership. One item of particular interest is the top ten blog posts each day. As you would expect, most of those posts were from the last couple of days, but with 16 years of publishing this blog, every once-in-a-while, a blog post from ancient history rises into that list. 

Today a blog post from November 2nd, 2013, made the list. It described an ICS-CERT alert about a cross-site scripting vulnerability wind turbine generator SCADA/HMI produced by Nordex. CISA’s predecessor used to issue ‘Alerts’ for reports of exploitable vulnerabilities while they were trying to work with the vendor to mitigate the issue. Unfortunately, these ‘Alerts’ were not subsequently tied to the Advisory that reported that mitigation. For this Alert the Advisory can be found here; that Advisory is as interesting as the alert. 

The Alert blog post also includes an interesting comment from Jake Brodsky about Shodan and the SHINE Project. 

BTW: The Darius Freamon Blog is still active. 

Tuesday, October 13, 2015

ICS-CERT Publishes Nordex Advisory

Today the DHS ICS-CERT published an advisory for a cross-site scripting vulnerability in the Nordex NC2 Wind Farm Portal application. The vulnerability was reported by Karn Ganeshen. Nordex has produced an update to mitigate this vulnerability, but there is no indication that Ganeshen has been provided the opportunity to verify the efficacy of the fix.


ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to download a malicious script.

Thursday, October 30, 2014

ICS-CERT Releases 3 Lesser Communications Advisories

While everyone is still talking about Black Energy the DHS ICS-CERT released three advisories today concerning lesser vulnerabilities in three applications used in control systems communications. One was a follow up to an alert issued last Halloween, while the other two are newer vulnerabilities that were released earlier this month on the US-CERT secure portal.

Nordex Advisory

Last Halloween ICS-CERT published an alert about an uncoordinated disclosure (complete with exploit) of a cross-site scripting vulnerability in the Nordex Control 2 (NC2) application. Today ICS-CERT announced that Nordex has (I think) produced a patch to mitigate the vulnerability; needless to say no one has contacted the uncooperative researcher, Darius Freamon, to verify its efficacy.

ICS-CERT reports that a relatively low skilled attacker could use the publicly available exploit to remotely “execute arbitrary script code in the user’s browser”.

I said ‘I think’ parenthetically above because of the wording of the following sentence in today’s advisory:

“Nordex will release a patch for all affected NC2-SCADA versions until the end of 2014.”

I think that that means that the patch is available but Nordex will only be applying the patches through the end of the year. The Advisory notes that the patching of the wind turbine control system has to be done by Nordex. A year to wait for the vendor to fix a cross-site scripting error and then have to wait until they can get around to your site to apply the fix; I hope Nordex is including all of this in their sales material.

Meinberg Advisory

This advisory reports another cross-site scripting vulnerability, this time in Meinberg Radio Clocks GmbH & Co. KG LANTIME M400 web interface. This was originally reported by Aivar Liimets of Martem Telecontrol Systems in a coordinated disclosure. ICS-CERT reports that Meinberg has produced a firmware update that has been verified by Liimets. This advisory was originally released on the US-CERT secure portal on October 2nd.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to “cause the time server to provide misinformation to devices”.

Accuenergy Advisory

This advisory reports two authentication vulnerabilities in the AXN-NET Ethernet module from Accuenergy. The vulnerabilities were reported by Laisvis Lingvevicius in a coordinated disclosure. According to ICS-CERT Accuenergy has produced a firmware update that has been validated by Lingvevicius. This advisory was also released on the US-CERT secure portal on October 2nd.

The two vulnerabilities are:

• Authentication bypass vulnerability, CVE-2014-2373; and
• Password disclosure vulnerability, CVE-2014-2374

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to change network settings for the AXM-NET module web server as part of a denial of service attack.

Interestingly, the Accuenergy web site offers the following information about the firmware update:

“Redesign and improve encryption method on web-server, tested and verified by Department of Homeland Security, industrial control system cyber emergency response team [sic]”.

In light of discussions about what ICS-CERT really does (see most recently Dale Peterson’s blog post “What Does ICS-CERT Do?”) it is nice to see positive signs of actual involvement in the process of fixing vulnerabilities. Of course there are lots of businesses out there that are trying to make payroll by doing the same sort of thing.


Of course Accuenergy could just be blowing smoke to try to make their own efforts look good.

Saturday, November 2, 2013

ICS-CERT Publishes Nordex Alert

Earlier this week DHS ICS-CERT published a control system alert for the wind turbine generator SCADA/HMI produced by Nordex. The cross-site scripting vulnerability was publicly disclosed by Darius Freamon on his blog (The Darius Freamon Blog, he is more creative in his cyber-vulnerability research than in his blog naming).

ICS-CERT does identify Darius as the source of this vulnerability report but only provides a link to his disclosure through OSVDB not his blog. To be fair though, you have to be something of a control system geek to see the actual vulnerability from the Darius blog post whereas the OSVDB listing makes it much clearer:

“Nordex NC2 Wind Farm Portal contains a flaw that allows a reflected cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'userName' parameter upon submission to the /login script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.”

An interesting thing that neither ICS-CERT or OSVDB noted in their write-ups about this vulnerability is that it was discovered via SHODAN. It appears that Darius is a prolific user of SHODAN to search for vulnerabilities. Most commentators have focused on the use of this search engine for finding internet facing control systems, Darius has been using it to find system vulnerabilities, particularly default credentials.


Darius has been looking mostly at servers and communications devices, but I expect that we will be hearing more from him about control systems.
 
/* Use this with templates/template-twocol.html */