Showing posts with label OSIsoft. Show all posts
Showing posts with label OSIsoft. Show all posts

Tuesday, November 9, 2021

Review - 7 Advisories and 1 Update Published – 11-9-21

Today, CISA’s NCCIC-ICS published six control system security advisories for products from OSIsoft (2), mySCADA, Siemens, and Schneider (2). They also published one update for an advisory for products from Advantech and one medical device security advisory for products from Philips.

Siemens published 12 other advisories and 10 updates today. I expect that some of those may be addressed by NCCIC-ICS on Thursday. I will address any remaining advisories and updates this weekend.

Schneider published five other advisories and three updates today. It is unlikely that any will be addressed by NCCIC-ICS on Thursday. I will address any remaining advisories and updates this weekend.

OSIsoft Advisory #1 - This advisory describes a cross-site scripting vulnerability in the OSIsoft PI Web API.

OSIsoft Advisory #2 - This advisory describes two vulnerabilities in the OSIsoft PI Vision data management platform.

mySCADA Advisory - This advisory describes a relative path traversal vulnerability in the mySCADA myDESIGNER.

Siemens Advisory - This advisory describes 13 vulnerabilities in the Siemens Nucleus RTOS TCP/IP Stack.

Schneider Advisory #1 - This advisory describes three vulnerabilities in the Schneider GUIcon software.

Schneider Advisory #2 - This advisory describes six vulnerabilities in the Schneider Network Management Cards (NMC) and NMC Embedded Devices.

Philips Advisory - This advisory describes three vulnerabilities in the Philips MRI 1.5T and 3T.

Advantech Update - This update provides additional information for an advisory that was originally published on June 22nd, 2021.

For more details on the advisories, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-and-1-update-published - subscription required.

Tuesday, November 10, 2020

5 Advisories and 2 Updates Published – 11-20-20

Today the CISA NCCIC-ICS published five control system security advisories for products from Siemens (2), Schneider, and OSIsoft. They also published updates for two advisories for products from Siemens.

SCALANCE Advisory

This advisory describes an improper input validation vulnerability in the Siemens SCALANCE W 1750D. The vulnerability is self-reported. The Siemens advisory notes that this is a third-party (Aruba Instant) vulnerability that was originally reported by Aruba in 2016 as three separate CVE’s (CVE-2016-2031, CVE-2016-0801, and CVE-2016-0802); there are publicly available exploits for the first two CVE’s. Siemens reports that they consolidated the vulnerabilities to a single CVE. Siemens has a new firmware version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to achieve remote code execution.

NOTE: Looking at the Aruba advisory and associated exploit reports it looks to me like there is more at risk here.

SIMATIC Advisory

This advisory describes an uncontrolled resource consumption vulnerability in the Siemens SIMATIC S7-300 CPUs and SINUMERIK Controller. The vulnerability was reported by WangFangLi from Beijing Winicssec Technology. Siemens is providing generic workarounds while working on appropriate updates.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow an attacker to cause a denial-of-service condition.

Schneider Advisory

This advisory describes an improper check for unusual or exceptional conditions vulnerability in the Schneider PLC Simulator for EcoStruxure Control Expert. The vulnerability was reported by Parity Dynamics Research Team. The Schneider advisory describes three additional vulnerabilities and two addition reporting research teams. Schneider has a new version that mitigates all four vulnerabilities. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The four vulnerabilities reported by Schneider are:

• Classic buffer overflow - CVE-2020-7559,

• Improper check for unusual or exceptional conditions - CVE-2020-7538,

• Incorrect authorization - CVE-2020-28211, and

• Download of code without integrity check - CVE-2020-28213

NCCIC-ICS reports (for their single vulnerability) that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial-of-service condition, which could result in a failure of the EcoStruxture Control Expert Simulator.

PI Vision Advisory

This advisory describes two vulnerabilities in the OSIsoft PI Vision 2020. The vulnerabilities are self-reported. OSIsoft has a new version that mitigates the vulnerabilities.

The two reported vulnerabilities are:

• Cross-site scripting - CVE-2020-25163, and

• Incorrect authorization - CVE-2020-25167

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow a remote attacker with write access to the PI ProcessBook files to inject code that is imported into PI Vision, or disclose information to a user with insufficient privileges.

PI Interface Advisory

This advisory describes a numeric errors vulnerability in the OSIsoft PI Interface. The vulnerability is self-reported. OSIsoft has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker-controlled OPC XML-DA Server to respond with a crafted XML message and exploit the PI Interface for OPC XML-DA, resulting in code execution.

UMC Stack Update

This update provides additional information on an advisory that was originally published on July 14th, 2020 and most recently updated on September 8th, 2020. The new information includes providing updated affected version information and mitigation measures for SIMOCODE ES.

SIMATIC Update

This update provides additional information on an advisory that was originally published on September 8th, 2020 and most recently updated on October 13th, 2020. The new information includes a corrected CVSS Score for CVE-2020-15791.

Other Advisories and Updates

Siemens published two additional updates today. Schneider published six additional advisories and five updates today. I will cover these this weekend.

Saturday, October 24, 2020

Public ICS Disclosures – Week of 10-17-20

We have one new vendor disclosure this week for products from HMS. We also have three vendor updates for products from Rockwell and Schneider (2). We also have news of a possible cyberattack on Softing, a control system vendor.

HMS Advisory

HMS published an advisory discussing the BLURtooth vulnerability. HMS reports that none of their products are affected by this vulnerability.

NOTE: The BLURtooth vulnerability is a currently unpatched vulnerability in some implementations of the Bluetooth standard that allows attacker-in-the-middle exploits. I expect that we will be seeing more vendor communications about this vulnerability in the coming weeks, especially from medical device manufacturers where the use of Bluetooth is more common.

Rockwell Update

Rockwell published an update for their advisory on OSIsoft PI System vulnerabilities that was originally published on May 12th, 2020. The new information includes new version information for vulnerability mitigation.

Schneider Updates

Schneider published an update for their Ripple20  advisory. The new information includes:

• Adding remediation for “EGX150/Link150 Ethernet Gateway”, “Acti9 PowerTag Link / HD”, “Acti9 Smartlink SI D”, and “Acti9 Smartlink SI B”, and

• Adding PowerLogic EGX100 to affected products list.

Schneider published an update for their APC by Schneider Electric Network Management Cards advisory that was originally published on June 23rd, 2020 and most recently updated on September 1st, 2020. The new information includes updated overview section, available remediations and affected products tables (some affected products were moved from the above advisory to this one).

Vendor News

When I checked the Softing advisory web page today an interesting popup appeared. It said:

“IMPORTANT NOTE:

“Softing AG fell victim to targeted cyber attacks through no fault of its own. Unknown perpetrators have invaded the internal networks. In order to avoid possible damage to the IT infrastructure, we have severely restricted the external communication options.

“For urgent inquiries we are still available to our customers under the following contact details:

“Softing Industrial Automation: +49 15119489547”

A brief Google® search reveals no news items about this attack.

As always with an attack on a control system vendor we have to be concerned about the potential product security problems that could arise from the compromise of the system. Access to product source code could allow for easier vulnerability detection by the attacker or even possible modification of that source code to insert vulnerabilities. Access to vendor web site code could allow for the establishment of drive-by code. None of the above is a given, but it does provide an area for potential concern, particularly if the company is not completely forthcoming about the extent of the attack. Hopefully we are just be early in the news cycle on this attack and more information will become publicly available in the coming days.

Saturday, June 27, 2020

Public ICS Disclosures – Week of 06-20-20


This week we have six Ripple20 [Corrected link, 10-18-20, 0856 EDT] advisories from vendors, one of them an update. There were also four vendor updates from Schneider, Rockwell (2) and Yokogawa. There was a researcher report for products from OSIsoft. There were also four exploits published for products from ABUS, SICK, mySCADA and Inductive Automation.

Ripple20 Advisories and Updates


HMS published a Ripple20 advisory that identifies affected products and generic mitigations.

Eaton published a Ripple20 advisory that identifies affected products and generic mitigations.

Boston Scientific published a Ripple20 advisory that admits that some (unidentified) products have the vulnerabilities but “concluded there is no increased security risk for patients who have our implantable products because of the Treck vulnerabilities”.

Schneider published a Ripple20 advisory that identifies affected products and generic mitigations.

Schneider published a Ripple20 advisory specifically for their network management card products.

Schneider updated their Ripple20 advisory that was originally published on June 16th, 2020. Refers to the first new advisory described above.

Schneider Update


Schneider published an update of their legacy Triconex advisory that was originally published on April 14th, 2020. The new information includes adding CVE numbers and descriptions and updated affected version and mitigation data.

NOTE: The revised advisory includes an interesting discussion about why Schneider decided that this update was necessary.

Rockwell Updates


Rockwell published an update for their FactoryTalk Linx Path Traversal advisory that was originally published on June 18th, 2020. The new information includes a revised list of affected products.

Rockwell published an update for FactoryTalk Linx multiple vulnerability advisory that was originally published on June 11th, 2020. The new information includes a revised list of affected products.

NOTE: The updated information is the same in both updates. See my note on the path traversal advisory in last week’s blog post.

Yokogawa Update


Yokogawa published an update for their unquoted service path advisory that was originally published on September 27th, 2019and most recently updated November 1st, 2019. The new information includes adding three new products to the affected product list and providing mitigation links for those products.

OSIsoft Report


Otorio published a report on a cross-site scripting vulnerability in the OSIsoft PI Web API 2019. The vulnerability was disclosed by OSIsoft on June 11th, 2020. The report includes a poor-quality video demonstrating an exploit of the vulnerability.

ABUS Exploit


Matthias Deeg published an exploit for a missing encryption of sensitive data vulnerability in the ABUS Secvest Wireless Control Device (FUBE50001). This was reportedly coordinated with ABUS.

SICK Exploit


Aliasrobotics published an exploit for a default credentials vulnerability in the SICK safety PLC. There is no indication that this was reported to SICK, so this is probably a 0-day exploit.

mySCADA Exploit


Emre ÖVÜNÇ published an exploit for a hard-coded credentials vulnerability in the mySCADA myPro HMI. There is no indication that this was reported to mySCADA, so this is probably a 0-day exploit.

Inductive Automation Exploit


Pedro Ribeiro and Radek Domanski published a Metasploit module for a a Java deserialization vulnerability in the Inductive Automation Ignition SCADA product. The vulnerability was disclosed by the vendor on June 2nd, 2020 and the NCCIC-ICS advisory was subsequently updated on June 11th, 2020.

Thursday, June 11, 2020

3 Advisories Published – 6-11-20


Today the CISA NCCIC-ICS published two control system security advisories for products from Rockwell Automation and OSIsoft as well as a medical device security advisory for products from Philips.

Rockwell Advisory 


This advisory describes four vulnerabilities in the Rockwell FactoryTalk Linx Software. The vulnerabilities were reported by Sharon Brizinov and Amir Preminger, of Claroty. Rockwell has patches that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Improper input validation (2) - CVE-2020-11999 and CVE-2020-12001,
• Path traversal - CVE-2020-12003, and
• Unrestricted upload of file of dangerous type - CVE-2020-12005

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to cause a denial-of-service condition, obtain remote code execution, and read sensitive information.

OSIsoft Advisory


This advisory describes a cross-site scripting vulnerability in the OSIsoft PI Web API 2019. The vulnerability was reported by Dor Yardeni and Eliad Mualem at OTORIO. OSIsoft has a new service pack that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow a remote authenticated attacker with write access to a PI Server to trick a user into interacting with a PI Web API endpoint that executes arbitrary JavaScript in the user’s browser, resulting in view, modification, or deletion of data as allowed for by the victim’s user permissions.

Philips Advisory


This advisory describes an insertion of sensitive information into log file vulnerability in the Philips  IntelliBridge Enterprise (IBE). Indiana University Health reported the vulnerability. Philips plans a new release to mitigate the vulnerability in 4th Qtr 2020; meanwhile they provide generic mitigation measures to address the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerability to allow an attacker to access credentials to the hospital’s clinical information systems (EMR).

Tuesday, June 9, 2020

6 Advisories and 4 Updates Published


Today the CISA NCCIC-ICS published six control system security advisories for products from Siemens (4), Mitsubishi Electric and Advantech. They also updated four advisories for products from Philips, Siemens (2) and OSIsoft.

SINUMERIK Advisory


This advisory describes 22 vulnerabilities in the Siemens SINUMERIK products. The vulnerabilities are self-reported. Siemens has updates that mitigate the vulnerabilities.

The 22 reported vulnerabilities are:

• Buffer underflow - CVE-2018-15361,
• Heap-based buffer overflow (5) - CVE-2019-8258, CVE-2019-8262, CVE-2019-8271, CVE-2019-8273, and CVE-2019-8274,
• Improper initialization - CVE-2019-8259,
• Out-of-bounds read (3) - CVE-2019-8260, CVE-2019-8267, and CVE-2019-8270,
• Stack-based buffer overflow (3) - CVE-2019-8263, CVE-2019-8269, and CVE-2019-8276,
• Access of memory location after ends of buffer (4) - CVE-2019-8264, CVE-2019-8265, CVE-2019-8266, and CVE-2019-8280,
• Off-by-one error (2) - CVE-2019-8268, and CVE-2019-8272,
• Improper null determination - CVE-2019-8275,
• Improper initialization - CVE-2019-8277,

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow remote code execution, information disclosure, and denial-of-service attacks under certain conditions.

Note: according to the Siemens advisory these are third-party vulnerabilities (in this case, UltraVNC, a remote access system) – that were reported by Kaspersky. A number of other VNC systems were included in that report.

SIMATIC Advisory #1


This advisory describes two vulnerabilities in the Siemens SIMATIC and SINAMICS products. The vulnerabilities were reported by Nadav Erez of Claroty. Siemens has new versions that mitigate the vulnerabilities. There is no indication that Erez has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Uncontrolled search path - CVE-2020-7585, and
• Heap-based buffer overflow - CVE-2020-7586

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to affect the availability of the devices under certain conditions.

NOTE: According to the Siemens advisory the vulnerabilities were reported by Uri Katz of Claroty.

SIMATIC Advisory #2


This advisory describes an unquoted search path or element vulnerability in the Siemens SIMATIC, SINAMICS, SINEC, SINEMA and SINUMERIK products. This vulnerability was reported by Ander Martinez of Titanium Industrial Security via INCIBE. Siemens has some updates that mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with authorized local access could exploit the vulnerability to execute custom code with SYSTEM level privileges.

LOGO! Advisory


This advisory describes a missing authentication for critical function vulnerability in the Siemens LOGO! Product. The vulnerability was reported by Alexander Perez-Palma of Cisco Talos and Emanuel Almeida of Cisco Systems. Siemens has provided generic mitigation measures for this vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to read and modify device configurations and obtain project files from affected devices.

NOTE: The Siemens advisory says that an attacker would have to have access to port 135/tcp to exploit this vulnerability.

Mitsubishi Advisory


This advisory describes a resource exhaustion vulnerability in the Mitsubishi MELSEC iQ-R series modules. The vulnerability was reported by Yossi Reuven of SCADAfence. Mitsubishi has provided generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause the Ethernet port to enter a denial-of-service condition.

Advantech Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Advantech WebAccess Node. The vulnerability was reported by Z0mb1E via the Zero Day Initiative. Advantech has a patch that mitigates the vulnerability. There is no indication that Z0mb1E has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to crash the application being accessed; a buffer overflow condition may allow remote code execution.

Philips Update


This update provides additional information on an advisory that was originally published on August 16th, 2018. The new information includes:

• Extending the expected update publication from mid-2019 to 3rd Quarter 2020, and
• Change mitigation instructions for PageWriter TC50 and TC70,

SIMATIC Update


This update provides additional information on an advisory that was was originally published on December 10th, 2019 and most recently updated on March 10th, 2020. The new information includes:

• Revised version and mitigation information for  SIMOCODE pro V PN, and
• Clarified update version information for SINAMICS G130/G150/S150 and SINAMICS S120

Industrial Products Update


This update provides additional information on an advisory that was originally published on September 10th, 2019 and most recently updated April 14th, 2020. The new information includes:

• Added products SIMATIC NET CP 443-1 OPC UA, CP 443-1 RNA, CP 442-1 RNA, CP 443-1, CP 443-1 Advanced and CP 343-1 Advanced,
• Included additional information to CP 1623 and CP 1628 regarding affected CVE,
• Added new vulnerability: Excessive data query operations in large data table - CVE-2019-8460

Other Siemens Update


There was one other Siemens update that was published today. I will cover it this weekend.

OSIsoft Update


This update provides additional information on an advisory that was originally published on May 12th, 2010. The new information includes:

• Four new affected products:
PI Connector for IEC 60870-5-104,
PI Connector for OPC-UA,
PI Connector for Siemens Simatic PCS 7, and
PI Connector for UFL
• Major change to mitigation measures

Saturday, May 23, 2020

Public ICS Disclosures – Week of 5-16-20


This week we have two vendor disclosures for products from HMS and BD. There is also a researcher report on previously disclosed vulnerabilities from OSIsoft.

HMS Advisory


HMS published an advisory describing a certificate verification vulnerability in their eCatcher product. The vulnerability was reported by TÜV Rheinland. HMS has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

BD Advisory


BD published an advisory describing two Windows Adobe Type Manager Library vulnerabilities in various BD products. BD is currently working to test and validate the appropriate Microsoft patch for these vulnerabilities.

OSIsoft Report


Applied Risk published a report on vulnerabilities in the OSIsoft PI System. These vulnerabilities were previously disclosed by NCCIC-ICS. This report provides links to the OSIsoft report on the vulnerabilities, but that report is behind a customer registration wall.

Saturday, May 16, 2020

Public ICS Disclosures – Week of 5-9-20


This week we have five vendor disclosures for products from Schneider (4) and Rockwell as well as six vendor updates from Schneider (5) and Siemens. We also have two researcher reports of vulnerabilities in products from Advantech.

Schneider Advisories


Schneider published an advisory describing a weak password requirement vulnerability in their Pro-face GP-Pro EX Programming Software product. The vulnerability was reported by Kirill Kruglov of Kaspersky Labs. Schneider has a new version that mitigates the vulnerability. There is no indication that Krublov has been provided an opportunity to verify the efficacy of the fix.


Schneider published an advisory describing a use of hard-coded credentials vulnerability in their Vijeo Designer Basic and Vijeo Designer software products. The vulnerability was reported by Jie Chen of NSFOCUS. Schneider has a HotFix available to mitigate the vulnerability. There is no indication that Jie has been provided an opportunity to verify the efficacy of the fix.


Schneider published an advisory describing two vulnerabilities in their U.motion servers and touch panel products. The vulnerabilities were reported by Rgod and Zhu Jiaqi. Schneider has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper access control - CVE-2020-7499, and
• SQL injection - CVE-2020-7500


Schneider published an advisory describing five vulnerabilities in their EcoStruxure™ Operator Terminal Expert product. The vulnerabilities were reported by Steven Seeley and Chris Anastasio of Incite Team, Sharon Brizinov and Amir Preminger of Claroty Research via the Zero Day Initiative (see here, here, and here), and Fredrik Østrem, Emil Sandstø, and Cim Stordal of Cognite. Schneider has a new version that mitigates four of the five vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• SQL command injection - CVE-2020-7493,
• Path traversal (3) - CVE-2020-7494, CVE-2020-7495, and CVE-2020-7497, and
• Argument injection or modification - CVE-2020-7496

Rockwell Advisory


Rockwell published an advisory describing five vulnerabilities in multiple Rockwell Automation software products. These are third-party vulnerabilities from OSIsoft components used in the Rockwell products. These vulnerabilities are self-identified. Rockwell provides workarounds to mitigate the vulnerabilities.

The five reported vulnerabilities are:

• Local privilege escalation via uncontrolled search path element - CVE-2020-10610,
• Local privilege escalation via improper verification of cryptographic key - CVE-2020-10608,
• Local privilege escalation via incorrect default permissions - CVE-2020-10606,
• Null pointer dereference - CVE-2020-10600, and
• Use of out-of-range pointer offset may lead to remote code execution - CVE-2020-10645

NOTE: These are five of the ten vulnerabilities in the OSIsoft PI System that were reported by NCCIC-ICS earlier this week. The fact that this Rockwell Advisory was published on the same day as the NCCIC-ICS advisory indicates that there was pre-disclosure coordination between OSIsoft and Rockwell, good show.

Advantech Advisories


The Zero Day Initiative published advisories (see links below) describing two vulnerabilities in Advantech WebAccess Node. ZDI published the two advisories as 0-day notifications under their 120-day response rule. NCCIC-ICS was reported involved in the coordination of these vulnerabilities. The vulnerabilities were reported by Z0mb1E.

The two reported vulnerabilities are:

• DATACORE Stack-based Buffer Overflow Remote Code Execution Vulnerability - ZDI-20-654, and
• Incorrect Permission Assignment Privilege Escalation Vulnerability - ZDI-20-655

Schneider Updates


Schneider published an update for the Urgent/11 advisory that was originally published on August 11th, 2019 and most recently updated on April 14th, 2020. The new information includes updated mitigation information for:

• Modicon Network Option Switch,
• Modicon X80 - I/O Drop Adapters,
• Modicon Quantum 140 CRA,
• Modicon Quantum Head 140 CRP,
• Modicon Quantum Ethernet DIO network module - 140NOC78x00 (C),
• SCD6000 Industrial RTU, and
• Pro-face HMI -GP4000H/R/E Series


Schneider published an update for their Andover Continuum System advisory that was originally published on March 10th, 2020 and most recently updated on April 14th, 2020. The new information includes minor updates to overview, vulnerability details, and product information for clarification.


Schneider published an update for their Embedded Web Servers for Modicon advisory that was originally published in November 2018 and most recently updated November 27th, 2019. The new information includes a corrected CVSS vector for CVE-2018-7812.


Schneider published an update for their Modicon Controllers advisory that was originally published on May 14th, 2019 and most recently updated on December 10th, 2019. The new information includes updated fix version information for CVE-2018-7857.


Schneider published an update for their Legacy Triconex advisory that was originally published on April 14th, 2020. Unfortunately, the link on the Schneider web site takes one to the original version of the advisory.

Siemens Update


Siemens published an update for their GNU/Linux advisory that was originally published on November 27th, 2018 and most recently updated on April 14th, 2020. The new information includes the addition of the following CVE’s:

• CVE-2019-9674,
• CVE-2019-18348,
• CVE-2019-20636,
• CVE-2020-8492,
• CVE-2020-11565,
• CVE-2020-11655, and
• CVE-2020-11656

Thursday, May 14, 2020

Verifying Fixes


I got some interesting feedback on a phrase in yesterday’s post about advisories from NCCIC-ICS; in particular the common sentence in too many of my responses: “There is no indication that Knowles [substitute the name of the current security researcher reporting the vulnerability] has been provided an opportunity to verify the efficacy of the fix.”

First, I got a TWITTER® DM from a long-time reader associated with OSIsoft, the subject of one of the advisories discussed yesterday. That DM informed me that while NCCIC-ICS did not routinely comment on researcher verification efforts, the OSIsoft advisory did include such language in this instance. Unfortunately, I cannot see that advisory since it is behind a customer only firewall. In any case, it seems (see below) that OSIsoft was actively involved in allowing researcher verification of the fix reported in this instance and are to be commended for that.

This in turn led to a series of emails from folks at Applied Risk, the company reporting the OSIsoft vulnerabilities. They confirmed that OSIsoft had actively worked with them to allow verification of the fixes announced in Tuesday’s advisory. In fact, according to William Knowles, the researcher involved in the situation, OSIsoft went so far as to provide a temporary license for the software to help Applied Risk in their evaluation.

Knowles went on to say:

“Verification of fixes of course always a good thing, but it really depends on whether software access is still available.  As you’ll know, getting access to this software isn’t always easy (expensive price tags, no trials, etc), and initial exposure often comes through consultancy work in third party environments. That access is often very transient.  At that point it all depends on the institutional openness and willingness of the vendor, and furthermore, who you’re even dealing with at the vendor on an individual level, and if they have the capability of dishing out temporary licenses and links to software downloads.  That isn’t always easy; however, in the case of OSIsoft it was, as the process was encouraged from their side.”

We have seen a number of instances where ‘fixed’ vulnerabilities had to be re-fixed at a later date when it was determined that the vulnerability still existed. I noted yesterday that the 3S update published by NCCIC-ICS was apparently one of those situations. If more researchers were involved in fix verification, this problem would be greatly reduced. For the vendors involved it would also demonstrate their commitment to work with the independent researcher community in identifying and fixing security vulnerabilities.

I will continue to call out vendors when they do not support researchers in this manner. And, of course, I will give credit when it is due.

Wednesday, May 13, 2020

2 Advisories and 7 Updates Published


Yesterday the CISA NCCIC-ICS published two control system security advisories for products from OSIsoft and Eaton. They also updated previously published advisories for products from 3S, Interpeak, and Siemens (5).

OSIsoft Advisory


This advisory describes ten vulnerabilities in the OSIsoft PI System. The vulnerabilities were reported by William Knowles at Applied Risk. OSIsoft provides workarounds to mitigate the vulnerabilities. There is no indication that Knowles has been provided an opportunity to verify the efficacy of the fix. Applied Risk has verified that Knowles was provided an opportunity to verify the efficacy of the fix (see https://chemical-facility-security-news.blogspot.com/2020/05/verifying-fixes.html) [5-14-20 8:00 EDT]

The ten reported vulnerabilities are:

• Uncontrolled search path element - CVE-2020-10610,
• Improper verification of cryptographic key - CVE-2020-10608,
• Incorrect default permissions - CVE-2020-10606,
• Uncaught exception - CVE-2020-10604,
• Null pointer dereference (2) - CVE-2020-10602 and CVE-2020-10600,
• Improper input validation - CVE-2019-10768,
• Cross-site scripting (2) - CVE-2020-10600 and CVE-2020-10614, and
• Insertion of sensitive information into log file - CVE-2019-18244

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to access unauthorized information, delete or modify local processes, and crash the affected device.

Eaton Advisory


This advisory describes two vulnerabilities in the Eaton Intelligent Power Manager software monitoring and management platform. The vulnerability was reported by Sivathmican Sivakumaran of Trend Micro’s Zero Day Initiative. Eaton has a new version that mitigates the vulnerability. There is no indication that Sivakumaran has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper input validation - CVE-2020-6651, and
• Incorrect privilege assignment - CVE-2020-6652

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to perform command injection or code execution and allow non-administrator users to manipulate the system configurations.

3S Update


This update provides additional information for an advisory that was originally reported on September 12th, 2019. The new information includes a link to an even newer version that more completely mitigates the vulnerability.

NOTE: This is part of the reason that advocate for the researchers that discovered the vulnerability being provided a specific opportunity to verify the efficacy of the reported fix.

Interpeak Update


This update provides additional information for the Urgent/11 advisory that was originally published on October 1st, 2019 and most recently updated on February 18th, 2020. The new information includes a link to the new Siemens Power Meters advisory that was published today.

SIPROTEC Update


This update provides additional information for an advisory that was originally published on July 9th, 2019 and most recently updated on December 10th, 2019. The new information includes affected version numbers and mitigation links for SIPROTEC 5 device types 7SS85 and 7KE85.

SINAMICS Update


This update provides additional information for an advisory that was originally published on August 15th, 2019 and most recently updated on December 10th, 2019. . The new information includes affected version numbers and mitigation links for SINAMICS SL150 V4.8.

SIMATIC Update


This update provides additional information for an advisory that was originally published on February 11th, 2020 and most recently updated on April 14th, 2020. The new information includes affected version numbers and mitigation links for SIMATIC NET PC Software.

KTK Update


This update provides additional information for an advisory that was originally published on April 14th, 2020. The new information includes the addition of the SIMATIC S7-400 H V6 CPU family to the list of affected products.

RUGGEDCOM Update


This update provides additional information for an advisory that was originally published on April 14th, 2020. The new information includes the removal of  IE/PB-Link V3 from the list of affected products.

Other Advisories


Siemens published one additional update that was not covered by NCCIC-ICS yesterday. I will address that on Saturday.

Schneider has also joined the 2nd Tuesday patch club. They published 3 new advisories and 4 updates that I will also address on Saturday.

Tuesday, September 10, 2019

6 Advisories and 3 Updates Published – 09-10-19


The DHS NCCIC-ICS published six control system security advisories for products from OSIsoft, Siemens (4), and Delta Electronics. They also updated two previously published advisories for products from Siemens and an alert from Mitsubishi Electric Europe.

OSIsoft Advisory


This advisory describes an integer overflow or wraparound vulnerability in the OSIsoft PI SQL Client. The vulnerability is self-reported. OSIsoft has a new version that mitigates the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow remote code execution or cause a denial of service, resulting in disclosure, deletion, or modification of information.

SIMATIC Advisory


This advisory describes an improper input validation vulnerability in the Siemens SIMATIC TDC CP51M1 multiprocessor automation system. The vulnerability is self-reported. Siemens has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to create a denial-of-service condition within UDP communication.

WirelessHart Gateway Advisory


This advisory describes a cross-site scripting vulnerability in the Siemens IE/WSN-PA Link WirelessHART Gateway. The vulnerability is self-reported. Siemens has provided generic mitigation measures for the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow information disclosure, code execution, or denial-of-service.

Comment: Usually a vendor provides generic mitigation measures for a vulnerability when they are forced to disclose a vulnerability due to the disclosure process. With this being a self-disclosed vulnerability, Siemens was not forced to disclose this vulnerability with a generic mitigation. That takes a certain amount of integrity, but it does place some of their customers at an unusual level of risk. The generic mitigation measure is not unusual or even an unexpected requirement, but some customers will not have taken the standard precaution and are unlikely to implement it now.

Industrial Product Advisory


This advisory describes three vulnerabilities in the Siemens Industrial Products. The vulnerabilities were self-reported. Siemens has new versions that mitigate the vulnerabilities is some of the affected products.

The three reported vulnerabilities are:

Integer overflow or wraparound - CVE-2019-11477;
Uncontrolled resource consumption (2) - CVE-2019-11478, and CVE-2019-11479

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to cause denial-of-service condition.

SINETPLAN Advisory


This advisory describes an improper authorization vulnerability in the Siemens Network Planner (SINETPLAN). The vulnerability is self-reported. Siemens has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow information disclosure, code execution, and denial-of-service. The Siemens Advisory notes that the vulnerability can only be exploited “local users”.

Delta Electronics Advisory


This advisory describes three vulnerabilities in the Delta Electronics TPEditor. The vulnerabilities were reported by kimiya of 9sg Security Team vis the Zero Day Initiative. Delta has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

Stack-based buffer overflow - CVE-2019-13540;
Heap-based buffer overflow - CVE-2019-13536; and
Out-of-bounds write - CVE-2019-13544

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow information disclosure, remote code execution, or may crash the application.

PCS7 Update


This update provides new information on an advisory that was originally reported on July 9th, 2019 and last updated on August 13th, 2019. The new information includes updated version information and mitigation links for SIMATIC WinCC Runtime Professional V14 and V15.

WinCC Update


This update provides new information on an advisory that was originally reported on July 11th, 2019 and updated on August 13th, 2019.

Mitsubishi Update


This update provides new information on an alert that was originally published on August 13, 2019. The revised alert changes the name of the vendor to “Mitsubishi Electric Europe B.V.”.

Other Siemens Advisories


Today was disclosure Tuesday for Siemens. They published six advisories and three updates. Two of those advisories are for third-party vulnerabilities (DejaBlue and Urgent/11). The Urgent/11 advisory could be added to the NCCIC-ICS advisory on those vulnerabilities via an update on Thursday. To date, NCCIC-ICS has not addressed DejaBlue, so I suspect that this Siemens advisory will be ignored. The last advisory will probably be addressed by NCCIC-ICS on Thursday.

Tuesday, August 13, 2019

1 Alert, 3 Advisories and 4 Updates Published – 08-13-19


Today the DHS NCCIC-ICS published a control system security alert for products from Mitsubishi Electric; three control system security advisories for products from Siemens, OSIsoft, and Delta Industrial; and four control system advisory updates for products from Siemens.

Mitsubishi Alert


This alert describes a report of seven vulnerabilities in the Mitsubishi smartRTU and INEA ME-RTU. The vulnerabilities were reported (with exploit code) by Mark Cross (@xerubus) (NCCIC-ICS did provide the link to the report, a first). Cross disclosed the vulnerabilities to CISA and published the public disclosure under the 45-day disclosure policy.

The seven reported vulnerabilities are:

OS command injection - CVE-2019-14931;
Unauthenticated download of configuration file - CVE-2019-14927;
Stored cross-site script - CVE-2019-14928;
Use of hard-coded cryptographic keys - CVE-2019-14926;
Hard-coded user passwords - CVE-2019-14930;
Plaintext password storage - CVE-2019-14929; and
Incorrect default permissions - CVE-2019-14925


Siemens Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the Siemens SCALANCE X switches. The vulnerability was reported by Younes Dragoni from Nozomi Networks. Siemens has provided generic workarounds. There is no indication that Dragoni has been provided an opportunity to verity the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial-of-service condition.

OSIsoft Advisory


This advisory describes two vulnerabilities in the OSIsoft PI Web API. The vulnerabilities are self-reported. OSIsoft has an update to mitigate the vulnerability.

The two reported vulnerabilities are:

Inclusion of sensitive information in log files - CVE-2019-13515; and
Protection mechanism failure.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerabilities to allow direct attacks against the product and disclose sensitive information.

Delta Advisory


This advisory describes two vulnerabilities in the Delta DOPSoft Human Machine Interface (HMI) editing software. The vulnerability was reported by kimiya of 9SG Security Team via the Zero Day Initiative. Delta has a new version that mitigates the vulnerabilities. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Out-of-bounds read - CVE-2019-13513; and
Use after free - CVE-2019-13514

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow information disclosure, remote code execution, or crash of the application.

SIMATIC WinCC Update


This update provides additional information on an advisory that was originally reported on July 11th, 2019. The update provides new affected version information and mitigation links for:

SIMATIC WinCC V7.3;
SIMATIC PCS 7 V8.1, and
SIMATIC WinCC Runtime Professional V14

Spectrum Power Update


This update provides additional information on an advisory that was originally reported on July 9th, 2019. The update provides corrected version information for Spectrum Power 5.

SIPROTEC Update


This update provides additional information on an advisory that was originally reported on July 9th, 2019. The update provides additional mitigation information.

SIMATIC PCS7 Update


This update provides additional information on an advisory that was originally reported on July 9th, 2019. The update provides corrected version information and mitigation links for:

SIMATIC WinCC V7.3; and
SIMATIC PCS 7 V8.1
NOTE: Siemens published an additional two advisories and two updates today that were not reported by NCCIC-ICS. They may be reported on Thursday, if not, I will report on them on Saturday.

Wednesday, February 13, 2019

6 Advisories and 7 Updates Published – 02-12-19


Yesterday the DHS NCCIC-ICS published six control system security advisories for products from Siemens (5) and OSIsoft. They also updated seven previously published advisories for products from Siemens.

CP1604 Advisory


This advisory describes three vulnerabilities in the Siemens CP1604 and CP1616 products. These vulnerabilities were self-reported. Siemens has a new version that mitigates the vulnerabilities.

The three reported vulnerabilities are:

• Clear-text transmission of sensitive information - CVE-2018-13808;
• Cross-site scripting - CVE-2018-13809; and
Cross-site request forgery - CVE-2018-13810

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow a denial-of-service condition and information exposure. An attacker could inject arbitrary JavaScript in a specially crafted URL request to execute on unsuspecting user’s systems, allowing an attacker to trigger actions via the web interface that a legitimate user is allowed to perform.

NOTE: I briefly discussed this advisory on January 12th.

Intel Active Management Advisory


This advisory describes three vulnerabilities in the Intel Active Management Technology (AMT) of Siemens SIMATIC IPCs. The vulnerabilities are self-reported. These vulnerabilities exist in third-party (Intel) firmware on the affected PCs. Siemens has firmware updates that mitigate the vulnerabilities.

The three reported vulnerabilities are:

• Cryptographic issues - CVE-2018-3616;
• Improper restrictions of operations within the bounds of a memory buffer - CVE-2018-3657; and
• Resource management errors - CVE-2018-3658

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow arbitrary code execution, a partial denial-of-service condition, or information disclosure. The Siemens advisory reports that:

“The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction.”

NOTE: These vulnerabilities could be found on a large number of industrial PC’s not related to the Siemens products in this advisory.

SIMATIC Advisory


This advisory describes an improper input validation vulnerability in the Siemens SIMATIC S7-300 CPU. The vulnerability was reported by the China Industrial Control Systems Cyber Emergency Response Team (CIC). Siemens has a firmware update that mitigates the vulnerability. There is no indication that CIC has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to all the attacker to  crash the device being accessed, resulting in a denial-of-service condition.

NOTE: I briefly discussed this advisory on January 12th.

Licensing Software Advisory


This advisory describes three vulnerabilities in the Siemens WibuKey Digital Rights Management (DRM) used with SICAM 230. These vulnerabilities are self-reported. Siemens has provided links to a third-party update to mitigate the vulnerabilities. These vulnerabilities were originally reported in the WibuKey product in December by Talos; see the links on the CVE numbers for the Talos reports.

The three reported vulnerabilities are:

• Input validation (3) - CVE-2018-3989, CVE-2018-3990, and CVE-2018-3991.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow information disclosure, privilege escalation, or remote code execution. NOTE: The Talos reports provide proof of concept exploit code.

Again, as with any third-party vulnerability, these problems could be seen in systems from other vendors that also use the WibuKey DRM.

EN100 Ethernet Communications Module Advisory


This advisory describes an improper input validation vulnerability in the Siemens EN100 Ethernet Communication Module and SIPROTEC 5 Relays. The vulnerability was reported by Lars Lengersdorf from Amprion GmbH. Siemens has updates for some of the affected products. There is no indication that Lengersdorf has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to conduct a denial-of-service attack over the network.

OSIsoft Advisory


This advisory describes a cross-site scripting vulnerability in the OSIsoft PI Vision application. The vulnerability is self-reported. OSIsoft has a new version that mitigates this vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow an attacker to read and modify the contents of the PI Vision web page and data related to the PI Vision application in the victim’s browser.

NOTE: I briefly discussed this vulnerability on December 18th, 2018.

Meltdown Spectre Update


This update provides additional information on an advisory that was originally published on January 11th, 2018 and updated on January 16th, 2018, January 17th, 2018, January 30th, 2018, February 20th, 2018, February 22nd, 2018, March 1st, 2018, July 10th, 2018, and most recently on September 11th, 2018.. The new information includes a link to a new Meltdown/Spectre advisory from Siemens for their SIMATIC Industrial Thin Clients.

EN100 Ethernet Communications Module Update


This update provides additional information on an advisory that was originally published on December 13th, 2018. The new information includes updated version data and mitigation links for or firmware variant IEC104 for EN100 Ethernet modules.

SIMATIC S7-1500 Update


This update provides additional information on an advisory that was originally published on October 9th, 2018. The new information includes updated version data and mitigation links for:

• SIMATIC ET 200 SP Open Controller; and
• SIMATIC S7-1500 Software Controller

Open SSL Update


This update provides additional information on an advisory that was originally published on August 14th, 2018 and updated on September 11th, 2018, October 9th, 2018, and again on November 13th, 2018. The update provides new affected version and mitigation information for:

• SIMATIC S7-1500 Software Controller; and
• SIMATIC ET 200SP Open Controller CPU 1515SP PC

SIPROTEC 4 Update


This update provides additional information on an advisory that was originally published on March 8th, 2018 and updated on April 18th, 2018. The update provides new affected version and mitigation information for IEC 104 variant of EN100 module.

Industrial Products Update #1

This update provides additional information on an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th, November 28th, February 27th, 2018, May 3rd, 2018 May 15th, 2018, September 11th, 2018, October 9th, 2018, November 13th, 2018, December 11th, 2018, and most recently on February 5th, 2019. The update provides new affected version and mitigation information for SIMATIC ET 200SP IM155-6 PN HA.

Industrial Products Update #2


This update provides additional information on an advisory that was originally published on January 12th, 2018. The update provides new affected version and mitigation information for SIMATIC CP 1626.

Siemens Advisory Update


Yesterday’s publications by ICS-CERT is really rather remarkable since most of the Siemens advisories covered were published yesterday. NCCIC-ICS has now reported on all of the original advisories from Siemens from January and all but one of the updates (the GNU/Linux vulnerabilities that have not been reported by NCCIC-ICS).

Of the four advisories and 12 updates published yesterday by Siemens only 8 updates have not been directly covered by NCCIC-ICS in yesterday’s reporting. Unless those are reported by NCCIC-ICS on Thursday, I will have more details this weekend.

 
/* Use this with templates/template-twocol.html */