Showing posts with label Open Automation Software. Show all posts
Showing posts with label Open Automation Software. Show all posts

Tuesday, January 24, 2012

ICS-CERT – Two New Advisories but Two Alerts from Last Week still Missing

This afternoon the DHS ICS-CERT published two new advisories, both with multiple vulnerabilities. The advisories are for Ocean  Data Systems’ Dream Reports and MICROSYS’ Promotic systems. Strangely missing are the two alerts that I predicted this weekend for vulnerabilities publicly disclosed by the Digital Security Research Group (DSecRG).

Ocean Data Systems Advisory


Rios and McCorkle reported the two vulnerabilities addressed in this advisory. The first is a cross-site scripting vulnerability that is remotely exploitable and does not require much in the way of skills to execute. The second is a write access violation vulnerability that is a tad bit more complicated to exploit, requiring a successful social engineering attack and the creation of a specially crafted data file.

Ocean Data Systems has published a new version of the Dream Report product that has been confirmed to be free of these two vulnerabilities. Separate CVE numbers have been assigned, but are not yet active.

MICROSYS Advisory


While it is not mentioned in this advisory, it is an update of an alert issued last October for three vulnerabilities found in the Promotic HMI. Those vulnerabilities were reported by our friend Luigi. The vulnerabilities identified were:

• Directory Transversal, CVE-2011-4518;

• ActiveX Stack Overflow, CVE-2011-4519; and

• ActiveX Heap Overflow, CVE-2011-4520

All three are remotely executable by a relatively low-skilled attacker. The first could be used to cause some data leakage and the other two could be used as part of a DOS attack. The latest version of Promotic is free of these vulnerabilities and is downloadable from the MICROSYS website. The above listed CVE numbers are not yet active.

Missing Alerts


Last Sunday I noted that in addition to the WAGO vulnerability covert in an ICS-CERT alert from Friday, there were two other system vulnerability reports from DSecRG describing vulnerabilities in Tecomat PLCs and the Open Automation Software (OAS) OPC system. Both of those should have received ICS-CERT alerts on Friday or yesterday. There were still not yet posted as of 20:30 EST today; curiouser and curiouser.

Thursday, January 12, 2012

ICS-CERT Closes-out a Luigi Alert

Today the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published an advisory that effectively closes out an earlier alert about a Luigi identified vulnerability on Open Automation Software’s OPC Systems.Net. It actually closes out two alerts, one of which is no longer publicly available, but you’ll have to go back and re-read an earlier blog post for that story.

The vulnerability would allow a malformed packet to be used by a moderately skilled attacker to remotely execute a denial of service attack. A CVE number has been assigned, but is not yet active. A software update is available that corrects this particular problem.

Wednesday, October 12, 2011

ICS-CERT Updates Two Notices and Issues New Advisory

This has been a busy week for the folks at the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT); they updated a recently issued alert and an advisory and issued a new advisory. The Unitronic Advisory was updated as was the Alert for ULE-OCP; actually that alert was re-issued after ICS-CERT got names straightened out. A new advisory was issued for Honeywell’s TEMA system.

Open Automation Software


The OPC Systems Alert that was published on Monday as part of the ICS-CERT response to the latest Luigi disclosures has been superseded by a new alert that corrected some apparent system naming errors that had been included in the Luigi documentation. Amazingly the link to the superseded document still works. Unfortunately, ICS-CERT cannot blame this error on Luigi because they refuse, as a matter of policy, to disclose the names of security researchers who release vulnerability information through an uncoordinated disclosure process.

BTW: I had an error in my blog posting on Monday’s three Alerts. Fortunately, Dan, a sharp eyed reader, caught the error and notified me of the problem. When I went to correct the problem this new version of the alert was already published and I put the link to the corrected document in that post. If anyone is interested that original Alert can be found here, at least for the time being. [NOTE: As of 1-12-12 this old alert is no longer available via this link. I'm not sure when it went dead]

Unitronics UniOPC


If this revision was not written by a lawyer is had to have at least been directed by a lawyer, probably the vendor’s lawyer. This is a three part change that you have to be very alert to track. The first change adds a footnote to a link to the web site of the third party vendor that provided the offending component. The second changes “other applications that support OLE for Personal Computers (OPC)” to read “other OPC applications”. The final revision changes “resides in the https.ocx component of ‘IP*Works! SSL’” to read “resides in the https50.ocx component of “IP*Works! SSL” and removes the footnote link to the third party vendor web site. This is a highly consequential change [Sarcasm Warning].

Honeywell Temaline Access Control


This new Advisory for the Honeywell Enterprise Buildings Integrator (EBI) system is based upon a coordinated disclosure by Billy Rios and Terry McCorkle. If you haven’t heard about this dynamic duo you certainly will; they discovered 665 vulnerabilities in 75 HMI applications in 100 days (see the Digital Bond posting for more details; make sure to read the Reader Comments) and coordinated them all through ICS-CERT. In any case this doesn’t look like it belongs in the list of 665 vulnerabilities and it isn’t really about an industrial control system as chemical engineers think about such systems, but it is potentially important to chemical facility security none-the-less.

It does involve a component of Honeywell’s Enterprise EBI called Temaline. According to the Honeywell web site:

“Honeywell Temaline offers handling and monitoring of electronic access control, visitor/contractor management, time and attendance and mustering. Integration with security management, enterprise resource planning (ERP) and closed-circuit television (CCTV) systems provides one-window access to and control over the cardholder database to determine who is allowed access to what places and at what times.”

The vulnerability occurs in the Tema Remote Installer that includes an ActiveX function that is “configured to ignore file authentication”. A moderately skilled attacker could remotely exploit this vulnerability to craft, download and install an MSI file that could allow execution of arbitrary code. It would seem to me that that code could include allowing an attacker physical access through the security system by any number of means.

Honeywell developed a patch for this vulnerability; unfortunately that patch also kills legitimate uses of the offending MSI file. Work-around instructions for that issue are included in the patch directions.
 
/* Use this with templates/template-twocol.html */