Showing posts with label OpenSSL. Show all posts
Showing posts with label OpenSSL. Show all posts

Thursday, January 19, 2023

Review - 1 Advisory Published – 1-19-23

Today, CISA’s NCCIC-ICS published one control system security advisory for products from Hitachi Energy.

Hitachi Energy Advisory - This advisory discusses the OpenSSL 3.0 in Hitachi Energy PCU400 products.

 

For more details about this advisory and a look back at the OpenSSL 3.0 vulnerabilities, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-advisory-published-1-19-23 - subscription required.

Saturday, December 24, 2022

Review – Public ICS Disclosures – Week of 12-17-22

This week we have an OpenSSL 3.0 disclosure from Palo Alto Networks. There are nine vendor disclosures from Dahua, Dell, DIGI, Hikvision, HPE, Microchip, Motorola Solutions, TandD, and Western Digital. Finally, there is a vendor update from Siemens.

OpenSSL. 3.0

Palo Alto Networks published an advisory discussing the OpenSSL 3.0 vulnerabilities.

Vendor Disclosures

Dahua Advisory - Dahua published an advisory that describes twelve vulnerabilities in a variety of Dahua products.

Dell Advisory - Dell published an advisory that describes nine vulnerabilities (includes 3 third-party vulnerabilities) in their Wyse Management Suite. 

DIGI Advisory - DIGI published an advisory that discusses the FragAttack vulnerabilities.

Hikvision Advisory - Hikvision published an advisory that describes an access control vulnerability in their wireless bridge products.

HPE Advisory #1 - HPE published an advisory that directory traversal vulnerability in their OfficeConnect 1820, and 1850 Switch Series.

HPE Advisory #2 - HPE published an advisory that describes a data injection vulnerability in their Superdome Flex and Superdome Flex 280 Servers.

Microchip Advisory - Microchip published an advisory that discusses the Blue's Clues vulnerabilities.

NOTE: Watch Blue’s Clues (sorry, I could not help myself), cute name and everything. It looks like this will be a major issue for Bluetooth enabled devices, particularly medical devices.

Motorola Advisory - Motorola published an advisory discussing the Fortinet buffer overflow vulnerability.

TandD Advisory - TandD published an end of support notice for products operating on Windows 7 and Windows 8 platforms.

Western Digital Advisory - Western Digital published an advisory describing an information disclosure vulnerability in their My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices.

Vendor Updates

Siemens Update - Siemens published an update for their SIPROTEC 5 Devices advisory that was originally published on December 13th, 2022.

NOTE: NCCIC-ICS has not updated their advisory (ICSA-22-349-14) for the new information.

 

For more details about these disclosures, including links to third-party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-f5b - subscription required.

Saturday, November 5, 2022

Review – Public ICS Disclosure – Week of 10-29-22

This week we have twelve vendor disclosures about the recent OpenSSL vulnerabilities from Aruba Networks, Broadcom, Keysight, Milestone, Moxa, Palo Alto Networks, Roche, Rockwell Automation, Software Toolbox, Watchguard, and Wind River.   We also have twelve other vendor disclosures from Belden, Hitachi, Insyde (6), Sick, and Tanzu (3). There are six vendor updates for products from CODESYS. Finally, we have two exploits for products from FLIR, and Veeder-Root.

OpenSSL Vulnerabilities Disclosures

Aruba reports that none of their products are affected by the vulnerabilities.

Broadcom provides a list of unaffected products.

Dell reports that they are reviewing their products to see which may be affected by the vulnerabilities.

Keysight reports that none of their products are affected by the vulnerabilities.

Milestone reports limited impact in their XProtect VMS 2022 R3. An update is pending.

Moxa reports that none of their products are affected by the vulnerabilities.

Palo Alto Networks reports that earlier versions of Cortex XDR Broker VM contain the affected OpenSSL version but are not affected by the vulnerabilities. Other products are not affected.

Roche reports that none of their products are affected by the vulnerabilities.

Rockwell reports that they are reviewing their products to see which may be affected by the vulnerabilities.

Software Toolbox reports that none of their products are affected by the vulnerabilities.

Watchguard provides a list of unaffected products.

Wind River provides a list of affected products. Fixes are pending.

Other Vendor Disclosures

Belden Advisory - Belden published an advisory that describes a command insertion vulnerability in their (Hirschmann) Industrial HiVision product.

Hitachi Advisory - Hitachi published an advisory that discusses 60 vulnerabilities in their Disk Array Systems. These are third-party (Microsoft) vulnerabilities

Insyde Advisory #1 - Insyde published an advisory that discusses an observable discrepancy vulnerability in their InsydeH2O product.

Insyde Advisory #2 - Insyde published an advisory that discusses two vulnerabilities in their InsydeH2O product.

Insyde Advisory #3 - Insyde published an advisory that discusses an out-of-bounds read vulnerability in their InsydeH2O product.

Insyde Advisory #4 - Insyde published an advisory that describes a stack-based buffer overflow vulnerability in their InsydeH2O product.

Insyde Advisory #5 - Insyde published an advisory that describes a stack-based buffer overflow in their InsydeH2O product.

Insyde Advisory #6 - Insyde published an advisory that describes a stack-based buffer overflow in their InsydeH2O product.

Sick Advisory - Sick reports a denial of service vulnerability in their FlexiCompact product.

NOTE: The Sick PSIRT web page continues to have problems with inoperable links.

Tanzu Advisory #1 - Tanzu published an advisory that describes a privilege escalation vulnerability in their pring-security-oauth2-client.

Tanzu Advisory #2 - Tanzu published an advisory that describes an authorization bypass vulnerability in their Spring Security product.

Tanzu Advisory #3 - Tanzu published an advisory that describes a remote code execution vulnerability in their Spring Tools 4 for Eclipse product.

CODESYS Update #1 - CODESYS published an update for their CODESYS communication server advisory that was originally published on May 19th, and most recently updated on October 6th, 2022.

CODESYS Update #2 - CODESYS published an update for their V3 web server advisory that was originally published on March 24th, 2022 and most recently updated on June 30th, 2022.

CODESYS Update #3 - CODESYS published an update for their a CODESYS communication server advisory that was originally published on March 24th, 2022 and most recently updated on June 30th, 2022.

CODESYS Update #4 - CODESYS published an update for their Control V3 online user management advisory that was originally published on March 24th, 2022 and most recently updated on June 30th 2022.

CODESYS Update #5 - CODESYS published an update for their V3 products using the CODESYS communication protocol advisory that was originally published on March 24th, 2022 and most recently updated on June 30th, 2022.

CODESYS Update #6 - CODESYS published an update for their Control V3 configuration file advisory that was originally published on March 24th, 2022, and most recently updated on October 6th, 2022.

Exploits

FLIR Exploit - Samy Younsi published a Metasploit module for a command injection vulnerability in the FLIR AX8 infrared monitoring camera.

Veeder-Root Exploit - Rose Security published an exploit for a remote configuration disclosure vulnerability in the Veeder-Rood (and probably other vendor) automated tank gauges.

 

For more details about these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-10-c49 - subscription required.

 

Thursday, March 17, 2022

Review – 1 Update and 1 3rd Party Advisory Published

Today CISA’s NCCIC-ICS published an update for an advisory for products from Treck. CISA (separately from NCCIC-ICS) published an advisory for products from OpenSSL that is very likely to show up as a third-party advisory for products from various vendors.

Treck Update - This update provides additional information on an advisory that was originally published on June 16th, 2020 and most recently updated on August 20th, 2020.

NOTE #1: I discussed the ‘new’ PEPPERL+FUCHS advisory on August 21st, 2021

OpenSSL Advisory - CISA briefly reports the OpenSSL advisory which describes an infinite loop vulnerability in the BN_mod_sqrt() function when parsing certificates.

NOTE: With so many industrial control systems using OpenSSL for a variety of security functions, I expect that we will be seeing this vulnerability being reported by multiple vendors as a third-party vulnerability.

 

For more details on these two advisories, including discussion about Ripple20 exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-update-and-1-3rd-party-advisory - subscription required.

Saturday, August 11, 2018

Public ICS Disclosures – Week of 08-04-18


This week we have four vendor advisories from Siemens (3) and ABB and an update of a vendor advisory from Siemens. There were also a number of BlackHat Briefings this week that touched on control system security issues.

Automation License Manager Advisory


Siemens reported two vulnerabilities in their Automation License Manager. The vulnerabilities were reported by Vladimir Dashchenko from Kaspersky Lab. Siemens has updates available to mitigate the vulnerabilities. There is no indication that Dashchenko was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Directory traversal - CVE-2018-11455; and
Network canning vulnerability - CVE-2018-11456

OpenSSL Advisory


Siemens reported an ‘open error state’ vulnerability in the OpenSSL implementation in a number of Siemens Industrial Products. This third-party software vulnerability is being self-reported by Siemens. Siemens has developed updates for some of the affected products (additional work is ongoing) to mitigate the vulnerability.

As always with third-party software issues, there is always the possibility that this vulnerability may affect control system products from other vendors.

SIMATIC Advisory


Siemens reported two improper file permission vulnerabilities in their SIMATIC Step 7 and WinCC products. The vulnerabilities were reported by Younes Dragoni from Nozomi Networks. Siemens has updates for some of the affected products and has reported work arounds.

NOTE: Siemens notes that this vulnerability was coordinated through ICS-CERT so we will probably see this reported by ICS-CERT next week.

ABB Advisory


ABB reported (registration required) an  LDAP authentication vulnerability in their eSOMS product. The vulnerability was reported by an undisclosed researcher. ABB is working on a new version to mitigate the vulnerability and has reported a work around.

Siemens Update


Siemens updated their Spectre/Meltdown advisory. This advisory was last updated on June 26th, 2018. This latest update adds update information for SIMATIC IPC6x7C, SIMAITC IPC8x7C, SIMOTION P320-4S, and SIMOTION P320-4E.

BlackHat Briefings


The latest BlackHat conference was held in Las Vegas this week. There were six briefings that the conference web site identifies as touching on Smart Grid/Industrial Security. There were:



Speaker: Thomas Roth

Speaker: Justin Shattuck


Speaker: Balint Seeber

Tuesday, December 9, 2014

ICS-CERT Publishes OpenSSL Update and 2 New (Almost) Advisories

The afternoon the DHS ICS-CERT updated (up to ‘F’ now) their Situational Awareness Alert for the OpenSSL vulnerability. They also published new advisories for vulnerabilities in systems from Trihedral Engineering and Yokogawa.

HeartBleed

This update adds ABB to the list of vendors with affected products. The Relion 650 series has a patch available to mitigate the vulnerability. There is no explanation as to why this update was so long in coming. The last HeartBleed update was published back in April and ABB published their advisory in July.

Trihedral Advisory

This advisory describes an integer overflow vulnerability in their VTS and VTScada products. The vulnerability was reported by an anonymous researcher through ZDI. ICS-CERT reports that Trihedral has produced a patch that mitigates the vulnerability.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to cause the application to crash.

Interestingly the Trihedral update page says nothing about this vulnerability in their upgrade descriptions. ZDI does report that they notified Trihedral of this vulnerability (ZDI-CAN-2599) on November 19th so this was a very quick response.

Yokogawa Advisory

This advisory reports an XML external entity processing vulnerability in the Yokogawa FAST/TOOLS application. The vulnerability was reported by Timur Yunusov, Alexey Osipov, and Ilya Karpov of Positive Technologies Inc. ICS-CERT reports that Yokogawa has developed a service pack that mitigates this vulnerability, but no mention is made that the researchers have verified the efficacy of the fix.

ICS-CERT reports that it would be difficult to craft an exploit of this vulnerability and local access would be required. Yokogawa also reports (in their CVSS calculation) that local access is required, but note that it can be exploited by an attacker that “intrudes into the WebHMI server in any way”. Something may be lost in translation there because that sounds to me like remote access could be used to exploit this vulnerability.


I mentioned earlier that Yokogawa had publicly reported this vulnerability over a week and a half ago; not very timely reporting by ICS-CERT.

Tuesday, October 14, 2014

ICS-CERT Acknowledges 1 of 3 Siemens Updates

Earlier today the DHS ICS-CERT published an update (#4) for the Siemens OpenSSL advisory that was last updated in August. It ignored updates for a RuggedCom certificate verification vulnerability (ICSA-14-135-03) originally published in May and an update for the Siemens GNU Bash vulnerability that ICS-CERT still has not reported. Batting 1 for 3 in baseball is pretty good; in security it SUCKS. All three updates were published yesterday on the Siemens ProductCert web page.

Open SSL Update

This update reports that Siemens now has updates available for all of the affected product lines. Steady progress made since the vulnerability was reported earlier this year with regular updates to public notifications by Siemens.

Certificate Verification Update

ICS-CERT may not care, but Siemens is reporting that it has firmware updates available for ROX 2 devices and continues to work on updates for ROX 1 devices.

GNU Bash Update


Siemens is reporting that the same ROX 2 firmware upgrade that fixed the certificate verification vulnerability also addresses their GNU Bash issue. Two vulnerabilities with a single upgrade, good move. ICS-CERT apparently still does not know that Siemens is affected by GNU Bash so the update passes unnoticed.

Thursday, June 5, 2014

ICS-CERT Updates Sign Alert and Publishes new OpenSSL Advisory

Today the DHS ICS-CERT published an update to yesterday’s alert about an automated road sign system and an advisory for a new vulnerability in OpenSSL. Neither system is what comes to most people’s minds when the term ‘industrial control system’ is mentioned. The first extends the definition because apparently ICS-CERT doesn’t already have enough on its plate and the second reminds us that secure communications is a key component of any secure cyber-system.

Daktronics Alert Update

Today’s update brings new information about the scope of the vulnerability and an expansion of the interim mitigation measures suggested by Daktronics and the Federal Highway Administration, the organization that notified ICS-CERT of this particular vulnerability.

According to Daktronics the ‘hard coded credential’ is actual a default password that can (and obviously should be) changed when the system is installed. I can understand why the FHA gets the two vulnerabilities confused, after all (SARCASM WARNING) they are a well-known font of control system security knowledge.

Then Update also includes three ‘device specific’ mitigation measures to add to the standard ICS-CERT generic security measures. The new mitigation suggestions are:

• Displays should not be on publicly accessible IP addresses. Placing a display on a private network or VPN helps mitigate the lack of security,
• Disable the telnet, webpage, and web LCD interfaces when not needed, and
• Change the default password to a strong password as soon as possible on all installed devices.

Nothing really new there; I hope that that is because ICS-CERT is not spending valuable resources on this particular vulnerability.

OpenSSL Advisory

Remember how upset the control system security community was with the initial ICS-CERT about the HeartBleed vulnerability because there was so little actual control system information available in the initial advisory. Well the folks at ICS-CERT did not learn the lesson, today’s advisory about the multiple vulnerabilities recently corrected by OpenSSL contains even less information. They don’t even list the vulnerabilities involved.

According to the OpenSSL Security Advisory the vulnerabilities include:

• SSL/TLS MITM vulnerability (CVE-2014-0224)[This was the only vulnerability mentioned in the KB-CERT Advisory that I tweeted about this morning];
• DTLS recursion flaw (CVE-2014-0221);
• DTLS invalid fragment vulnerability (CVE-2014-0195);
• SSL_MODE_RELEASE_BUFFERS NULL point dereference (CVE-2014-0198);
• SSL_MODE_RELEASE_BUFFERS session injection or denial of service (CVE-2010-5298); and
• Anonymous ECDH denial of service (CVE-2014-3470)

In many ways we are in the same place we were when the HeartBleed alert was first published, we don’t know what systems use the vulnerable OpenSSL versions. ICS-CERT does point users at their HeartBleed affected list with the following comment:

“NCCIC/ICS-CERT has produced an OpenSSL affected/unaffected products list that specifies which vendors, products, and product versions are affected by the OpenSSL HeartBleed vulnerability. This document also contains a list of vendors, products, and product versions that evaluated their products and have asserted that their products are not affected by the OpenSSL HeartBleed vulnerability. Owners and operators of control systems might use this list to determine whether their equipment may also contain a version of OpenSSL that is affected by these newly reported vulnerabilities. This document will be updated as needed.”

This is helpful for some versions of OpenSSL, but version 0.9.8 were not affected by HeartBleed, but will be affected by some of the vulnerabilities listed above. So some of the vendors listed as clean for HeartBleed may actually have problems with some of these vulnerabilities.


Of course, this is the type of information that we would expect from ICS-CERT. Based upon the HeartBleed experience we can expect to see this type information in version D or E of this advisory. But we are kept up to date on Automated Road Sign vulnerabilities.

Wednesday, April 23, 2014

ICS-CERT Updates HeartBleed Alert

This afternoon the DHS ICS-CERT updated their ‘Situational Awareness Alert for OpenSSL Vulnerability’, commonly referred to as the HeartBleed bug. The information added to date is the most extensive to date and includes:

• An advance notice about an ICS-CERT Advisory for HeartBleed in Atvise;
• An extensive (but probably not exhaustive) list of ICS related applications and devices that have been determined not to be affected by HeartBleed;
• A reminder that while older versions of OpenSSL may not be affected by HeartBleed, they do have their own known vulnerabilities; and
• A reminder that the use of SHODAN and other search engines may make it relatively easy to find ICS components that are susceptible to HeartBleed.

Atvise

ICS-CERT took the unusual step of announcing that an “ICS-CERT advisory [was] coming soon” for the Certec atvise scada products. It provides a link to the atvise notice about the vulnerability. That stilted notice (okay I lived in Berlin for 7 years and my German syntax was way worse at its best than this English language notice) claims that while some versions of their products have the HeartBleed bug “but wasn't affected by known attacks”. Now they “face new kinds of attacks found nearly daily”. I certainly look forward to hearing more about the ‘new kinds of attacks’ on a SCADA system.

Atvise does have a patch available for the vulnerable OpenSSL components.

Systems Not Affected

There is a fairly long list of systems here that are not affected by the HeartBleed bug because either they ‘don’t use OpenSSL’ or ‘don’t use an affected version of OpenSSL’. Unfortunately there is not an actual control system or component on the list. They are all either communications tools or security tools. This list will be invaluable to a security manager or integrator. It does let them concentrate of other parts of their systems, but it is strangely unhelpful for control systems.

The lack of any control system applications or devices on the list is more than a little disconcerting. Two weeks into the public discussion of HeartBleed and we have two vendors (Siemens and atvise) self-identifying their infection with this bug, but no one saying that they are infection free. At this point I think that any ICS system that has not identified itself as being free of HeartBleed should, for the sake of safety and security, must be considered to be infected until proven otherwise.

Other OpenSSL Vulnerabilities

There have been any number of system vendors that have bragged that their system uses an older version of OpenSSL that is not affected by HeartBleed. Today’s update reminds people that earlier versions of the software have their own problems that should not be ignored. The Update provides a link to the OpenSSL web page that lists a large number of reported vulnerabilities in the system. If all of the patches and upgrades have not been applied to earlier versions, there may be more serious problems than HeartBleed.

SHODAN and Others

Any time you have a widespread vulnerability like HeartBleed it is valuable to be reminded that search engines like SHODAN make it relative easy for people to find vulnerable systems. That combined with the wide spread availability of automated attack and exploit tools makes it easier for both the opportunistic and targeted attackers to gain access to improperly secured systems.


ICS-CERT notes in the Alert that: “As tools and adversary capabilities advance, ICS-CERT expects that exposed systems will be more effectively discovered, and targeted.” They also remind owner/operators that they can use many of the same tools to discover if their systems are vulnerable. Knowing that their systems are accessible and vulnerable should allow owners to better protect their systems.

Tuesday, April 8, 2014

US-CERT Publishes Heartbleed Bug Alert

This morning the US-CERT (NOT my normal ICS-CERT) published an alert for a TLS/DTLS heartbeat functionality vulnerability in the OpenSSL system. Now I don’t normally follow US-CERT vulnerability announcements very closely, but it has been pointed out  that this vulnerability may have a very big control system component.

The Vulnerability

US-CERT notes that a remote attacker with a publicly available exploit could gain access to sensitive data, possibly including user authentication credentials and secret keys, through incorrect memory handling in the TLS heartbeat extension. This could allow the attacker to decrypt data, obtain log-in credentials, or perform man-in-the-middle attacks using the OpenSSL protocols.

There is an interesting discussion of this vulnerability at HeartBleed.com.

The Control System Connection

The popular press has made the point that this makes a number of supposedly secure communications protocols vulnerable. One such protocol could be an organizations virtual private network (VPN). Since ICS-CERT has been pushing the use of VPN for ‘secure’ remote connections to control systems, a number of people are using the OpenSSL protocol to connect with their control system. These ‘secure’ connections are now vulnerable.

In a post over on the SCADASEC list at Infracritical.com Jake Brodsky notes that “this is a problem with the source code of OpenSSL/TLS. This code is embedded in many places, including many SCADA RTUs and associated network hardware”. People are going to have to do some hard looking to find all of the implementations of this system and get them corrected.

It would be real nice if ICS-CERT were to get out in front of the control system vulnerability side of this issue.
 
/* Use this with templates/template-twocol.html */