Showing posts with label Otorio. Show all posts
Showing posts with label Otorio. Show all posts

Tuesday, June 25, 2024

Review – 2 Advisories Published – 6-25-24

Today, CISA’s NCCIC-ICS published two control system security advisories for products from PTC and ABB.

Advisories

PTC Advisory - This advisory describes a missing authentication vulnerability in the PTC Creo Elements Direct License Server.

ABB Advisory - This advisory describes an improper input validation vulnerability in the ABB 800xA Base services in PC based client/server nodes.

 

For more information on these advisories, including another Otorio reported vulnerability in the ABB product, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-published-6-25-24 - subscription required.

Saturday, February 11, 2023

Review – Public ICS Disclosures – Week of 2-4-23

This week we have eleven vendor disclosures from ABB, Baicells, Dahua, Palo Alto Networks (5), Ruckus, and Zyxel Networks (2). We also have three vendor updates from CONTEC, HPE, and Moxa. Finally, we have thirteen researcher reports on products from Siemens, and Open Design Alliance (12).

NOTE: There have been problems with the NIST NVD CVE listings this morning. They have been slow to load or have not been found. Hopefully this will be corrected in the near future.

Vendor Disclosures

Baicells Advisory - Baicells published an advisory that describes a cross-site scripting vulnerability in their Nova 436Q, Nova 430E, Nova 430I, and Neutrino 430 LTE TDD eNodeB devices.

Dahua Advisory - Dahua published an advisory that describes an unauthorized modification of device timestamp vulnerability in some of their embedded products.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory that discusses an improper privilege management vulnerability in SUDO.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that discusses the OpenSSL vulnerabilities disclosed Feb 7, 2023.

Palo Alto Networks Advisory #3 - Palo Alto Networks published an advisory that describes a protection mechanism failure vulnerability in their Cortex XDR agent.

Palo Alto Networks Advisory #4 - Palo Alto Networks published an advisory that describes an information disclosure vulnerability in their Cortex XDR agent.

Palo Alto Networks Advisory #5 - Palo Alto Networks published an advisory that describes a file disclosure vulnerability in their Cortex XSOAR server.

Ruckus Advisory - Ruckus published an advisory that describes a cross-site request forgery vulnerability in multiple products using their AP Web application.

NOTE: Multiple end-of-life products are listed as being affected by this vulnerability.

Zyxel Advisory #1 - Zyxel published an advisory that describes a command injection vulnerability in their firewalls.

Zyxel Advisory #2 - Zyxel published an advisory that describes an improper check for unusual or exceptional conditions vulnerability in their Aps.

Vendor Updates

CONTEC Update - JP CERT published an update for their Solar View Compact advisory that was originally published on May 26th, 2022 and most recently updated on December 13th, 2022.

HPE Update - HPE published an update for their OneView advisory that was originally published on January 31st, 2023.

Moxa Update - Moxa published an update for their UC Series advisory that was originally published on November 29th, 2023.

NOTE: NCCIC-ICS has not updated their advisory (ICSA-22-333-04) for this new information.

Researcher Reports

Siemens Report - Otorio published a report describing two vulnerabilities in the Siemens Automation License Manager.

ODA Report #1 - The Zero Day Initiative published a report that describes a memory corruption vulnerability in the ODA Drawing SDK.

ODA Report #2 - ZDI published a report that describes a memory corruption vulnerability in the ODA Drawing SDK.

ODA Report #3 - ZDI published a report that describes an out-of-bounds write vulnerability in the ODA Drawing SDK.

ODA Report # 4 - ZDI published a report that describes an out-of-bounds write vulnerability in the ODA Drawing SDK.

ODA Report #5 - ZDI published a report that describes a heap-based buffer overflow vulnerability in the ODA Drawing SDK.

ODA Report #6 - ZDI published a report that describes an out-of-bounds write vulnerability in the ODA Drawing SDK.

ODA Report #7 - ZDI published a report that describes an out-of-bounds write vulnerability in the ODA Drawing SDK.

ODA Report #8 - ZDI published a report that describes an out-of-bounds write vulnerability in the ODA Drawing SDK.

ODA Report # 9 - ZDI published a report that describes an out-of-bounds write vulnerability in the ODA Drawing SDK.

ODA Report #10 - ZDI published a report that describes an out-of-bounds write vulnerability in the ODA Drawing SDK.

ODA Report #11 - ZDI published a report that describes a heap-based buffer overflow vulnerability in the ODA Drawing SDK.

ODA Report #12 - ZDI published a report that describes a use-after-free vulnerability in the ODA Drawing SDK.

 

For more details about these disclosures, including links to third-party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-2-6e9 - subscription required.

Saturday, February 4, 2023

Review – Public ICS Disclosures – Week of 1-28-23

This week we have twelve vendor disclosures from BaiCells, B&R, Hitachi, HP, HPE, JTEKT Electronics, Moxa, Pulse Secure (2), QNAP, and VMware (2). There is also a vendor update from VMware. Finally, we have two researcher reports for products from Sierra Wireless and describing vulnerabilities in the Open Charge Point Protocol for electric vehicle charging stations.

Advisories

BaiCells Advisory - BaiCells published an advisory that describes a use of hard-coded credentials vulnerability in their Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB devices.

B&R Advisory - B&R published an advisory that describes five vulnerabilities in their ARPOL database.

Hitachi Advisory - Hitachi published an advisory that discusses 60 vulnerabilities in their Disk Array Systems.

HP Advisory - HP published an advisory that describes an escalation of privilege vulnerabilities in their Factory Preinstalled Images.

HPE Advisory - HPE published an advisory that discusses a use-after-free vulnerability in their HPE OneView.

JTEKT Advisory - JP CERT published an advisory that describes seven vulnerabilities in the JTEKT Screen Creator Advance product.

Moxa Advisory - Moxa published an advisory that describes six vulnerabilities in their SDS-3008 Series web server.

Pulse Secure Advisory #1 - Pulse Secure published an advisory that discusses four OpenSSL vulnerabilities.

Pulse Secure Advisory #2 - Pulse Secure published an advisory that describes a cross-site request forgery vulnerability in their Pulse Connect Secure.

QNAP Advisory - QNAP published an advisory that describes an SQL injection vulnerability in their QTS or QuTS hero products.

VMware Advisory #1 - VMware published an advisory that describes a cross-site request forgery bypass vulnerability in their vRealize Operations (vROps).

VMware Advisory #2 - VMware published an advisory that describes an arbitrary file deletion vulnerability in their VMware Workstation product. 

Updates

VMware Update - VMware published an update for their vRealize Log Insight advisory that was originally published on January 24th, 2023.

Researcher Reports

Sierra Wireless Report - Otorio published a report describing two vulnerabilities in the Sierra Wireless AirLink products. The report contains proof-of-concept code.

OCPP Report - SaiFlow published a report describing two vulnerabilities in the WebSocket communications used by the Open Charge Point Protocol (OCPP).

 

For more details about these disclosures, including links to researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-768 - subscription required.

Thursday, May 13, 2021

4 Advisories Published – 5-13-21

Today CISA’s NCCIC-ICS published four control system security advisories for products from Unified Automation, OPC Foundation, Johnson Controls, and Rockwell.

Unified Automation Advisory

This advisory describes an exposure of sensitive information to an unauthorized actor vulnerability in the Unified Automation .NET based OPC UA Client/Server SDK Bundle. The vulnerability was reported by Eran Jacob with the Otorio Research Team. UA has new software to mitigate the vulnerability. There is no indication that Jacob has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an unauthenticated attacker to read any file on the file system.

 

NOTE: NCCIC-ICS reports that the vulnerability was originally documented by Microsoft in CVE-2015-6096.

OPC Foundation Advisory

This advisory describes an uncontrolled recursion vulnerability in the OPC Foundation OPC UA Servers. The vulnerability was reported by Eran Jacob with the Otorio Research Team. OPC has an update that mitigates the vulnerability. There is no indication that Jacob has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to trigger a stack overflow.

Johnson Controls Advisory

This advisory describes an off-by-one error vulnerability in the Sensormatic Electronics Tyco AI. This is a third-party (SUDO) vulnerability with multiple published exploits (see here, here, and here for instance). Johnson Controls has a new version that mitigates the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerability to obtain super-user access to the underlying openSUSE Linux operating system.

NOTE: The Johnson Control advisory says the product is the American Dynamics Tyco AI.

Rockwell Advisory

This advisory describes three vulnerabilities in the Rockwell Connected Components Workbench. The vulnerability was reported by Mashav Sapir of Claroty. Rockwell has a new version that mitigates the vulnerability. There is no indication that Sapir has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Deserialization of untrusted data - CVE-2021-27475,

• Path traversal - CVE-2021-27471, and

• Improper input validation - CVE-2021-27473

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow remote code execution, authentication bypass, or privilege escalation.

Tuesday, March 2, 2021

3 Advisories Published – 3-2-21

The CISA NCCIC-ICS published three control system security advisories for products from MB connect line, Rockwell Automation and Hitachi ABB Power Grids.

MB Connect Advisory

This advisory describes 18 vulnerabilities in the MB connect line mymbCONNECT24 and mbCONNECT24 remote access products. The vulnerabilities were reported by OTORIO. MB connect has a new version that mitigates most of the vulnerabilities, the remaining vulnerabilities will be fixed in a future release. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The 18 reported vulnerabilities are:

• Improper privilege management (4) - CVE-2020-12527, CVE-2020-12528, CVE-2020-35557, and CVE-2020-10384,

• Server-side request forgery (3) - CVE-2020-12529, CVE-2020-35558, and CVE-2020-35561,

• Cross-site scripting (4) - CVE-2020-12530, CVE-2020-35563, CVE-2020-35564, and CVE-2020-35569,

• Uncontrolled resource consumption - CVE-2020-35559,

• Open redirect - CVE-2020-35560,

• Insecure default initialization of resource - CVE-2020-35565,

• PHP remote file inclusion - CVE-2020-35566,

• Use of hard-coded credentials - CVE-2020-35567,

• Exposure of sensitive information to an unauthorized actor - CVE-2020-35568, and

• Files or directories accessible to external parties - CVE-2020-35570

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow a remote attacker to gain unauthorized access to arbitrary information or allow remote code execution. The OTORIO report lists that same general potential effects with much more vivid language.

NOTE: The OTORIO report refers to ‘more than 20 critical security flaws’, but does not provide a list of the vulnerabilities.

Rockwell Advisory

This advisory describes an improper input validation vulnerability in the Rockwell  CompactLogix and ControlLogix controllers. The vulnerability was reported by Yeop Chang. Rockwell has newer firmware that mitigates the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to send specially crafted CIP packet requests to a controller, which may cause denial-of-service conditions in communications with other products.

Hitachi ABB Advisory

This advisory describes two vulnerabilities in the Hitachi ABB Ellipse Enterprise Asset Management products. The vulnerabilities are self-reported. Hitachi ABB has a new version that mitigates the vulnerabilities.

NOTE: The Hitachi ABB advisory reports that the vulnerability was reported to them by a private individual via a responsible disclosure. There is no indication that the individual was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Cross-site scripting - CVE-2021-27416, and

• User interface misrepresentation of critical information - CVE-2021-27414

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to steal sensitive information, hijack a user’s session, or compromise authentication credentials.

Sunday, December 13, 2020

Public ICS Disclosures – Week of 12-5-20, Part II

This week we have nine disclosures for products from Schneider. We also have eight vendor updates for products from Siemens (5) and Schneider (3). Finally, we have two researcher reports about vulnerabilities in products from Schneider.

Schneider Advisories

Schneider published an advisory describing a write-what-where condition vulnerability in their EcoStruxure™ Control Expert. The vulnerability was reported by Jared Rittle of Cisco Talos; the report contains proof-of-concept code. Schneider provides generic workarounds pending development of remediation measures.

 

Schneider published an advisory describing an insufficiently protected credentials vulnerability in their EcoStruxure Geo SCADA Expert. The vulnerability is being self-reported. Schneider has updates available that mitigate the vulnerability.

 

Schneider published an advisory describing two vulnerabilities in their Web Server on Modicon M340 communication modules. The vulnerabilities were reported by DongJian Security Lab and the Russian BDU FSTEC (report here). Schneider has new firmware versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Forced browsing - CVE-2020-7541, and

• Improper check for unusual or exceptional conditions - CVE-2020-7539

 

Schneider published an advisory describing a missing authentication for critical function vulnerability in their Web Server on Modicon M340 communications modules. The vulnerability was reported by DongJian Security Lab. Schneider has new firmware versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

 

Schneider published an advisory describing a path traversal vulnerability on the Web Server on Modicon M340 communications modules. The vulnerability was reported by Zheng Qiang. Schneider has new firmware versions that mitigate the vulnerability. There is no indication that the researcher have been provided an opportunity to verify the efficacy of the fix.

 

Schneider published an advisory describing an improper check for unusual or exceptional conditions vulnerability in their Web Server on Modicon M340 communications modules. The vulnerability is being self-reported.

 

Schneider published an advisory describing an improper check for unusual or exceptional conditions vulnerability in their Modicon M340 CPU’s. The vulnerability was reported by the VAPT Team from C3i IITK, India. Schneider has new firmware versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

 

Schneider published an advisory describing three separate improper check for unusual or exceptional conditions vulnerabilities in their Modicon M580 controllers. The vulnerabilities were reported by Gao Jian of NSFOCUS, Daniel Lubel of OTORIO, Armis Security, Victor Fidalgo Villar of INCIBE-CERT, and Gideon Guo. Schneider has firmware updates that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

 

Schneider published an advisory describing an improper restriction of operations within the bounds of a memory buffer vulnerability in their M258 Logic Controllers and SoMachine/SoMachine Motion software. The vulnerability was reported by Kai Feng. Schneider has new versions that mitigate the vulnerability. There is no indication that Kai has been provided an opportunity to verify the efficacy of the fix.

Siemens Updates

Siemens published an update for their SegmentSmack advisory that was originally published on April 14th, 2020 and most recently updated on September 8th, 2020. The new information include updating information regarding successor products for SIMATIC RF180C and RF182C.

NOTE: NCCIC-ICS updated their advisory for this vulnerability back in September but has not updated for this Siemens update.

 

Siemens published an update for their GNU/Linux subsystem advisory that was originally published in 2018 and most recently updated on November 10th, 2020. The new information includes adding the following new vulnerabilities:

• CVE-2020-25284,

• CVE-2020-25668,

• CVE-2020-25705,

• CVE-2020-27618, and

• CVE-2020-27777

 

Siemens published an update for their Industrial Products advisory that was originally published on December 10th, 2019 and most recently updated on September 8th, 2020. The new information includes updating d information regarding successor products for SIMATIC RF182C and RFID 181EIP.

NOTE: NCCIC-ICS last updated their advisory for this product back in August.

 

Siemens published an update for their advisory that was originally published on September 9th, 2020 and most recently updated on October 13th, 2020. The new information includes adding patch links for:

• SIMATIC HMI Basic (2nd generation),

• Comfort (including SIPLUS variants), and

• Mobile Panels

NOTE: NCCIC-ICS published their advisory for these vulnerabilities back in September but has not updated it since.

 

Siemens published an update for their ZombieLoad advisory that was originally published on July 9th, 2019 and most recently updated on March 10th, 2020. The new information includes:

• Correcting mitigations for SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP and

• Providing updates for SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP

Schneider Updates

Schneider published an update for their Ripple20 advisory that was originally published on June 23, 2020 and most recently updated on November 10th, 2020. The new information includes adding remediation for:

• SCADAPack 32 RTU,

• XUPH001 OsSense communication module,

• XGCS850C201 OsiSense RFID compact smart antenna,

• ATV340E Altivar Machine Drives,

• ATV630/650/660/680/6A0/6B0 Altivar Process Drives,

• ATV930/950/960/980/9A0/9B0 Altivar Process Drives,

• VW3A3720, VW3A3721 Altivar Process Communication Modules,

• ACE850 Sepam communication interface,

• PowerLogic EGX300 Ethernet Gateway,

• PowerLogic EGX100 Ethernet Gateway, and

• Acti9 Smartlink IP

 

Schneider published an update for their CodeMeter advisory that was originally published on October 13th, 2020. The new information includes reporting that the CodeMeter V7.10a fix qualification is confirmed for EcoStruxure Machine SCADA Expert.

 

Schneider published an update for their Modicon controllers advisory that was originally published on May 14th, 2019 and most recently updated on October 18th, 2020. The new information includes adding a fix for additional attack scenario is available on M340 V3.30 for CVE-2018-7857.

Schneider Reports

Claroty published a report discussing the Modicon M221 PLC vulnerabilities reported Tuesday by Schneider.

Trustwave published a report discussing one of the Modicon M221 PLC vulnerabilities reported Tuesday by Schneider. This report contains proof-of-concept code for the one-way hash vulnerability.

Tuesday, September 29, 2020

3 Advisories Published – 9-29-20

Today the CISA NCCIC-ICS published three control system security advisories for products from B&R Automation, Yokogawa, and MB Connect.

B&R Advisory

This advisory describes six vulnerabilities in the B&R SiteManager and GateManager products. The vulnerabilities were reported by Nikolay Sokolik and Hay Mizrachi. B&R has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Path traversal - CVE-2020-11641,

• Uncontrolled resource consumption - CVE-2020-11642,

• Information exposure - CVE-2020-11643,

• Improper authentication - CVE-2020-11644,

• Uncontrolled resource consumption - CVE-2020-11645, and

• Information disclosure - CVE-2020-11646

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to  allow for arbitrary information disclosure, manipulation, and a denial-of-service condition.

Yokogawa Advisory

This advisory describes a buffer copy without checking size of input vulnerability in the Yokogawa WideField3 PLC programming tool. The vulnerability was reported by Parity Dynamics. Yokogawa has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to  terminate the program abnormally.

NOTE: I briefly discussed this vulnerability last Saturday.

MB Connect Advisory

This advisory describes four vulnerabilities in the MB Connect mymbCONNECT24, mbCONNECT24 products. The vulnerabilities were reported by Otorio. MB Connect has newer versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• SQL injection (2) - CVE-2020-24569 and CVE-2020-24568,

• Cross-site request forgery - CVE-2020-24570, and

• Command injection – no CVE has been assigned.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow a remote attacker to gain unauthorized access to arbitrary information or allow remote code execution.

NOTE: I briefly discussed these vulnerabilities last Saturday.

Saturday, September 26, 2020

Public ICS Disclosures – Week of 9-19-20

This week we have two vendor disclosures about the CodeMeter vulnerabilities from Bosch and 3S. There are four vendor disclosures for products from Mitsubishi (2), Yokogawa, and Eaton. We also have two researcher reports for vulnerabilities in products from Siemens and Aveva.

CodeMeter Advisories

Bosch published an advisory describing the CodeMeter vulnerabilities in their Rexroth Products. Bosch recommends updating the CodeMeter software. One Bosch update is available to mitigate the vulnerabilities.

3S published an advisory [.PDF download link] describing the CodeMeter vulnerabilities in a number of their products. 3S has new versions of CODESYS V3 that mitigates the vulnerability.

NOTE: This advisory would seem to indicate that the universe of vulnerable products is much larger than previously thought. Vendors using CODESYS products would not have known to check for the CodeMeter vulnerability in their systems.

Mitsubishi Advisories

Mitsubishi published an advisory describing a TCP/IP stack session management vulnerability in a number of their products. The vulnerabilities were reported by Ta-Lun Yen of Trend Micro via the Zero Day Initiative. Mitsubishi has new versions that mitigate the vulnerability in many of the affected products. There is no indication that Ta-Lun has been provided an opportunity to verify the efficacy of the fix.

Mitsubishi published an advisory describing the Ripple20 vulnerabilities in the WiFi interface for a number of their products. Mitsubishi provides generic workarounds for the vulnerabilities.

NOTE: There is no overlap in the product lists for the two advisories which would indicate that two different TCP/IP stacks are being used.

Yokogawa Advisory

Yokogawa published an advisory describing a classic buffer overflow vulnerability in their  FA-M3 Programming Tool. The vulnerability has been reported by Parity Dynamics. Yokogawa has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Eaton Advisory

Eaton published an advisory describing an uncontrolled search path element vulnerability in their 9000x programing and configuration software. The vulnerability was reported by Yongjun liu. Eaton has a new version that mitigates the vulnerability. There is no indication that Yongjun has been provided an opportunity to verify the efficacy of the fix.

Siemens Report

Otorio published a blog post describing two vulnerabilities in the Siemens PCS 7 products. According to the post Siemens will provide instruction to avoid the vulnerabilities in the “next update of SIMATIC PCS 7 Compendium Part F”.

The two reported vulnerabilities are:

• A WinCC configuration flaw, and

• A PCS 7 configuration flaw.

NOTE: I cannot find a Siemens advisory that addresses similarly described vulnerabilities, but without a CVE number I cannot really be sure that Siemens has not addressed them.

Aveva Report

Talos published a report describing three vulnerabilities in the Aveva Enterprise Data Management Web data management platform. These vulnerabilities were previously disclosed by Aveva. The Talos report includes proof-of-concept code.

Saturday, September 19, 2020

Public ICS Disclosures – Week of 9-12-20

 This week we have four disclosures for CodeMeter vulnerabilities for products from ABB and Rockwell. There are also three vendor disclosures for products from MB Connect Line, Hi-Silicon, and B&R. There are 21 researcher reports for vulnerabilities in products from Fuji Electric (20) and Sierra Wireless.

CodeMeter Advisories

ABB published an advisory for the CodeMeter vulnerabilities in their Automation Builder product. ABB provides generic workarounds while it continues to investigate the vulnerabilities.

ABB published an update for their CodeMeter advisory for ABB Products. The new information includes providing a link to the advisory described above.

ABB published an update for their CodeMeter advisory for ABB Drives applications. The new information includes changing the recommended version of CodeMeter for Windows application to version 7.10a.

Rockwell published an update for their CodeMeter advisory for FactoryTalk Activation Manager. The new information includes:

• Updated mitigation information, and

• Updated CodeMeter version information

MB Advisory

CERT-VDE published an advisory describing four vulnerabilities in the mymbCONNECT24 and mbCONNECT24 products. The vulnerabilities were reported by Otorio. MB has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Blind SQL injection - CVE-2020-24569 and CVE-2020-24568,

• SSRF/CSRF - CVE-2020-24570, and

• Unauthenticated RCE – no CVE assigned

HI-Silicon Advisory

Incibe-cert published an advisory describing five vulnerabilities in the IPTV / H.264 / H.265 video encoders based on HiSilicon Hi3520d hardware. The vulnerabilities were reported by Alexei Kojenov; the report contains proof-of-concept code. Affected manufacturers include:

• URayTech;

• J-Tech Digital;

• VeCASTER PRO from Pro Video Instruments.

The five reported vulnerabilities include:

• Backdoor password - CVE-2020-24215 and CVE-2020-24218,

• Path transversal - CVE-2020-24219,

• Unauthenticated file uploads - CVE-2020-24217,

• Buffer overflow - CVE-2020-24214, and

• Unauthorized access to video streaming through RTSP - CVE-2020-24216

B&R Advisory

B&R published an advisory for the Ripple20 vulnerabilities in their products. They report that none of their products are affected by these vulnerabilities.

Fuji Electric Reports

Kimiya published 20 reports (ZDI-20-1184 thru ZDI-20-1204) of vulnerabilities in the Fuji Electric Tellus Lite product. The vulnerabilities were reported to ‘ICS-CERT’ (presumably, NCCIC-ICS) by the Zero Day Initiative back in April. These are apparently separate vulnerabilities from the 14 that were reported last week. The reported vulnerabilities include:

• Stack-based buffer overflow,

• Out-of-bounds write, and

• Out-of-bounds read

Sierra Wireless Report

Ruben Santamarta published a blog post describing two vulnerabilities in Sierra Wireless Air Link Products. Sierra Wireless has published an advisory [.PDF download link] for these vulnerabilities. The blog post includes proof-of-concept code.

The two reported vulnerabilities are:

• Privilege escalation - CVE-2020-8781, and

• Remote code execution - CVE-2020-8782

Saturday, June 27, 2020

Public ICS Disclosures – Week of 06-20-20


This week we have six Ripple20 [Corrected link, 10-18-20, 0856 EDT] advisories from vendors, one of them an update. There were also four vendor updates from Schneider, Rockwell (2) and Yokogawa. There was a researcher report for products from OSIsoft. There were also four exploits published for products from ABUS, SICK, mySCADA and Inductive Automation.

Ripple20 Advisories and Updates


HMS published a Ripple20 advisory that identifies affected products and generic mitigations.

Eaton published a Ripple20 advisory that identifies affected products and generic mitigations.

Boston Scientific published a Ripple20 advisory that admits that some (unidentified) products have the vulnerabilities but “concluded there is no increased security risk for patients who have our implantable products because of the Treck vulnerabilities”.

Schneider published a Ripple20 advisory that identifies affected products and generic mitigations.

Schneider published a Ripple20 advisory specifically for their network management card products.

Schneider updated their Ripple20 advisory that was originally published on June 16th, 2020. Refers to the first new advisory described above.

Schneider Update


Schneider published an update of their legacy Triconex advisory that was originally published on April 14th, 2020. The new information includes adding CVE numbers and descriptions and updated affected version and mitigation data.

NOTE: The revised advisory includes an interesting discussion about why Schneider decided that this update was necessary.

Rockwell Updates


Rockwell published an update for their FactoryTalk Linx Path Traversal advisory that was originally published on June 18th, 2020. The new information includes a revised list of affected products.

Rockwell published an update for FactoryTalk Linx multiple vulnerability advisory that was originally published on June 11th, 2020. The new information includes a revised list of affected products.

NOTE: The updated information is the same in both updates. See my note on the path traversal advisory in last week’s blog post.

Yokogawa Update


Yokogawa published an update for their unquoted service path advisory that was originally published on September 27th, 2019and most recently updated November 1st, 2019. The new information includes adding three new products to the affected product list and providing mitigation links for those products.

OSIsoft Report


Otorio published a report on a cross-site scripting vulnerability in the OSIsoft PI Web API 2019. The vulnerability was disclosed by OSIsoft on June 11th, 2020. The report includes a poor-quality video demonstrating an exploit of the vulnerability.

ABUS Exploit


Matthias Deeg published an exploit for a missing encryption of sensitive data vulnerability in the ABUS Secvest Wireless Control Device (FUBE50001). This was reportedly coordinated with ABUS.

SICK Exploit


Aliasrobotics published an exploit for a default credentials vulnerability in the SICK safety PLC. There is no indication that this was reported to SICK, so this is probably a 0-day exploit.

mySCADA Exploit


Emre ÖVÜNÇ published an exploit for a hard-coded credentials vulnerability in the mySCADA myPro HMI. There is no indication that this was reported to mySCADA, so this is probably a 0-day exploit.

Inductive Automation Exploit


Pedro Ribeiro and Radek Domanski published a Metasploit module for a a Java deserialization vulnerability in the Inductive Automation Ignition SCADA product. The vulnerability was disclosed by the vendor on June 2nd, 2020 and the NCCIC-ICS advisory was subsequently updated on June 11th, 2020.

Thursday, June 11, 2020

3 Advisories Published – 6-11-20


Today the CISA NCCIC-ICS published two control system security advisories for products from Rockwell Automation and OSIsoft as well as a medical device security advisory for products from Philips.

Rockwell Advisory 


This advisory describes four vulnerabilities in the Rockwell FactoryTalk Linx Software. The vulnerabilities were reported by Sharon Brizinov and Amir Preminger, of Claroty. Rockwell has patches that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Improper input validation (2) - CVE-2020-11999 and CVE-2020-12001,
• Path traversal - CVE-2020-12003, and
• Unrestricted upload of file of dangerous type - CVE-2020-12005

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to cause a denial-of-service condition, obtain remote code execution, and read sensitive information.

OSIsoft Advisory


This advisory describes a cross-site scripting vulnerability in the OSIsoft PI Web API 2019. The vulnerability was reported by Dor Yardeni and Eliad Mualem at OTORIO. OSIsoft has a new service pack that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow a remote authenticated attacker with write access to a PI Server to trick a user into interacting with a PI Web API endpoint that executes arbitrary JavaScript in the user’s browser, resulting in view, modification, or deletion of data as allowed for by the victim’s user permissions.

Philips Advisory


This advisory describes an insertion of sensitive information into log file vulnerability in the Philips  IntelliBridge Enterprise (IBE). Indiana University Health reported the vulnerability. Philips plans a new release to mitigate the vulnerability in 4th Qtr 2020; meanwhile they provide generic mitigation measures to address the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerability to allow an attacker to access credentials to the hospital’s clinical information systems (EMR).

Saturday, March 28, 2020

Public ICS Disclosures – Week of 03-21-20


This week we have five vendor disclosures for products from Phoenix Contact (2), 3S (2) and Philips along with an update of a previous vendor disclosure from Belden. There is also an exploit publication for products from GE. Finally, an interesting look at control system security and COVID-19 ‘industrial distancing’.

Phoenix Contact Advisories


Phoenix Contact published an advisory [.PDF download link] describing a privilege escalation vulnerability in their Portico Remote desktop control software. The vulnerability was reported by an unnamed researcher. Phoenix Contact has a new version that mitigates the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.


Phoenix Contact published an advisory [.PDF download link] describing an insecure permissions vulnerability in their PC WORX SRT. The vulnerability was reported by  Sharon Brizinov of
Claroty. Phoenix Contact provides generic workarounds to mitigate the vulnerability.

3S Advisories


3S published an advisory [.PDF download link] describing an out-of-bounds memory buffer access vulnerability in their  CODESYS communication protocol. The vulnerability was reported by Carl Hurd of Cisco Talos and an OEM customer. 3S has a new version that mitigates the vulnerability. There is no indication that Hurd has been provided an opportunity to verify the efficacy of the fix.

NOTE: The Talos report includes proof-of-concept exploit code.


3S published an advisory [.PDF download link] describing a heap-based buffer overflow vulnerability in their Web Service application. The vulnerability was reported by Tenable. 3S has a new version that mitigates the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

NOTE: The Tenable report includes proof-of-concept exploit code.

Philips Advisory


Philips published an advisory describing two vulnerabilities in their AC 2719 Air Purifier when using the Air Matters Android application. Philips reports that this is a chip-level problem, but reportedly a newer version of the application mitigates the vulnerabilities (?). The vulnerabilities were reported by an unnamed researcher.

The two (3 or 4 depending on where you read in the advisory) reported vulnerabilities are:

• Cleartext transmission of information;
• Insufficient Diffie Helman strength; and
• Decompiling Android app

NOTE: Okay, I will admit that I am confused by this advisory. I cannot find a researcher report of these vulnerabilities. If someone wants to step forward and explain this to me, I would appreciate it.

GE Exploit


Ivan Marmolejo has published an exploit for a password denial of service vulnerability in the GE ProficySCADA for iOS. There is no CVE number associated with the exploit report nor any vendor contact reports and I cannot find a report of a similar vulnerability on the GE security advisory page so this looks like a 0-day exploit.

COVID-19


Otorio.com has an interesting blog post about the increase in remote access to industrial systems due to COVID-19. They introduce a fun new term ‘industrial distancing’. It is a quick read, but worth it.

Saturday, February 15, 2020

Public ICS Disclosure – Week of 2-7-20


This week we have eight vendor disclosures for products from Siemens (2), Schneider Electric, Phoenix Contact, HMS, ABB (2) and Moxa. We also have three advisory updates from Siemens and one from Schneider.

Siemens Advisories


Siemens published an advisory describing three vulnerabilities found in Intel chips used in Siemens products. The vulnerabilities were identified and reported (advisory links below) by Intel. Siemens has provided generic workarounds to mitigate the vulnerabilities.

The three reported vulnerabilities are:

• Insufficient memory protection (2) - CVE-2019-0151 and CVE-2019-0152; and
• Heap-based buffer overflow - CVE-2019-0169

Siemens published an advisory describing a resource allocation vulnerability in their Profinet-IO stack. The vulnerability was reported by Yuval Ardon and Matan Dobrushin from OTORIO. Siemens has updates that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Schneider Advisory


Schneider Published an advisory describing an uncontrolled search path element vulnerability in their ProSoft Configurator. The vulnerability was reported by Yongjun Liu from nsfocus. Schneider has a new version that mitigates the vulnerability. There is no indication that Yongiun has been provided an opportunity to verify the efficacy of the fix.

Phoenix Contact Advisory


Phoenix Contact has published an advisory [.PDF download link] describing a remote configuration vulnerability in their Emalytics Controllers. The vulnerability was reported by Anil Parmar. Phoenix Contact has a new firmware version that mitigates the vulnerability. There is no indication that Parmar has been provided an opportunity to verify the efficacy of the fix.

HMS Advisory


HMS has published an advisory describing a cross-site scripting vulnerability in their Flexy and Cosy products. The vulnerability was reported by Ander Martínez from Titanium Industrial Security. HMS has a new firmware version that mitigates the vulnerability. There is no indication that Martinez has been provided an opportunity to verify the efficacy of the fix.

ABB Advisories


ABB published an advisory describing a direct object reference vulnerability in their Asset Suite product. The vulnerability is self-reported. ABB has a new version that mitigates the vulnerability.

ABB published an advisory describing 14 vulnerabilities in their eSOMS product. The vulnerabilities are self-reported. ABB has a new version that mitigates the vulnerabilities.

Moxa Advisory


Moxa published an advisory describing 8 vulnerabilities in their OnCell cellular gateway. The vulnerabilities were reported by Alexander Zaytsev from Kaspersky Lab. Moxa has new firmware versions that mitigate the vulnerabilities. There is no indication that Zaytsey has been provided an opportunity to verify the efficacy of the fix.

Siemens Updates


Siemens published an update to their  Linux TCP SACK PANIC advisory for Industrial Products that was originally published on September 10th, 2019 and most recently updated on November 14th, 2019. The new information includes revised version data and mitigation links for:

• TIM 1531 IRC;
• SIMATIC CP 1242-7, CP 1243-7 LTE (EU andUS versions), CP 1243-1, CP 1243-8 IRC, CP 1543-1, CP 1542SP-1, CP 1542SP1 IRC, CP 1543SP-1; and
• SCALANCE W1700.

NOTE: NCCIC-ICS updated their advisory on February 11th, but did not list it on their web site.

Siemens published an update for their ZombieLoad advisory that was originally published on July 9th, 2019 and most recently updated on December 10th, 2019. The new information includes updated version data and mitigation links for:

• SIMATIC IPC547E;
• SIMATIC IPC347E; and
• SIMATIC IPC3000 SMART V2
Siemens published an update for their GNU/Linux subsystem vulnerabilities advisory that was originally published on November 27th, 2018 and most recently updated on January 14th, 2020. The new information includes adding the following new vulnerabilities;

• CVE-2019-5188;
• CVE-2019-11190;
• CVE-2019-19956;
• CVE-2019-20054,
• CVE-2019-20079;
• CVE-2019-20388; and
• CVE-2020-7595

Schneider Update


Schneider published an update for their U.motion Builder advisory that was originally published on April 5th, 2018. The new information includes an updated remediation section.

Wednesday, February 12, 2020

13 Advisories and 5 Updates Published – 2-11-20

Today the CISA NCCIC-ICS published 13 control system security advisories for products from Synergy Systems and Solutions, Digi International and Siemens (11). They also updated five control system security advisories for products from Siemens.

Synergy Systems Advisory


This advisory describes two vulnerabilities in the SSS HUSKY RTU. The vulnerabilities were reported by VAPT Team, C3i Center. SSS has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper authentication - CVE-2019-20046; and
• Improper input validation - CVE-2019-20045

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to read sensitive information, execute arbitrary code, or cause a denial-of-service condition.

Digi Advisory


This advisory describes two vulnerabilities in the Digi ConnectPort LTS 32 MEI. The vulnerabilities were reported by Murat Aydemir and Fatih Kayran of Biznet Bilisim. Digi has a new release that mitigates the vulnerabilities. There is no indication that the researchers have been provided with an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Unrestricted upload of file with dangerous type - CVE-2020-6975; and
• Cross-site scripting - CVE-2020-6973

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to limit system availability.

SIPROTEC Advisory


This advisory describes an improper input validation vulnerability in the Siemens SIPROTEC 4 and SIPROTEC Compact. The vulnerability was reported by Tal Keren from Claroty. Siemens has provided generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to conduct a denial-of-service attack over the network.

SIMATIC S7-1500 Advisory


This advisory describes a resource exhaustion vulnerability in the Siemens SIMATIC S7-1500 CPU family. The vulnerability is self-reported. Siemens has provided generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to conduct denial-of-service attacks.

SCALANCE S-600 Advisory


This advisory describes three vulnerabilities in the Siemens SCALANCE S-600 Firewall. One of the vulnerabilities was reported by Melih Berk EkÅŸioÄŸlu. Siemens has provided generic workarounds to mitigate the vulnerability.

The three reported vulnerabilities are:

• Cross-site scripting - CVE-2019-6585; and
• Uncontrolled resource consumption (2) - CVE-2019-13925 and CVE-2019-13926

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to conduct denial-of-service or cross-site scripting attacks. User interaction is required for a successful exploitation of the cross-site-scripting attack.

OZW Web Server Advisory


This advisory describes and information disclosure vulnerability in the Siemens OZW web server. The vulnerability was reported by Maxim Rupp. Siemens has a new version that mitigates the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow unauthenticated users to access project files.

SIPORT Advisory


This advisory describes an insufficient logging vulnerability in the Siemens SIPORT MP. The vulnerability is self-reported. Siemens has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow the attacker to create special accounts with administrative privileges.

SCALANCE Advisory


This advisory describes a protection mechanism failure vulnerability in the Siemens SCALANCE X switches. The vulnerability is self-reported. Siemens has updates that mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to perform administrative actions.

SIMATIC PCS 7 Advisory


This advisory describes an incorrect calculation of buffer size vulnerability in the Siemens SIMATIC PCS 7, SIMATIC WinCC, SIMATIC NET PC products. The vulnerability was reported by Nicholas Miles from Tenable. Siemens has new versions that mitigate the vulnerability. There is no indication that Miles has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker with network access to cause a denial-of-service condition.

SIMATIC S7 Advisory


This advisory describes a resource exhaustion vulnerability in the Siemens SIMATIC S7 devices. The vulnerability was reported by China Industrial Control Systems Cyber Emergency Response Team. Siemens has a new version that mitigates the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow remote attackers to perform a denial-of-service attack by sending a specially crafted HTTP request to the web server of an affected device.

PROFINET Advisory


This advisory describes a resource exhaustion vulnerability in the Siemens PROFINET-IO Stack. The vulnerability was reported by Yuval Ardon and Matan Dobrushin of OTORIO. Siemens has updates that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to lead to a denial-of-service condition.

NOTE: OTORIO reports that this same vulnerability is found in multiple vendor products including the Moxa EDS Ethernet Switches.

SIMATIC CP Advisory


This advisory describes two vulnerabilities in the Siemens SIMATIC CP 1543-1. The vulnerabilities are self-reported. Siemens has a new version that mitigates the vulnerabilities.

The two reported vulnerabilities are:

• Improper access control - CVE-2019-12815; and
• Loop with unreachable exit condition - CVE-2019-18217

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow for remote code execution and information disclosure without authentication, or unauthenticated denial of service.

Industrial Products Advisory


This advisory describes two vulnerabilities in the Siemens SCALANCE, SIMATIC, SIPLUS products. The vulnerabilities were reported by Artem Zinenko of Kaspersky Lab. Siemens has new versions that mitigate the vulnerabilities. There is no indication that Zinenko has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Data processing errors - CVE-2015-5621; and
• Null pointer dereference - CVE-2018-18065

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow remote attackers to conduct a denial-of-service attack by sending specially crafted packets to Port 161/UDP (SNMP).

SIMOCODE Update


This update provides additional information on an advisory that was originally published on March 9th, 2019 and most recently updated on January 14th, 2020. The new information includes the addition of two affected products:

• SITOP PSU8600; and
• TIM 1531 IRC

Industrial Products w/OPC UA Update


This update provides additional information on an advisory that was originally published on April 9th, 2019 and most recently updated on January 14th, 2020. The new information includes updated affected version data and mitigation links for SIMATIC NET PC Software.

PROFINET Update


This update provides additional information on an advisory that was originally published on October 10th, 2019 and most recently updated on January 14th, 2020. The new information includes updated affected version data and mitigation links for SINAMICS DCP.

Industrial Real Time Devices Update


This update provides additional information on an advisory that was originally published on October 10th, 2019 and most recently updated on January 14th, 2020. The new information includes updated affected version data and mitigation links for SINAMICS DCP.

SIMATIC Update


This update provides additional information on an advisory that was originally published on December 10th, 2019. The new information includes updated affected version data and mitigation links for:

• TIM 1531 IRC;
• SIMATIC NET PC Software

Other Siemens Advisories and Updates


Siemens also published two additional advisories and 3 updates yesterday that have not yet been addressed by NCCIC-ICS.

Additionally, on Monday Siemens published updates of 58 previously published advisories. All of these updates were adding references to the SIPLUS device variants as affected products. Siemens has been adding references to this as they have been updating advisories for the last couple of months, so it looks like they are just doing the final house cleaning on the issue. I do not expect NCCIC-ICS to update all of their applicable advisories.
 
/* Use this with templates/template-twocol.html */