Showing posts with label Pedro Ribeiro. Show all posts
Showing posts with label Pedro Ribeiro. Show all posts

Saturday, June 27, 2020

Public ICS Disclosures – Week of 06-20-20


This week we have six Ripple20 [Corrected link, 10-18-20, 0856 EDT] advisories from vendors, one of them an update. There were also four vendor updates from Schneider, Rockwell (2) and Yokogawa. There was a researcher report for products from OSIsoft. There were also four exploits published for products from ABUS, SICK, mySCADA and Inductive Automation.

Ripple20 Advisories and Updates


HMS published a Ripple20 advisory that identifies affected products and generic mitigations.

Eaton published a Ripple20 advisory that identifies affected products and generic mitigations.

Boston Scientific published a Ripple20 advisory that admits that some (unidentified) products have the vulnerabilities but “concluded there is no increased security risk for patients who have our implantable products because of the Treck vulnerabilities”.

Schneider published a Ripple20 advisory that identifies affected products and generic mitigations.

Schneider published a Ripple20 advisory specifically for their network management card products.

Schneider updated their Ripple20 advisory that was originally published on June 16th, 2020. Refers to the first new advisory described above.

Schneider Update


Schneider published an update of their legacy Triconex advisory that was originally published on April 14th, 2020. The new information includes adding CVE numbers and descriptions and updated affected version and mitigation data.

NOTE: The revised advisory includes an interesting discussion about why Schneider decided that this update was necessary.

Rockwell Updates


Rockwell published an update for their FactoryTalk Linx Path Traversal advisory that was originally published on June 18th, 2020. The new information includes a revised list of affected products.

Rockwell published an update for FactoryTalk Linx multiple vulnerability advisory that was originally published on June 11th, 2020. The new information includes a revised list of affected products.

NOTE: The updated information is the same in both updates. See my note on the path traversal advisory in last week’s blog post.

Yokogawa Update


Yokogawa published an update for their unquoted service path advisory that was originally published on September 27th, 2019and most recently updated November 1st, 2019. The new information includes adding three new products to the affected product list and providing mitigation links for those products.

OSIsoft Report


Otorio published a report on a cross-site scripting vulnerability in the OSIsoft PI Web API 2019. The vulnerability was disclosed by OSIsoft on June 11th, 2020. The report includes a poor-quality video demonstrating an exploit of the vulnerability.

ABUS Exploit


Matthias Deeg published an exploit for a missing encryption of sensitive data vulnerability in the ABUS Secvest Wireless Control Device (FUBE50001). This was reportedly coordinated with ABUS.

SICK Exploit


Aliasrobotics published an exploit for a default credentials vulnerability in the SICK safety PLC. There is no indication that this was reported to SICK, so this is probably a 0-day exploit.

mySCADA Exploit


Emre ÖVÜNÇ published an exploit for a hard-coded credentials vulnerability in the mySCADA myPro HMI. There is no indication that this was reported to mySCADA, so this is probably a 0-day exploit.

Inductive Automation Exploit


Pedro Ribeiro and Radek Domanski published a Metasploit module for a a Java deserialization vulnerability in the Inductive Automation Ignition SCADA product. The vulnerability was disclosed by the vendor on June 2nd, 2020 and the NCCIC-ICS advisory was subsequently updated on June 11th, 2020.

Tuesday, May 26, 2020

2 Advisories Published – 5-26-20

Today the NCCIC-ICS published two control system security advisories for products from Johnson Controls and Inductive Automation.

Johnson Controls Advisory


This advisory describes an improper access control vulnerability in the Johnson Controls Kantech EntraPass software. This vulnerability is self-reported. Johnson Controls has a new version that mitigates the vulnerability.

NCCIC-ICS reports that an relatively low-skilled attacker with uncharacterized access to allow an authorized low-privileged user to gain full system-level privileges.

Inductive Automation Advisory


This advisory describes three vulnerabilities in the Inductive Automation Ignition. The vulnerabilities were reported by Pedro Ribeiro, Radek Domanski, Chris Anastasio (muffin), and Steven Seeley via the Zero Day Initiative. Inductive Automation has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Missing authentication for critical function - CVE-2020-12004, and
• Deserialization of untrusted data (2) - CVE-2020-10644 and CVE-2020-12000

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to obtain sensitive information and perform remote code execution with SYSTEM privileges.

Saturday, February 23, 2019

Public ICS Disclosures – Week of 02-16-19


This week we have one vendor disclosure for products from CODESYS and two exploits for previously disclosed vulnerabilities for products from NUOO.

CODESYS Advisory


CODESYS has published an advisory that describes a directory traversal vulnerability in their runtime system. This vulnerability was reported by Ivan Cheyrezy of Schneider Electric. 3S has released a new version that mitigates the vulnerability. There is no indication that Cheyrezy has been provided an opportunity to verify the efficacy of the fix.

NOTE: Somehow, I suspect that Schneider identified this vulnerability in one of their products and traced it back to CODESYS code in that product. We may be seeing a Schneider advisory for this vulnerability in the near future.

NUOO Exploits


Pedro Ribeiro published two Metasploit modules for two vulnerabilities (here and here) that he had previously disclosed through NCCIC-ICS for vulnerabilities in the NUOO Central Management Software platform.

The two vulnerabilities for which the Metasploit modules were published are:

• Unrestricted upload of file of dangerous type; and
SQL injection


Saturday, January 26, 2019

Public ICS Disclosures – Week of 01-19-19


This week we have vendor notifications from Bosch, AVEVA, Drager, Yokogawa and BD. We also have an exploit of a previously disclosed set of vulnerabilities for products from NUUO.

Bosch Advisory


Bosch has published an advisory for two vulnerabilities in their DIVAR 400 & 600 digital recorders. The vulnerabilities were reported by Maxim Rupp. Bosch has provided generic workarounds to mitigate the vulnerability. There is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper access control; and
Unprotected credentials

AVEVA Advisory


AVEVA has published an advisory for three vulnerabilities in their Wonderware System Platform. The vulnerabilities were reported by Vladimir Dashchennko from Kaspersky Lab. AVEVA has a new update that mitigates the vulnerabilities. There is no indication that Daschennko has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Insufficiently protected credentials;
• Execution with unnecessary privilege; and
• Missing authorization

These vulnerabilities were coordinated through ‘ICS-CERT’ so I expect that we will see an advisory from NCCIC-ICS next week (though they may have a backlog to work through now that the Federal Funding Fiasco is at least temporarily over).

Drager Advisory


Drager published an advisory that is not technically for a control system vulnerability. They are advising customers of a number of reported fraudulent emails from apparent Drager email addresses that have been part of schemes to have companies make payments to non-Drager accounts.

Yokogawa Advisory


Yokogawa has published an advisory for an access control vulnerability in their License Manager Service. The vulnerability was reported by Kaspersky Lab. Yokogawa has patches that mitigate the vulnerability. There is no indication that Kaspersky Lab has been provided an opportunity to verify the efficacy of the fix.

BD Advisory


BD has published an advisory  (actually an update for an advisory that was issued last summer) for a Microsoft Windows vulnerability in the task scheduler that affects a number of BD products. BD will patch the software during the next patch cycle.

NUOO Exploit


Pedro Ribeiro published a set of exploits for the NUOO CMS software management platform. The vulnerabilities were reported by NCCIC-ICS in an advisory published on October 12th, 2018 and updated on November 20th, 2018. Ribeiro was the one who originally reported the NUOO vulnerabilities to NCCIC-ICS.

In addition to publishing four Metasploit modules as part of his exploit report, Ribeiro reports that one of the vulnerabilities reported through NCCIC-ICS (Use of hard-coded credentials - CVE-2018-17894) has not actually been fixed as was reported in the NCCIC-ICS advisory.

Reading the exploit report from Ribeiro provides an interesting look into the coordinated disclosure process where the vendor is less than cooperative. Pedro has all sorts of nice things to say about the folks he worked with at ‘ICS-CERT’ during the two-year process but suffice to say he is disappointed with NUOO.

Friday, October 12, 2018

3 Advisories and 4 Updates


Yesterday the DHS NCCIC-ICS published three control system security advisories for products from Delta Industrial Automation and NUUO (2). They also updated a previously published control system security advisory for products from Yokogawa medical device security advisories for products from Medtronic, BD and Phillips.

Delta Advisory


This advisory describes two vulnerabilities in the Delta Industrial Automation TPEditor. The vulnerabilities were reported by Ariele Caltabiano (kimiya) of 9SG Security Team and Mat Powel. Delta has a new version that mitigates the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-17929; and
Out-of-bounds write - CVE-2018-17927

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to crash the accessed device, resulting in a buffer overflow condition that may allow remote code execution.

CMS Advisory


This advisory describes four vulnerabilities in the NUUO CMS software management platform. The vulnerabilities were reported by Pedro Ribeiro. NUUO has a firmware update that mitigates the vulnerabilities. There is no indication that Ribeiro has been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Use of insufficiently random values - CVE-2018-17888;
• Use of obsolete function - CVE-2018-17890;
• Incorrect permission assignment for critical resource - CVE-2018-17892; and
• Use of hard-coded credentials - CVE-2018-17894

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to result in arbitrary remote code execution.

NVRmini2 Advisory


This advisory describes two vulnerabilities in the NUUO NVRmini2, NVRsolo network video recorders. The vulnerabilities were reported by Jacob Baines of Tenable. NUUO has a firmware update that mitigates the vulnerabilities. There is no indication that Baines has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-1149; and
• Leftover debug code - CVE-2018-1150

NCCIC-ICS reports that a relatively low-skilled attacker using publicly available exploit code could remotely exploit the vulnerabilities to achieve remote code execution and user account modification.

Yokogawa Update


This update provides additional information on an advisory that was originally reported on May 31st, 2018. The new information includes:

• Addition of four new vulnerabilities;
• Revision of exploit consequences;
• Addition of new products affected; and
• Addition of mitigation information for newly identified products.

NOTE: All of this new information was reported in a separate Yokogawa advisory that I discussed here last month. That new advisory was not referenced in this update.

Medtronic Update


This update provides additional information on an advisory that was originally published on February 27th, 2018 and updated on June 27th, 2018. The new information includes:

• Addition of a new affected product;
• Addition of statement on possible remote access exploitation;
• Addition of a third vulnerability;
• Addition of report of new mitigation measure implemented by Medtronic

An FDA notice was published for the revised Medtronic advisory.

BD Update


This update provides additional information on an advisory that was originally published on May 22nd, 2018. The new information includes a report of implementation of the promised mitigation measures.

Phillips Update


This update provides additional information on an advisory that was originally published on August 21st, 2018 and updated on August 30th, 2018. The new information includes the announcement of future mitigation measures to be undertaken by Phillips.

 
/* Use this with templates/template-twocol.html */