Showing posts with label Pen Test Partners. Show all posts
Showing posts with label Pen Test Partners. Show all posts

Sunday, May 29, 2022

Review - Public ICS Disclosures – Week of 5-21-22 – Part 2

For Part 2 this week, we have four vendor updates from HP, Mitsubishi (2), and VMware. We also have researcher reports for vulnerabilities for products from Intel (3), VMware, and Boeing.

HP Update - HP published an update for their PC BIOS advisory that was originally published on February 28th, 2022 and most recently updated on April 8th, 2022.

Mitsubishi Update #1 - Mitsubishi published an update for their Factory Automation advisory that was  originally published on July 30th, 2020 and most recently updated on December 17th, 2020.

Mitsubishi Update #2 - Mitsubishi published an update for their TCP Protocol Stack advisory that was originally published on September 1st, 2020 and most recently updated on August 24th, 2021.

VMware Update - VMware published an update for their Workspace One Access advisory that was originally published on March 18th, 2022.

Intel Reports - BINARLY published three reports (including proof of concept code) of vulnerabilities in the SMM Driver On Intel Platforms.

VMware Report - Pentera Labs published a report of an incorrect default permission vulnerability (including proof-of-concept code) in the VMware vCenter Server.

Boeing Report - Okay, this one is a bit odd, but Pen Test Partners published a blog post about their recent physical investigation of a recently decommissioned (with all equipment intact) Boeing 747.

 

For more details on these disclosures, including links to third-party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-5-3a1 - subscription required.

Saturday, September 7, 2019

Public ICS Disclosures – Week of 08-31-19


This week we have a vendor disclosure from Niagara and vendor updates from Belden and Phoenix Contact. There is also a researcher report of vulnerabilities for products from Danfoss and a public report of an exploit for previously reported vulnerabilities from Siemens.

Niagara Advisory


Niagara published an advisory describing two privilege escalation vulnerabilities in their QNX operating system that is used in a number of embeded automotive systems. The vulnerabilities are apparently self-reported. Niagara has updates that mitigate the vulnerabilities.

Belden Update


Belden published an update for their advisory on the WindRiver VX works vulnerabilities (Urgent/11). The new information includes product version numbers that mitigate the vulnerabilities.

Phoenix Contact Update


Phoenix Contact published an update [.PDF download] for previously reported vulnerabilities in their AXC F 2152 products. The new information includes an added remediation option for SD-Card issue (page 6).

Danfoss Report


RiskBased Security published a report (see threatpost.com article) describing seven vulnerabilities in the Danfoss AK-EM 800 Enterprise Management solution from Danfoss for the food retail industry. This was a coordinated disclosure and Danfoss has released an updated version that mitigates the vulnerabilities. There is no indication that the researchers have verified the efficacy of the fix.

The seven reported vulnerabilities are:

Undocumented debug service predictable password remote backdoor;
LogFilesDownloadServlet unauthorized remote access;
Web interface user authentication account lockout remote DoS;
Insecure default permissions local privilege escalation;
Multiple files insecure default permissions local credential disclosure;
Web interface default credentials; and
Unsafe third-party components

Siemens Exploit


Pen Test Partners published a report on their development of an exploit for reversable encryption vulnerabilities in the Siemens SCALANCE switches. Siemens reported these vulnerabilities back in June.

Wednesday, June 12, 2019

1 Alert, 4 Advisories and 4 Updates Published – 06-11-19


Yesterday the DHS NCCIC-ICS published a medical device security advisory for the DICOM (Digital Imaging and Communications in Medicine) standard; four control system security advisories for products from Siemens; and four updates of previously published advisories for products from Siemens.

DICOM Standard Alert


This alert describes a public release with proof-of-concept code for an information disclosure vulnerability in the DICOM standard. The vulnerability was reported by Markel Picado Ortiz of Cylera Labs. NCCIC-ICS reports that an uncharacterized attacker with local access could use the POC code to allow an attacker to embed executable code into image files used by medical imaging devices.

SCALANCE X Advisory


This advisory describes a storing passwords in a recoverable format vulnerability in the Siemens SCALANCE X products. The vulnerability was reported by Christopher Wade from Pen Test Partners. Siemens has an update for one of the affected products. There is no indication that Wade has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to reconstruct passwords for users of the affected devices, if the attacker is able to obtain a backup of the device configuration.

LOGO!8 Advisory


This advisory describes two vulnerabilities in the Siemens LOGO!8 devices. The vulnerabilities were reported by Thomas Meesters from cirosec GmbH and Ruhr University of Bochum, and Christian Siemers and Irakli Edjibia from Hochschule Augsburg. Siemens has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Improper restriction of operations within the bounds of a memory buffer - CVE-2019-6571; and
Session fixation - CVE-2019-6584

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to read the communication between the affected device and a user, and compromise the availability of the targeted system.

SIMATIC Advisory


This advisory describes two vulnerabilities in the Siemens SIMATIC Ident MV420 and MV440 Families. These vulnerabilities are self-reported. Siemens has provided generic workarounds.

The two reported vulnerabilities are:

Improper privilege management - CVE-2019-10925; and
Clear-text transmission of sensitive information - CVE-2019-10926

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow a remote attacker to escalate privileges and view data transmitted between the device and the user.

Siveillance Advisory


This advisory describes three vulnerabilities in the Siemens Siveillance VMS. The vulnerabilities are self-reported. Siemens has updates available that mitigate the vulnerabilities.

The three reported vulnerabilities are:

Improper authorization - CVE-2019-6580;
Incorrect user management - CVE-2019-6581; and
Missing authorization - CVE-2019-6582

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker with network access to Port 80/TCP to change device properties, user roles, and user-defined event properties.

Industrial Products Update


This update provides additional information on an advisory that was originally published on April 9th, 2019 and updated on May 14th, 2019. The new information includes updated affected version and mitigations for:

SIMATIC Software Controller; and
SIMATIC ET 200 SP Open Controller CPU 1515SP PC2

SIMATIC Update


This update provides additional information on an advisory that was originally published on April 9th, 2019 and updated on May 14th, 2019. The new information includes updated affected version and mitigations for:

SIMATIC Software Controller; and
SIMATIC ET 200 SP Open Controller CPU 1515SP PC2

SCALANCE X Update


This update provides additional information on an advisory that was originally published on March 26th, 2019. The new information includes updated affected version and mitigations for SCALANCE X-200.

SCALANCE X Switches Update


This update provides additional information on an advisory that was originally published on June 18th, 2018 and updated on January 31st, 2019. The new information includes updated affected version and mitigations for SCALANCE X200RNA.

NOTE: There were two other Siemens updates issued yesterday that were not covered by NCCIC-ICS, now do I suspect that they will address them. I will report on them Saturday.

 
/* Use this with templates/template-twocol.html */