Showing posts with label Philippe Z Lin. Show all posts
Showing posts with label Philippe Z Lin. Show all posts

Thursday, January 3, 2019

Three Advisories Published – 01-03-19


Today the DHS NCCIC-ICS proved that they were not currently furloughed (though still not being paid for their service) by publishing three control system security advisories for products from Hetronic, Yokogawa, and Schneider Electric.

Hetronic Advisory


This advisory describes a authentication bypass by capture-replay vulnerability in the Hetronic Nova-M family of remote control transmitters and receivers. The vulnerability was reported by Jonathan Andersson, Philippe Z Lin, Akira Urano, Marco Balduzzi, Federico Maggi, Stephen Hilt, and Rainer Vosseler via the Zero Day Initiative. Hetronic has new firmware versions that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow unauthorized users to view commands, replay commands, control the device, or stop the device from running.

Yokogawa Advisory


This advisory describes a resource management error vulnerability in the Yokogawa Vnet/IP Open Communication Driver. The vulnerability was self-reported. Yokogawa has new versions that mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to cause Vnet/IP network communications to controlled devices to become unavailable.

NOTE: I briefly discussed this vulnerability almost two weeks ago.

Schneider Advisory


This advisory describes an improper input validation vulnerability in the Schneider Pro-face GP-Pro EX devices. The vulnerability was reported by Yu Quiang of Venustech’s ADLab. Schneider has a new version that mitigates the vulnerability. There is no indication that Yu has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to modify code to launch an arbitrary executable upon launch of the program.

NOTE: I briefly discussed this vulnerability almost two weeks ago.

Commentary


I am really glad to see that NCCIC-ICS is publishing advisories during the Federal Funding Fiasco. The people doing the writing, editing, reviewing and posting of these advisories are currently working without pay though they may (probably will) be paid once the FFF is fixed, but that does not make their day-to-day life outside of the office any easier. Please remember them in your thoughts and prayers, and most importantly in your letters to your congresscritters.


Wednesday, October 24, 2018

Three Advisories Published


Yesterday the DHS NCCIC-ICS published three control system security advisories for products from Telecrane, GAIN Electronics and Advantech.

Telecrane Advisory


This advisory describes an authentication bypass by capture-replay vulnerability in the Telecrane F25 Series remote control. The vulnerability was reported by Jonathan Andersson, Philippe Z Lin, Akira Urano, Marco Balduzzi, Federico Maggi, Stephen Hilt, and Rainer Vosseler via the Zero Day Intiative. Telecrane has a new firmware version that mitigates the vulnerability. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to view commands, replay commands, control the device, or stop the device from running.

GAIN Advisory


This advisory describes three vulnerabilities in the Gain SAGA1-L series remote control. The vulnerability was reported by Marco Balduzzi, Philippe Z Lin, Federico Maggi, Jonathan Andersson, Urano Akira, Stephen Hilt, and Rainer Vosseler via ZDI. GAIN has a new firmware version that mitigates the vulnerability. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Authentication bypass by capture replay - CVE-2018-17903;
• Improper access control - CVE-2018-20783; and
Improper authentication - CVE-2018-17923

NCCIC-ICS reports that a relatively low-skilled attacker with access to an adjacent network could exploit the vulnerability to allow remote code execution and potentially delete the product’s firmware.

NOTE: It is interesting that these researchers have found similar capture and replay vulnerabilities in two different industrial remote control systems. As these wireless systems become more common will we continue to see this type of vulnerability?

Advantech Advisory


This advisory describes four vulnerabilities in the Advantech WebAccess application. The vulnerabilities were reported by Matt Powell via ZDI. Advantech has a new version available that mitigates the vulnerability. There is no indication that Powell has been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-14816;
• External control of filename or path - CVE-2018-14820;
• Improper privilege management - CVE-2018-14828; and
• Path traversal - CVE-2018-14806

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to execute arbitrary code, access files and perform actions at a privileged level, or delete files on the system.

 
/* Use this with templates/template-twocol.html */