Showing posts with label Pro-Face. Show all posts
Showing posts with label Pro-Face. Show all posts

Tuesday, April 5, 2016

ICS-CERT Publishes 3 Advisories

This morning the DHS ICS-CERT published three advisories for control system components from Rockwell, Eaton Lighting Systems and Pro-Face. Two of the three advisories had previously been released on the US CERT Secure Portal.

Rockwell Advisory


This advisory describes an access violation memory error in the Rockwell Automation Integrated Architecture Builder (IAB) application. The vulnerability was reported by Ivan Sanchez from Nullcode Team. Rockwell has produced a software update to mitigate the vulnerability, but there is no indication that Sanchez has been afforded the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a social engineering attack is required to get an authorized user to load to introduce or change project files and then access the malformed file. ICS-CERT does not count such social engineering attacks as being remotely executable.

The advisory includes a number of additional mitigation measures that Rockwell recommends that owners implement when using the IAB application.

Eaton Lighting Systems Advisory


This advisory describes twin vulnerabilities in the Eaton Lighting Systems EG2 Web Control application. The vulnerabilities were reported by Maxim Rupp. Eaton has produced a firmware patch to mitigate the vulnerability, but there is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.

The two vulnerabilities were:

• Reliance on cookies without validation and integrity checking - CVE-2016-2272; and
• Cleartext storage of sensitive information - CVE-2016-0871

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to configure the system.

ICS-CERT reports that though a firmware patch has been made available, that Eaton will be moving this product to end of life later this year and recommends that owners upgrade to the new system. It is nice to see that the patch was developed anyway.

Pro-face Advisory


This advisory describes four vulnerabilities in the Pro-face GP-Pro EX HMI software. The vulnerabilities were reported by ZDI (the first three) and Jeremy Brown. Pro-face has produced an update module to mitigate the vulnerabilities, but there is no indication that the researchers were afforded to the opportunity to verify the efficacy of the fix.

The vulnerabilities include:

• Heap-based buffer overflow - CVE-2015-2290;
• Out-of-bounds read - CVE-2015-2291;
• Stack-based buffer overflow - CVE-2015-2292; and
• Use of hard-coded credentials - CVE-2015-7921

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerabilities to execute arbitrary code.


It is odd that a Schneider Electric company would not publish a security advisory for four vulnerabilities, two of which are fairly serious.

Friday, May 25, 2012

Two DHS ICS-CERT Advisories


Yesterday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published two advisories for control system vulnerabilities identified in Measuresoft’s SCADAPRO and the xArrow Software HMI system. Alert readers will note that the xArrow Advisory is an update from an earlier xArrow Alert.

Measuresoft Advisory


Measuresoft is an Irish SCADA manufacturer and this advisory is based upon an uncontrolled search path element vulnerability (DLL hijack) reported by Carlos Mario Penagos Hollmann in a coordinated disclosure. The vulnerability could be remotely exploited by a moderately skilled attacker; possibly resulting in execution of arbitrary code.

Measuresoft has produced upgrades for both its ScadaPro Server and Client. According to the Advisory Hollmann has verified that the upgrades appropriately mitigate the vulnerability.

xArrow Advisory


xArrow Software is a Chinese software development firm. The four vulnerabilities were identified in their HMI by Luigi back in March and reported in an uncoordinated disclosure. The vulnerabilities listed are:

• Null pointer de-reference;

• Heap-based buffer overflow;

• Out-of-bounds read; and

• Improper restriction of operations within the bounds of the memory buffer.

The Advisory states that; “No known exploits specifically target these vulnerabilities.” This contradicts what ICS-CERT said in their original Alert and Luigi is well known for having exploit code on his web site (and it looks like exploit code to me for this disclosure). This is probably one of those formatting mistakes (using a canned format for the Advisory) rather than a deliberate misstatement on the part of ICS-CERT.

Missed Alert and Advisory


I did not report on an alert and an advisory published by ICS-CERT last week. The alert was for another Luigi uncoordinated disclosure for multiple (4) vulnerabilities in the Pro-Face Pro-Server SCADA/HMI product. The advisory was a follow-up to an earlier alert about a buffer overflow vulnerability in the Advantech Studio, an automation tool used to develop HMI and SCADA systems. There is no telling what sytems Studio has been used to develop of if any have been compromised through this vulnerability.
 
/* Use this with templates/template-twocol.html */