Showing posts with label Progea. Show all posts
Showing posts with label Progea. Show all posts

Saturday, November 4, 2017

Public ICS Disclosure – Week of 10-29-17

This week Karn Ganeshen provided proof of concept (POC) information on three previously published ICS-CERT vulnerabilities and Joel Langill provided a link to an ABB KRACK advisory.

POC Information


Karn continues to use the FullDisclosure web site to provide to provide additional information about control system vulnerabilities that he has previously disclosed through the DHS ICS-CERT. This week he has provided POC information on the following control system vulnerabilities:

Progea Movicon SCADA/HMI – earlier reported here (there was no mention of publicly available POC in the ICS-CERT advisory);
JanTek JTC-200 – earlier reported here (publicly available POC was mentioned in ICS-CERT advisory); and
SpiderControl SCADA Web Server – earlier reported here (there was no mention of publicly available POC in the ICS-CERT advisory)

Based upon past experience, I do not expect ICS-CERT to update their vulnerability reports to reflect the fact that POC information is now available. Given the fact that ICS-CERT has reported that relatively low skilled attackers could exploit these vulnerabilities, I think that it is important that owners of these systems has this information available to help them appropriately assess the risks to their systems.

KRACK Vulnerability


Joel’s post on LinkedIn pointed at a cybersecurity advisory from ABB for their  ABB TropOS wireless mesh products concerning the WPA2 Key Reinstallation Vulnerabilities (also known as the Key Reinstallation Attack – KRACK).

As I pointed out in the resulting LinkedIn conversation this is the second vendor specific advisory on the KRACK vulnerability. Unlike the earlier report, ABB includes 7 of the 10 CVE found in the KRACK report, indicating that they have probably reviewed all 10 of the vulnerabilities in their system.


I continue to be disappointed in ICS-CERT for not having published a control system alert for the KRACK problem since these vulnerabilities will affect almost all ICS products that use WPA2 security for wireless communications in their control system products.

Tuesday, October 17, 2017

ICS-CERT Publishes Progea Advisory

Today the DHS ICS-CERT published a control system security advisory for the Progea Movicon SCADA/HMI. It describes two vulnerabilities in the product. The vulnerabilities were reported by Karn Ganeshen. Progea has only provided a generic Microsoft workaround for DLL hijacking at this point. ICS-CERT does not report any further scheduled response.

The two reported vulnerabilities are:

• Uncontrolled search path element - CVE-2017-14017; and
• Unquoted search path or element - CVE-2017-14019


ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerabilities to allow privilege escalation or arbitrary code execution.

Tuesday, April 15, 2014

ICS-CERT Publishes Three Advisories – Two from HeartBleed

Today the DHS ICS-CERT published three advisories for vulnerabilities in industrial control systems applications from Siemens, Progea Movicon, and Innominate. Two of those (the first and last) are related to HeartBleed.

Siemens Advisory

This advisory provides a list of Siemens products that contain or are affected by the HeartBleed vulnerability. They currently only provide one updated to mitigate the vulnerability but do note that they are working on the other product updates. The unusual move to self-identify vulnerable systems before mitigation measures are available was almost certainly undertaken because tools to test for the HeartBleed vulnerability and exploit code for the bug both exist in the wild.

Siemens reports that the following products are affected:

● eLAN-8.2 eLAN < 8.3.3 (affected when RIP is used - update available)
● WinCC OA only V3.12 (always affected)
● S7-1500 V1.5 (affected when HTTPS active)
● CP1543-1 V1.1 (affected when FTPS active)
● APE 2.0 (affected when SSL/TLS component is used in customer implementation)
Siemens has an update available for eLAN (v 8.3.3) and recommends the following interim mitigation measures for the other products until the appropriate update is published:

● WinCC OA V3.12:
o Use VPN for protecting SSL traffic
o Use WinCC OA in a trusted network
●  S7-1500 V1.5:
o Disable the web server, or
o Limit web server access to trusted networks only
o Remove the certificate from the browser
● CP1543-1 V1.1:
o Disable FTPS, or
o Use FTPS in trusted network, or
o Use the VPN functionality to tunnel FTPS
● APE 2.0:
o Update OpenSSL to 1.0.1g before distributing a solution. Follow instructions from Ruggedcom [3] to patch APE 2.0
The VPN recommendations should have come with a caveat that the VPN should have its HeartBleed status investigated before it is used to protect a control system remote access.

Progea Advisory

This advisory is for an information disclosure vulnerability reported by Celil Ünüver of SignalSEC Ltd in a coordinated disclosure. Progea has developed an update that ICS-CERT reports has been checked and validated by Celil.

ICS-CERT reports that a moderately skilled attacker could remotely execute an attack using this vulnerability to gain access of OS version information.

Innominate Advisory

This advisory notes that Bob Radvanovsky of Infracritical notified ICS-CERT that Innominate has updated their mGuard product firmware to deal with the HeartBleed vulnerability included in versions of those devices. The advisory points at the Innominate advisory published last Friday. Bob also reported this last Friday on the SCADASec List.

HeartBleed Reporting

It will be interesting to see how many of these HeartBleed advisories get published by ICS-CERT. Most of these will end up being self-reported (even the Innominate advisory was essentially self-reported). I also doubt that there will be much more information in any of the upcoming advisories than we have seen in these two today.


It may be easier for ICS-CERT to just set up a HeartBleed page and updated it when necessary by listing the vendors that have published firmware or software updates that mitigate the vulnerability. I think it would be easier and more informative.
 
/* Use this with templates/template-twocol.html */