Showing posts with label Progea Movicon. Show all posts
Showing posts with label Progea Movicon. Show all posts

Saturday, October 22, 2011

ICS-CERT Updates Duqu and Luigi

Yesterday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) issued a second update to their alert about the W32.Duqu Trojan and provided an advisory for one the round-2 Luigi vulnerabilities (leaving by my count just two round-2.1 vulnerabilities unaddressed by vendors).

Duqu and ICS Vendors/Systems


Did Duqu get over hyped? Well the latest update to the ICS-CERT alert would certainly seem to indicate that. The lead paragraph to the updated section states:

“ICS-CERT, in close coordination with Symantec and the original researchers, has determined after additional analysis that neither industrial control systems nor vendors/manufacturers were targeted by Duqu [emphasis in original]. In addition, as of October 21, 2011, there have been very few infections and there is no evidence based on current code analysis that Duqu presents a specific threat to industrial control systems.”

Boy doesn’t that make Symantec seem to be a tad bit overblown in their report? Maybe, but it gets less clear when you go to the Symantec blogs and see what they have to say. This is from Eric Chien on their late night update yesterday:

I wrote Symantec's original blog post describing the discovery of Duqu. In that blog I use the term "industrial control system manufacturers" and (after discussions with a variety of parties) we want to change that term to "industrial industry manufacturers" to more accurately define where Duqu has been found. We already made this change to our paper.”

Okay, can someone please explain to me what an ‘industrial industry manufacturer’ is? Symantec doesn’t define the term but they do note that the change in language doesn’t affect who they think is at risk. Then they add this clarifying remark:

“Considering the history of Stuxnet, the potential of the same attackers, and currently known targets, we urge industrial control system manufacturers and any other organizations who provide solutions to industrial facilities to audit their network for Duqu. The command and control IP is a reliable network indicator of Duqu infection for all the variants discovered so far.”

Well, it is still early in the Duqu story and if Stuxnet is any clue we will be talking about updates for quite some time.

Updates for Luigi 2.0


Okay that (Luigi 2.0) is my term so I better explain it; it refers to the second batch of multiple disclosures made by Luigi Auriemma back in September. There have been some individual disclosures made by Luigi since then they could be numbered 2.X sequentially. If he makes another mass disclosure it would be 3.0. Enough about terminology…

The last of the 2.0 disclosures was addressed in the ICS-CERT advisory issued yesterday and it dealt with the Progrea Movicon HMI. Three vulnerabilities were addressed, two buffer overflows (CVE-2011-3491 and CVE-2011-3498) and one memory corruption (CVE-2011-3499). A ‘hot fix’ has been developed by Progea to address these vulnerabilities.

According to the ICS-CERT Advisory a low skilled attacker could remotely exploit these vulnerabilities to conduct a DOS attack. A ‘skilled attacker’ (Sorry guys an ‘attacker with a low skill level’ is still a ‘skilled attacker’; your terminology needs to be cleaned up; try at least a ‘more skilled attacker’) could exploit these vulnerabilities to execute arbitrary code.

Tuesday, June 14, 2011

ICS-CERT Updates Progea Movicon Advisory for Known Exploits

When the DHS Industrial Control System Cyber Emergency Response Team (ICS- CERT) first published their advisory on the Progea Movicon TCPUploadServer Vulnerability back in March they stated that: “No exploits are known to target this vulnerability.” That has obviously changed as the revision to that advisory published today notes that: “Known exploits are now targeting this vulnerability. ICS-CERT strongly urges existing users to update vulnerable installations as soon as possible.”

Have There Been Attacks?

The ‘strongly urges’ wording would seem to imply that exploits have been detected in actual use against systems using the Progea Movcon human machine interface identified in this advisory. If this is the case, it would be nice if ICS-CERT would clearly state that and provide appropriate (and probably limited) details about such attacks (appropriately scrubbed to protect the victim’s identity, of course).

HMI Vulnerabilities

Readers might recall that this was just one of a number of HMI related ICS-CERT advisories and alerts issued this year. One of the problems with these systems is that they are typically bundled as part of an overall control system. While one might expect to find this vulnerable HMI in a Progea SCADA system, it is not clear that only Progea systems would contain this HMI.

Given the recent history of HMI vulnerabilities and now possibly actual attacks via those HMI vulnerabilities, it would be a very smart move for facility cyber security officers to know what HMI is used in their on-site SCADA systems. The vendor should certainly be able to provide that information (whether they are willing is potentially a completely different story).

Remember though; if your SCADA system uses (for example) the Progea Movicon HMI do not assume that you can apply the Progea patch to a non-Progea system. Contact your vendor or ICS-CERT for advice on how to proceed.
 
/* Use this with templates/template-twocol.html */