Showing posts with label Radu Motspan. Show all posts
Showing posts with label Radu Motspan. Show all posts

Tuesday, December 17, 2019

2 Advisories Published – 12-17-19


Today the CISA NCCIC-ICS published two control system security blogs for products from Siemens and GE.

Siemens Advisory


This advisory describes 54 vulnerabilities in the Siemens SPPA-T3000 servers. The vulnerabilities were reported by Gleb Gritsai, Eugenie Potseluevskaya, Sergey Andreev, and Radu Motspan from Kaspersky Lab; Vyacheslav Moskvin, and Ivan B from Positive Technologies; and Can Demirel from Biznet Bilisim Sistemleri ve Danışmanlık. Siemens has an update that mitigates three of the vulnerabilities on one of the affected products. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

Sorry, I am not going to list the 54 vulnerabilities.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to execute arbitrary code on the server, cause a denial-of-service condition, view and modify passwords, gain root privileges, access sensitive information, and read and write arbitrary files on the local system.

NOTE: This is the new vulnerability of the Siemens monthly drop from last week. I briefly discussed these vulnerabilities last Saturday.

GE Advisory


This advisory describes a cross-site scripting vulnerability in the GE S2020/S2020G Fast Switch 61850, a managed Ethernet switch. The vulnerability was reported by Murat Aydemir of Biznet Bilisim A.S.. GE has a new version that mitigates the vulnerability. There is no indication that Aydemir has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to inject arbitrary code and allow disclosure of sensitive data.

Wednesday, December 12, 2018

Two Advisories and Three Updates Published – 12-11-18


Yesterday the DHS NCCIC-ICS published two control system security advisories and updates to two previously published control system advisories; all for products from Siemens. They also published a medical device security advisory for products from Philips.

SINUMERIK Advisory


This advisory describes ten vulnerabilities in the Siemens SINUMERIK Controllers. The vulnerabilities were reported by Anton Kalinin, Danila Parnishchev, Dmitry Sklyar, Gleb Gritsai, Kirill Nesterov, Radu Motspan, and Sergey Sidorov from Kaspersky Lab. Siemens has updates for several of the products and provides work arounds for the others. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The ten reported vulnerabilities are:

• Heap-based buffer overflow - CVE-2018-11457;
• Integer overflow or wraparound - CVE-2018-11458;
• Protection mechanism failure (2) - CVE-2018-11459 and CVE-2018-11460;
• Permission, privileges and access control (2) - CVE-2018-11461 and CVE-2018-11462;
• Stack-based buffer overflow - CVE-2018-11463; and
Uncaught exception (3) - CVE-2018-11464, CVE-2018-11465 and CVE-2018-11466

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to cause denial-of-service conditions, privilege escalation, or allow remote code execution.

SINAMICS Advisory


This advisory describes an improper access control vulnerability in the Siemens SINAMICS PERFECT HARMONY GH180 (based upon a 3rd party vulnerability – McAffee Application and Change Control). The vulnerability was reported by McAffee. Siemens recommends installing a McAffee update to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with physical access could exploit the vulnerability to compromise the HMI, and by extension, the drive system.

PROFINET Update


This update provides new information on an advisory that This update provides additional information on an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th,  November 28th, 2017January 18th, 2018, January 25th, 2018, January 27th, 2018, March 6th, 2018, May 3rd, 2018 and most recently on November 13th, 2018. The update provides new affected version information and mitigation measures for:

• SIMATIC ET 200MP IM155-5 PN HF; and
• SIRIUS ACT 3SU1 interface module PROFINET

Industrial Products Update


This update provides new information on an advisory that This update provides additional information on an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th, November 28th, February 27th, 2018, May 3rd, 2018 May 15th, 2018, September 11th, 2018, October 9th, 2018 and most recently on November 13th, 2018. This update provides new mitigation information for SIMATIC ET 200MP IM155-5 PN HF.

Philips Update


This update provides new information on an advisory that was originally published on March 27th, 2018. This update slips the new version expected date from ‘December 2018’ to ‘Q1 of 2019’.

Other Siemens Updates


Yesterday Siemens published a total of three new advisories and seven updates. We may see more from NCCIC-ICS later this week, but some will not be specifically addressed by NCCIC-ICS. I will have further information on the remainder on Saturday.

Thursday, March 1, 2018

ICS-CERT Published 3 Advisories and Update the Meltdown Alert


Today the DHS ICS-CERT published three new control system security advisories for products from Delta Industrial Automation, Moxa and Siemens. They also updated the previously published alert for the Meltdown and Spectre chip vulnerabilities.

Delta Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Delta DOPSoft human machine interface. The vulnerability was reported by Ghirmay Desta via the Zero Day Initiative. Delta has a new version that mitigates the vulnerability. There is no indication that Desta has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause the device the attacker is accessing to crash; a buffer overflow condition may allow remote code execution.

Moxa Advisory


This advisory describes three vulnerabilities in the Moxa OnCell high-speed industrial-grade IP gateway. The vulnerabilities were reported by Kirill Nesterov, Eugenie Potseluevskaya, and Radu Motspan of Kaspersky Labs. Moxa has released a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Reliance on cookies without validation and integrity checking - CVE-2018-5455;
• Improper handling of length parameter inconsistency - CVE-2018-5453; and
Null pointer dereference - CVE-2018-5449

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability  to remotely execute code on the device.

Siemens Advisory


This advisory describes multiple vulnerabilities in the Siemens SIMATIC, SIMOTION, and SINUMERIK industrial computers. These vulnerabilities were self-reported by Siemens. The Siemens security advisory reports that these are 3rd party vulnerabilities in the Intel Management Engine (ME), Intel Server Platform Services (SPS), and Intel Trusted Execution Engine (TXE)

The eight reported vulnerabilities are:

• Stack-based buffer overflow (5) - CVE-2017-5705, CVE-2017-5706, CVE-2017-5707, CVE-2017-5712, and CVE-2017-5711; and
• Permissions, privileges, and access controls (3) - CVE-2017-5708, CVE-2017-5709, and CVE-2017-5710

ICS-CERT reports that a relatively low-skilled attacker could remotely (some of the vulnerabilities require local access) to execute arbitrary code or gain unauthenticated access to sensitive data.

NOTE: Again, with 3rd party vulnerabilities one has to wonder what other systems will be affected. But, since Intel is such a small company (right) it is unlikely that any other vendors will use this vulnerable code (pardon the sarcasm).

Meltdown Update


This update provides additional information on an alert that was originally published on January 11th, 2018 and updated on January 16th, 2018, January 17th, 2018, January 30th, 2018, February 20th, 2018, and again on February 22nd, 2018.

The advisory provides links to new vendor reports on the vulnerabilities:

Dräger;
Pepperl+Fuchs; and

 
/* Use this with templates/template-twocol.html */