Showing posts with label Raheem Beyah. Show all posts
Showing posts with label Raheem Beyah. Show all posts

Saturday, May 18, 2019

2 Advisories Published – 05-16-19


On Thursday the DHS NCCIC-ICS published two control system security advisories for products from Fuji Electric and Schneider Electric.

Fuji Advisory


This advisory describes an out-of-bounds read vulnerability in the Fuji Alpha7 PC Loader motor controller. The vulnerability was reported by kimiya of 9SG Security Team via the Zero Day Initiative. Fuji has a new version that mitigates the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to crash the device..

Schneider Advisory


This advisory describes a use of insufficiently random values vulnerability in the Schneider Modicon M580, Modicon M340, Modicon Premium, and Modicon Quantum products. The vulnerability was reported by David Formby and Raheem Beyah of Fortiphyd Logic and Georgia Tech. Schneider has a firmware update available for one of the products and has provided generic workarounds for the others. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to to hijack TCP connections or cause information leakage.

Tuesday, May 23, 2017

ICS-CERT Publishes 3 Advisories

Today the DHS ICS-CERT published two industrial control system advisories for products from Rockwell and Moxa. They also published a medical control system advisory for products from B Braun Medical. The Rockwell advisory was previously published on the NCCIC Portal on April 25th, 2017. The Braun Medical advisory was previously published on the NCCIC Portal on March 23rd, 2017l

B Braun Medical Advisory


This advisory describes an open redirect vulnerability on the B Braun Medical SpaceCom module. The vulnerability was reported by Marc Ruef and Rocco Gagliardi of scip AG. Braun has produced a software update that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to  allow URL redirection to untrusted web sites.

Rockwell Advisory


This advisory describes multiple vulnerabilities in the Allen-Bradley MicroLogix 1100 and 1400 PLCs. The three of the vulnerabilities were reported by David Formby and Raheem Beyah of Georgia Tech and Fortiphyd Logic, Inc with the last one being reported by Ilya Karpov of Positive Technologies. Rockwell has provided a firmware update for one of the affected products and recommends disabling the web server as an alternative and/or additional mitigation measure. There is no indication that the researchers have been provide an opportunity to verify the efficacy of the fix.

The reported vulnerabilities are:

• Predictable value range from previous values - CVE-2017-7901;
• Reusing a nonce, key pair in encryption - CVE-2017-7902;
• Information exposure - CVE-2017-7899;
• Improper restriction of excessive authentication attempts- CVE-2017-7898; and
• Weak password requirements - CVE-2017-7903

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerabilities  to gain unauthorized access to the affected programmable logic controllers and to spoof or disrupt TCP connections.

Moxa Advisory


This advisory describes three vulnerabilities in the Moxa OnCell IP gateways. The vulnerabilities were reported by Maxim Rupp. Moxa reports that the latest version of two of the products mitigate the vulnerabilities and provides a work around for the remainder. There is no indication that Rupp was provided an opportunity to verify the efficacy of the fix.

The reported vulnerabilities are:

• Improper restriction of excessive authentication attempts - CVE-2017-7915;
• Plain text storage of a password - CVE-2017-7913; and
• Cross-site request forgery - CVE-2017-7917


ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to allow an attacker to use brute force to determine parameters needed to access the application. An attacker may also obtain credentials by obtaining files that store passwords in clear text.

Thursday, March 10, 2016

ICS-CERT Publishes Schneider Advisory

This afternoon the DHS ICS-CERT published an advisory for an improper Ethernet frame padding vulnerability in the Schneider Electric Telvent SAGE 2300 and 2400 remote terminal units (RTUs). The vulnerability was reported by David Formby and Raheem Beyah of Georgia Tech. A previously released software version mitigates the vulnerability. The researchers have validated the efficacy of the current software to fix the vulnerability.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to read the leaked packet data.

This is the same ‘IEEE conformance issue’ that this research team has reported in systems from other two suppliers (here and here). Interestingly the most recent other example (first one listed here) included an early release of the advisory on the US CERT Secure Portal, even though as in this case, the vulnerability had been corrected in a previously released version of the software.

GPS Timing Issue



While looking at the Schneider web site for information on this vulnerability (I did not find any) I came across a very interesting notice about a GPS timing issue that had been identified (no attribution of identification was provided) in the Trimble GPS card. Those cards are now reporting dates with year 1996 instead of 2016 and have been since February 14th, 2013 because of an error in the firmware. I suppose that system owners that actually use those affected 0x41 and 0x8F-20 messages will have already noticed this problem. According to Trimble (.PDF download) they are not able to update the firmware to correct this problem, so it has to be corrected in the software/firmware that uses the reported data. The Schneider notice reports that they have updated the firmware for their C3413 and C3414 CPU Cards.

Tuesday, November 24, 2015

ICS-CERT Publishes Two Advisories

This afternoon the DHS ICS-CERT published two control system advisories for systems from Eaton’s Cooper and Moxa.

Eaton’s Cooper Advisory

This advisory describes an IEEE conformance issue involving improper frame padding in Eaton’s Cooper Power Systems Form 6 controls and Idea/IdeaPLUS relays equipped with Ethernet. The vulnerability was reported by David Formby and Raheem Beyah of Georgia Tech. An updated version of the systems (associated with another recent ICS-CERT Advisory) has been confirmed by the researchers to be free of the vulnerability.

ICS-CERT reports that a relatively unskilled attacker with network access to unencrypted packets would be able to read the leaked data.

This advisory was published on the US CERT Secure Portal on October 22nd, 2015. Again, the early notification is available to all critical infrastructure owners and legitimate researchers granted access by ICS-CERT. See bottom of the ICS-CERT landing page for information on how to apply for this access.

This is the second advisory for this sort of issue. Both were based upon reports by Formby and Beyah. How many more systems will they find with this vulnerability? Who knows, perhaps vendors should start looking themselves? Or not. Maybe Formby and Beyah can build a startup business on their technique for finding this vulnerability and then expand it into other areas of vulnerability research. I seem to recall another team that started out in a similar manner.

BTW: Eaton’s Cooper calls this a TCP/IP protocol stack vulnerability. It sounds a little bit more impressive, but perhaps not quite as descriptive.

Moxa Advisory

This advisory describes two vulnerabilities in the Moxa OnCell Central Manager Software. The vulnerabilities were reported through the Zero Day Initiative by Andrea Micalizzi. Moxa has produced a new version but there is no indication that Micalizzi has been provided an opportunity to verify the efficacy of the fix.

The two vulnerabilities are:

• Use of hard-coded credentials - CVE-2015-6481; and
• Authentication by-pass issues - CVE-2015-6480.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to gain full system access.


BTW: The Moxa release notes on the new version do list the authentication by-pass issue, but does not mention the hard-coded credentials

Thursday, June 18, 2015

ICS-CERT Publishes Two Advisories

This afternoon the DHS ICS-CERT published two advisories for vulnerabilities in industrial control systems from Schneider Electric and Wind River.

Schneider Advisory

This advisory describes a fixed search path vulnerability (Schneider calls it a binary planting vulnerability) in the Wonderware System Platform. The vulnerability was reported by Ivan Sanchez of WiseSecurity Team. Schneider has produced a patch to mitigate the vulnerability and according to ICS-CERT Sanchez has verified the efficacy of the fix.

ICS-CERT reports that this vulnerability would require a social engineering attack to get an authorized user to load a specially configured DLL file. A successful exploit would allow execution of arbitrary code.

Wind River Advisory

This advisory describes a TCP predictability vulnerability in the VxWorks operating system. The vulnerability was reported by Raheem Beyah, David Formby, and San Shin Jung of Georgia Tech. Wind River has produced patches for the vulnerability, but there is no indication that the Georgia Tech team has been given the opportunity to verify the efficacy of the fix.

ICS-CERT reports that VxWorks is used in a number of ICS devices from a number of vendors. The VxWorks web site notes that the operating system is used in drones, medical devices and consumer IOT devices in addition to the ICS devices. ICS-CERT has contacted a number of vendors about the vulnerability. To date only Schneider Electric has produced a firmware patch to fix the VxWare vulnerability in some of their SAGE RTUs. Additional updates to the advisory will be issued when additional vendor information becomes available.


ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to spoof or disrupt TCP connections to the affected devices. The Schneider advisory [.PDF Download] for the Sage RTUs notes that a successful exploit could allow a man-in-the-middle attack.

Tuesday, June 2, 2015

ICS-CERT Publishes Two Advisories

This morning the DHS ICS-CERT published two new control system advisories; one for Moxa SoftCMS and the other for Beckwith Electric TCP.

Moxa Advisory

This advisory describes a buffer overflow vulnerability in the SoftCMS software package that manages large scale surveillance systems. The vulnerability was reported through HP’s Zero Day Initiative (ZDI) by Ariele Caltabian. Moxa has developed a new version that mitigates the vulnerability but there is no indication that Caltabian has been given the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to execute arbitrary code.

Beckwith Electric Advisory

This advisory describes a TCP initial sequence numbers vulnerability in two of Beckwith Electric’s digital voltage regulator controllers. The vulnerability was initially reported by Raheem Beyah, David Formby, and San Shin Jung of Georgia Tech in two devices. Subsequent work by Beckwith Electric disclosed similar vulnerabilities in four other devices. Beckwith has produced firmware updates for five of the six devices and the researchers have verified the efficacy of the fix in the original two devices. A separate mitigation measure is being made available for the other device (the M-6280 Digital Capacitor Bank Control).

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to spoof a TCP connection to the device.

As always I would like to commend Beckwith Electric for taking the extra effort to uncover similar vulnerabilities in other devices. This indicates a proactive approach to control system security design.
 
/* Use this with templates/template-twocol.html */