Showing posts with label Rainer Vosseler. Show all posts
Showing posts with label Rainer Vosseler. Show all posts

Saturday, July 11, 2020

Public ICS Disclosures – Week of 7-4-20


This week we have three new Ripple20 advisories and one update. We have two additional vendor disclosures for products from Moxa and GE.

Ripple20 Advisories and Updates


HMS published a Ripple20 advisory which provides a list of HMS products which are not affected by the vulnerabilities.

CERT-VDE published a Ripple20 advisory for the MIELE Communication Module XKM3000 L MED. It provides information on affected equipment and announces that: “A security patch will be installed on the devices during regular maintenance and device requalification by the Miele customer service or authorized service partners.”

Draeger published a Ripple20 advisory announcing that Draeger medical devices are not affected.

Braun published a Ripple20 update that lists their Outlook 400ES infusion pump as their only affected product and that they are continuing to review Treck patches for applicability.

Moxa Advisory


Moxa has published an advisory describing two vulnerabilities in their MGate 5105-MB-EIP Series Protocol Gateways. The vulnerabilities were reported by Philippe Lin, Marco Balduzzi, Luca Bongiorni, Ryan Flores, Charles Perine, and Rainer Vosseler via the Zero Day Initiative. Moxa has new firmware that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Authentication bypass by capture replay - CVE-2020-15494, and
• Exposure of sensitive information to an unauthorized actor - CVE-2020-15493

GE Advisory


GE has published an advisory describing the third-party Ghostcat vulnerability in their APM Connect UDLP 2.8 and earlier products relying upon Apache Tomcat servers. GE provides detailed mitigation measures.

NOTE: As with all third-party vulnerabilities, there is a potential for other ICS vendors to be affected by the same problem.

Thursday, January 3, 2019

Three Advisories Published – 01-03-19


Today the DHS NCCIC-ICS proved that they were not currently furloughed (though still not being paid for their service) by publishing three control system security advisories for products from Hetronic, Yokogawa, and Schneider Electric.

Hetronic Advisory


This advisory describes a authentication bypass by capture-replay vulnerability in the Hetronic Nova-M family of remote control transmitters and receivers. The vulnerability was reported by Jonathan Andersson, Philippe Z Lin, Akira Urano, Marco Balduzzi, Federico Maggi, Stephen Hilt, and Rainer Vosseler via the Zero Day Initiative. Hetronic has new firmware versions that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow unauthorized users to view commands, replay commands, control the device, or stop the device from running.

Yokogawa Advisory


This advisory describes a resource management error vulnerability in the Yokogawa Vnet/IP Open Communication Driver. The vulnerability was self-reported. Yokogawa has new versions that mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to cause Vnet/IP network communications to controlled devices to become unavailable.

NOTE: I briefly discussed this vulnerability almost two weeks ago.

Schneider Advisory


This advisory describes an improper input validation vulnerability in the Schneider Pro-face GP-Pro EX devices. The vulnerability was reported by Yu Quiang of Venustech’s ADLab. Schneider has a new version that mitigates the vulnerability. There is no indication that Yu has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to modify code to launch an arbitrary executable upon launch of the program.

NOTE: I briefly discussed this vulnerability almost two weeks ago.

Commentary


I am really glad to see that NCCIC-ICS is publishing advisories during the Federal Funding Fiasco. The people doing the writing, editing, reviewing and posting of these advisories are currently working without pay though they may (probably will) be paid once the FFF is fixed, but that does not make their day-to-day life outside of the office any easier. Please remember them in your thoughts and prayers, and most importantly in your letters to your congresscritters.


Wednesday, October 24, 2018

Three Advisories Published


Yesterday the DHS NCCIC-ICS published three control system security advisories for products from Telecrane, GAIN Electronics and Advantech.

Telecrane Advisory


This advisory describes an authentication bypass by capture-replay vulnerability in the Telecrane F25 Series remote control. The vulnerability was reported by Jonathan Andersson, Philippe Z Lin, Akira Urano, Marco Balduzzi, Federico Maggi, Stephen Hilt, and Rainer Vosseler via the Zero Day Intiative. Telecrane has a new firmware version that mitigates the vulnerability. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to view commands, replay commands, control the device, or stop the device from running.

GAIN Advisory


This advisory describes three vulnerabilities in the Gain SAGA1-L series remote control. The vulnerability was reported by Marco Balduzzi, Philippe Z Lin, Federico Maggi, Jonathan Andersson, Urano Akira, Stephen Hilt, and Rainer Vosseler via ZDI. GAIN has a new firmware version that mitigates the vulnerability. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Authentication bypass by capture replay - CVE-2018-17903;
• Improper access control - CVE-2018-20783; and
Improper authentication - CVE-2018-17923

NCCIC-ICS reports that a relatively low-skilled attacker with access to an adjacent network could exploit the vulnerability to allow remote code execution and potentially delete the product’s firmware.

NOTE: It is interesting that these researchers have found similar capture and replay vulnerabilities in two different industrial remote control systems. As these wireless systems become more common will we continue to see this type of vulnerability?

Advantech Advisory


This advisory describes four vulnerabilities in the Advantech WebAccess application. The vulnerabilities were reported by Matt Powell via ZDI. Advantech has a new version available that mitigates the vulnerability. There is no indication that Powell has been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-14816;
• External control of filename or path - CVE-2018-14820;
• Improper privilege management - CVE-2018-14828; and
• Path traversal - CVE-2018-14806

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to execute arbitrary code, access files and perform actions at a privileged level, or delete files on the system.

 
/* Use this with templates/template-twocol.html */