Showing posts with label Ralf Spenneberg. Show all posts
Showing posts with label Ralf Spenneberg. Show all posts

Friday, April 14, 2017

ICS-CERT Publishes Two Advisories

Yesterday the DHS ICS-CERT published two control system security advisories for products from Schneider Electric and Wecon Technologies.

Schneider Advisory


This advisory describes two vulnerabilities in the Schneider Modicon M221 PLCs and SoMachine Basic. The vulnerabilities were reported by Simon Heming, Maik Brüggemann, Hendrik Schwartke, and Ralf Spenneberg of Open Source Security. Schneider has announced an encryption work around and that they will introduce a new version of SoMachine Basic in June.

The two reported vulnerabilities are:

• Use of Hard-Coded Cryptographic Key – CVE-2017-7574; and
• Protection Mechanism Failure – CVE-2017-7575

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities using a publicly available exploit to extract a protected project file from the controller to obtain sensitive project information, or allow a user with access to a protected project file to decrypt it in order to obtain sensitive information without authorization.

Interestingly, the Schneider security notification only addresses the vulnerability in their SoMachine Basic; ignoring the vulnerability in their Modicon M221 PLCs. Could that vulnerability be a ‘design feature’?

NOTE: These are the vulnerabilities that I reported on last weekend. OpenSource published the vulnerabilities on their web site (here and here) a week ago last Tuesday.

Wecon Advisory


This advisory describes two buffer overflow vulnerabilities in the Wecon LEVI Studio HMI Editor. The vulnerabilities were reported by Andrea (rgod) Micalizzi, working with iDefense Labs. Wecon has developed a new version that mitigates the vulnerabilities. There is no indication that rgod has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Heap-based buffer overflow – CVE-2017-6037; and
• Stack-based buffer overflow – CVE-2017-6035


ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to cause the device to become unresponsive; a buffer overflow condition may allow remote code execution.

Saturday, April 8, 2017

Public ICS Vulnerability Disclosure – Week of 04-02-17

This week there were three public control system security vulnerability disclosures; two published on the Full Disclosure web site and one on SecurityWeek.com. The affected devices include data loggers, network connection devices and PLCs.

PLCs


On Wednesday Eduard Kovacs published an article about twin vulnerabilities in the Schneider Electric Modicon programmable logic controllers (PLCs) that were reported by Simon Heming, Maik Brüggemann, Hendrik Schwartke, Ralf Spenneberg of OpenSource Security. The reported vulnerabilities were:

• Hardcoded encryption key; and
• Password sent in clear text

Schneider received notification of the vulnerabilities back in December, but some snafu occurred and no action was taken. OpenSource published the vulnerabilities on their web site (here and here) on Tuesday.

NOTE: I tweeted about this vulnerability on Wednesday.

Data Logger


On Thursday Karn Ganeshen announced multiple vulnerabilities in data loggers, meter monitors and electric meters from SenNet. The reported vulnerabilities are:

• No access control on the remote shell;
• Shell services running with excessive privileges;
• OS command injection (with POC); and
• Insecure transport

Ganeshen reported that the vendor has fixed the vulnerabilities and ICS-CERT will be issuing an advisory.

Network Connection Devices


On Thursday Karn Ganeshen announced SNMP vulnerabilities in network communication equipment from Cambium. The reported vulnerabilities are:

• SNMP community strings privileges are not enforced correctly;
• Device configuration backups – access control issues; and

Ganeshen also reports that the Cambium devices are also subject to the following design flaws that magnify the above vulnerabilities:

• It is possible to access full device configuration using SNMP. Device configuration includes usernames, passwords, SSIDs, keys, certificates, syslog config, and other network & wifi specific details.
• It is possible to trigger configuration backups, which can then be retrieved using SNMP.
• It is possible to wipe out and / or make changes to the device configuration remotely.


Ganeshen reports that ICS-CERT was notified on September 12th, 2016 and on April 5th Cambium announced that the vulnerabilities would be fixed in 2nd Quarter 2017.

Tuesday, March 15, 2016

ICS-CERT Publishes Siemens Advisory

This morning the DHS ICS-CERT published an advisory for a protection mechanism failure vulnerability in the Siemens SIMATIC S7-1200 CPU. The vulnerability was reported by Maik Brüggemann and Ralf Spenneberg from Open Source Training. The newest version (December 2014) of the firmware does not include this vulnerability.


ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to circumvent user program block protection. The Siemens Security Advisory notes that the attacker must have network access to an affected device, and the PLC’s access protection must be disabled for this vulnerability to be exploited.

Friday, January 23, 2015

ICS-CERT Publishes Advisory and TIP

Yesterday the DHS ICS-CERT published an advisory for a vulnerability in a Siemens system and a tip about best practices for continuity of operations.

Siemens Advisory

This advisory describes an open redirect vulnerability in the Siemens SIMATIC S7-1200 CPU family. The vulnerability was reported to Siemens by Ralf Spenneberg, Hendrik Schwartke, and Maik Brüggemann from OpenSource Training. Siemens has provided an update that mitigates this vulnerability, but there is no indication that the researchers have verified the efficacy of the fix.

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to redirect users to a malicious web site. The exploit would require a social engineering attack.

BTW: Still no mention of the Siemens NTP vulnerability.

Continuity TIP

This document provides a rather extensive list of things to ensure the survivability of a network from a malicious intrusion. This looks to be more targeted at IT and network systems than specifically directed at control system security.


I did not see anything new or earth shattering, nor is anything described in the detail necessary for someone that doesn’t already understand this stuff to implement. This may, however, provide a basic check list for managers to use to question their cybersecurity folks on the status of their security processes.
 
/* Use this with templates/template-twocol.html */