Showing posts with label RandoriSec. Show all posts
Showing posts with label RandoriSec. Show all posts

Saturday, October 5, 2019

Public ICS Disclosures – Week of 09-28-19


This week we have one vendor disclosure from Moxa.

Moxa Advisory


Moxa published an advisory describing a stack-based buffer overflow vulnerability in the Moxa EDR-810 Series Secure Routers. The vulnerability was reported by Guillaume Lopes of Randorisec. Moxa has a new firmware version that mitigates the vulnerability. There is no indication that Lopez has been provided an opportunity to verify the efficacy of the fix.

Commentary


This advisory was available on the Moxa CSRT web page when the NCCIC-ICS Moxa advisory for the same product (different vulnerabilities) was published earlier this week. It affects the same product versions and looks like it was mitigated with the same firmware update, and the vulnerabilities were reported by the same organization/researcher. Should the three vulnerabilities have been covered in a single advisory? Probably, but it is hard to tell from the outside.

The interesting thing here is that Moxa now has a CSRT web page where they publish their advisories. They have four advisories that were published on September 25th that would have made it onto last week’s blog post if I had known the CSRT web site existed last week.

It is nice to see an industrial IOT vendor moving forward into the responsible security realm. Let’s hope that this is the start of a trend.

Tuesday, October 1, 2019

4 Advisories Published – 10-01-19


Today the DHS NCCIC-ICS published three control system security advisories for products from Moxa, Yokogawa and Interpeak and a medical device security advisory for products from Interpeak.

Moxa Advisory


This advisory describes two vulnerabilities in the Moxa Moxa EDR 810 router. According to the Moxa advisory these vulnerabilities was reported by Guillaume Lopes of Randorisec (not included in NCCIC-ICS advisory). Moxa has new firmware that mitigates the vulnerabilities. There is no indication that Lopes was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Improper input validation - CVE-2019-10969; and
Improper access control - CVE-2019-10963

 NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow remote code execution or access to sensitive information.

Yokogawa Advisory


This advisory describes an unquoted search path or element vulnerability in the Yokogawa Exaopc, Exaplog, Exaquantum, Exasmoc, Exarqe, GA10, and InsightSuiteAE products. The vulnerability is self-reported. Yokogawa has revisions or updates for most of the affected products.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow a local attacker to execute malicious files.

NOTE: I briefly reported this vulnerability on Saturday.

Interpeak ICS Advisory


This advisory describes eleven vulnerabilities in Interpeak IPnet stack. These vulnerabilities were previously reported as the Wind River URGENT/11 vulnerabilities. This advisory now reports that the vulnerabilities are also found the following real-time operating systems (RTOS):

ENEA - OSE4 and OSE5;
Green Hills Software - INTREGRITY RTOS;
ITRON; and
IP Infusion – Zebos;

Interpeak Medical Device Advisory


This advisory describes the same URGENT/11 vulnerabilities due to problems in the Interpeak IPnet stack as described above. The only difference is that this version provides links to medical device vendor advisories.

Commentary


The two Interpeak advisories point out (AGAIN) how interconnected software systems are. Vulnerabilities found in one system are frequently found in 3rd party software that is used by vendor instead of writing new code. This is done for a variety of reasons, but frequently it is because a vendor does not have either the resources or the expertise in-house to develop the necessary code. This certainly makes economic sense.

Unfortunately, there does not seem to be a system in place to ensure that other vendors that use the same code are notified in a timely manner so that they can fix the related problems. In some cases, I suspect notifications are made, corrective action is taken, but the vendor never reports the vulnerability. The lack of notification is usually due to not wanting to look bad, but it does little to help owners of the affected products who do not update because their systems are ‘working fine’; their decisions might be made differently (or not) if they knew about the vulnerabilities.

Wednesday, March 21, 2018

ICS-CERT Publishes 2 Advisories and 3 Updates

Yesterday the DHS ICS-CERT published two new control system advisories for products from Siemens and Geutebruck. It also updated three previously published control system advisories for products from Siemens (2) and AutomationDirect. ICS-CERT has missed some recent Siemens updates and an advisory.

Siemens Advisory


This advisory describes an improper input validation vulnerability in the Siemens SIMATIC, SINUMERIK, and PROFINET IO products. The vulnerability is being self-reported by Siemens. Siemens has provided updates that mitigate the vulnerability is some products and has provided generic workarounds for the remaining products while updates are developed for them.

ICS-CERT reports that an uncharacterized attacker on an adjacent network could exploit this vulnerability to execute a denial-of-service condition requiring a manual restart to recover the system. The Siemens security advisory notes that OSI Layer 2 access is required to exploit the vulnerability.

Geutebruck Advisory


This advisory describes six vulnerabilities in the Geutebruck IP cameras. The vulnerabilities were reported by Davy Douhine of RandoriSec and Nicolas Mattiocco of Greenlock. Geutebruck has a new firmware version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Improper authentication - CVE-2018-7532;
• SQL injection - CVE-2018-7528;
• Cross-site request forgery - CVE-2018-7524;
• Improper access control - CVE-2018-7520;
• Server-side request forgery - CVE-2018-7516; and
• Cross-site scripting - CVE-2018-7512

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to lead to proxy network scans, access to a database, adding an unauthorized user to the system, full configuration download including passwords, and remote code execution.

SIMATIC Update


This update provides additional information on an advisory that was originally published on February 27th, 2018. It provides updated version information and mitigation measures for:

• SIMATIC IPC547G: Update BIOS to R1.21.0

SIPROTEC Update


This update provides additional information on an advisory that was originally published on July 6th, 2017, and updated on July 18th, on July 28th, on October 10th, on November 30th, and then again on January 4th, 2018. It provides updated version information and mitigation measures for:

• SIPROTEC 7SJ66: All versions prior to V4.30


AutomationDirect Update


This update provides additional information on an advisory that was originally published on November 9th, 2017. It adds a new product (Do-more Designer) to the list of vulnerable products and provided mitigation links for that product.

Missing Siemens Updates


Siemens has published updates and advisories that have not been covered in this latest series of ICS-CERT publications. Normally, I would not mention the ones from yesterday (two updates here and here, and a new advisory here), but today’s new Siemens advisory was also released yesterday. There is also an update from last week (here) that was not mentioned.

Two of the updates (here and here) are for the Spectre and Meltdown vulnerabilities in the Siemens Industrial products. ICS-CERT is unlikely to update their alert to reflect these new mitigation measures since the existing link to the Siemens advisory will take someone to the new information. This is a potential problem for anyone that is relying on ICS-CERT for information, but because of the way that ICS-CERT does their updates (and does not provide detailed change information) this appears to be unavoidable.

Thursday, September 14, 2017

ICS-CERT Updates an Advisory and Publishes Another

Today the DHS ICS-CERT updated a previously published advisory for a product from Siemens. They also published a new advisory for a product from LOYTEC.

Siemens Update


This update provides additional information on an advisory that was originally published on originally published on May 9th, 2017 and updated on June 15, 2017, on July 25th, 2017, and then again on August 18th, 2017. The update provides new affected version information and mitigation links for:

• SCALANCE M-800,S615: All versions prior to V04.03,

LOYTEC Advisory


The advisory describes four vulnerabilities in the LOYTEC LVIS-3ME HMI touch panel. The vulnerabilities were reported by Davy Douhine of RandoriSec. LOYTEC has released a firmware update to mitigate the vulnerabilities. There is no indication that Douhine was provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Relative path traversal - CVE-2017-13996;
• Insufficient entropy - CVE-2017-13992;
• Improper neutralization of input during web page generation - CVE-2017-13994; and
• Insufficiently protected credentials - CVE-2017-13998


ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to cause information exposure or allow arbitrary code execution.

Tuesday, February 14, 2017

ICS-CERT Publishes 3 Advisories and 3 Updates

Today the DHS ICS-CERT published three control system security advisories for products from Siemens, Geutebrück and Advantech. They also updated three control system security advisories for products from Siemens and Rockwell.

Siemens Advisory


This advisory describes an authentication bypass vulnerability in the Siemens SIMATIC Logon application. This vulnerability is being self-reported by Siemens. Siemens has produced an updated version of the application to mitigate the vulnerability.

ICS-CERT reports that an relatively low skilled attacker could remotely exploit this vulnerability to circumvent user authentication under certain conditions.

Geutebrück Advisory


This advisory describes two vulnerabilities in the Geutebrück G-Cam IP camera. The vulnerabilities were reported by Davy Douhine of RandoriSec, Florent Montel and Frédéric Cikala. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Authentication bypass using an alternative path or channel - CVE-2017-5174;
• Improper neutralization of special elements used in an OS command - CVE-2017-5173

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to bypass authentication and obtain remote anonymous access to the device; these vulnerabilities may allow remote code execution.

Advantech Advisory


This advisory describes a DLL hijacking vulnerability in the Advantech WebAccess application. The vulnerability was reported by Li MingZheng Kuangn. Advantech has produced a new version to mitigate the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could exploit the vulnerability o execute arbitrary code within the system. ICS-CERT does not mention what type access is required or comment on the need for an social engineering attack.

Siemens APOGEE Update


This update provides additional information about an advisory originally published on March 22nd, 2016. The update includes:

• A correction of the name of one of the reporting institutions;
• Additional information about the affected versions; and
• Reports a new version that mitigates the vulnerability.

Siemens Industrial Produces Update


This update provides additional information about an advisory originally published on November 8th, 2016 and then updated on November 22nd, 2016 and updated again on December 22nd. The update includes:

• Updated ‘version affected’ information on SIMATIC IT Production Suite;
• Provided mitigation information for SIMATIC IT Production Suite; and
• Removed SIMATIC IT Production Suite from the temporary fix list.

Rockwell Update


This update provides additional information about an advisory originally published on January 5th, 2017. The update includes:

• Adds PowerFlex 700S drives to the list of affected devices;
• Adds DriveLogix 5730 controller option explanation; and

• Explains that the PowerFlex 700S is not covered by the new firmware version mitigation.

Thursday, January 26, 2017

ICS-CERT Publishes Two Advisories

Today the DHS ICS-CERT published two control system security advisories for products from Belden and Eaton.

Belden Advisory


This advisory describes a path traversal vulnerability in the Belden Hirschmann GECKO. The vulnerability was reported by Davy Douhine of RandoriSec. Belden produced a new version to mitigate the vulnerability. There is no indication that Douhine was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a highly skilled attacker could remotely exploit this vulnerability to access a copy of the configuration file of an affected device without authenticating, exposing sensitive information. The Belden Security Bulletin notes that only administrators that are using the configuration download feature are affected.

Eaton Advisory


This advisory describes path traversal vulnerability in legacy Eaton ePDUs. The vulnerability was reported by Maxim Rupp. The affected products are no longer supported; Eaton suggests using defense in depth mitigation measures if the devices are not replaced.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to access configuration files.


NOTE: For some reason this vulnerability was presented in last year’s format. I’ve already gotten so used to the new format that this reversion feels odd. Oh well….
 
/* Use this with templates/template-twocol.html */