Showing posts with label Recurity Labs. Show all posts
Showing posts with label Recurity Labs. Show all posts

Wednesday, April 17, 2019

Three Advisories Published – 04-16-19


Yesterday the DHS NCCIC-ICS published two control system security advisories for products from WAGO and Delta Industrial Automation, and one for PLC products from multiple vendors.

PLC Advisory


This advisory describes an uncontrolled resource consumption vulnerability in specific PLC products from ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO. The vulnerability was reported by Matthias Niedermaier (Hochschule Augsburg), Jan-Ole Malchow (Freie Universität Berlin), and Florian Fischer (Hochschule Augsburg). The responses range from a firmware update from Schneider, to ‘its not really a vulnerability but here are generic workarounds’, to ‘its not a vulnerability’ from Siemens. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fixes.

NCCIC-ICS reports that a relatively low-skilled attacker could use a publicly available exploit to emotely influence configured cycle times.

NOTE: The Schneider advisory referenced in this advisory was released in February and listed a 2018 CVE number for the reported vulnerability. Neither CVE number is currently available.

WAGO Advisory


This advisory describes a hard-coded credential vulnerability in the WAGO Series 750-88x and 750-87x PLCs. The vulnerability was reported by Jörn Schneeweisz of Recurity Labs. WAGO has new firmware that mitigates the vulnerability. There is no indication that Schneeweisz has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to change the settings or alter the programming of the device.

NOTE: I briefly mentioned this vulnerability last Saturday.

Delta Advisory


This advisory describes three vulnerabilities in the Delta Industrial Automation CNCSoft screen editor software. The vulnerabilities were reported by Natnael Samson and an anonymous researcher via the Zero Day Initiative. Delta has an updated version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

Stack-based buffer overflow - CVE-2019-10947;
Heap-based buffer overflow - CVE-2019-10951; and
Out-of-bounds read - CVE-2019-10949

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to cause buffer overflow conditions that may allow information disclosure, remote code execution, or crash the application.

Saturday, April 13, 2019

Public ICS Disclosures – Week of 04-06-19


This week we have four vendor disclosures from WAGO, Bosch (2), and Schneider; and two vendor updates from Siemens.

WAGO Advisory


CERT-VDE published an advisory describing a use of hardcoded credentials vulnerability in the WAGO Series 750-88x and 750-87x devices. The vulnerability was reported by Jörn Schneeweisz of Recurity Labs. WAGO has firmware updates available that mitigate the vulnerability. There is no indication that Schneeweisz has been provided an opportunity to verify the efficacy of the fix.

NOTE: I suspect that NCCIC-ICS will publish an advisory on this vulnerability next week.

Bosch Advisories


Bosch published an advisory describing a buffer overflow vulnerability in the Bosch Security Systems Software for Video, PSIM and Access. This vulnerability is apparently self-reported. Bosch has software updates that mitigate the vulnerability.

Bosch published an advisory describing an improper access control vulnerability in the Bosch Security Systems Software for Video, PSIM and Access Control Systems. This vulnerability is apparently self-reported. Bosch has software updates that mitigate the vulnerability.

Schneider Advisory


Schneider published an advisory describing an externally controlled reference to a resource vulnerability in the Schneider Modbus Serial Driver. The vulnerability was reported by Reid Wightman of Dragos. Schneider has an updated driver that mitigates the vulnerability. There is no indication that Reid has been provided an opportunity to verify the efficacy of the fix.

Siemens Updates


Siemens updated an advisory for Spectre-NG (Variants 3a and 4) Vulnerabilities in Industrial Products. Siemens added a solution for SIMATIC HMI Panels V14.
NOTE: NCCIC-ICS will not update their advisory for this vulnerability since the link to the Siemens advisory will take one to the current version.

Siemens updated an advisory for Vulnerabilities in the additional GNU/Linux subsystem
of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP. Siemens added CVE-2019-6293 to the list of vulnerabilities covered by this advisory.

NOTE: NCCIC-ICS has not published an advisories or alert on this family of Linux vulnerabilities.

 
/* Use this with templates/template-twocol.html */