Showing posts with label Reid Wightman. Show all posts
Showing posts with label Reid Wightman. Show all posts

Thursday, September 24, 2020

1 Update Published – 9-24-20

 Today the CISA NCCIC-ICS published an update for a control system security advisory for products from 3S.

CODESYS Update

This update provides additional information on an advisory that was originally published on January 11th, 2013. The new information includes:

• Adding CODESYS Control RTE to list of affected products,

• For CVE-2012-6068, replaced the ‘CVSS v2 base score of 10.0’ with the ‘CVSS v3 base score of 9.8’ along with the associated changes in CVSS vector string, and

• For CVE-2012-6069, replaced the ‘CVSS v2 base score of 10.0’ with the ‘CVSS v3 base score of 10.0’ along with the associated changes in CVSS vector string.

The update is a bit more complicated than that as NCCIC-ICS partially updated the format of the advisory to reflect a number of editorial changes made in the last seven years.

Commentary

Okay, a little background is in order on this ancient (in cyber years, but not as ancient in control system years) advisory. The CVE-2012-6068 vulnerability was initially reported by Reid Wightman at AppSec DC in April 2012. Dale Peterson has an excellent write up of the importance of this vulnerability over on DigitalBond. ICS-CERT published an Alert about the vulnerability on April 6th, 2012 and then updated that Alert on October 26th, 2012 to reflect the publication of two exploit tools by Reid. Eventually (January 11th, 2013) ICS-CERT upgraded the Alert to the Advisory that was updated today. Oh, BTW, the 3S advisory for these vulnerabilities is no longer on their Security Reports web page; they only go back to February 14th, 2017.

It seems a little more than odd that 3S would add a product to the affected product list seven+ years later. They either just now realized that the product was affected even though it was apparently ‘fixed’ at the same time as the other two affected products were, or they knew all along and just did not want to tell anyone about the problem in that product since it had not been identified by Reid. In either case it just emphasizes the apparent lack of concern at 3S about device security. And that is very disconcerting given the number of other vendors that use these affected products.

Friday, July 24, 2020

1 Advisory Published – 7-23-20


Yesterday the CISA NCCIC-ICS published a control system security advisory for products from Schneider Electric.

Schneider Advisory

This advisory describes five vulnerabilities in the Schneider Triconex TriStation and Triconex Tricon Communication Module. The vulnerabilities were reported by Reid Wightman of Dragos, Inc. Schneider has new versions that mitigate the vulnerabilities and has pushed notification to customers.

The five reported vulnerabilities are:

• Cleartext transmission of sensitive information - CVE-2020-7483,
• Uncontrolled resource consumption - CVE-2020-7484 and CVE-2020-7486,
• Hidden functionality - CVE-2020-7485, and
• Improper access control - CVE-2020-7491

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to view clear text data on the network, cause a denial-of-service condition, or allow improper access.

Tuesday, July 14, 2020

9 Advisories Published – 7-14-20


Today the CISA NCCIC-ICS published eight control system security advisories for products from Siemens (6), Moxa and Advantech. They also published one medical device security advisory for products from Capsule Technologies.

NOTE: NCCIC-ICS also published 12 updates, but I will not try to get a report done on those this evening. Look for it tomorrow morning

Logo Advisory


This advisory describes a classic buffer overflow vulnerability in the Siemens LOGO! Web Server. The vulnerability was reported by Alexander Perez-Palma and Dave McDaniel from Cisco Talos and Emanuel Almeida from Cisco Systems. Siemens has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to  allow remote code execution..

Opcenter Advisory


This advisory describes three vulnerabilities in the Seiemens  Opcenter Execution Core. The vulnerabilities are self-reported. Siemens has a new version that mitigates the vulnerabilities.

The three reported vulnerabilities are:

• Cross-site scripting - CVE-2020-7576,
• SQL injection - CVE-2020-7577, and
• Improper access control - CVE-2020-7578
NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to obtain session cookies, read and modify application data, read internal information, and perform unauthorized changes. Should the attacker gain access to the session cookies, they could then hijack the session and perform arbitrary actions in the name of the victim.

SIMATIC S7 Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the Siemens SIMATIC S7-200 SMART CPU family. The vulnerability was reported by Ezequiel Fernandez. Siemens has a new version that mitigates the vulnerability. There is no indication that Fernandez has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to cause a denial-of-service condition.

UMC Stack Advisory


This advisory describes three vulnerabilities in the Siemens UMC Stack. The vulnerabilities were reported by Victor Fidalgo of INCIBE and Reid Wightman of Dragos. Siemens has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Unquoted search path or element - CVE-2020-7581,
• Uncontrolled resource consumption - CVE-2020-7587, and
• Improper input validation - CVE-2020-7588

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to cause a partial denial-of-service condition on the UMC component of the affected devices under certain circumstances. This could also allow an attacker to locally escalate privileges from a user with administrative privileges to execute code with SYSTEM level privileges.

SIMATIC HMI Advisory


This advisory describes a cleartext transmission of sensitive information in the Siemens SIMATIC HMI Panels. The vulnerability was reported by Richard Thomas and Tom Chothia of the University of Birmingham.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to access sensitive information under certain circumstances.

SICAM Advisory


This advisory describes nine vulnerabilities in the Seimens SICAM MMU, SICAM T and SICAM SGU products. The vulnerabilities were reported by Luca Simbürger, Luca Hofschuster, Lukas Kahnert, Jakob Lachermeier, Christian Costa, Simon Huber, Lukas Sas Brunschier, Florian Freiberger, Florian Burger, Marie-Louise Oostveen, Magdalena Thomeczek, and Johann Uhrmann from Landshut University of Applied Sciences and Max Hirschberger, Simon Hofmann, and Peter Knauer from Augsburg University of Applied Sciences. Siemens has updates that mitigate the vulenrabilites. There is no indication that researchers have been provided an opportunity to verify the efficacy of the fix.

The nine reported vulnerabilities are:

• Out-of-bounds read - CVE-2020-10037,
• Missing authentication for critical function - CVE-2020-10038,
• Missing encryption of sensitive data - CVE-2020-10039,
• Use of password has with insufficient computational effort - CVE-2020-10040,
• Cross-site scripting - CVE-2020-10041,
• Classic buffer overflow - CVE-2020-10042,
• Basic XSS - CVE-2020-10043, and
• Authentication bypass by capture replay - CVE-2020-10045

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to affect the availability, read sensitive data, and gain remote code execution on the affected devices.

Moxa Advisory


This advisory describes a stack-based buffer overflow in the Moxa EDR-G902 and EDR-G903 Series Routers. The vulnerability was reported by Tal Keren of Claroty. Moxa has a firmware patch that mitigates the vulnerability. There is no indication that Keren has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to  crash the device being accessed; a buffer overflow condition may allow remote code execution.

NOTE 1: NCCIC-ICS did not publish a link to the Moxa advisory.

NOTE 2: I briefly discussed this vulnerability last month.

Advantech Advisory


This advisory describes six vulnerabilities in the Advantech iView device management application. The vulnerabilities were reported by rgod via the Zero Day Initiative. Advantech has a new version that mitigates the vulnerability. There is no indication that rgod has been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• SQL injection - CVE-2020-14497,
• Path traversal - CVE-2020-14507,
• Command injection - CVE-2020-14505,
• Improper input validation - CVE-2020-14503,
• Missing authentication for critical function - CVE-2020-14501, and
• Improper access control -CVE-2020-14499

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to read/modify information, execute arbitrary code, limit system availability, and/or crash the application.

Capsule Technologies Advisory


This advisory describes protection mechanism failure in the Capsule Technologies SmartLinx Neuron 2 medical device platform. The vulnerability was reported by Patrick DeSantis of Cisco Talos (NOTE: Talos report includes exploit code). Capsule Technologies has a new version that mitigates the vulnerability. There is no indication that DeSantis has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could use publicly available code to exploit the vulnerability to provide an attacker with full control of a trusted device on a hospital’s internal network.

Saturday, June 6, 2020

Public ICS Disclosures – Week of 5-30-20


This week we have three vendor disclosures from Phoenix Contact, PEPPERL+FUCHS and SICK plus an update of a previous vendor disclosure from Johnson Controls.

Phoenix Contact Advisory


Phoenix Contact published an advisory [.PDF download link] describing a buffer overflow vulnerability in the Linux Point-to-Point Protocol (PPP) daemon in their FL MGUARD, TC MGUARD, TC ROUTER and TC CLOUD CLIENT devices. The vulnerability is apparently being self-reported. Phoenix Contact has firmware versions that mitigate the vulnerability.

NOTE: this is the same vulnerability, CVE-2020-8597, reported the week before by Belden.

PEPPERL+FUCHS Advisory


CERT VDE published an advisory describing two vulnerabilities in the PEPPERL+FUCHS PACTware. The vulnerabilities were reported by Reid Wightman of Dragos, Inc. PEPPERLY+FUCHS has new versions that mitigate the vulnerabilities. There is no indication that Wightman has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Storing passwords in recoverable format - CVE-2020-9403, and
• Unverified password change - CVE-2020-9404

SICK Advisory


SICK published an advisory describing a profile programming vulnerability in their bar code scanners. The vulnerability was reported by Ruben Santamarta of IOActive. SICK provides a workaround to mitigate the vulnerability.

NOTE: This is another ‘a feature is a vulnerability’ situation. These barcode scanners can be ‘programed’ by the barcodes that they scan. Thus, substituting a malicious bar code can upset the system to which the scanner is attached. The fix is to disable the feature.

Johnson Controls Update


Johnson Controls published an update for an advisory that was originally published on May 21st, 2020 and most recently updated on May 29th, 2020. The new information includes a minor modification to the mitigation instruction for American Dynamics victor Video Management System v5.2 (change “Securely delete the installer log file…” to “Delete the installer log file…”).

The NCCIC-ICS published their advisory on these vulnerabilities (ICSA-20-142-01), but has not yet addressed any of the Johnson Controls updates.

Saturday, April 11, 2020

Public ICS Disclosures -Week of 4-4-20


This week we have three vendor disclosures for products from B&R Automation, Moxa and Rockwell Automation. There are also two sets of researcher reports for products from Advantech and Universal Robots.

B&R Advisory


B&R published an advisory describing three vulnerabilities in their Automation Studio. The vulnerabilities were reported by Yehuda Anikster and Amir Preminger from Claroty. B&R has updates that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Privilege escalation – CVE-2019-19100;
• Incomplete communication encryption and validation CVE-2019-19101;
Zip Slip vulnerability (third-party vulnerability) CVE-2019-19102

Moxa Advisory


Moxa published an advisory on the kr00k vulnerability in their products. They report that none of their products are affected.

NOTE: Negative reports about 3rd party vulnerabilities are just as important as reporting an active vulnerability in a product.

Rockwell Advisory


Rockwell published an advisory describing a file permission vulnerability in their Current Program Updater software. The vulnerability was reported by Reid Wightman from Dragos. Rockwell has new versions that mitigate the vulnerability. There is no indication that Reid has been provided an opportunity to verify the efficacy of the fix.

NOTE: Rockwell is reporting a 2017 CVE (CVE-2017-5176) for this vulnerability. That vulnerability was reported by ICS-CERT on March 21st, 2017. If NCCIC-ICS were to pick up this advisory it would probably be as an update to that earlier advisory.

Advantech Reports


The Zero Day Initiative published five related reports (here, here, here, here, and here) for 0-day arbitrary file deletion vulnerabilities in the Advantech WebAccess program. The vulnerabilities were reported by Natnael Samson. ZDI reports that it has reported all five vulnerabilities to Advantech and ICS-CERT (their naming not mine) noting: “The vendor communicated that they will rely on existing measures and will add no amendments to the code.”

Universal Robots Reports


Aliasrobotics published four reports of vulnerabilities for products from Universal Robots. The vulnerabilities were reported by rvd-bot, bedieber and bbreilin. Aliasrobotics reportedly contacted Universal Robots about these vulnerabilities but has received no replies.

The four reported vulnerabilities are (links are to github pages which include proof-of-concept exploit code):

• Missing encryption of sensitive data - CVE-2020-10267;
• Missing authentication for critical function - CVE-2020-10265;
• Insufficient verification of data authenticity - CVE-2020-10266; and
• Exposure of sensitive information to unauthorized actor - CVE-2020-10264

Friday, May 3, 2019

Three Advisories Published – 05-02-19


Yesterday the DHS NCCIC-ICS published three control system security advisories for products from Sierra Wireless, GE, and Orpak

Sierra Wireless Advisory


This advisory describes seven vulnerabilities in the Sierra Wireless AirLink ALEOS. The vulnerabilities were reported by Carl Hurd and Jared Rittle of Cisco Talos. Sierra Wireless reports that the latest version of ALEOS (not all yet available) mitigates the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The seven reported vulnerabilities are:

OS command injection - CVE-2018-4061;
Use of hard-coded credentials - CVE-2018-4062;
Unrestricted upload of file with dangerous type - CVE-2018-4063
Cross-site scripting - CVE-2018-4065;
Cross-site request forgery - CVE-2018-4066;
Information exposure - CVE-2018-4067; and
Missing encryption of sensitive data - CVE-2018-4069

The Talos web site lists six additional vulnerabilities (with exploits) {NOTE: the Sierra Wireless advisory (.PDF Download) explains these ‘vulnerabilities’}:

Information exposure -  CVE-2018-4068;
Unverified password change - CVE-2018-4064;
Information disclosure (2) - CVE-2018-4070, CVE-2018-4071; and
Permission assignment (2) - CVE-2018-4072, CVE-2018-4073

NCCIC-ICS reports that a relatively low-skilled attacker could use publicly available exploits to remotely exploit these vulnerabilities to remotely execute code, discover user credentials, upload files, or discover file paths.

GE Advisory


This advisory describes five vulnerabilities in the General Electric Communicator. Reid Wightman of Dragos. GE has a new version that mitigates the vulnerability. There is no indication that Reid has been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

Uncontrolled search path (2) - CVE-2019-6564 and CVE-2019-6546;
Hard-coded credentials - CVE-2019-6548; and
Improper access controls (2) - CVE-2019-6544 and CVE-2019-6566

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to gain administrative privileges, manipulate widgets and UI elements, gain control over the database, or execute administrative commands.

Orpak Advisory


This advisory describes six vulnerabilities in the Orpak SiteOmat fuel management software. The vulnerabilities were reported by Ido Naor of Kaspersky Lab. Orpak has an update available that mitigates the vulnerability. This is no indication that Naor has been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

Use of hard-coded credentials - CVE-2017-14728;
Cross-site scripting - CVE-2017-14850;
SQL injection - CVE-2017-14851;
Missing encryption of sensitive data - CVE-2017-14852;
Code injection - CVE-2017-14853; and
Stack-based buffer overflow - CVE-2017-14854

NCCIC-ICS reports that a relatively low-skilled attacker could use publicly available exploits (NOTE: The exploits have been available for over one year) to remotely exploit these vulnerabilities to effect arbitrary remote code execution resulting in possible denial-of-service conditions and unauthorized access to view and edit monitoring, configuration, and payment information.

Saturday, April 13, 2019

Public ICS Disclosures – Week of 04-06-19


This week we have four vendor disclosures from WAGO, Bosch (2), and Schneider; and two vendor updates from Siemens.

WAGO Advisory


CERT-VDE published an advisory describing a use of hardcoded credentials vulnerability in the WAGO Series 750-88x and 750-87x devices. The vulnerability was reported by Jörn Schneeweisz of Recurity Labs. WAGO has firmware updates available that mitigate the vulnerability. There is no indication that Schneeweisz has been provided an opportunity to verify the efficacy of the fix.

NOTE: I suspect that NCCIC-ICS will publish an advisory on this vulnerability next week.

Bosch Advisories


Bosch published an advisory describing a buffer overflow vulnerability in the Bosch Security Systems Software for Video, PSIM and Access. This vulnerability is apparently self-reported. Bosch has software updates that mitigate the vulnerability.

Bosch published an advisory describing an improper access control vulnerability in the Bosch Security Systems Software for Video, PSIM and Access Control Systems. This vulnerability is apparently self-reported. Bosch has software updates that mitigate the vulnerability.

Schneider Advisory


Schneider published an advisory describing an externally controlled reference to a resource vulnerability in the Schneider Modbus Serial Driver. The vulnerability was reported by Reid Wightman of Dragos. Schneider has an updated driver that mitigates the vulnerability. There is no indication that Reid has been provided an opportunity to verify the efficacy of the fix.

Siemens Updates


Siemens updated an advisory for Spectre-NG (Variants 3a and 4) Vulnerabilities in Industrial Products. Siemens added a solution for SIMATIC HMI Panels V14.
NOTE: NCCIC-ICS will not update their advisory for this vulnerability since the link to the Siemens advisory will take one to the current version.

Siemens updated an advisory for Vulnerabilities in the additional GNU/Linux subsystem
of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP. Siemens added CVE-2019-6293 to the list of vulnerabilities covered by this advisory.

NOTE: NCCIC-ICS has not published an advisories or alert on this family of Linux vulnerabilities.

Saturday, February 16, 2019

Public ICS Disclosures – Week of 02-09-19


This week we have five vendor disclosures for products from Kunbus, Schneider (3) and Rockwell; five vendor updates from Siemens; one coordinated disclosure for products from Resource Data Management and one exploit for a previously disclosed vulnerability for products from AVEVA.

Kunbus Advisory


Kunbus published an advisory for five vulnerabilities in its KUNBUS-GW Modbus TCP PR100088 product. The vulnerabilities were reported by Nicolas Merle of Applied Risk. Kunbus is working on an update to mitigate the vulnerabilities.

The five reported vulnerabilities are:

• Conditional authentication bypass;
• Missing authentication for critical function;
• Denial of service;
• Publication of information by parameter data in an HTTP GET request; and
Plain text storage of passwords

Schneider Advisories


Schneider has published an advisory describing six vulnerabilities in its Sarix Enhanced and Spectra Enhanced cameras. The vulnerabilities were reported by Deng Yongkai (NSFOCUS) and Gjoko Krstic (Zero Science). Schneider has a new firmware version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• A permissions, privileges, and access control vulnerability - CVE-2018-7816;
• A command injection vulnerability (2) - CVE-2018-7825 and CVE-2018-7826;
• A cross-site scripting (XSS) vulnerability (2) - CVE-2018-7827 and CVE-2018-7828; and
• An improper neutralization of special elements in query vulnerability - CVE-2018-7829


Schneider has published an advisory describing a buffer error vulnerability in its Vijeo Designer Lite software. The vulnerability is self-reported. Schneider has provided generic mitigations as the product has reached end-of-life status.


Schneider has published an advisory describing three vulnerabilities in its  Modicon M221 and
SoMachine Basic products. The vulnerabilities were reported by Matthias Niedermaier (Hochschule Augsburg), Jan-Ole Malchow (Freie Universität Berlin), Florian Fischer (Hochschule Augsburg) and Reid Wightman (Dragos Inc.). Schneider has updates available to mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• An environment vulnerability (2) - CVE-2018-7821 and CVE-2018-7823; and
• An incorrect default permissions vulnerability - CVE-2018-7822

Rockwell Advisory


Rockwell has published an advisory describing two vulnerabilities in its PowerMonitor 1000 monitor that were publicly reported (with exploits) in December (here and here) by Luca Chiou. Rockwell has provided generic mitigation measures pending development of updates. It also provides a link to intrusion prevention system (by CheckPoint) rules to detect the cross-site scripting vulnerability.

The two reported vulnerabilities are:

• Cross-site scripting - CVE-2019-19615; and
• Authentication bypass - CVE-2019-19616

 Siemens Updates


Siemens published an update for their advisory on Spectre and Meltdown Vulnerabilities in Industrial Products. They added updated affected version data and provided links to mitigations for:

• SIMATIC ET 200 SP Open Controller; and
• SIMATIC IPC547E

NOTE: NCCIC-ICS updated their alert (ICS-ALERT-18-011-01) for this vulnerability when Siemens added a new advisory. That technically included this update since the link provided in the alert goes to the latest version of the Siemens advisory.


Siemens published an update for their advisory on Spectre-NG (Variants 3a and 4) Vulnerabilities in Industrial Products. They added updated version data and provided links to mitigations for:

• SIMATIC ET 200 SP Open Controller:
• SIMATIC ET 200 SP Open Controller (F);
• SIMATIC S7-1500 Software Controller;
• SIMATIC IPC547E;
• SIMATIC ITP1000;
• SIMATIC IPC3000 SMART V2;
• SIMATIC IPC347E;
• SIMATIC HMI Basic; and
• Panels 2nd Generation:

They also removed the following unaffected products from the advisory:

• SIMATIC IPC227E;
• SIMATIC IPC277E;
• SIMATIC IPC327E; and
• SIMATIC IPC377E

NOTE: NCCIC-ICS is expected to update their advisory.


Siemens published an update for their advisory on Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP. They added two additional vulnerabilities to the list for these products:

• CVE-2018-1000876; and
• CVE-2018-16862
NOTE: NCCIC-ICS has not published an advisory/alert on these vulnerabilities.

Siemens has published an update for their advisory on Denial-of-Service in SICAM A8000 Series. They updated the CVSS vector due to known exploit.


Siemens has published an update for their advisory on Foreshadow / L1 Terminal Fault Vulnerabilities in Industrial Products. They updated the affected version data and provided links to the mitigation measures for:

• SIMATIC IPC547E;
• SIMATIC IPC547G;
• SIMATIC ITP1000;
• SIMATIC IPC3000 SMART V2; and
• SIMATIC IPC347E

They also removed the following unaffected products from the advisory:

• SIMATIC IPC227E;
• SIMATIC IPC277E;
• SIMATIC IPC327E; and
• SIMATIC IPC377E
NOTE: NCCIC-ICS has not published an advisory/alert on these vulnerabilities.

Resource Data Management


Safety Detective published an article describing default credential vulnerabilities for commercial refrigeration systems from Resource Data Management. The article describes how the researchers were able to locate vulnerable systems, change settings, and manipulate controls in systems in hospitals and stores.

AVEVA Exploit


Jacob Baines published an exploit for vulnerabilities in the AVEVA InduSoft Web Studio. The vulnerabilities were reported by NCCIC-ICS earlier this month.

Saturday, February 18, 2017

Reader Comment – Moxa NPort Advisory

Today Reid Wightman posted a comment to a December blogpost that mentioned a control system security advisory published by ICS-CERT for Moxa NPort products. Reid was identified as one of the researchers that identified one or more of the vulnerabilities covered in that advisory. Reid’s comments that the reported fix for CVE-2016-9361 does not work. Please read his comment for more details.

Alert readers might remember that Digital Bond (with whom Reid was associated at the time) publicly disclosed the vulnerability in April of last year, resulting in an ICS-CERT control system security alert. Given the total elapsed time between the initial notification by Digital Bond and the published “fix”, it is especially disconcerting that Reid has to report that the fix does not work.

Assuming that there was no deliberate malfeasance involved on the part of Moxa, I can only conclude that Moxa did not really understand the cause of the vulnerability discovered by Reid. This is one of the reasons that it is important to have someone not employed by the vendor verify the efficacy of the fix. I think it would be best if the discovering researcher were the one to do the verification testing. That way there can be no doubt about how well the fix mitigates the discovered vulnerability.


Reid does not mention in his comment whether or not he had coordinated the report of the failure of the vendor’s fix with ICS-CERT. In some ways, I am hoping that he did not. If he had, it would seem to indicate that ICS-CERT (or perhaps Moxa) did not accept Reid’s judgement about the efficacy of the fix. Given the seriousness of the vulnerability (CVSS v3 base score of 9.8) I would have hoped that ICS-CERT would have tried to corroborate Reid’s report.

Wednesday, April 27, 2016

ICS-CERT Updates Moxa Alert Again

This afternoon the DHS ICS-CERT published a new update to their Moxa alert (originally issued on April 8th and then updated on April 20th). The new update adds an acknowledgement of the original disclosure and more details about the ports involved in the vulnerabilities.

The Changes


The Alert now reports that Reid Wightman of Digital Bonds Labs was the original reporter of the five vulnerabilities upon which this alert was based. It also now acknowledges that Reid did coordinate with Moxa (but not, shame for shame, with ICS-CERT).

A paragraph has also been added to the mitigation section of the report that lists the ports that Moxa recommends should be either blocked or have access restrictions applied. The list of ports was in the original alert, but was removed in the first update. The port information in this update is more complete in that it distinguishes between the ports that are not needed by the device and the ports that may be used in normal operation. The same information was available in the DBLabs report that was responsible for the initiation of this alert.

Intellectual Property


I am glad to see that ICS-CERT is finally giving Reid credit for discovering these vulnerabilities. ICS-CERT has had an on-again, off-again policy of disclosing the researchers responsible for alerts. I understand that ICS-CERT would prefer that they (or some other CERT) would be used as a disclosure intermediary. Their thought is that their official office can apply more pressure to vendors to take vulnerability reports more seriously. While that may be true (more on that later) that should have nothing to do with giving credit where credit is due. Not giving credit smacks of theft of intellectual property.

Vulnerability Coordination


Now as to the larger question of the role of ICS-CERT as a coordinator of vulnerability disclosures, let’s take a look at that role. First off, I have seen nothing in legislation or regulation that provides ICS-CERT with any specific authority to act as such a coordinator. That probably is not really necessary as long as researchers and vendors mutually recognize ICS-CERT as an independent arbiter of disagreements about the legitimacy of vulnerability claims, on the one hand, and the legitimacy of vendor mitigations on the other hand.

It is becoming increasingly obvious that there are elements within the research community that no longer have much respect for ICS-CERT as a dispassionate intermediary. I have read a number of social media comments over the last year or so from a number of different researchers that expressed their concerns about the apparent willingness of ICS-CERT to side with the vendors when there is a disagreement on vulnerabilities.

Appearance of Favoring Vendors


In my very limited interactions with ICS-CERT, I have never had any problems. But then again, I am a security gadfly not a researcher. But that really does not make any difference. As I told young NCO’s in numerous leadership classes; it doesn’t make a damn bit of difference if you are or are not prejudiced. If those that report to you think you are prejudiced, then they are going to respond to you as if you were prejudiced.

At the very least ICS-CERT has a problem with the appearance that they favor vendors when there is a dispute between researchers and vendors. That appearance is going to help drive away researchers, particularly those without enough of an industry reputation to have their disclosures stand on their own merit. Those researchers are going to take less desirable modes of disclosure, public zero-day disclosures or, even worse, sell disclosures to the highest bidder.

This is particularly disturbing as the ICS security world is expanding by leaps and bounds. The number of researchers in this space is continuing to expand as new researchers (and established researchers from other fields) continue to see ICS research as an expanding field. Even more important the number of vendors affected by ICS vulnerabilities is also increasing as more industries (medical, automotive, aircraft, and security controls) begin to realize that their control systems have important security vulnerabilities that are no longer masked by obscurity.

Need for Coordination


The other question that this specific set of vulnerabilities raises is whether or not a disclosure coordinator is really needed. A legitimate case can be made that new researchers in the field, without a well established reputation, probably do need to have an independent agency act as a go between particularly when the security issues being raised are novel or difficult to understand.

That was certainly not the case here. Reid Wightman is not, by anyone’s measure, an ICS neophyte. He has a well-established personal reputation built across a number of organizations. That plus his current association with Digital Bond Labs should provide as much weight to the vulnerability disclosure as could ICS-CERT. He should be able to approach any ICS vendor in the world and have his report of vulnerabilities taken seriously and promptly acted upon. I question the commitment to security of any vendor that fails to respond promptly to a researcher of Reid’s stature and knowledge.

To take over a year to correct serious security vulnerabilities (and we are hoping that they will be completed in August as promised) is inexcusable. Particularly when the devices in question exist in a critical communications nexus in so many critical installations. Even if there is a legitimate reason for it taking a year to correct all of the problems (and I find that difficult to believe) most of these issues could certainly have been corrected well before now.

The Siemens model of disclosing a vulnerability even before all of the affected devices have patches/updates available is one that deserves close study by the industry. This is particularly true when there are legitimate methods of reducing the risk of vulnerability exploits that the owner can take while waiting for an update to become available.

A Good Step Forward


In closing, I want to make a clear statement that I think ICS-CERT took a valuable and correct step today with their making these changes to the Moxa Alert. Reid deserves credit for the vulnerability discovery and for his efforts to properly disclose those vulnerabilities to Moxa. System owners deserve to have the information on mitigation measures that are now available in the Alert. I continue to believe that ICS-CERT has an important role to play in coordinating vulnerability disclosures. The changes made today will help to ensure that they look like they are playing the role of a disinterested intermediary that both sides can respect and trust.


Tuesday, October 23, 2012

ICS-CERT Publishes 2nd Wightman Advisory


A month ago ICS-CERT published an advisory for a hard-coded root credential vulnerability in the ORing DIN-Rail Device Server that was reported in an uncoordinated disclosure by Reid Wightman, then working with DigitalBond. Reid’s blog post about that vulnerability reported that the same vulnerability existed in Korenix Jetport 5600. In fact, he noted that the backdoors were identical and “the firmwares are eerily similar”. Today, ICS-CERT published the advisory for the Jetport 5600.

Unlike the earlier advisory where ICS-CERT threw the vendor under the bus for failure to correct the deficiency, ICS-CERT reports that Korenix has developed an upgraded version of the firmware that removes the root and guest accounts as well as the current version of OpenSSL. The advisory doesn’t note, however, that anyone has confirmed that this corrects the problem.

If Reid is right about the two devices sharing the same firmware, then this update should also correct the problem in the ORing server. I wonder if anyone has checked this out?

Where’s the Alerts?


Okay, I tried to avoid it, but I just have to ask. Why wasn’t there an alert published back in June when Reid published his blog post about the vulnerability (complete with exploit code) about both of these systems? Wouldn’t the owners of these devices (most of which had probably never heard of DigitalBond) want to know that they were vulnerable to having their system completely taken over by anyone with an interest in messing with them?
 
/* Use this with templates/template-twocol.html */