Showing posts with label Resource Data Management. Show all posts
Showing posts with label Resource Data Management. Show all posts

Friday, December 23, 2016

ICS-CERT Publishes Two Advisories and Updates Five

Yesterday the DHS ICS-CERT published two control system security advisories for products from Wago and Fidelix. It also published updates for previously issued advisories for products from Moxa (2), iRZ, Resource Data Management, Environmental Systems and Siemens.

Wago Advisory


This advisory describes an authentication bypass vulnerability in the WAGO Ethernet Web-based Management products. The vulnerability was reported by Maxim Rupp. WAGO has produced a firmware update and workarounds to mitigate the vulnerability. There is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled hacker could remotely exploit this vulnerability to view and edit settings without authenticating.

Fidelix Advisory


This advisory describes a path traversal vulnerability in the Fidelix FX-20 series controllers. The vulnerability was reported by Semen Rozhkov of Kaspersky Lab. Fidelix has produced a new software version that mitigates the vulnerability. There is no indication that Rozhkov has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability  to read data from the device.

Moxa EDR-G903 Update  


This update provides additional information on an advisory that was originally published on May 17th, 2016.  It changes the name of one of the vulnerabilities from ‘memory leak’ to ‘information exposure’. On the unauthenticated download vulnerability, the CVE vector string has a change in the ‘A’ component at the end from ‘H’ to ‘N’.

iRZ Update


This update provides additional information on an advisory that was originally published on May 17th, 2016. It changes the CVSS v3 base score from 6.1 to 7.2 and changes two components of the CVE vector string; ‘UI’ from ‘R’ to ‘N’ and ‘C’ from ‘N’ to ‘H’.

Resource Data Management Update


This update provides additional information on an advisory that was originally published on May 19th, 2016. It changes the CVSS v3 base score on the cross-site request forgery vulnerability from 6.5 to 8.0 and changes three components of the CVE vector string for the same vulnerability; ‘UI’ from ‘N’ to ‘R’, ‘C’ from ‘N’ to ‘H’, and ‘I’ from ‘N’ to ‘H’.

Moxa MiiNePort Update


This update provides additional information on an advisory that was originally published on May 24th, 2016. It changes the CVSS v3 base score on the cross-site request forgery vulnerability from 6.1 to 9.6 and changes three components of the CVE vector string for the same vulnerability; ‘UI’ from ‘R’ to ‘N’, ‘C’ from ‘L’ to ‘H’, and ‘I’ from ‘N’ to ‘H’.

Environmental Systems Update


This update provides additional information on an advisory that was originally published on May 26th, 2016, and then updated on June 2nd, 2016. It changes the CVSS v3 base score on the authentication bypass vulnerability from 7.5 to 9.1.

Siemens Update


This update provides additional information on an advisory that was originally published on November 8th, 2016 and then updated on November 22nd, 2016. It updates both the affected version and mitigation information for SIMIT V9.0 SP1 and SecurityConfiguration Tool (SCT) V4.3 HF1. Siemens has updated their security advisory and reported this update via a tweet on Wednesday.

Commentary


This cluster of incorrect CVE v3 base scores and vector strings from May of this year is interesting. As of this date it does not apparently affect all the advisories produced during that period and only affects one of the reported vulnerabilities in multiple vulnerability advisories. This would seem to indicate that it was not a systemic problem, but rather human error. While we would like to think that the folks at ICS-CERT were perfect, alas they are only human.


I am impressed with the four updates addressing these CVE related errors. I’m not sure what instigated the review of these advisories, but their publication does demonstrate a high level of integrity and attention to detail. ICS-CERT is to be commended on publishing them.

Thursday, May 19, 2016

ICS-CERT Publishes Two Advisories

This afternoon the DHS ICS-CERT published two new industrial control system advisories for products from Siemens and Resource Data Management.

Siemens Advisory


This advisory describes twin information disclosure vulnerabilities in the Siemens SPIROTEC Ethernet modules. The vulnerabilities were independently reported by Aleksandr Bersenev from HackerDom team and Pavel Toporkov from Kaspersky Lab. Siemens has produced a firmware update to mitigate the vulnerabilities. There is no indication that either researcher has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to obtain sensitive device information if the attacker has network access to the devices. The Siemens CERT advisory notes that the firmware update only applies to the SPIROTEC Compact versions equipped with the EN 100 Ethernet modules. For other models of the SPIROTEC Compact Siemens recommends protection of the affected networks with standard cybersecurity protections like firewalls, segmentation, and VPN access.

Resource Data Management Advisory


This advisory describes two vulnerabilities in the Resource Data Management Intuitive 650 TDB Controller. The vulnerability was reported by Maxim Rupp. RDM has produced a new version of their TDB Control Editor that is used to program their controllers to mitigate these vulnerabilities. There is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.

The two vulnerabilities are:

• Privilege escalation - CVE-2016-4505; and
• Cross-site request forgery - CVE-2016-4505


ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to gain elevated access to alter logs and parameters or execute unwanted actions.

Tuesday, September 22, 2015

ICS-CERT Publishes Three Advisories

This morning the DHS ICS-CERT published three advisories for control system vulnerabilities in systems from Everest Software, IBC Solar and Resource Data Management.

Everest Advisory

This advisory describes two pointer dereference vulnerabilities in the Everest Software LLC PeakHMI application. The vulnerabilities were reported by Josep Pi Rodriguez. Everest has produced a new version that mitigates the vulnerabilities, but there is no indication that Rodrigues has verified the efficacy of the fix. This advisory was released to the US CERT Secure portal on August 20th, 2015 and is probably one of the ones that I mentioned last week.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability.

ICS-CERT has two additional mitigation activities to recommend in addition to their standard recommendations for HMI systems. They are:

• Carefully monitor or block traffic to Port 49454.
• Disable the video server if it is not being used. This video server is only for remote HMI video support. (It is disabled by default on installation)

IBC Solar Advisory

This advisory describes three vulnerabilities in two different IBC Solar products. The vulnerabilities were reported by Maxim Rupp. ICS-CERT reports that IBC Solar has not mitigated these vulnerabilities

The three vulnerabilities are:

• Disclosure of source code, CVE-2015-6469;
• Plain text passwords, CVE-2015-6474; and
• Cross-site scripting, CVE-2015-6475

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities.

For the first two vulnerabilities ICS-CERT suggests upgrading to a source that does not have these vulnerabilities. It sounds to me like they are recommending a new vendor, but they don’t come right out and say that (DHS lawyers will be happy). For the cross-site scripting vulnerability they recommend data validation and they also provide a link to an NSA fact sheet on XSS.

Resource Data Management Advisory

This advisory describes two vulnerabilities in the Resource Data Management Data Manager application. The vulnerabilities were reported by Maxim Rupp. Resource Data Management has produced a new version that mitigates the vulnerability, but there is no indication that Rupp has been given the opportunity to verify the efficacy of the fix.

The two vulnerabilities are:

• Privilege escalation, CVE-2015-6470; and
• Cross-site request forgery, CVE-2015-6468


 ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities.
 
/* Use this with templates/template-twocol.html */