Showing posts with label Robus. Show all posts
Showing posts with label Robus. Show all posts

Tuesday, November 19, 2013

Identical Twin ICS-CERT DNP3 Advisories Published

Today the DSH ICS-CERT published two virtually identical DNP3 advisories for twin improper input validation vulnerabilities in Catapult Software DNP3 Drivers and GE Proficy platform. The reason that they are nearly identical is because the Proficy vulnerability is due to the use of the Catapult Software drivers. Since these are familiar DNP3 vulnerabilities, it should come as no surprise that they were first reported by the team of Crain and Sistrunk. Technically, GE self-reported their vulnerability when notified of the problem by Catapult Software.

These are the same IP-based and serial-based validation vulnerabilities that we have seen before in similar Crain-Sistrunk based advisories. ICS-CERT reports that the IP-based vulnerability has a higher CVSS v2 base score (7.1 vs 4.7) but that reflects the fact that the IP-based vulnerability can be more easily exploited remotely. Many cybersecurity commentators (though certainly not all) note that physically accessing the serial connection may actually be easier at remote, low-security sites.

Catapult Software has produced updated software that mitigates both their system vulnerabilities and the Proficy vulnerabilities. The Catapult advisory does report that Crain and Sistrunk have validated the efficacy of the new software version. While that is not specifically mentioned in the GE advisory, I would assume that the same validation applies to the Proficy issues.

The Automatak web site reports these vulnerabilities as numbers 10 and 11 of the 25 vulnerable systems that they have discovered. I wonder how many of the remaining 14 are also based upon either the Catapult system or the earlier Triangle Microworks library. Both have obviously been made available (sold) to other vendors. Of course, it is also possible that Crain and Sistrunk have not yet found all of the system vulnerabilities since they have apparently stopped looking for these vulnerabilities; no challenge left I suppose.

Hopefully, any unidentified DNP3 vendors will take the leads posted by these two and self-correct and self-report their problems without being identified by Project Robus.

NOTE: A quick update from an Adam Crain Tweet® - None of the remaining vulns are catapult related. Should probably read 11/26 now, but we've kinda stopped counting.

Friday, August 9, 2013

Robus – More ICS Vulnerability Reports to Come

Thanks to Chris Jager (via Twitter®) for pointing me at the web site of Robus, the collaboration of  Adam Crain and Chris Sistrunk that has already brought us the latest ICS-CERT advisory on SEL. This is a deceptively simple web site with only a single page and the only external links going to the ICS-CERT web site, the LinkedIn® profiles of the two principles and the web site of Automatak, their corporate sponsor.

The real interesting part of the site is the listing of the ICS-CERT advisories that there research has been responsible for initiating. There are currently three advisories listed and the word pending shown a number of times. Yesterday when I first saw this site there were 12 ‘pendings’, this morning there are 16; each one reflects (as I understand it) coordinated disclosures for ICS vulnerabilities that have already been made.

It looks like we are going to be hearing a lot from these two young men.

Keeping in mind that free suggestions are typically worth what you pay for them; I have two suggestions for the web site. First put a date on each ‘pending’ signifying when the disclosure was actually made; this could help the industry track the general responsiveness of vendors. Second establish an internal standard (the ICS-CERT 45 day limit for instance) for a reasonable time to fix a vulnerability and then add the vendor’s name to the pending listing. This could be followed by a second time limit to add the generic vulnerability description to the pending listing.


BTW: Suggested reading: Here be Dragons
 
/* Use this with templates/template-twocol.html */