Showing posts with label RuggedCom. Show all posts
Showing posts with label RuggedCom. Show all posts

Thursday, July 23, 2015

ICS-CERT Corrects Error in Siemens RuggedCom Advisory

This afternoon the DHS ICS-CERT updated the advisory that it had issued earlier this week for the Siemens RuggedCom Devices. The update corrects an error in list of affected products.

The original advisory listed “RuggedCom devices with ROX: All firmware versions prior to v2.6.3”. The new version shows “RuggedCom devices with ROX II: All firmware versions” and then specifically notes that “ROX I” devices are not affected. This change reflects the information that was printed in the original Siemens Advisory and is not because of any change initiated by Siemens.

I learned of the updated version from a Tweet made by ICS-CERT. The changed advisory is not on top of the list of advisories provided on their landing page that would typically indicate that it was added today. What has been done is that the original listing made on July 21st has been changed to reflect the new advisory number (‘A’ added to the end of the original) and has the words “Update A” added at the end of the title.

Since we saw the same thing last week with the updated Schneider advisory, I think that this may reflect a change in the way that ICS-CERT is running their list of vulnerabilities. The list on the landing page will only show the vulnerability listing on its original order making it very difficult to tell when an advisory is updated. And the older advisories drop off the landing page as new ones are added. Fortunately they are announcing the updates on Twitter (@ICS-CERT) so we can keep track of them that way as long as they continue to do this.


Tuesday, July 21, 2015

ICS-CERT Publishes 4 Advisories – Three for Siemens

This afternoon the DHS ICS-CERT published four new advisories for control system security issues. Three of the advisories were for products from Siemens (RuggedCom, Smart Client and Siprotec) and the other was for another Hospira infusion pump.

Hospira Advisory

This advisory reports that a new unnamed vulnerability found in the Symbiq Infusion System, in conjunction with previously reported vulnerabilities reported in the Hospira infusion pump line of products allow the product to be “remotely directed to perform unanticipated operations”. Billy Rios originally reported the vulnerability. Hospira has developed operational mitigation measures to stop a remote exploit of this vulnerability.

ICS- CERT reports that: “As previously announced by Hospira in 2013, the Symbiq Infusion System would be retired on May 31, 2015, and will be fully removed from the market by December 2015.” This advisory was originally released to the US-CERT Secure Portal on June 23rd. This is probably the advisory that I reported hearing rumors about earlier this month.

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability.

The operational mitigation measures include:

“Disconnect the affected product from the network. Disconnecting the affected product from the network will have operational impacts. Disconnecting the device will require drug libraries to be updated manually. Manual updates to each pump can be labor intensive and prone to entry error.

“Ensure that unused ports are closed, to include Port 20/FTP and Port 23/TELNET.

“Hospira strongly recommends that healthcare providers contact Hospira’s technical support to change the default password used to access Port 8443 or to close Port 8443. Contact Hospira’s technical support at 1-800-241-4002. Hospira is working directly with Symbiq customers to update the configuration of the pump to close access ports.”

Commentary – Disconnect the pumps from the network? We know that is not a fail safe action. Besides how many of the technicians and nurses have experience updating the drug libraries manually? In my opinion (if anyone didn’t already suspect) Hospira/FDA/Owners should have already pulled these devices from use. I see law suits in the future.

Siemens RuggedCom Advisory

This advisory describes a TLS POODLE vulnerability in Siemens RuggedCom ROS and ROX-based devices. This is apparently a self-identified vulnerability. Siemens has developed a firmware update for this vulnerability.

ICS-CERT reports that a social engineering attack would be required to exploit this vulnerability.

The Siemens Advisory notes that the current firmware update is just for the ROS based devices and that work is continuing on the ROX based device update.

Siemens Sm@rt Client Advisory

This advisory describes a password storage vulnerability in the Siemens Sm@rtClient Android application. The vulnerability was reported by Karsten Sohr from Universität Bremen and Stephan Huber from Fraunhofer SIT. Siemens has produces a new version of the application that mitigates the vulnerability. There is no indication that the researchers have been given the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker with local access to the mobile device could obtain the password. This could allow a successful attacker remote mobile operation and observation of SIMATIC HMI systems.

Siemens SIPROTEC Advisory

This advisory describes a denial of service vulnerability in SIPROTEC 4 and SIPROTEC Compact devices. The vulnerability was reported by Victor Nikitin from i‑Grids LLC. Siemens has produced a firmware update to mitigate the vulnerability, but there is no indication that Nikitin has been given the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to effect a denial of service attack and a manual re-boot is required to return the device to service.

There is a minor discrepancy in the description of the affected devices. ICS-CERT reports the affected devices as:

“SIPROTEC 4 and SIPROTEC Compact product families
“All devices that include the EN100 Ethernet module version V4.24 or prior”

The Siemens Advisory, on the other hand, describes the affected devices this way:

“SIPROTEC 4 and SIPROTEC Compact product families: All devices where the Ethernet module EN100 with version V4.24 or lower is included.”


I am pretty sure, however, that owners of these devices would pretty quickly figure out that the ICS-CERT verbiage is meant to describe what Siemens reported.

Friday, December 6, 2013

ICS-CERT Publishes RuggedCom Advisory

This afternoon the DHS ICS-CERT published an advisory for a pair of self-reported vulnerabilities in the RuggedCom devices with ROS firmware. Siemens reported the vulnerabilities today as well as announcing the availability of a firmware update that mitigates the vulnerabilities.

ICS-CERT describes the vulnerabilities as:

• Use of insufficiently random values, CVE-2013-6925; and
• Authentication bypass issues, CVE-2013-6926
NOTE: The CVE links are not yet active.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to be able to perform limited administrative operations over the network. Siemens notes that an attacker must have network access (port 443/tcp) to the affected devices for both vulnerabilities.


BTW: Siemens ProductCERT also published another industrial control system advisory today for a privilege escalation vulnerability in the COMOS engineering solution. Siemens has patches available for the affected versions of COMOS. There is no indication of why ICS-CERT does not have a similar advisory published.

Monday, April 29, 2013

ICS-CERT Updates Ruggedcom Advisory


Earlier today the DHS ICS-CERT published an updated version of their advisory from December that reported mitigations in response to the original ICS-CERT alert from August and an update of that alert in September. If that seems confusing, try this; today’s update notes that “ROS Update V3.12 has been produced to mitigate these issues” but the Ruggedcom web site reports that V3.12 became available on December 7th, 2012; eleven days before the original advisory was published. It looks like this update should have been included in the original advisory.

BTW: There is still no word on a more permanent fix for the HTTPS/SSL service beyond disabling the service that is still being reported in this updated advisory.

BTW Again: There is no mention in this updated advisory that Justin Clarke, the researcher who reported the vulnerability in the first place, has had a chance to review the V3.12 update to verify that it mitigates the reported vulnerabilities.

Thursday, December 20, 2012

ICS-CERT Closes-out Two Alerts


Today the folks at DHS ICS-CERT published two advisories for different systems that were based upon uncoordinated disclosures reported earlier by ICS-CERT. Actually ICS-CERT only notes that one is based upon an earlier alert, but records show that both were. The affected systems are from RuggecCom and Carlo Gavazzi Automation.

RuggedCom Advisory


This advisory is based upon Key Management Errors originally reported by Justin W. Clarke of Cylance Inc and the ICS-CERT Alert was published in August and updated later that month. According to this Advisory a moderately skilled attacker could use the publicly available exploit “to establish a secure communication link with RuggedCom network devices and manipulate settings that would result in a denial of service condition”. Why that would only allow a ‘DOS condition’ is not made clear.

RuggedCom has developed a number of device specific mitigations for this vulnerability, ranging from an update for ROS devices, to a recommendation to update SSL and SSH keys for ROX devices. The situation for RUGGEDMAX devices appears to be more complicated because there is one solution for SSH service and a temporary solution for HTTPS access; the last doesn’t sound encouraging.

Carlo Gavazzi Automation Advisory


This advisory seems to me to be clearly based upon an alert issued in October for the Sinapsi eSolar Light Photovoltaic System Monitor. That alert clearly notes that the Gavazzi EOS box is one of the names under which the Sinapsi product was sold. This advisory does not mention the earlier alert and it only addresses two of the vulnerabilities (hard-coded credentials and SQL injection) addressed in that earlier alert. If the earlier alert does not in fact apply to the EOS box, ICS-CERT should revise the earlier alert to reflect that fact.

The advisory notes that a relatively unskilled attacker could use the publicly available exploit code (another reason to believe the alert should have been referenced) to remotely gain administrative access and control of the system (credential vuln) or gain access to information about the system (SQL vuln). Carlo Gazazzi has developed an updated firmware version to mitigate these vulnerabilities and has released the new firmware ‘directly to the devices’. Interestingly that is just what Sinapsi did almost a month earlier to their devices affected by the same vulnerabilities. As I have mentioned in the past, I thing that the ability of the manufacturer to release the firmware updates directly to the devices is a vulnerability in and of itself, even if it is not misused.

Two questions remain unanswered; what happened to the other two vulnerabilities mentioned in the original alert (and the Sinapsi advisory) and when will we see the advisories for the other manufacturers listed in the original alert?

Wednesday, September 5, 2012

Update on ICS-CERT RuggedCom Update


Last week in a blog post about an ICS-CERT update of the latest RuggedCom Alert I noted that ICS-CERT had labeled that update “B”, implying that there had been an earlier “A” update that hadn’t been published. Somehow I missed providing a link to that update in the post, but it seems like that was a good miss. The “B” update has been erased and has been supplanted with an identical “A” update.

I admit that I’m a bit OCD about things like that and I am glad to see that ICS-CERT has corrected this sooo serious mistake (sarcasm alert).

Saturday, September 1, 2012

ICS-CERT – New JSAR, Advisory and Updated Alert


Still getting caught up after Isaac; while ICS-CERT hasn’t been real busy they haven’t waited for me either. So here is a quick look at a new Joint Security Awareness Report (JSAR), a new privilege escalation advisory and an update on a Siemens related alert.

Shamoon JSAR


ICS-CERT and US-CERT published a JSAR on Wednesday for the information-stealing malware W32.DistTrack, also known as Shamoon. Actually calling this an ‘information-stealing’ malware is misleading since it also contains a module that corrupts selected existing files on the hard drive and then erases the Master Boot Record so that the computer cannot be re-started. To me this sounds like a software bomb that also steals information. Oh, and before it destroys the virtual computer it spreads to other computers on the network.

The JSAR is very light on details about this threat, but it does reference two pages from the Symantec web site that provide more details. Of the two sites referenced the best one contains all of the publicly available Symantec information.

Symantec rates this as a low level threat in the wild, but that is based upon the small number of times this has been detected (less than 50). Neither the JSAR or the Symantec site mention that the Shamoon is suspected of being responsible for the shut down on the Saudi oil company’s computer systems last month. I suppose they think that if you are not a targeted company you may be okay. But this is another low-risk, high-consequence piece of malware.

There is no mention in the JSAR of why this is a joint US-CERT ICS-CERT publication. There is nothing that currently indicates that this is targeted at control systems, but it would appear to be difficult to determine exactly what information was stolen from a subsequently unusable computer. Since one of the targets appears to have been an energy sector company, it would seem prudent to think that control system access information may have been part of what may have been stolen.

GarrettCom Advisory


Justin Clarke of Cylance has identified another hard coded password in an industrial control system component. This time it was in the GarrettCom Magnum MNS-6K (an Ethernet switch) Management Software. Since access to the network is required to exploit this vulnerability it is called an ‘escalation of privilege’ vulnerability; someone with limited access can gain administrator level access to the system.

GarrettCom has released a patch that ‘mitigates this vulnerability’, though there is nothing in the advisory that indicates that either ICS-CERT or Justin has verified this mitigation. Interestingly though, the advisory does note that the vulnerability is not specifically identified in the release notes for the updated software version that was released back in May. This may mean that system owners are not aware of how important the upgrade may actually be and thus may decide to delay or completely forgo implementing the upgrade.

I have noticed that Justin has been taken to task on some internet sites (the SCADASEC list in particular) for this disclosure. It is apparent, however, that his detractors were not aware that this was a coordinated disclosure where the vendor was able to produce a patch and that patch to be publicized on the secure server at US-CERT before it became general public knowledge. Part of the fault there lies with this Advisory as it does not specifically state that this was a coordinated disclosure, but that really is clear if you read the ‘Overview’ portion of the Advisory carefully.

RuggedCom Alert Update


This is the second update of the RuggedCom Alert originally published back on August 21st. Well, it looks like a second update as it is version B. I can’t find where ICS-CERT published anything on this between August 21st and yesterday when this version was published. Maybe they got confused with the A version of the earlier RuggedCom Alert published in May.

In any case this update is based upon a Siemens CERT report published on Friday (NOTE: the Revised Alert points at the page where the Siemens alerts are posted not this specific alert). Siemens reported that vulnerabilities similar to those identified by Justin in the RuggedCom ROS were also found in the ROX operating system and the RuggedMax operating system. Interim mitigations are have been provided by Siemens/RuggedCom.

Siemens is to be commended for their effort to identify the fact that other systems produced by their recently purchased subsidiary have similar problems and to publicly report that fact. Hopefully they are also taking internal measures to ensure that security is a higher priority in the production of future products.

Wednesday, August 22, 2012

Another RuggedCom ICS-CERT Alert


Yesterday ICS-CERT published another alert for the RuggedCom Rugged Operating System that was based upon a vulnerability that was publicly disclosed by Justin W. Clarke of Cylance Inc. The public report (once again there is no link to the report and the Cylance web site is very discrete) identifies a hard-coded RSA SSL private key vulnerability in the RuggedCom ROS. This is the second serious vulnerability that Clarke has identified in this system.

NOTE: Just got an email from Justin and he provides this information about why I can find no link to this public disclosure: "The reason there’s no link to the report is that the Friday disclosure was actually a live presentation at BSidesLA 2012 on Friday (http://www.securitybsides.com/w/page/36552449/BSidesLosAngeles). The relevant slides were written by me and presented by Stuart McClure, Founder/CEO of my employer. Former Global CTO of McAfee, and Founder/CEO of FoundStone (acquired by McAfee sometime after 2000)." So maybe ICS-CERT should have mentioned the BSidesLA 2012. Updated 8-22-12 0615 EDT.

The earlier vulnerability report concerned an undocumented backdoor account in the system. Clarke had attempted to coordinate the disclosure on the earlier vulnerability but was rebuffed. It would be interesting to hear from Clarke if he attempted a coordinated disclosure this time or if he just decided to go directly to a public disclosure because of his past experience with RuggedCom.

It will be interesting to see how quickly RuggedCom responds to this disclosure.

Sunday, June 24, 2012

ICS-CERT Updates ICS Internet Accessibility Alert


On Friday afternoon the DHS ICS-CERT updated their alert on internet accessibility of ICS systems that was originally issued in January. The original report outlined a large number of reports of ICS systems being found on the Internet through the use of SHODAN, Googel, ERIPP and other search engines. This update provides information about Internet facing ICS systems with default passwords or weak authentication.

The update starts off (pg 2) by explaining that: “ICS-CERT has recently become aware of multiple systems with default usernames and passwords that are accessible via the Internet.”

This generic claim is not much help to the general ICS community, but the Alert does note that ICS-CERT has directly contacted the owner/operators of the affected systems to let them know of their vulnerability.

There is a new vendor name included in this initial paragraph, Echelon and their i.LON series of communications devices. ICS-CERT notes that the new reports that they have received include information on “the Echelon i.LON product that is commonly deployed within ICS devices such as motors, pumps, valves, sensors, etc., which contain a default username and password”. They do note that this is not an ‘inherent vulnerability’ (read; the user should have corrected the situation during the installation process).

The alert revision goes on to remind their audience that there have been a number of ICS-CERT advisories (including: ClearSCADA, Siemens Simatic, and RuggedCom) about systems with weak authentication mechanisms. They do not specifically mention that any of these systems that have been reported to be Internet facing, but given the current state of ICS security it would seem inevitable that there would be a number of these systems that are relying solely on their weak authentication systems for Internet protection.

Nothing has changed in the sections of this Alert that deal with mitigation efforts. Neither ICS-CERT nor any other ICS security player has come up with a magic bullet to protect Internet facing ICS equipment. The revised alert simply serves as an updated reminder that every ICS owner/operator needs to take a hard look at their control systems to ensure that they are appropriately protected. As such this updated alert deserves the widest possible dissemination.

NOTE: There is an interesting follow-up to this post written by Reid Wightman over on DigitalBond. Well worth reading and makes some additional points that bear attention. Plus he was nice enough to mention this post. [6-25-12 20:20 EDST]

Tuesday, June 19, 2012

ICS-CERT Updates RuggedCom Advisory


This afternoon the DHS ICS-CERT published an unusual update of an advisory that was published last month for a weak cryptography for password vulnerability in the RuggedCom operating system (ROS). The update corrects a poorly worded notice in the overview section of the original advisory that claimed that RuggedCom had “produced new firmware versions that resolve the reported vulnerability” (pg 1). As I noted in my earlier blog on the advisory, that over stated the extent of the mitigation; as a close reading of the original advisory really did make clear.

The update also announces that firmware updates have been issued for additional versions of the ROS. At least one additional firmware update is scheduled to be released “within the next few weeks“ (pg 3). It will be interesting to see if an additional update is issued when that next firmware update becomes available. I had half-way expected to see one for each of the version updates listed in this advisory; hopefully there was some other communications methodology used to alert system owners when these firmware updates were made available (and a passive listing on the RuggedCom web site doesn’t hardly count).

Sunday, May 27, 2012

RuggedCom Update and ICS-CERT Tips Published


Friday the folks at ICS-CERT published an advisory updating the vulnerability information for RuggedSwitch and RuggedServer that were identified last month. They also published a technical information paper covering mitigation strategies for dealing with identified or suspected cyber  intrusions.

RuggedCom Advisory


This Advisory is actually the second ICS-CERT follow-up to the initial alert on this vulnerability; there was an amended alert issued two days after the initial alert noting that RuggedCom would be issuing a firmware update within the month. This Advisory confirms that the firmware update was made available and ICS-CERT has confirmed that it effectively mitigates the vulnerability.

Actually that’s an overstatement of facts as a closer reading of the Advisory makes clear. The firmware update provided only applies to ROS 3.10.1. Updates for other versions will be released ‘in the next few weeks on a staggered basis’. The reason is that each version requires its own variations to be developed, tested and verified. While this may be initially confusing (especially for system owners that have equipment with different versions of the ROS in their various pieces of RuggedCom equipment) it does insure that the updated firmware gets into the field as quickly as possible.

RuggedCom will publish a new product bulletin for each of the updates as they are made available. It is not clear if ICS-CERT will update this advisory each time a new ROS version is updated. I suspect that they probably will.

Apparently RuggedCom is not planning on providing firmware updates to ROS versions earlier than 3.7. They are urging customers to upgrade products with older versions. ICS-CERT notes that RuggedCom has indicated a willingness to work with customers that are unable to make such upgrades.

Updating firmware has its own special challenges in installed equipment. To make matters more interesting in this case is the apparent fact that the update changes the way that the RuggedCom equipment will now handle recovery of administrative passwords. The ICS-CERT Advisory provides this information:

“These new versions of the ROS firmware remove the factory account and the associated security vulnerability. Customers using these new versions of the firmware should take special care not to lose the user defined password to a device’s administrative account as recovering from a lost administrative password will now require physical access to the device to reset the passwords.”

On a purely editorial note, it appears that ICS-CERT is providing a little more credit for the initiators of uncoordinated disclosures. This Advisory provides a link to the Justin Clark public disclosure of the vulnerability in these systems. In my opinion this is long overdue as a minimum standard of the acknowledgement of the intellectual property of the researcher involved.

Cyber Intrusion Mitigation


Friday also saw the publication of one of ICS-CERT’s infrequent tip sheets. According to the introduction this 8-page document provides “ high-level strategies that should can improve overall visibility of a cyber intrusion and aid in recovery efforts should an incident occur” (pg 1). While it is not stated anywhere in the document, I would assume that this is at least partially in response to the phishing attacks on US gas companies that were reported earlier this month.

The document addresses:

• Preserving forensic data;

• Detection and mitigation activities, including:

∙ Intrusion detection / preventing lateral network movement;

∙ Credential management;

∙ Increased logging capabilities;

∙ DNS logging with host level granularity; and

∙ Auditing network hosts for suspicious files;

• What to do with an infected host;

• Longer-term recommendations, including:

∙ Strict role-based access control;

∙ Network segmentation;

∙ Application whitelisting, and;

∙ Phishing prevention.

As one would expect, there is nothing really new here, but it is a nice summary of the multiple levels of cyber protection that need to be employed to help reduce the effectiveness and impact of a targeted cyber-attack.

Friday, April 27, 2012

Quick Response from RuggedCom


This afternoon the folks at DHS ICS-CERT published an updated version of the RuggedCom alert that they published earlier this week. They added the following paragraph to the ‘mitigation’ section of the alert;

“ICS-CERT is coordinating with RuggedCom who has indicated that they intend to release a patch that removes the backdoor access to address this reported vulnerability. They plan to release this patch within the next month. In addition, RuggedCom has released a notification regarding this issue that can be accessed at http://www.ruggedcom.com/productbulletin/ros-security-page/.”

Less than a week to get this response from is fairly impressive, even if they have had the vulnerability information for just about a year now. Sometimes you just have to get someone’s attention.

Actually I would assume that they had been doing at least some work on the patch done since they were notified of the vulnerability. I would guess that it was a low priority project since it wasn’t going to be making the company any money. As long as the researchers wasn’t going public there wouldn’t be any real need to get the patch developed in a timely manner.

There is another potential explanation. The alert notes that RuggedCom was acquired by Siemens ‘earlier this year’. Given Siemens problems with vulnerabilities in their control systems it might seem that a company that was looking to be bought by Siemens might have a reason to ensure that a recently identified vulnerability didn’t make the news. It might even be a good idea to insure that the team doing a due-diligence inspection didn’t find out about the problems.

We won’t ever know which of the two possibilities (or maybe some other that I haven’t thought of) was really responsible for the delay in getting the development under way. In the long run, I guess it doesn’t really matter; a vulnerability has been identified and is being patched. Hopefully the bad guys won’t use it in the meantime.

Fortunately, the only people slower to exploit cybersecurity vulnerabilities than Congress are the terrorists. Hopefully it remains that way.

Wednesday, April 25, 2012

Another Widespread ICS Vulnerability


Today the DHS ICS-CERT published a more than slightly delayed alert about a serious vulnerability in various network devices from RuggedCom. The vulnerability was reported (in an attempted coordinated disclosure) by Justin W. Clarke.

Justin reported that:

“An undocumented backdoor account exists within all released versions of RuggedCom's Rugged Operating System (ROS®).  The username for the account, which cannot be disabled, is ‘factory’ and its password is dynamically generated based on the device's MAC address.”

The Advisory briefly notes that there was an “an attempted but unsuccessful coordination with the vendor” but there is a more detailed description of the apparent failure of RuggedCom to adequately respond to the disclosure.

Unusual for an alert, ICS-CERT is reporting that RuggedCom has recommended that “customers to disable the rsh (remote shell) service and set the number of Telnet connections allowed to 0”, but ICS-CERT also notes that they have not verified that this resolves the vulnerability issue.
 
/* Use this with templates/template-twocol.html */