Showing posts with label S4x14. Show all posts
Showing posts with label S4x14. Show all posts

Thursday, January 16, 2014

ICS-CERT Publishes Advisory for Yesterday’s Ecava Alert

Today, in what is probably record time, ICS-CERT published an advisory for the Ecava IntegraXor buffer overflow vulnerability that was reported yesterday in an ICS-CERT alert. The vulnerability was reported yesterday by Luigi at the S4x14 security conference in Miami. Would that all vulnerabilities could be resolved this quickly

ICS-CERT notes that the vulnerability can be remotely exploited by a relatively unskilled attacker using publicly available exploit code. A successful exploit could result in a denial of service.

ICS-CERT reported that Ecava confirmed the existence of the vulnerability and developed a patch for the problem which is now available on-line. Additionally Ecava published a vulnerability notice describing the problem and proposing some additional mitigation measures that can be used to deal with the situation. There is no indication that Luigi has had a chance to verify the efficacy of the mitigation measures/ It is understandable that the Ecava management wants to get this problem addressed as quick as possible since the exploit code is publicly available.

Specifically Ecava notes that to successfully exploit this vulnerability one need the complete project URL. They suggest that users of this system take care not to publish the full URL of projects. They also suggest that system operators not use the default port with the system.


Ecava is to be commended on their quick response to this issue.

Wednesday, January 15, 2014

ICS-CERT Publishes First S4x14 Alert

Dale must be proud (grin); this evening DHS ICS-CERT published their first alert for a vulnerability disclosure from Digital Bond’s S4 conference in Miami. Appropriately enough the vulnerability was disclosed by Luigi, the first since Luigi and his partner Donato formed ReVuln.com.

According to the alert Luigi disclosed a buffer overflow vulnerability in the Ecava IntegraXor SCADA/HMI interface. As with past Luigi disclosures this was accompanied by proof-of-concept code.

I think that this is the same disclosure that Dale Tweeted about this afternoon:

@digitalbond - Luigi & Donato demoing ICS vuln and there fix to it, without any vendor involvement, #S4x14

A buffer overflow vulnerability is hardly worth mentioning at a conference like S4x14. The big news was apparently that Luigi and company had discovered a way to fix the vulnerability without getting the vendor involved. This would certainly be good news for Luigi’s system owner clients; they could get their systems fixed before anyone else, including the vendor, was made aware of the vulnerability.


While some vendors are working hard at establishing a reputation for quickly responding to vulnerability disclosures, most still have a long way to go (for example we are still waiting for a piss pot load of Crain-Sistrunk vulnerability disclosures by the vendors for vulnerabilities identified last summer).
 
/* Use this with templates/template-twocol.html */