Showing posts with label SEC Consult. Show all posts
Showing posts with label SEC Consult. Show all posts

Saturday, December 9, 2023

Review – Public ICS Disclosures – Week of 12-2-23

This week we have 37 vendor disclosures from CODESYS, Dell (2), HP, HPE, Insyde, Pilz (3), QNAP (3), SEL (2), Siemens, Tanzu (20), and Wago (2). There are three vendor updates from Atos, CODESYS, and Dell. We have two researcher reports for vulnerabilities in products from Atos and R Radio Network. Finally, we have two exploits for products from FortiGuard and Orpak.

Advisories

CODESYS Advisory - CODESYS published an advisory that describes an OS command injection vulnerability in their Control runtimes running on Linux or QNX operating systems.

Dell Advisory #1 - Dell published an advisory that discusses an out-of-bounds write vulnerability in the ThisOS.

Dell Advisory #2 - Dell published an advisory that discusses 28 vulnerabilities in their Dell Wyse Management Suite.

HP Advisory - HP published an advisory that discusses an improper input validation vulnerability in multiple notebook and desktop computers.

HPE Advisory - HPE published an advisory that describes an information disclosure vulnerability in their HP-UX System Management Homepage.

Insyde Advisory - Insyde published an advisory that discusses an improper input validation vulnerability in multiple kernels

Pilz Advisory #1 - CERT-VDE published an advisory that discusses two vulnerabilities in the Pilz PASvisu and PMI products.

Pilz Advisory #2 - CERT-VDE published an advisory that discusses an out-of-bounds write vulnerability in the Pilz PASvisu, PIT Transponder Manager, and PMI products.

Pilz Advisory #3 - Pilz published an advisory that discusses vulnerabilities in multiple products.

QNAP Advisory #1 - QNAP published an advisory that describes a cross-site scripting vulnerability in their QTS and QuTS hero products.

QNAP Advisory #2 - QNAP published an advisory that describes an OS command injection vulnerability in their legacy VioStor NVR product.

QNAP Advisory #3 - QNAP published an advisory that describes two classic buffer overflow vulnerabilities in their QTS and QuTS hero products.

QNAP Advisory #4 - QNAP published an advisory that discusses five vulnerabilities in their QTS and QuTS hero products.

SEL Advisories - SEL announced new versions of two products that address cybersecurity issues.

Siemens Advisory - Siemens discussed a Black Hat Europe presentation describing the details of the legacy PG/PC and HMI communication protocol as used between TIA Portal / HMIs and SIMATIC S7-1500 SW Controller in versions before V17.

Tanzu Advisories - Tanzu published 20 advisories discussing third-party vulnerabilities in various Tanzu products.

Wago Advisory #1 - CERT-VDE published an advisory that describes an observable discrepancy vulnerability in the Wago Smart Designer product.

Wago Advisory #2 - CERT-VDE published an advisory that describes an improper input validation vulnerability in the Wago Telecontrol Configurator and WagoAppRTU products.

Updates

Atos Update - Atos published an update for their Unify OpenScape advisory that was originally published on October 4th, 2023 and most recently updated on September 10th, 2023.

CODESYS Update - CODESYS published an update for their WIBU CodeMeter Runtime advisory that was originally published on August 17th, 2023 and most recently updated on October 31st, 2023.

Dell Update - Dell published an update for their Rugged Control Center advisory that was originally published on November 30th, 2023.

Researcher Reports

Atos Report - SEC Consult published a report that describes an argument injection vulnerability in the Atos Unify OpenScape products.

R Radio Network Report - Zero Science published a report describing two vulnerabilities in the R Radio Network.

Exploits

FortiGuard Exploit - Cody Sixteen published an exploit for a post authentication CLI crash vulnerability in the FortiWeb VM product.

Orpak Exploit - Parsa Rezaei Khiabanloo published an exploit for a default password vulnerability in the Orpak fueling systems.

 

For more details about these disclosures, including links to researcher reports, 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-66a - subscription required.

Saturday, July 8, 2023

Review – Public ICS Disclosures – Week of 7-1-23

This week we have eleven vendor disclosures from Aruba Networks, Bosch (2), Enphase, Frauscher Sensortechnik, Hikvision, Moxa, Softing (2), VMware and Zyxel. And we have 29 researcher reports for products from Panasonic (3), Milesight (25), and Siemens.

Advisories

Aruba Advisory - Aruba published an advisory that describes nine vulnerabilities in the Aruba OS products.

Bosch Advisory #1 - Bosch published an advisory that discusses two vulnerabilities in their FL MGUARD family devices.

Bosch Advisory #2 - Bosch published an advisory that discusses a missing authentication for critical function vulnerability in their SLC-0-GPNT00300 interface module.

Enphase Advisory - Enphase published an advisory that describes an OS command injection vulnerability in their Enphase IQ Gateway (Envoy).

Frauscher Advisory - CERT-VDE published an advisory that describes a path traversal vulnerability in the Frauscher Diagnostic System FDS001 for FAdC R1 and FAdCi R1.

Hikvision Advisory - Hikvision published an advisory that describes two vulnerabilities in their access control/intercom products.

Moxa Advisory - Moxa published an advisory that describes an observable response discrepancy vulnerability in their TN-5900 Series product.

Softing Advisory #1 - Softing published an advisory that describes two vulnerabilities in their OPC UA C++ SDK and Secure Integration Server.

Softing Advisory #2 - Softing published an advisory that describes an uncontrolled resource consumption vulnerability in a number of their products.

VMware Advisory - VMware published an advisory that describes an authentication bypass vulnerability in their SD-WAN (Edge) product.

Zyxel Advisory - Zyxel published an advisory that describes a classic buffer overflow vulnerability in their 4G LTE and 5G NR outdoor routers.

Researcher Reports

Panasonic Reports - AWESEC published three reports describing individual vulnerabilities in the Panasonic Panasonic AiSEG2.

Milesight Reports - Talos Intelligence published 25 reports (some with multiple vulnerabilities) for the Milesight UR32L urvpn_client and MilesightVPN server.

Siemens Report - SEC Consult published a report describing the four vulnerabilities in the Siemens A8000 product.

 

For more details about these disclosures, including links to third-party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-bcb - subscription required.

Saturday, June 18, 2022

Review – Public ICS Disclosures – Week of 6-11-22 – Part 2

For Part 2 we have nine vendor disclosures from Dell and Schneider (8). We also have four vendor updates for products from Fujitsu, Dell, HP, and HPE. We also have three researcher reports for products from Bachmann Visutec, Blynk, and Nexans. Part 3 tomorrow will cover Schneider and Siemens updates.

Dell Advisory - Dell published an advisory that discusses the SpringShell vulnerabilities.

Schneider Advisory #1 - Schneider published an advisory that describes two vulnerabilities in their EcoStruxure™ Cybersecurity Admin Expert.

Schneider Advisory #2 - Schneider published an advisory that describes an improper restriction of operations within the bounds of a memory buffer in their CanBRASS design and costing tool.

Schneider Advisory #3 - Schneider published an advisory that describes two vulnerabilities in their C-Bus Home Automation Products.

Schneider Advisory #4 - Schneider published an advisory that describes three vulnerabilities in their EcoStruxure Power Commission software.

Schneider Advisory #5 - Schneider published an advisory that describes three vulnerabilities in their Conext™ Combox communications and monitoring device.

Schneider Advisory #6 - Schneider published an advisory that describes an exposure of resource to wrong sphere vulnerability in their Geo SCADA Mobile application.

Schneider Advisory #7 - Schneider published an advisory that describes eight vulnerabilities in their Interactive Graphical SCADA System (IGSS).

Schneider Advisory #8 Schneider published an advisory that describes four vulnerabilities in their Data Center Expert product.

NOTE: This advisory was updated on June 16th, 2022. The new information included updating affected version information and clarification of fixed versions.

Fujitsu Update - JPCert published an update for the FUJITSU Network IPCOM advisory that was originally published on  May 19th, 2022 and most recently updated on June 10th, 2022.

Dell Update - Dell published an update for their Log4Shell advisory.

HP Update - HP published an update for their Wireless Bluetooth advisory that was originally published on February 8th, 2022.

HPE Update - HPE published an update for their Synergy Servers advisory that was originally published on May 10th, 2022 and most recently updated on May 31st, 2022.

Bachmann Report - Talos published a report describing an information disclosure vulnerability in the Bachmann Atvise SCADA registration function.

Blynk Report - Talos published a report describing a stack-based buffer overflow vulnerability in the Blynk-Library.

Nexans Report - SEC Consult published a report describing the four vulnerabilities in the Nexans FTTO GigaSwitch series due to using outdated software components.

 

For more details about these disclosures, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-af5 - subscription required.

Saturday, March 13, 2021

Public ICS Disclosures – Week of 3-6-21

This week we have seven disclosures from Aruba Networks (2), Boston Scientific, PEPPERL+FUCHS, Siemens, and Schneider (2). We have vendor updates for products from Siemens (2) and Schneider (2). There is a researcher report for products from Fatek Automation. Finally, there was an exploit published for products from VMware.

Aruba Advisories

Aruba published an advisory discussing the SAD DNS vulnerability in their Instant Access Points products. Aruba has new versions that mitigate the vulnerability.

 

Aruba published an advisory describing nineteen vulnerabilities in their Instant Access Points products. Aruba has new versions that mitigate the vulnerabilities.

The 19 reported vulnerabilities are:

• Buffer overflow (3) - CVE-2019-5319, CVE-2021-25144, and CVE-2021-25149,

• Authenticated arbitrary remote command injection - CVE-2021-25150,

• Authenticated arbitrary file write - CVE-2021-25148,

• Unauthenticated command injection via DHCP options - CVE-2020-24636,

• Unauthenticated denial of service via PAPI protocol -CVE-2021-25143,

• Unauthenticated command injection via Web UI - CVE-2021-25162,

• Authenticated arbitrary file write via Web UI (2) - CVE-2021-25155, and CVE-2021-25159,

• Authenticated remote command execution (2) - CVE-2020-24635, and CVE-2021-25146,

• Authentication bypass - CVE-2019-5317 (Jenkins third-party),

• Authenticated reflected cross-site scripting - CVE-2021-25161,

• Unauthenticated arbitrary file read via race condition - CVE-2021-25158,

• Authenticated arbitrary directory create via Web UI - CVE-2021-25156,

• Authenticated arbitrary file read via Web UI - CVE-2021-25157,

• Authenticated arbitrary file write via Web UI to specific backup site - CVE-2021-25160, and

• Remote unauthorized disclosure of information - CVE-2021-25145,

Boston Scientific

Boston Scientific published an advisory discussing the Microsoft TCP/IP vulnerabilities. They report that they are looking into the impact on their products “that use the affected Microsoft Window 7 and higher operating systems”.

PEPPRERL+FUCHS Advisory

CERT-VDE published an advisory describing three vulnerabilities in the PEPPERL+FUCHS P+F RocketLinx products. The vulnerabilities were reported by T. Weber of SEC Consult Vulnerability Lab.  PEPPERL+FUCHS has new firmware versions that mitigate the vulnerabilities. There is no indication that Weber was provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Cross-site request forgery - CVE-2020-12502,

• Improper input validation - CVE-2020-12503, and

• Hidden functionality - CVE-2020-12504

Siemens Advisory

Siemens published an advisory describing an improper access control vulnerability in their Mendix Forgot Password Appstore module. Siemens has a new version that mitigates the vulnerability.

Schneider Advisories

Schneider published an advisory describing an improper restriction of operations within the bounds of a memory buffer vulnerability in their PowerLogic power meters. The vulnerability was reported by Tal Keren and Rei Henigman of Claroty. Schneider has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Schneider published an advisory describing an improper restriction of operations within the bounds of a memory buffer vulnerability in their PowerLogic power meters. The vulnerability was reported by Tal Keren and Rei Henigman of Claroty. Schneider has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NOTE: The Claroty report explains the reason for the separate reports for these very similar vulnerabilities. They note that the different product sets are affected differently resulting in very different CVSS v3.0 Base Scores.

Siemens Updates

Siemens published an update for their GNU/Linux subsystem advisory that was originally published in 2018 and most recently updated on February 9th, 2021. The new information includes adding the following CVEs:

• CVE-2020-8625,

• CVE-2021-3347,

• CVE-2021-20193,

• CVE-2021-23839,

• CVE2021-23840,

• CVE-2021-23841, and

• CVE-2021-27212

 

Siemens published an update for their CodeMeter advisory that was originally published in 2018 and most recently updated on February 9th, 2021. The new information includes updating mitigation measures for:

• SINEC INS, and

• SINEMA Remote Connect

Schneider Updates

Schneider published an update for their Ripple20 advisory that was originally published on June 23, 2020 and most recently updated on January 12th, 2021. The new information includes:

• Adding mitigation measures for EcoStruxure Building SmartX IP MP Controllers, and

• Updating affected version information for EcoStruxure Building SmartX IP RP Controllers

 

Schneider published an update for their PLC Simulator advisory that was originally reported on November 11th, 2020. The new information includes announcing the development of a remediation plan for CVE2020-7559.

NOTE: NCCIC-ICS may not update ICSA-20-315-03 for this announcement.

Fatek Report

The Zero Day Initiative published a report of a 0-day improper validation of user supplied data vulnerability in the Fatek PLC WinProladder. According to the report, NCCIC-ICS was supposed to issue an advisory on this last Thursday. I would expect to see it published this coming week.

VMware Exploit

Mikhail Klyuchnikov published a Metasploit module for an improper privilege management vulnerability in the VMware vCenter Server. VMware reported the vulnerability on February 23rd, 2021 with new versions to mitigate.

Saturday, January 9, 2021

Public ICS Disclosures – Week of 1-2-21

This week we have six vendor disclosures from Siemens Healthineers, PEPPERL+FUCHS, Johnson and Johnson, Meinberg, Ruckus, and WIBU systems. There is an updated disclosure from HMS. Finally, there is a researcher report on vulnerabilities in products from Rockwell Automation.

Siemens Advisory

Siemens published an advisory describing a third-party (Telerik UI) java script deserialization vulnerability in their syngo.via software. The vulnerability was reported by Ryan Wincey from Securifera and Austin Nuttal. Siemens has patches for some of the affected versions. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NOTE: There are exploits available (here and here) for the underlying Telerik vulnerability.

PEPPERL+FUCHS Advisory

CERT VDE published an advisory describing six vulnerabilities in the PEPPERL+FUCHS Comtrol IO-Link Master product. The vulnerabilities were reported by T. Weber of SEC Consult Vulnerability Lab. PEPPERL+FUCHS has new versions that mitigate the vulnerabilities. There is no indication that Weber has been provide an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Cross-site scripting (2) - CVE-2020-12511 and CVE-2020-12512,

• OS Command injection - CVE-2020-12513,

• Null pointer dereference - CVE-2020-12514,

• Out-of-bounds read - CVE-2018-20679, and (CISCO vuln, exploit available)

• Key management errors - CVE-2018-0732 (OpenSSL vuln)

Johnson and Johnson Advisory

Johnson and Johnson published an advisory announcing a new version of the Biosense Webster CARTO® 3 Systems that provides mitigation measures for a number of third-party (Windows OS) vulnerabilities.

Meinberg Advisory

Meinberg published an advisory describing a third-party (OpenSSL) null pointer dereference vulnerability in their LANTIME firmware. This vulnerability is self-reported. Meinberg has new versions that mitigate the vulnerability.

Ruckus Advisory

Ruckus published an advisory describing an arbitrary file read vulnerability in their Access Point products. The vulnerability is self-reported. Ruckus has new firmware versions available that mitigate the vulnerability.

WIBU Systems Advisory

WIBU Systems published an advisory describing three third-party (XStream) vulnerabilities in their AxProtector for Java product. The vulnerabilities are self-reported. They note that the AxProtector for Java is not affected itself by any of these vulnerabilities because a whitelist is used, but they are providing an update that mitigates the XStream vulnerabilities. Exploits are available for all three vulnerabilities at the links below.

The three reported vulnerabilities are:

• Command injection - CVE-2020-26217,

• Server-side request forgery - CVE-2020-26258, and

• OS command injection - CVE-2020-26259

HMS Update

HMS published an update of their Amnesia:33 vulnerabilities advisory that was originally published on December 11th, 2020. The new information includes adding additional products to the ‘confirmed not affected’ list.

Rockwell Report

Talos published a report describing a denial-of-service vulnerability in the Rockwell RSLinx classic ethernet/IP server. This is a coordinated disclosure, but Rockwell has not yet published an advisory describing this vulnerability. The Talos report contains proof-of-concept code.

Saturday, September 5, 2020

Public ICS Disclosures – Week of 8-29-20


This week we have two new vendor disclosures for products from SICK and BD. There were also three Ripple20 [Corrected link, 10-18-20, 0857] updates published for products from HMS, Braun and Schneider. We also have a vendor update from Yokogawa. There is also one researcher report with exploits for vulnerabilities for products from Red Lion.

SICK Advisory


SICK published an advisory describing an improper handling of exceptional conditions vulnerability in their SOPAS Engineering Tool. The vulnerability was reported by Ruben Santamarta of IOActive. SICK has released new firmware versions that mitigate the vulnerability. There is no indication that Santamarta has been provided an opportunity to verify the efficacy of the fix.

BD Advisory


BD published an advisory describing three third-party (VMware) vulnerabilities in selected BD products. BD is currently testing the VMware update.

The three reported vulnerabilities are:

• Local privilege escalation - CVE-2020-3957,
• Denial of service - CVE-2020-3958, and
• Memory leak - CVE-2020-3959

Ripple20 Updates


HMS published an update of their Ripple20 advisory that was originally published on June 23, 2020. The new information includes adding the following products to the not affected list:

• Anybus M-Bus to Modbus TCP gateway,
• Anybus WLAN Access Points (AWB4xxx), and
• Ewon Netbiter 100, 200 and 300-series

Braun published an update of their Ripple20 advisory that was originally published on June 30th, 2020. The updated information includes more details on the Ripple20 effect on the Outlook 400ES infusion pump.

Schneider published an update of their Ripple20 advisory that was originally published on June 23, 2020 and most recently updated on August 6th, 2020. The new information includes:

• Adding mitigation measures for Cooling Products using NMC2, and
• Adding partial remediations for TM3BC bus coupler module – EIP, TM3BC bus coupler module – SL, and TM3BC bus coupler module – CANOpen

Yokogawa Update


Yokogawa published an update for their CAMS for HIS advisory that was originally published on July 31st, 2020. The new information includes updated affected product data.

Red Lion Report


SEC Consult published a report on multiple vulnerabilities in the Red Lion N-Tron products that were reported last week by CISA NCCIC-ICS. The SEC Consult report includes proof-of-concept exploit code and a list of outdated third-party components.

Saturday, March 14, 2020

Public ICS Disclosures – Week of 3-7-20


This week we have eight vendor disclosures for products from WAGO (7) and Beckhoff. We also have a researcher report of exploit code for previously disclosed vulnerabilities for products from Phoenix Contact.

WAGO Advisories


VDE CERT published an advisory describing two vulnerabilities in the WAGO e!Cockpit. The vulnerabilities were reported by Nico Jansen of FH Aachen and Carl Hurd of Cisco Talos. WAGO provides generic mitigation measures for these vulnerabilities.

The two reported vulnerabilities are:

Cleartext transmission of sensitive information - CVE-2019-5107; and
Use of broken or risky cryptographic algorithm - CVE-2019-5106

NOTE: The CVE link above are to Talos vulnerability reports that contains exploit code.


VDE CERT published an advisory describing two vulnerabilities in the WAGO Web-Based Management Authentication. The vulnerabilities were reported by Daniel Szameitat and Jan Hoff of innogy SE, and Daniel Patrick DeSantis and Lilith [-_-] of Cisco Talos. WAGO has a new firmware version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Regular expression without anchor - CVE-2019-5134; and
Information exposure through timing discrepancy - CVE-2019-5135

NOTE: The CVE links above are to Talos vulnerability reports that contains exploit code.


VDE CERT published an advisory describing an insufficient resource pool vulnerability in the WAGO Web-Based Management (wbm) of WAGO PLCs. The vulnerability was reported (report contains exploit code) by  Daniel Patrick DeSantis of Cisco Talos.


VDE CERT published an advisory describing four vulnerabilities in the Wago Cloud Connectivity. The vulnerabilities were reported by Kelly Leuschner of Cisco Talos. WAGO provides generic mitigation measures for these vulnerabilities.

The four reported vulnerabilities are:

Improper access control - CVE-2019-5160;
Improper neutralization of special elements used in OS command (3) - CVE-2019-5155, CVE-2019-5157 and CVE-2019-5156;

NOTE: The CVE links above are to Talos vulnerability reports that contains exploit code.


VDE CERT published an advisory describing two vulnerabilities in the WAGO eCockpit Update Package. The vulnerabilities were reported by Kelly Leuschner of Cisco Talos. WAGO provides hashes for the wup files.

The two reported vulnerabilities are:

External control of file name path - CVE-2019-5159; and
Improper input validation - CVE-2019-5158

NOTE: The CVE links above are to Talos vulnerability reports that contains exploit code.


VDE CERT published an advisory describing a reliance on file name or extension of external-supplied file vulnerability in the WAGO Cloud Connectivity service. The vulnerability was reported (report contains exploit code) by Kelly Leuschner of Cisco Talos. WAGO provides generic mitigations for this vulnerability.


VDE CERT published an advisory describing 20 vulnerabilities in the WAGO I/O-Check Service. The vulnerabilities were reported by Kelly Leuschner of Cisco Talos. WAGO provides generic mitigation measures for these vulnerabilities.

The 20 reported vulnerabilities are:

Double free - CVE-2019-5184

NOTE: The CVE links above are to Talos vulnerability reports that contains exploit code.

Beckhoff Advisory


VDE CERT published an advisory describing an uncontrolled resource vulnerability in the Beckhoff BK9000 couplers. The vulnerability was reported by Martin Menschner from Rhebo GmbH. According to VDE CERT, Beckhoff is not changing this behavior.

Phoenix Contact Exploit


SEC Consult published a report containing exploit code for the command injection vulnerability reported earlier this month by Phoenix Contact. This was a coordinated disclosure.

Saturday, December 7, 2019

Public ICS Disclosures – Week of 11-30-19


This week we have three vendor disclosures for products from BD, GE and Johnson Controls and an URGENT/11 update from Belden. There are also three exploit code reports for products from Fronius, Salto and YachtControl.

BD Advisory


BD published an advisory describing and anti-virus bypass vulnerability in BD products with workstations running CylancePROTECT®. The third-party vulnerability was originally reported by Skylight. BD recommends updating the CylancePROTECT product.

NOTE: I wonder what other ICS vendors bundle CylancePROTECT as a cybersecurity tool? Since the product does not need to do signature updates it would seem to be a tool designed for control system security.

GE Advisory


GE published an advisory describing two privilege escalation vulnerabilities in the GE Digital HMI/SCADA iFIX product. The vulnerability was reported by Applied Risk. GE provides generic mitigation guidance for the vulnerability.

Johnson Controls Advisory


Johnson Controls published an advisory describing vulnerabilities in a third-party component of their Software House C•CURE 9000 application. The vulnerabilities in the Flexera FlexNet Publisher licensing manage have been previously reported. Johnson Controls has an update that mitigates the vulnerability.

Belden Update


Belden published an update of their URGENT/11 advisory that was originally published July 29th, 2019 and most recently updated on October 30th, 2019. The new information includes update information for Hirschmann HiOS RSPE TSN.

Fronius Expliot


SEC Consult published a report containing exploit code for four vulnerabilities in the solar inverter series of Fronius. This is reportedly a coordinated disclosure. Fronius has a firmware patch that mitigates the vulnerabilities. There is no indication that SEC Consult has been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Unencrypted communication;
• Authenticated path traversal - CVE-2019-19229;
• Backdoor account - CVE-2019-19228; and
• Outdated and vulnerable software components

NOTE: This is the first time that I have seen an easter-egg included in a vulnerability report.

Salto Exploit


SEC Consult published a report containing exploit code for six vulnerabilities in the Salto ProAccess Space management software for an access control system. This is reportedly a coordinated disclosure. Salto has a patch that mitigates the vulnerabilities. There is no indication that SEC Consult has been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Path traversal - CVE-2019-19458;
• Arbitrary file write - CVE-2019-19459;
• Stored cross-site scripting - CVE-2019-19457;
• Webserver running as Windows Service per default - CVE-2019-19460;
• Authorization issues; and
• Cleartext transmission of sensitive data

Yachtcontrol Exploit


Hodorsec published exploit code for a remote code execution vulnerability in the Yachtcontrol web application. The report includes a CVE number so this may be a coordinated disclosure.

Saturday, October 13, 2018

Public ICS Disclosures – Week of 10-06-18


This week there was a vendor vulnerability disclosure from Siemens. There were also four exploits published for products from Delta Industrial, WAGO, and Phoenix Contact (2). I am also going to take a quick look at some additional information on an NCCIC-ICS advisory for the Hangzhou XMeye P2P Cloud Server published this week.

Siemens Advisory


Siemens published an advisory on Foreshadow and L1 Terminal Fault (L1TF) in their industrial product line. These are another pair of speculative execution attack vulnerabilities based on processors used in the affected devices. More details on the generic vulnerabilities can be found here. Siemens has some bios updates available to mitigate the vulnerabilities (three separate CVE’s involved) and has provided workarounds for other products.

This advisory was published in the same batch that was covered extensively by NCCIC-ICS on Tuesday. I have no idea why this was not included unless NCCIC-ICS is lumping these new vulnerabilities in with the Spectre and Meltdown problem. Even if that is the case, this would then have deserved an update to their alert on those issues.

Delta Industrial Exploit


A Metasploit module was published for a previously identified stack-based buffer overflow vulnerability in the Delta Industrial COMMGR software.

WAGO Exploit


SecuNinja published an exploit for a cross-site scripting vulnerability in the WAGO 750-881 ethernet controller. There is no CVE number provided so it is possible that this is a 0-day vulnerability being exploited.

Phoenix Contact Exploit


Photubias published two exploits for previously identified vulnerabilities in the Phoenix Contact ILC PLC vis their WebVisit HMI page.

The three reported vulnerabilities covered in these exploits are:

• Cleartext storage of sensitive information - CVE-2016-8366;
• Authentication bypass issues - CVE-2016-8371; and
• Access to critical private variable via public method - CVE-2016-8380.

Hangzhou Advisory


Earlier this week NCCIC-ICS published their advisory for three vulnerabilities in the Hangzhou XMeye P2P Cloud Server. As is typical for these advisories NCCIC-ICS provided summary data on the issue. Since Hangzhou effectively did not respond to the coordination efforts of NCCIC-ICS there was no vendor information provided in the advisory. While NCCIC-ICS did acknowledge the vulnerability reporting effort of SEC Consult, they did not (as is their apparent policy) provide any link to the reporting agency’s information on the vulnerabilities.

Generally speaking this policy of not linking to supporting documentation from researchers is a mistake and, in this instance, it does a gross disservice to the affected community by severely understating the potential problems associated with the affected devices. In particular, it fails to explain that the vulnerabilities affect a large number of vendors that rebrand and sell the affected Hangzhou DVR products.

SEC Consult published an advisory on the vulnerabilities as well as a lengthy blog post. Brian Krebs also did a lengthy blog post on the topic.

Saturday, July 14, 2018

ICS Public Disclosure – Week of 07-07-18


This week we have two vendor disclosures from Siemens and WAGO with a concurrent publication of exploit code for the WAGO vulnerabilities.

Siemens Advisory


This advisory describes two denial of service vulnerabilities in the Siemens EN100 Ethernet communication module and SIPROTEC 5 relays. The vulnerabilities were reported by Victor Nikitin, Vladislav Suchkov, and Ilya Karpov from ScadaX. Siemens recommends blocking access to port 102/tcp e.g. with an external firewall.

WAGO Advisory


This VDE-CERT advisory describes three vulnerabilities in the WAGO e!DISPLAY. The vulnerabilities were reported by SEC Consult. WAGO has a new firmware version that mitigates the vulnerabilities. There is no indication that SEC Consult has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Improper neutralization of input during web page generation - CVE-2018-12981;
• Unrestricted upload of file with dangerous type - CVE-2018-12980; and
Incorrect permission assignment for critical resource - CVE-2018-12979

The day after VDE-CERT released this advisory SEC Consult published exploit code for all three vulnerabilities on their web site and other locations (see here for example).

Tuesday, February 13, 2018

ICS-CERT Publishes Two Advisories

Today the DHS ICS-CERT published two control system security advisories for products from Schneider Electric and WAGO.

Schneider Advisory


This advisory describes a security misconfiguration vulnerability in the Schneider IGSS SCADA software. The vulnerability was reported by Ivan Sanchez of Nullcode. Schneider has developed a new version that mitigates the vulnerability. There is no indication that Sanchez has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively high-skilled attacker with local access could exploit the vulnerability to crash or execute arbitrary code.

WAGO Advisory


This advisory describes an improper authentication vulnerability in the WAGO PFC200 Series. The firmware vulnerability is due to a vulnerability in the CoDeSys Runtime that is included in that firmware. The CoDeSys Runtime vulnerability was reported by Reid Wightman in 2012 and was addressed by ICS-CERT in 2013. The vulnerability was reported in this WAGO product by SEC Consult. NOTE: ICS-CERT published an alert about this vulnerability last December.

ICS-CERT reports that a relatively low-skilled attacker could use a publicly available exploit to remotely exploit the vulnerability to gain unauthorized access to the PLC to perform operations on the file system without authentication.

Saturday, February 10, 2018

Public ICS Disclosures – Week of 02-04-18


This week we have two vendor (ABB and OSIsoft) released security reports that were not addressed by ICS-CERT, most likely because the vendor did not report these directly to that organization. We also have an interesting report on an unusual class of IOT devices

ABB Advisory


ABB published a security advisory describing an improper access control vulnerability in their SYS600 product. The vulnerability was reported by Fritz Sands via the Zero Day Initiative. ABB has provided a work around to mitigate the vulnerability.

An attacker with physical access to the server or with authenticated network access could exploit the vulnerability to add files and run arbitrary code and possibly escalate privileges.

OSI Advisory


OSIsoft released a new version of their PI Web API that addressed (among other things) an escalation of privilege vulnerability. The release notes [page for .PDF download] for the new version report the vulnerability as being fixed and note that it is a critical vulnerability. The vulnerability is described as:

“Core Services – CRITICAL VULNERABILITY: Escalation of privileges when Kerberos and Basic Authentication are enabled is mitigated.”

Further information on the vulnerability is supposed to be included in a dedicated security bulletin which has apparently not yet been published.

IOT Security Issue


For those with a prurient interest in cybersecurity of IOT, I will provide this link to SEC Consult’s blog post on the ‘Internet of Dildos’. I nearly stopped reading the post when I got to: “Moreover, an attacker was able to remotely pleasure individuals without their consent.” This is, however, a serious report on a large number of vulnerabilities in a real IOT product.

Saturday, December 2, 2017

Public ICS Disclosure – Week of 11-25-17

This week there were two industrial control system vulnerability disclosures on the Full Disclosure web site. They addressed products from Hikvison and CODESYS.

Hikvision Vulnerability


This report by IOT Sec describes a Wi-Fi access vulnerability in Hikvision Wi-Fi IP Cameras installed in a wired configuration. A default wireless SSID exists in the products with a setting of no WiFi encryption or authentication.

This disclosure was coordinated with Hikvision. No fix has been reported but a work around was described.

The disclosure timeline reported by IOT Sec includes an unsuccessful attempt to coordinate the vulnerability with ICS-CERT {as recommended by (US-?)CERT}. While IP cameras are only industrial control systems in the broadest sense, ICS-CERT has posted advisories for these products in the recent past (including some of the specific devices included in this report). I am very surprised that ICS-CERT did not respond to IOT Sec; I would hope that this was due to miscommunications issues, not bureaucratic inaction.

CODESYS Vulnerability



This report by SEC Consult describes an improper authentication vulnerability in the CODESYS WAGO PFC 200 Series. This appears to be an extension of a previously reported vulnerability. ICS-CERT reported on that advisory that it would affect products from as many as 260 other vendors that used the affected code. This disclosure was a coordinated with CODESYS and SEC Consult reports that CODESYS will release a patch next month.

Saturday, November 18, 2017

Public ICS Disclosure – Week of 11-12-17

Today this is not about a new disclosure but about some new information on an ICS-CERT advisory that was published this week. SEC Consult published additional information on the Siemens SICAM vulnerabilities on the FullDisclosure web site.

The ICS-CERT advisory reported that publicly available exploits were available, but did not provide a link. This report from SEC Consult provides proof of concept code for exploiting the first two vulnerabilities and a link to a very old (2003) link to an earlier report on the code injection vulnerability. That link leads to a report by Luigi Auriemma, a name that hasn’t been seen on this blog in quite some time.

The Luigi report is about the GoAhead web server that was apparently used by Siemens in the affected versions of the SICAM devices. This is not noted in either the ICS-CERT advisory or the Siemens security advisory. Luigi describes GoAhead this way:

“Goahead (sic) webserver is an embedded OpenSource server that can be build (sic) on a lot of systems (CE, Ecos, GNU/Linux, Lynx, MacOS, NW, QNX4, VXWORKS, Win32 and others).
“It is supported by a lot of companies that use it for their projects and it is also used like ‘base’ for other webservers, furthermore it has been developed for be very tiny and to run on embedded systems.”

Apparently, Siemens used an unpatched version of the webserver (Luigi reported that the vulnerability he reported was fixed in December 2003) in the affected versions of the SICAM devices. Since Siemens (and almost all other ICS vendors) did not start to take control system security seriously until after 2010 (STUXNET), it is not surprising that a newer version of the webserver was not incorporated in these devices; in fact, it is quite possible that they were not informed of the vulnerability.

This is an old, but continuing problem, with third party software used in many of the control system devices used still today. If the original vendor does not have an active method for sharing vulnerability information with all of its customers, the using vendor may not become aware of the vulnerability until some third-party researcher discovers the problem.


More disturbing in this case is the fact that neither ICS-CERT nor Siemens mentioned that the vulnerabilities (apparently all three) in the SICAM devices were based upon vulnerabilities in a GoAhead web server. If it were not for this separate SEC Consult disclosure, the community would not realize that that there was a third-party vulnerability involved that may still exist in other non-Siemens devices.

Thursday, February 18, 2016

ICS-CERT Publishes Two Advisories

Today the DHS ICS-CERT published two control system advisories for products from Harmon AMX and B+B SmartWorx. Note: In January Advantech acquired B+B SmartWorx for $99.85 million.

AMX Advisory

This advisory describes dual credential management vulnerabilities in a wide variety of Harman AMX multimedia devices. The advisory does not credit the research team (SEC Consult) that reported the vulnerabilities even though it was a coordinated disclosure. ICS-CERT notes that this had previously been publicly disclosed (for example see ars technica). AMX has produced patches or updates for some of the products covered and the remainder are in progress. SEC Consult was not provided an opportunity to verify the final fixes.

There are two separate vulnerabilities reported, but they apply to different lists of affected products. They are both listed as credential management vulnerabilities with separate CVE number: CVE-2015-8362 and CVE-2016-1984.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities with publicly available exploits to gain system access with elevated privileges.

There is an interesting blog post about these vulnerabilities from SEC Consult. Long live S.H.I.E.L.D.

BTW: Vulnerable devices are apparently used at the White House.

SmartWorx Advisory

This advisory describes an authentication bypass vulnerability in B+B SmartWorx VESP211 serial servers. The vulnerability was reported by Maxim Rupp. SmartWorx is still in the process of mitigating this vulnerability.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to perform administrative functions on the network without authentication.

Advantech recommends only deploying the affected devices behind a firewall while further mitigation measures are developed.


NOTE: The CVE number is a 2016 based number, ICS-CERT is reporting this without real mitigation in place and there are no publicly available exploits. Something odd is going on here. ICS-CERT usually holds off announcing a vulnerability until at least some mitigation measures are in place unless the vendor response is slow played. The CVE number would seem to indicate a recent report….
 
/* Use this with templates/template-twocol.html */