Showing posts with label SEC Consult Vulnerability Lab. Show all posts
Showing posts with label SEC Consult Vulnerability Lab. Show all posts

Saturday, October 10, 2020

Public ICS Disclosures – Week of 10-03-20

This week we have one vendor disclosure from PEPPERL+FUCHS and one vendor update for products from 3S.

PEPPERL+FUCHS Advisory

CERT-VDE published an advisory describing five vulnerabilities in the PEPPERL+FUCHS Comtrol RocketLinx ethernet switches. The vulnerabilities were reported by T. Weber of SEC Consult Vulnerability Lab. PEPPERL+FUCHS has new firmware versions available that mitigate the vulnerabilities. There is no indication that Weber has been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Unauthenticated device administration (2) - CVE-2020-12500 and CVE-2020-12502,

• Undocumented accounts - CVE-2020-12501,

• Multiple authenticated command injections - CVE-2020-12500, and

• Active TFTP-service - CVE-2020-12504

NOTE 1: The current version of this advisory on the CERT-VDE web page is marked as ‘Update A’, the original version was apparently published earlier in the week.

NOTE 2: SEC Consult reports that this is an OEM vulnerability which they do not name pending response to the vulnerability notification.

3S Update

3S published an update [.PDF download link] for their CodeMeter advisory that was originally published on September 16th, 2020 and most recently updated on September 24th, 2020. The new information includes more details about the coverage of the update for CODESYS v3.5.16.20.

Thursday, August 27, 2020

1 Advisory and 1 Update Published – 8-27-20


Today the CISA NCCIC-ICS published a control system security advisory for products from Red Lion and updated a medical device security advisory for products from OpenClinic GA.

Red Lion Advisory


This advisory describes five vulnerabilities in the Red Lion N-Tron 702W series products. The vulnerabilities were reported by Thomas Weber from SEC Consult Vulnerability Lab. These products went out of support in 2018 and cannot be updated.

The five reported vulnerabilities are:

• Cross-site scripting - CVE-2020-16210 and CVE-2020-16206,
• Cross-site request forgery - CVE-2020-16208,
• Backdoor - CVE-2020-16204, and
• Use of unmaintained third-party components - CVE-2017-16544

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to gain unauthorized access to sensitive information, execute system commands, and perform actions in the context of an attacked user.

NOTE: There are multiple proof-of-concept exploits available for the last vulnerability, actually multiple vulnerabilities. Some of those exploits of the BusyBox vulnerabilities can be found here, here and here.

OpenClinic Update


This update provides additional information on an advisory that was originally published on July 2nd, 2020. The new information includes three CVE numbers for vulnerabilities covered under the single listed ‘use of unmaintained third-party components vulnerability’; those CVE’s are

CVE-2014-0114 (Apache Struts, improper input validation, multiple exploits)
CVE-2016-1181 (Apache Struts, insufficient information, multiple exploits), and
CVE-2016-1182 (Apache Struts, improper input validation, multiple expoits)


Saturday, March 7, 2020

Public ICS Disclosure – Week of 2-29-20


This week we have lots of new ‘information’ on SweynTooth vulnerabilities and three vendor disclosures for products from Rockwell, Phoenix Contact and Moxa.

SweynTooth


In addition to the CISA alert for the SweynTooth  Bluetooth vulnerabilities published this week there was an advisory from the FDA and brief disclosures from the following medical device vendors:

Medtronic;
BD; and
Drager

Rockwell Advisory


Rockwell published an advisory describing four vulnerabilities in their MicroLogix Controllers and RSLogix 500 Software. The vulnerabilities were reported by Ilya Karpov, Evgeny Druzhinin from ScadaX Security and Dmitry Sklyarov from Positive Technologies. Rockwell has new versions for some products that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Use of hard-coded cryptographic key - CVE-2020-6990;
• Use of broken or risky algorithm for password protection - CVE-2020-6984;
• Use of client-side authentication - CVE-2020-6988; and
• Unsecured SMTP data storage - CVE-2020-6980

Phoenix Contact Advisory


Phoenix Contact published an advisory [.PDF download link] describing three vulnerabilities in their  TC ROUTER & TC CLOUD CLIENT devices. The vulnerabilities were reported by Thomas Weber, SEC Consult Vulnerability Lab. Phoenix Contact has new firmware that mitigates the vulnerability. There is no indication that Weber was provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Improper control of generation of code - CVE-2017-16544;
• Command injection - CVE-2020-9436; and
• Hard-coded certificate - CVE-2020-9435

NOTE: the first vulnerability is an old library problem that has lots of exploits available.

Moxa Advisory


Moxa published an advisory describing an improper authentication vulnerability in their MGate MB3180/MB3280/MB3480/MB3170/MB3270 Series Protocol Gateways. This is a self-reported vulnerability. Moxa has new firmware versions available that mitigate the vulnerability.

Thursday, June 13, 2019

3 Advisories Published – 06-13-19


Today the DHS NCCIC-ICS published two control system security advisories for products from WAGO and Johnson Controls. They also published a medical device security advisory for products from BD.

WAGO Advisory


This advisory describes three vulnerabilities in the WAGO 852 Industrial Managed Switches. The vulnerability was reported by T. Weber of SEC Consult Vulnerability Lab. WAGO reports that the latest firmware for the affected products mitigate the vulnerabilities. There is no indication that Weber has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

Use of hard-coded credentials - CVE-2019-12550;
Use of hard-coded cryptographic key - CVE-2019-12549;
Use of components with known vulnerabilities

Note: The CERT VDE advisory lists the following component vulnerabilities:

BusyBox (v 1.12.0) - CVE-2013-1813, CVE-2016-2148, CVE-2016-6301, CVE-2011-2716, CVE-2011-5325, CVE-2015-9261, CVE-2016-2147, CVE-2017-16544 etc.; and
GNU glibc (v 2.8) - CVE-2010-0296, CVE-2010-3856, CVE-2012-4412, CVE-2014-4043, CVE-2014-9402, CVE-2014-9761, CVE-2014-9984, CVE-2015-14 etc.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow a compromise of the managed switch, resulting in disruption of communication, and root access to the operating system. The SEC Consult report includes proof of concept code for the first two vulnerabilities.

Johnson Controls Advisory


This advisory describes an improper authorization vulnerability in the Johnson Controls exacqVision Enterprise System Manager. The vulnerability was reported by @bzyo_. Johnson Controls reports that the latest version mitigates the vulnerability. There is no indication that @bzyo_ has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerability to allow malicious code execution.

BD Advisory


This advisory describes two vulnerabilities in the BD Alaris Gateway Workstation. The vulnerability was reported by Elad Luz of CyberMDX. BD reports that the latest firmware mitigates the first vulnerability and provides generic mitigations for the second. The is no indication that Luz has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Improper access control - CVE-2019-10962; and
Unrestricted upload of file with dangerous type - CVE-2019-10959

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to view and edit device status and configuration details as well as cause devices to become unavailable.

Wednesday, October 10, 2018

7 Advisories and 7 Updates Published


Yesterday the DHS NCCIC-ICS published seven control system security advisories for products from Fuji Electric, Hangzhou Xiongmai Technology Co, Siemens (4) and GE. They also updated seven previously issued advisories for products from Siemens.

Fuji Advisory


This advisory describes an uncontrolled search path element advisory in the Fuji Electric Energy Savings Estimator. The vulnerability was reported by Karn Ganeshen. Fuji has released an update that mitigates the vulnerability. There is no indication that Ganeshen has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit this vulnerability to allow an attacker to load a malicious DLL and execute code on the affected system with the same privileges as the application that loaded the malicious DLL.

Hangzhou Advisory


This advisory describes three vulnerabilities in the Hangzhou XMeye P2P Cloud Server. The vulnerabilities were reported by Stefan Viehböck of SEC Consult Vulnerability Lab. Hangzhou has not provided mitigations for these vulnerabilities.

The three reported vulnerabilities are:

• Predictable from observable state - CVE-2018-17917;
• Hidden functionality - CVE-2018-17919; and
Missing encryption of sensitive data - CVE-2018-17915

NCCIC-ICS reports that a relatively low-skilled attacker with remote access could use a publicly available exploit to exploit these vulnerabilities to allow unauthorized access to video feeds with the potential to modify settings, replace firmware, and/or execute code.

SIMATIC S7-1500 Advisory


This advisory describes an improper input validation vulnerability in the Siemens SIMATIC S7-1500, SIMATIC S7-1500 Software Controller and SIMATIC ET 200SP Open Controller. The vulnerability was reported by Marcin Dudek, Jacek Gajewski, Kinga Staszkiewicz, Jakub Suchorab, and Joanna Walkiewicz from National Centre for Nuclear Research Poland. Siemens has updates to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to cause a denial-of-service condition on the network stack.

SIMATIC S7-1200 Advisory


This advisory describes a cross-site request forgery vulnerability in the Siemens SIMATIC S7-1200 CPU Family Version 4. The vulnerability was reported by Lisa Fournet and Marl Joos from P3 communications GmbH. Siemens has a firmware update that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow a CSRF attack if an unsuspecting user is tricked into accessing a malicious link.

ROX II Advisory


This advisory describes two improper privilege management vulnerabilities in the Siemens ROX II. The vulnerabilities were reported by Gerard Harney from NCC Group (reported in Siemens advisory not NCCIC-ICS). Siemens has a new version that mitigates the vulnerabilities. There is no indication that Harney has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow valid users to escalate their privileges and execute arbitrary commands.

SCALANCE Advisory


This advisory describes a cryptographic issues vulnerability in the Siemens SCALANCE W1750D. The vulnerability is fully described on the Return of Bleichenbacher's Oracle Threat (ROBOT) web site. Siemens is self-reporting the vulnerability. Siemens has a firmware update that mitigates the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit this vulnerability using publicly available exploits to allow an attacker to decrypt TLS traffic.

NOTE: I suspect that other ICS devices using TLS services could face similar TLS ROBOT problems. Too bad NCCIC-ICS has not done an alert on this issue. Then again, does NCCIC-ICS do alerts?

GE Advisory


This advisory describes an unsafe ActiveX control marked safe for scripting vulnerability in the GE Gigasoft component of iFix. The vulnerability was reported by LiMingzheng of 360 aegis security team. Recent versions of iFIX mitigate the vulnerability. There is no indication that LiMingzheg has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a buffer overflow condition.

Industrial Products Update


This update provides additional information on an advisory that was that originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th, November 28th, February 27th, 2018, May 3rd, 2018 May 15th, 2018, , and most recently on September 11th, 2018. The new information includes revised affected versions data and mitigation measures for SIMATIC S7-1200 CPU.

SIMATIC Update


This update provides additional information on an advisory that was originally published on March 20th, 2018. The new information includes revised affected versions data and mitigation measures for SINUMERIK 828D.

SIMATIC PCS7 Update


This update provides additional information on an advisory that was This update provides new information on an advisory that was originally published on November 2nd, 2018 and updated on June 12th, 2018. The new information includes revised affected versions data and mitigation measures for:

• OpenPCS 7 V8.1; and
• SIMATIC WinCC Runtime Professional V13

SIMATIC WinCC Update


This update provides additional information on an advisory that was originally published on April 19th, 2018. The new information includes revised affected versions data and mitigation measures for WinCC OA Operatopr App.

SINAMICS Update


This update provides additional information on an advisory that was originally published on May 8th, 2018. The new information includes revised affected versions data and mitigation measures for SINAMICS GM150 V4.7 w. PROFINET.

SIMATIC Step7 Update


This update provides additional information on an advisory that was originally published on August 14th, 2018. The new information includes revised affected versions data and mitigation measures for:

• SIMATIC STEP 7 (TIA Portal); and
• WinCC (TIA Portal) V13

OpenSSL Update


This update provides additional information on an advisory that was originally published on August 14th, 2018 and updated on September 11th, 2018. The new information includes revised affected versions data and mitigation measures for:

• SIMATIC S7-1200 CPU;
• SIMATIC STEP 7 (TIA Portal) V13; and
• SIMATIC WinCC (TIA Portal) V13

Saturday, October 6, 2018

Public ICS Disclosures – Week of 09-29-18


This week we have two new vendor notifications for products from Schneider Electric and PTC. We also have a vendor update from BD.

Schneider Advisory


This advisory describes an insufficient verification of data authenticity vulnerability in the Schneider Modicon M221. The vulnerability was reported by Eran Goldstein of CRITIFENCE. Schneider reports on workarounds to mitigate the vulnerability. There is no indication that Goldstein has been provided an opportunity to verify the efficacy of the fix.

PTC Advisory


This advisory describes three vulnerabilities in the PTC ThingWorx Platform. The vulnerability was reported by Matteo Tomaselli from the SEC Consult Vulnerability Lab. PTC has new versions that mitigate the vulnerabilities. There is no indication that Tomaselli has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Disclosure of User Password Hashes to Privileged Users - CVE-2018-17216;
• Disclosure of Encrypted Credentials and Use of Hard-Coded Passwords - CVE-2018-17217; and
Reflected Cross-Site Scripting - CVE-2018-17218

BD Update


This update provides additional information on an advisory that was originally published on May 22, 2018. The update provides previously promised mitigation measures.

Saturday, February 3, 2018

Public ICS Disclosures – Week of 1-25-18


This week we have a new coordinated disclosure for a Sprecher Automation remote terminal unit (RTU), exploit code for an Advantech WebAccess vulnerability and a late discussion of new information on the TRISIS attack.

Sprecher


SEC Consult Vulnerability Lab published a vulnerability report on the FullDisclosure.com web site this week for multiple vulnerabilities in the Sprecher SPRECON-E-C RTU. It reports five vulnerabilities (with proof of concept code), including:

• Authenticated path traversal;
• Client-side password hashing;
• Missing authentication;
• Permanent denial of service via port scan; and
Outdated Linux kernel.

Three of the five vulnerabilities have reportedly been fixed and work arounds have been provided for the other two.

Advantech Exploit


Chris Lyne published exploit code on the ExploitDataBase.com web site this week for an SQL injection vulnerability in the Advantech WebAccess application. The vulnerability was included in a recent ICS-CERT Advisory that was most recently updated on January 11th. For obvious reasons, ICS-CERT did not mention the publicly available exploit code and they have not made it a practice to further update their advisories to report the presence of exploits.

TRISIS Update


Most readers will probably be familiar with the Schneider presentation at S4X18 about new information on the recent attack on a Triconex safety system. The Schneider reported that they discovered a zero-day vulnerability used by the attacker and have provided a firmware update that mitigates the vulnerability. Schneider updated their security notification to reflect the new information.

ICS-CERT published a malware report not a control system advisory for the situation. It did provide a link to the original Schneider notification. I do not expect ICS-CERT to update their malware report, but I have been hoping to see an advisory for the newly reported vulnerability.

I cannot wait for DigitalBond to make the Schneider presentation available on their site.

Thursday, November 16, 2017

ICS-CERT Publishes Two Advisories

Today the DHS ISC-CERT published two control system security advisories for products from Siemens and Moxa.

Siemens Advisory


This advisory describes multiple vulnerabilities in Siemens SICAM RTU products. The vulnerabilities were reported by SEC Consult Vulnerability Lab. Siemens is recommending that the web server be disabled after system commissioning to mitigate the vulnerabilities in current versions.

The three vulnerabilities reported are:

• Missing authentication for critical function - CVE-2017-12737;
• Improper neutralization of input during web page generation - CVE-2017-12738; and
• Improper control of generation of code - CVE-2017-12739

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability using a publicly available exploit to execute arbitrary code. The Siemens security advisory notes that network access to the affected devices is required.

Moxa Advisory


This advisory describes multiple vulnerabilities in the Moxa NPort serial network interface products. The vulnerabilities were reported by Florian Adamsky. Moxa has a new firmware version that mitigates the vulnerability. There is no indication that Adamsky has been provided an opportunity to verify the efficacy of the fix.

The three vulnerabilities reported are:

• Improper neutralization of special elements in output used by downstream component - CVE-2017-16719;
• Information exposure - CVE-2017-16715; and
• Uncontrolled resource consumption - CVE-2017-14028

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow for remote code execution on the device.

Saturday, November 19, 2016

Public ICS Vulnerability Disclosure – 11-19-16

This week SEC Consult Vulnerability Lab published a report about multiple vulnerabilities in the I-Panda SolarEagle - Solar Controller Administration Software. The reported vulnerabilities include:

• Broken local admin authentication;
• Missing server side authentication;
• Unencrypted communication; and
• Denial of service


SEC Consult reported that they attempted to coordinate the disclosure with the vendor but got no response.
 
/* Use this with templates/template-twocol.html */