Showing posts with label SVA. Show all posts
Showing posts with label SVA. Show all posts

Saturday, December 19, 2020

Public ICS Disclosures – Week of 12-12-20

This week we have five vendor disclosures regarding the Amnesia33 vulnerabilities. There were three vendor disclosures for the SUNBURST vulnerability. There were ten other vendor disclosures for products from ABB (3), Bosch (3), WAGO, Phoenix Contact (2), and VMware. There was one vendor update from Mitsubishi. We have seven researcher reports of vulnerabilities in products from Lantronix (2), Secomea, and Eaton (4).

Amensia33 Advisories

Braun published an advisory discussing the Amnesia33 vulnerabilities. They report that none of their ‘connected devices’ is affected.

Drager published an advisory discussing the Amnesia33 vulnerabilities. They report that their medical devices are not affected.

HMS published an advisory discussing the Amnesia33 vulnerabilities. They provide a list of their products that they have confirmed are not affected.

Johnson and Johnson published an advisory discussing the Amnesia33 vulnerabilities. They report that they are investigating the potential impact of the vulnerabilities on their product line.

Spacelabs Healthcare published an advisory discussing the Amnesia 33 vulnerabilities. They report that none of their products are affected by the vulnerabilities.

Sunburst Advisories

Drager published an advisory discussing the SUNBURST vulnerability. They report that their medical devices are not affected.

Boston Scientific published an advisory discussing the SUNBURST vulnerability. They report that their products are not affected.

Philips published an advisory discussing the SUNBURST vulnerability. They report that they are monitoring developments.

ABB Advisories

ABB published an advisory [corrected link, 12-19-20 1941 EST] describing five vulnerabilities in their Central Licensing System. The vulnerabilities were reported by William Knowles at Applied Risk. ABB has new versions that mitigate the vulnerabilities. There is no indication that Knowles has been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Information disclosure - CVE-2020-8481,

• XML external entity injection - CVE-2020-8479,

• Denial of service - CVE-2020-8475,

• Elevation of privilege - CVE-2020-8476, and

• Weak file permissions - CVE-2020-8471

 

ABB published an advisory describing eight vulnerabilities in their Symphony® Plus Historian. The vulnerabilities are self-reported. ABB has an update that mitigates the vulnerabilities.

The eight reported vulnerabilities are:

• SQL injection - CVE-2020-24673,

• Improper authorization - CVE-2020-24674,

• Weak authentication - CVE-2020-24675,

• Insecure Windows services - CVE-2020-24676 -,

• Web application security - CVE-2020-24677,

• Privilege escalation - CVE-2020-24678,

• Denial of Service - CVE-2020-24679, and

• Improper credential storage - CVE-2020-24680

 

ABB published an advisory describing nine vulnerabilities in their Symphony® Plus Operations. The vulnerabilities are self-reported. ABB has an update that mitigates the vulnerabilities.

The nine reported vulnerabilities are:

• SQL injection - CVE-2020-24673,

• Improper authorization - CVE-2020-24674,

• Weak authentication - CVE-2020-24675,

• Insecure Windows services - CVE-2020-24676 -,

• Web application security - CVE-2020-24677,

• Privilege escalation - CVE-2020-24678,

• Denial of Service - CVE-2020-24679,

• Improper credential storage - CVE-2020-24680, and

• Authentication bypass - CVE-2020-24683

Bosch Advisories

Bosch published an advisory describing a null pointer dereference vulnerability in their ctrlX Products. This is a third-party OpenSSL vulnerability. Bosch has an update that mitigates the vulnerability.

 

Bosch published an advisory describing two vulnerabilities in their Rexroth IndraMotion Products. Both vulnerabilities are third-party CODESYS vulnerabilities (CVE links below are to the respective CODESYS advisories). Bosch recommends using their ctrlX CORE product to mitigate these vulnerabilities.

The two reported vulnerabilities are:

• Uncontrolled memory allocation - CVE-2020-7052 [.PDF download link], and

• Memory Corruption - CVE-2019-5105 [.PDF download link]

NOTE: Proof-of-concept code is available for the CODESYS vulnerabilities in the respective reports from Tenable and Talos.

 

Bosch published an advisory describing six vulnerabilities in their Rexroth PRC7000. These are third-party CODESYS vulnerabilities (CVE links below are to the respective CODESYS advisories). Bosch has a new firmware version that mitigates the vulnerabilities.

The six reported vulnerabilities are:

• Memory Corruption - CVE-2019-5105 [.PDF download link] Tenable report,

• Heap-based buffer overflow - CVE-2019-18858 [.PDF download link] Tenable report,

• Unverified ownership - CVE-2019-9010 [.PDF download link] NCCIC-ICS report,

• Uncontrolled memory allocation - CVE-2019-9012 [.PDF download link] NCCIC-ICS report,

• Insufficiently protected credentials - CVE-2019-9013 [.PDF download link] NCCIC-ICS report, and

• Heap-based buffer overflow - CVE-2020-10245 [.PDF download link] Tenable report.

NOTE: The respective Tenable reports include proof-of-concept code for he CODESYS vulnerabilities;

WAGO Advisory

VDE-CERT published an advisory describing an improper neutralization of special elements in an OS command vulnerability in the WAGO I/O-Check Service. The vulnerability was reported by Uri Katz of Claroty. WAGO has a new firmware version that mitigates the vulnerability.

NOTE: The Claroty report includes a Snort rule to detect the vulnerability.

Phoenix Contact Advisories

Phoenix Contact published an advisory [.PDF download link] describing a missing initialization of resource vulnerability in their mGuard products. The vulnerability was reported by SMST Designers & Constructors. Phoenix Contact has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

 

Phoenix Contact published an advisory [.PDF download link] describing four vulnerabilities in their PLCnext Control devices. The vulnerabilities were reported by Patrick Muench, Torsten Loebner, Maurice Rothe, Pascal Keul, Melanie Tholen and Daniel Hackel of SVA Systemvertrieb Alexander GmbH. Phoenix Contact has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• XSS - CVE-2020-12517,

• Exposure of sensitive information - CVE-2020-12518,

• Improper privilege management - CVE-2020-12519, and

• Improper input validation (in the PROFINET stack) - CVE-2020-12521.

NOTE: There is no indication whether the last vulnerability is unique to the Phoenix Contact implementation of PROFINET or if it is a third-party vulnerability.

VMware Advisory

VMware published an advisory describing an improper input validation vulnerability in their  ESXi, Workstation and Fusion products. The vulnerability was reported by Lucas Leong (@_wmliang_) of the Zero Day Initiative and Murray McAllister of Insomnia Security. VMware has patches that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Mitsubishi Update

Mitsubishi published an update of their Factory Automation advisory that was  originally published on July 30th, 2020 and most recently updated on November 5th, 2020. The new information includes providing mitigation information for GT SoftGOT1000.

NOTE: NCCIC-ICS published their advisory for this vulnerability and updated it in November.

Lantronix Reports

Talos published two reports (see CVE’s below for links) for vulnerabilities in the Lantronix XPort EDGE Web Manager. These are coordinated disclosures. The reports do not mention if the vulnerabilities have been corrected.

The two reported vulnerabilities are:

• Cleartext transmission of sensitive information - CVE-2020-13528, and

• CSRF - CVE-2020-13527

Secomea Report

Tenable published a report describing two vulnerabilities in the Secomea GateManager. This is a coordinated disclosure. The Tenable report includes proof-of-concept code. Tenable does not report that Secomea has produced any mitigation measures.

The two reported vulnerabilities are:

• Cross-site scripting - CVE-2020-29021, and

• HTTP host header injection - CVE-2020-29022

Tenable notes that these will be third-party vulnerabilities in products from at least B&R Industrial Automation and perhaps other vendors as well.

Eaton Reports

The Zero Day Initiative published four reports (see ZDI numbers for links) from Francis Provencher for vulnerabilities in the Eaton EASYsoft application. This is a coordinated disclosure but ZDI is reporting these as zero-day vulnerabilities.

The four reported vulnerabilities are:

• Out-of-bounds read - ZDI-20-1443, and

• File parsing type confusion (3) - ZDI-20-1444, ZDI-20-1442, and ZDI-20-1441

Wednesday, July 20, 2016

DHS Publishes CSAT 2.0 Notice

Today the DHS Infrastructure Security Compliance Division (ISCD) published a notice in the Federal Register (81 FR 47001-47004) outlining the plan for the implementation of their new risk assessment protocol and the revisions to the Chemical Security Assessment Tool that are being called CSAT 2.0. This includes the temporary suspension of requirements to submit Top Screens (TS) and Security Vulnerability Assessments (SVA) effective today.

Three-Step Process


Today’s notice outlines a three-step process that ISCD will be undertaking to implement the new risk assessment protocol and CSAT 2.0. Those steps are:

Temporarily suspend, effective July 20, 2016, the requirement for CFATS chemical facilities of interest to submit a Top-Screen and SVA;
Replace the current CSAT Top-Screen, SVA, and SSP applications with CSAT 2.0 (i.e., the revised CSAT Top-Screen, SVA, and SSP applications) in September 2016; and
Reinstate the Top-Screen and SVA submission requirements in 6 CFR 27.210(a) on October 1, 2016.

The Top Screen and SVA submission suspension affects all chemical facilities that may be required to submit either initial or resubmission Top Screens and SVAs.

Presumably the implementation of CSAT 2.0 will include the publication of new CSAT manuals during the month of September.

Facilities Not Affected


The notice makes clear that four specific classes of facilities will not be affected by the changes included in the implementation of CSAT 2.0. They include:

• Agricultural production facilities and miscellaneous extensions;
• Chemical facilities of interest with reportable COI that are only present in a gasoline mixture;
• Statutorily excluded facilities; and
• Untiered facilities that previously notified the department they had no reportable COI.

TS Submission Notifications


Once CSAT 2.0 is up and running ISCD will begin notifying ‘chemical facilities of interest’ of their need to submit a Top Screen. The notice makes it clear that the term ‘chemical facilities of interest’ was used deliberately instead of ‘covered facilities’ because it includes facilities that may have already submitted a Top Screen that indicated that they possessed DHS chemicals of interest (COI) inventories at or above the Screening Threshold Quantity (STQ).

The notification letters will be sent out in a phased manner over a number of months, presumably in a manner reflecting ISCD’s potential risk assessment of the previous information provided. There is no specific language in the notice that would indicate that all facilities that have provided Top Screens to ISCD will be notified to re-submit Top Screens at this time.

Facilities that do not have current COI inventories at or above the STQ will not be required to submit Top Screens to ISCD, even if they are notified by letter to submit a Top Screen. Those facilities may either submit a zero COI Top Screen or otherwise notify ISCD that they have no COI at or above the STQ and will not be submitting a Top Screen.

The notice does state that currently covered facilities that believe that the new risk assessment methodology will result in a lower tiering may submit a Top Screen before being notified by ISCD to do so. This certainly implies that ISCD will be sharing more information about the new risk assessment methodology and that tracks with what I have heard from ISCD privately. I do not expect that they will be sharing their actual model publicly, but they will be sharing more information about how the risk assessment methodology works.

Existing SVAs and SSPs


The notices makes it clear that only completed and submitted SVAs and Site Security Plans (SSPs) will be retained in CSAT 2.0. Partially completed SVAs and SSPs will be lost when CSAT 2.0 is implemented. This is of particular importance to remember this because ISCD will continue to accept new or revised SSP/ASP up until the date of the CSAT 2.0 switch over.

New SVA/SSP Timetable


For the most part, since ISCD expects to make a tiering decision based upon the new Top Screen, there will be no need to delay the SSP submission until after the receipt of the SVA. This notice, therefore, the new SVA and SSP tools in CSAT 2.0 have been designed to have facilities submit both documents concurrently. While more details are expected when the new manuals are published in September, it would seem that there will be more direct sharing of information between the two tools that should make the submission of both documents easier.

This means that ISCD is changing the submission deadline for the SVA from the current 90 days in §27.210(a)(2) to 120 days. It is interesting to note that the current regulation specifically allows ISCD to change that deadline with a Federal Register notice rather than requiring a rulemaking. The notice also makes it clear that the same notification of high-risk and tiering that now initiates the SVA submission requirement also is being used to initiate the SSP requirement. That certainly means that ISCD will be modifying the current notification letters.

Since the SVA and SSP tools will be so closely linked, facilities that revise their SSP will now also be required to revise their SVA at the same time.

Regular Top Screen Submissions


The notice indicates that regular Top Screen submissions for facilities reporting new inventories of COI at or above the STQ will resume on October 1st, 2016. Facilities that acquire such inventories between now and then will have 60-days from October 1st to submit their Top Screen.

CSSS Update



I am sure that there will be more information available at today’s session at the Chemical Sector Security Summit presentation on “Infrastructure Security Compliance Division (ISCD) Regulatory Update”. That session will be web cast at 10:00 am EDT.

Tuesday, June 28, 2016

Top Screen Roll Out Information

I have been hearing comments from a couple of readers about the new Top Screen being developed by the DHS Infrastructure Security Compliance Division (ISCD). There appears to be some confusion about the roll out of the new Top Screen. I have not seen any official documents from ISCD about the roll out timing, but some recent submissions (April) to the OMB’s Office of Information and Regulatory Affairs (OIRA), plus some private conversations that I have had may help clarify some of the issues being discussed.

The New Top Screen


Back in February ISCD announced that they would be changing the Top Screen and Security Vulnerability Assessment (SVA) tools in the on-line Chemical Security Assessment Tool (CSAT). DHS subsequently made it known that the changes in the two tools were being done to reflect the new risk analysis and tiering methodology that ISCD has been working on for a couple of years now. ISCD intends to implement the new risk analysis methodology sometime this fall and that implementation will include the new Top Screen and SVA.

I reported on the webinar where ISCD demonstrated the new Top Screen. The version that was demonstrated was more streamlined and it did include some questions that are currently in the SVA tool. The earlier presentation of these questions is necessitated by the new risk analysis model.

I understand that ISCD plans to demonstrate both the new Top Screen and SVA tools at the Chemical Sector Security Summit next month. I am hoping that they will be included in the presentations that will be web cast. We should be seeing a final listing of the web cast presentations in the next couple of weeks. DHS will be sending that out to people who have registered for the web cast.

Rulemaking


DHS does have a rulemaking in progress for changes in the Chemical Facility Anti-Terrorism Standards (CFATS) program and according to the latest Unified Agenda a notice of proposed rulemaking (NPRM) is scheduled to be published in September. The change in risk analysis protocol and subsequent changes in the Top Screen and SVA tools will not require rulemaking to effect since there will be no changes to the regulations required.

Because the Top Screen and SVA are information collections, ISCD is required to update their information collection request (ICR) with the OMB’s Office of Information and Regulatory Affairs (OIRA). A revised ICR for the Chemical Security Assessment Tool (CSAT) was submitted to OIRA on April 29th, 2016. OIRA’s published acceptance of the ICR will be required before ISCD can implement the changes to the Top Screen or SVA. There is no way to know when OIRA will approve the ICR.

Implementation


Based upon past actions by the ISCD, once OIRA publishes their approval of the changes to the ICR we can expect to see a notice published in the Federal Register outlining how DHS will implement the new Top Screen and SVA. This notice will not require any formal OMB approval since they will have already approved that implementation plan as part of the ICR.

There is a rumor going around that DSH is going to require all currently regulated facilities to submit a new Top Screen. Additionally, the rumor goes, all facilities that have (or have had in the last 60 days) an inventory of any of the 300+ DHS chemicals of interest (COI) at or above the screening threshold quantity (STQ) for the COI, regardless of whether or not they have already been notified by ISCD that they are not considered to be a high risk facility.

Section 27.200(a) of 6 CFR provides the DHS Secretary the authority to, “at any time, request information from chemical facilities that may reflect potential consequences of or vulnerabilities to a terrorist attack or incident, including questions specifically related to the nature of the business and activities conducted at the facility”. Thus, the authority does exist for the wholesale ‘re-do’ of the Top Screen as outlined in the rumors that I have been hearing.

On the other hand, on page 15 of the ICR support document [.DOC download] submitted to OIRA, DHS is expecting only 1,000 facilities to submit Top Screens each year and on average half of those facilities will submit 2 Top Screens in a year, reflecting changes in their COI inventory. This hardly sounds like a wholesale requirement to re-do Top Screens.

I would expect ICSD to have a pretty good idea as to whether the changes in the risk tiering methodology will result in any changes in the Tiering level of existing facilities. I would not be surprised if ISCD were to notify such facilities to submit a new Top Screen. The notification of facilities that had previously been notified that they were not at high-risk of terrorist attack would be more problematic because of the numbers involved (about 45,000 facilities), but it would be possible on a case-by-case basis.

It must be remembered that existing CFATS facilities are already on a regulatory schedule {§27.210(b)} to re-submit Top Screens (in addition to the requirement to submit a new Top Screen when there is a material change in COI or processes involving those COI). So all CFATS facilities will have to submit the new Top Screen at some point in their future.

In Short


In short, ISCD is planning on rolling out their Congressionally mandated, revised and vetted risk assessment methodology later this year, probably in the Fall. This methodology will be used to determine which facilities are at high-risk of terrorist attack and thus covered by the CFATS program. It is also used to establish the Tier level (relative degree of high risk) that determines the relative level of coverage of the security measures included in the Site Security Plan based upon the Risk Based Performance Standards guidance.

The revised methodology can be expected to require changes in the information submitted in Top Screen and Security Vulnerability Assessment tools in the CSAT process. The new information could result in changes in the CFATS status of a chemical facility or the Tier rankings of covered facilities. All CFATS facilities will eventually have to submit data about their facility under the new Top Screen. All chemical facilities that have new COI added to their chemical inventories at or above the SQT or have an increase in inventories already reported to ISCD will also have to complete the new Top Screen.


More information is expected to be released at the Chemical Sector Security Summit next month.

Tuesday, January 11, 2011

DHS Updates SVA Instructions

The Infrastructure Security Compliance Division at DHS updated their Chemical Security Assessment Tool (CSAT) web site this morning. They updated the SVA Instruction Manual. The revised manual does not have a change page so I don’t currently know what changes have been made to the new manual. They did not change the Questions manual so I don’t suspect that the new changes are too major. I will know more after I have a chance to do a side-by-side review of the new and old manuals.

There were no changes associated with the new SVA manual listed on the CFATS Knowledge Center page.

Wednesday, February 25, 2009

Reader Comment – 02-24-09

Anonymous left a comment about my blog on a proposal for IST legislation. His comments, in their entirety are shown below:

“The trouble with putting IST security reviews on a slower timeline than conventional security assessments is that you have to know what you need to protect before you can decide how to protect it. Why spend $ millions on permanent security measures that are soon made obsolete through implementation of IST? IST reviews should take place first as a matter of efficiency.”

 This is certainly a common argument for doing the IST review first. Unfortunately, it assumes three things: first that the IST review will result in a process/chemical change, second that there are no threats against the facility in the meantime and finally that developing the site security plan is costly. There are inherent problems with all three assumptions.

Cost of Site Security Plans 

We’ll start with the last assumption, the high cost of site security plans. The development of a site security plan is separate from the implementation of that plan. When DHS roles-out their site security plan and gives a facility 90 days to complete that plan, they are not going to be requiring that all of the security measures are complete and in place. They fully expect that a number of the measures outlined in the plan will take time and money to implement.

What they will be looking for is a plan forward on these expensive, and time consuming capital projects. Secondly, the cost of implementing the security plan is an integral part of the IST evaluation. An IST implementation plan that costs $2 M may seem unreasonable and an unjustifiable business expense. If that implementation obviates the need for a $3 M security plan, the plan becomes a lot more plausible.

Now Anonymous is certainly correct that it makes no economic sense for a facility to put into place a high-cost capital project to protect a chlorine storage tank that might be replaced by an IST project. The legislation could easily take this into account by allowing facilities to identify and defer implementation of security measures that are dedicated to the protection of the PIH assets at the facility while they continue to work on the other layers of protection required under CFATS.

IST Implementation is Not Inevitable 

Just because there appears at first glance to be a process or chemical that can be readily substituted for a PIH COI does not mean that it is economically feasible to make the substitution. In fact there may be engineering reasons that would make the substitution impracticable. Many advocacy groups in their pro-IST arguments point to the use of chlorine gas in water treatment and waste water treatment as the most obvious case where a less hazardous chemical or process could be substituted for an admittedly dangerous PIH chemical.

In his testimony before the House Subcommittee on Environment and Hazardous Materials, Brad Coffey, Water Treatment Manager, Metropolitan Water District of Southern California, provides an excellent description of the process that organization went through to do their IST analysis for ridding their multiple facilities of chlorine gas. As a result of their analysis many of their facilities did switch, but it was not practical to do so for their largest water treatment facility.

 Interestingly, Mr Coffey noted that immediately after 9/11 they recognized that the security situation had significantly changed and they implemented security arrangements to protect their PIH targets. They even went to the extent of employing armed guards to protect their rail cars of chlorine gas.

Facility Protection During Implementation 

Even when an IST review determines that a project is feasible and practical there is going to be a long period of time before it can be implemented. The Central Valley Wastewater Treatment Facility in Utah is a case in point. In a November, 2008 newspaper report the facility manager, Reed Fisher, noted that his facility had just completed a design for a UV system to replace their chlorine gas system. He expected to put the system out for bid this last January and have it in running in 2010.

Assuming that it took six months to determine that the process was now doable and design the system (a conservative estimate if I ever made one) it would still be two years from the start to finish on this project. And the whole time there would be railcars of chlorine gas or chlorine gas storage tanks sitting there as a target. At high-risk facilities other than water treatment facilities, the time to implement an IST project could be even longer.

Because of quality issues and customer requirements the time frame could be extended by years. In the specialty chemical business where I used to work it often took as long as a year to get approvals to substitute the same chemical from a cheaper supplier. It could take years to develop the new manufacturing processes, complete the requisite testing and gain customer approval for substituting a safer chemical.

 Again, the whole time that the IST review and implementation process is running the facility is a high-risk chemical facility. Facilities with multiple COI, including one or more PIH COI, are likely to remain on the high-risk facility list after their IST project is approved and implemented. As high-risk facilities, they still need to be protected.

Run IST Review and SVA/SSP in Parallel

 To properly protect the surrounding community, and that is what we are really talking about here, the SVA and SSP process needs to be completed while the IST review is taking place. The legislation should require that an IST review start when the facility with a PIH COI is give the preliminary designation of a Tier 1/2 high-risk facility. By the time the SSP submission is required the facility should have a preliminary idea of whether the IST has a chance of being implanted.

 The SSP tool should include a series of questions about the status of the IST project. If there is a substantial probability that the IST will go forward, then DHS should allow a deferment of some of the most expensive security measures pending final determination on the IST question. If there is a low probability or a long lead time for implementing the IST, all security measures should be required to be implemented.
 
/* Use this with templates/template-twocol.html */