Showing posts with label SWARCO. Show all posts
Showing posts with label SWARCO. Show all posts

Tuesday, June 2, 2020

6 Advisories and 1 Update Published – 6-2-20


Today the CISA NCCIC-ICS published six control system security advisories for products from ABB (4), GE and SWARCO Traffic Systems. They also updated an advisory for products from Inductive Automation

System 800xA Advisory


This advisory describes two incorrect default permissions vulnerabilities in the ABB System 800xA. The vulnerabilities were reported by William Knowles of Applied Risk. ABB provides generic work arounds to mitigate the vulnerabilities.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to escalate privileges, cause system functions to stop, and corrupt user applications.

NOTE: I briefly described these vulnerabilities in early April.

System 800xA Base Advisory


This advisory describes an incorrect permission assignment for critical resource vulnerability in the ABB System 800xA Base. The vulnerabilities were reported by William Knowles of Applied Risk. ABB has a new version that mitigates the vulnerabilities. There is no indication that Knowles has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to escalate privileges and cause system functions to stop or malfunction.

NOTE: I briefly described these vulnerabilities in early April and then I discussed the ABB update later that month. The updated version is being reported by NCCIC-ICS.

System 800xA Products Advisory


This advisory describes seven incorrect default permission vulnerabilities in various ABB System 800xA products. The vulnerabilities were reported by William Knowles of Applied Risk. NCCIC-ICS reports that ABB plans to correct these vulnerabilities in a future version.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to make the system node inaccessible or tamper with runtime data in the system.

NOTE: I briefly described these vulnerabilities in early April and then I discussed the ABB update later that month. The updated version is being reported by NCCIC-ICS.

Central Licensing System Advisory


This advisory describes five vulnerabilities in the ABB Central Licensing System. The vulnerabilities were reported by William Knowles of Applied Risk. ABB has new versions that mitigate the vulnerabilities. There is no indication that Knowles has been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Information exposure - CVE-2020-8481,
• Improper restriction of XML external entity reference - CVE-2020-8479,
• Uncontrolled resource consumption - CVE-2020-8475,
• Permissions, privileges and access controls - CVE-2020-8476, and
• Improper access controls - CVE-2020-8471

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to take control of the affected system node remotely and cause an affected CLS Server node to stop or prevent legitimate access to the affected CLS Server.

I briefly reported these vulnerabilities in late April.

GE Advisory


This advisory describes a missing authentication for critical function vulnerability in the GE Grid Solutions Reason RT Clocks. The vulnerability was reported by Ehab Hussein of IOActive. GE has a new firmware version that mitigates the vulnerability. There is no indication that Hussein has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow access to sensitive information, execution of arbitrary code, and cause the device to become unresponsive.

SWARCO Advisory


This advisory describes an improper access control vulnerability in the SWARCO CPU LS4000. The vulnerability was reported by Martin Aman of ProtectEM. SWARCO has a patch that mitigates the vulnerability. There is no indication that Aman has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow access to the device and disturb operations with connected devices.

I briefly discussed this vulnerability last Saturday.

Inductive Automation Update


This update provides additional information on an advisory that was originally published on May 26th, 2020. The new information includes adding Ignition 7 Gateway to the list of affected products and providing mitigation measures for that product.

Saturday, May 30, 2020

Public ICS Disclosures – Week of 5-23-20


This week we have 11 vendor disclosure for products from SWARCO Traffic Systems, Bosch, ABB (8), and Belden. There are also two updated vendor disclosures from Johnson Controls and Belden.

SWARCO Advisory


INCIBE-CERT published an advisory describing an inadequate access control vulnerability on the SWARCO LS4000 CPU. The vulnerability was reported by Martin Aman, from the company ProtectEM. SWARCO has a patch that mitigates the vulnerability. There is no indication that Aman was provided an opportunity to verify the efficacy of the fix.

Bosch Advisory


Bosch has published an advisory describing four vulnerabilities in their Bosch Recording Station (BRS). The vulnerabilities are apparently self-reported. Bosch provides generic work arounds and recommends a new product upgrade.

The four reported vulnerabilities are:

EternalBlue - CVE-2017-0144,
BlueKeep - CVE-2019-0708,
• Improper access control - CVE-2020-6774, and
• Lack of full disc encryption – (no CVE)

ABB Advisories


ABB published eight advisories dealing with the effects of the Urgent/11 vulnerabilities on specific product lines. ABB initially published a series of initial reports on the UGRGENT/11 vulnerabilities back in July of last year and those were referenced in the NCCIC-ICS URGENT/11 advisory. At that time ABB was only able to provide generic workarounds for the vulnerabilities. This week’s advisories provide more specific mitigation measures:

CI845 – new version,
FOX615 Multiservice-Multiplexer – new version,
AFS66x – new version,
NSD570 Teleprotection Equipment – new versions,
ETL600 Power Line Carrier System – new version,
REB500 – new version, and
RTU500 series – new versions

Belden Advisory


Belden published an advisory describing a buffer overflow vulnerability in the Linux Point-to-Point Protocol (PPP) daemon in the Belden Hirschman OWL devices. This vulnerability is apparently self-reported. Belden has a new version that mitigates the vulnerability.

NOTE: There are a number of proof-of-concept exploits (see here for example) available for this vulnerability.

Johnson Controls Update


Johnson Controls published an update for an advisory that was originally published on May 21st, 2020. The new information includes:

• Updated affected version information for the C•CURE 9000, and
• More detailed mitigation instructions

Belden Update


Belden published an update for an advisory that was originally published on February 14th, 2020 and most recently updated on February 26th, 2020. The new information includes a CVE identifier (with link) for the vulnerability.

 
/* Use this with templates/template-twocol.html */