Showing posts with label ScadaX. Show all posts
Showing posts with label ScadaX. Show all posts

Tuesday, February 23, 2021

3 Advisories Published – 2-23-21

Today CISA’s NCCIC-ICS published three control system security advisory for products from Advantech (2) and Rockwell Automation.

Spectre RT Advisory

This advisory describes nine vulnerabilities in the Advantech Spectre RT Industrial Routers. The vulnerabilities were reported by Ilya Karpov and Evgeniy Druzhinin of Rostelecom-Solar and Vlad Komarov of ScadaX. Advantech has a newer version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The nine reported vulnerabilities are:

• Improper neutralization of input during web page generation - CVE-2019-18233,

• Cleartext transmission of sensitive information - CVE-2019-18231,

• Improper restriction of excessive authentication attempts - CVE-2019-18235,

• Use of broken or risky cryptographic algorithm (3) - CVE-2018-20679, CVE-2016-6301, and CVE-2015-9261 {3rd party vulnerabilities (BusyBox)}, and

• Use of platform-dependent third-party components (3) - CVE-2016-2842, CVE-2016-0799, CVE-2016-6304 {3rd party vulnerabilities (OpenSSL)}.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow information disclosure, deletion of files, and remote code execution. A number of the NIST CVE reports contain links to publicly available exploits for selected vulnerabilities.

NOTE: I briefly discussed these vulnerabilities back in January.

BB-ESWGP Advisory

This advisory describes a use of hard-coded credentials vulnerability in the Advantech BB-ESWGP506-2SFP-T industrial ethernet switches. The vulnerability was reported by an anonymous researcher via the Zero Day Initiative. Advantech no longer supports this product.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to gain unauthorized access to sensitive information and execute arbitrary code.

Rockwell Advisory

This advisory describes a use of password hash with insufficient computational effort vulnerability in the Rockwell FactoryTalk Services Platform. The vulnerability is self-reported. Rockwell has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a remote, unauthenticated attacker to create new users in the FactoryTalk Services Platform administration console. These new users could allow an attacker to modify or delete configuration and application data in other FactoryTalk software connected to the FactoryTalk Services Platform.

NOTE: I briefly discussed this vulnerability in August of last year.

Saturday, January 16, 2021

Public ICS Disclosure – Week of 1-9-21 – Part 1

This week we have six vendor disclosures from Advantech, PEPPERL+FUCHS, WAGO, Philips, RUCKUS, and Rockwell (2). We have five vendor updates from Carestream, Mitsubishi, Rockwell, Siemens, and Software Toolbox.

Advantech Advisory

Advantech published an advisory describing six vulnerabilities in their Spectre RT ERT351 and

B+B SmartWorx ERT351 products. The vulnerabilities were reported by Vlad Komarov of ScadaX, and Evgeniy Druzhinin and Ilya Karpov of Rostelecom-Solar. Advantech has new firmware versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Improper neutralization of input during web page generation - CVE-2019-18233,

• Cleartext transmission of sensitive information - CVE-2019-18231,

• Improper restriction of excessive authentication attempts - CVE-2019-18235 (Linux vuln),

• Insufficiently protected credentials (no CVE number),

• Usage of broken or risky cryptographic algorithm - CVE-2019-18237,

• Use of vulnerable third-party software - CVE-2019-18239 (OpenSSH and OpenSSL)

PEPPERL+FUCHS Advisory

CERT VDE published an advisory describing a deserialization of untrusted data vulnerability in the PEPPERL+FUCHS PACTware product. This is a third-party (fdtCONTAINER component by M&M Software GmbH) vulnerability. The vulnerability was reported by M&M Software. The vulnerability will be corrected in a version to be released in the second quarter.

WAGO Advisory

CERT VDE published an advisory describing a deserialization of untrusted data vulnerability in unnamed WAGO workstations. This is the same third-party (M&M Software) vulnerability described above.

Philips Advisory

Philips published an advisory describing an undescribed vulnerability on products running on their older Haswell workstations. Philips has a patch that mitigates the vulnerability.

RUCKUS Advisory

RUCKUS published an advisory describing two vulnerabilities in the LLDP module of Ruckus Network’s AP products. These are third-party library vulnerabilities originally reported by Florian Weimer (see links below for original reporting). RUCKUS has patches that mitigate the vulnerabilities.

The two reported vulnerabilities are:

• Classic buffer overflow - CVE-2015-8011, and

• Reachable assertion - CVE-2015-8012

Rockwell Advisories

Rockwell published an advisory describing a side-channel leakage vulnerability in the NXP 7x Secure Authentication Microcontrollers. This is a third-party (Google Titan Security Key) vulnerability reported by NinjaLab. Rockwell provides generic mitigation measures.

NOTE: This is going to be an interesting one for a variety of vendors.

 

Rockwell published an advisory describing the third-party (M&M Software) fdtCONTAINER vulnerability described above in their FactoryTalk AssetCentre products. Rockwell has a software update that mitigates the vulnerability.

NOTE: Third-party vulnerabilities strike far and wide (SIGH).

Carestream Update

Carestream published an update [.PDF download link] for their Bad Neighbor advisory that was originally published on October 15th, 2020. The new information includes:

• A list of unaffected products, and

• A list of two affected products (Image Suite and Omni) with mitigation measures.

Mitsubishi Update

Mitsubishi published an update for their MC Works 64 advisory that was originally published on June 18th, 2020 and most recently updated on December 8th, 2020. The new information includes adding mitigation measures for MC Works64 Version 2.00A - 2.02C.

NOTE: NCCIC-ICS published an advisory for these vulnerabilities back in June but has not yet updated it for any of the updates that Mitsubishi has published. This is probably due to a failure by Mitsubishi to inform NCCIC-ICS of the updates.

Rockwell Update

Rockwell published an update for their FactoryTalk Linx advisory that was originally published on December 27th, 2020. The new information includes links to mitigation measures for three of the vulnerabilities.

Siemens Update

Siemens published an out-of-zone update for their SolidEdge advisory that was originally published on January 12th, 2021. The new information includes additional mitigation information for SolidEdge SE2020.

Software Toolbox Update

Software Toolbox published an update for their TopServer advisory that was originally published on December 9th, 2020. The new information includes adding the CVE numbers for the included vulnerabilities.

NOTE: This advisory was included in  ICSA-20-352-02. This update will probably not be mentioned by NCCIC-ICS since the link provided in their advisory takes one to this update.

Tuesday, November 26, 2019

2 Advisories Published – 11-26-19

Today the CISA NCCIC-ICS published two control system security advisories for products from ABB.

ABB Advisory #1


This advisory describes a path traversal vulnerability in the ABB Relion 670 series. The vulnerability was reported by Kirill Nesterov of Kaspersky Lab. ABB has new versions that mitigate the vulnerability. There is no indication that Nesterov has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to read and delete files on the device.

ABB Advisory #2


This advisory describes an improper input validation vulnerability in the ABB  Relion 650 and 670 Series. The vulnerability was reported by Ilya Karpov, Evgeniy Druzhinin, and Victor Nikitin of ScadaX. ABB has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to reboot the device, causing a denial of service.

NOTE: I briefly reported on both of these vulnerabilities and a third that was also reported by ABB on the same day back in October. The third advisory dealt with OpenSSL vulnerabilities.

Thursday, February 7, 2019

2 Advisories and 3 Updates Published – 02-07-19


Today the DHS NCCIC-ICS published two control system advisories for products from Siemens and three updates for products from Kunbus, Omron and Fuji electric.

EN100 Advisory


This advisory describes two improper input validation vulnerabilities in the Siemens EN100 Ethernet module. These vulnerabilities were reported by Victor Nikitin, Vladislav Suchkov, and Ilya Karpov from ScadaX. Siemens has provided updates for some of the affected products. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to conduct a denial-of-service attack over the network.

NOTE: I briefly discussed this update on January 12th.

SICAM Advisory


This advisory describes an uncaught exception vulnerability in the Siemens SICAM A8000 RTU. The vulnerability was reported by Emanuel Duss and Nicolas Heiniger from Compass Security. Siemens has updates that mitigate the vulnerability. There is no indication that the researchers have been offered an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow unauthenticated remote users to cause a denial-of-service condition on the web server of affected products.

NOTE: I briefly discussed this update on January 12th.

Siemens Update – There are two advisories from the January 8th tranche of vulnerability disclosures from Siemens. It will be interesting to see if they are processed by NCCIC-ICS before the next scheduled Siemens advisory disclosures on February 12th.

Kunbus Update


This update provides additional information on an advisory that was originally published on February 5th, 2019. The update includes:

• Adding two additional vulnerabilities (Information exposure through query strings in get request and clear-text storage of sensitive information); and
Report that the two added vulnerabilities will be mitigated in the next version (end of the month).

Omron Update


This update provides additional information on an advisory that was originally published on January 17th, 2019. The update includes:

• Adding two additional vulnerabilities (access of uninitialized pointer and out-of-bounds read); and
• Added Michael DePlante as a vulnerability reporter;

Fuji Update


This update provides additional information on an advisory that was originally published on September 27th, 2018. The updates reports that a new version is available that mitigates the vulnerability.

Saturday, January 12, 2019

ICS Public Disclosures – Week of 01-05-19


This week we have five new vendor disclosures and seven vendor updates, all for products from Siemens.

EN100 Ethernet Advisory


Siemens published an advisory for their EN100 Ethernet communication module for SWT 3000 describing two denial of service vulnerabilities. The vulnerabilities were reported by Victor Nikitin, Vladislav Suchkov, and Ilya Karpov from ScadaX. Siemens has identified a workaround that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

SICAM A8000 Advisory


Siemens published an advisory for their SICAM A8000 RTU series describing an denial of service vulnerability. The vulnerability was reported by Emanuel Duss and Nicolas Heiniger from Compass Security. Siemens has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

CP1604 and CP1616 Advisory


Siemens published an advisory for their CP1604 and CP1616 devices describing a denial of service vulnerability. The vulnerability is self-reported. Siemens has new versions that mitigate the vulnerability.

SIMATIC S7-300 Advisory


Siemens published an advisory for their SIMATIC S7-300 CPU describing a denial of service vulnerability. The vulnerability was reported by the Electronic Technology Information Research Institute. Siemens has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

S7-1500 Advisory


Siemens published an advisory for their S7-1500 CPU describing two denial of service vulnerabilities. The vulnerabilities were reported by Georgy Zaytsev, Dmitry Sklyarov, Druzhinin Evgeny, Ilya Karpov, and Maxim Goryachy from Positive Technologies. Siemens has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Siemens Updates


As part of the swath of 12 advisories and updates issued by Siemens this week there was one update that was not covered by NCCIC-ICS updates. This was for vulnerabilities addressed in ICS-CERT generic alerts; NCCIC-ICS does not update these alerts for new information from the existing vendor list on the alert, the links on those alerts already take interested parties to this latest information.

SSB-439005: v 1.2 - Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP - Added CVE-2018-19931 and CVE-2018-19932;

There were six additional updates that I suspect that NCCIC-ICS could still pick-up in the coming week.

SSA-592007: v 1.3 - Denial-of-Service Vulnerability in Industrial Products – NCCIC-ICS published their latest update (ICSA-18-079-02A) on October 9th, 2018 - Added update for SIMATIC S7-300 incl. F and T;
SSA-535640: v 1.3 - Vulnerability in Industrial Products – NCCIC-ICS published their latest update (ICSA-17-243-01B) on November 30th, 2017 - Added fix for SIMATIC NET PC Software;
SSA-348629: v 1.7 - Denial-of-Service Vulnerability in SIMATIC PCS 7, SIMATIC WinCC, SIMATIC WinCC Runtime Professional and SIMATIC NET PC Software - NCCIC-ICS published their latest update (ICSA-18-088-03E) on December 13th, 2018 - Updated patch links for WinCC 7.2 and 7.4;
SSA-346262: v 2.1 - Denial-of-Service in Industrial Products - NCCIC-ICS published their latest update (ICSA-17-339-01J) on December 12th, 2018 - Updated solution for SIMATIC S7-300;4
SSA-293562: v 2.6 - Vulnerabilities in Industrial Products - NCCIC-ICS published their latest update (ICSA-17-129-02N) on December 12th, 2018 - Updated information for CP 1243-1; and
SSA-181018: v 1.3 - Heap Overflow Vulnerability in SCALANCE X switches, RUGGEDCOM WiMAX, RFID 181-EIP, and SIMATIC RF182C - NCCIC-ICS published their original advisory (ICSA18-165-01) on June 13th, 2018 - Added solution for RUGGEDCOM WiMAX

Thursday, December 13, 2018

5 Advisories and 2 Updates Published – 12-13-18

Today the DHS NCCIC-ICS published four control system security advisories for products from GE, Geutebruck, Siemens and Schneider and one medical device security advisory for products from Medtronic. They also published an update for a previously published control system security advisory for products from Siemens and a medical device security advisory for products from Philips.

GE Advisory


This advisory describes a path traversal vulnerability in the GE Mark VIe, EX2100e, EX2100e_Reg, and LS2100e distributed control systems. The vulnerability was reported by Can Demirel of Biznet Bilisim. GE has a new version that mitigates the vulnerability. There is no indication that Demirel has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to access system data, which could result in escalation of privilege and unauthorized access to the controller.

Geutebruck Advisory


This advisory describes an OS command injection vulnerability in the Geutebruck E2 Camera Series. The vulnerability was reported by Davy Douhine of RandoriSec. Geutebruck has a new version that mitigates the vulnerability. There is no indication that Douhine has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a remote attacker to inject OS commands as root.

Siemens Advisory


This advisory describes two improper input validation vulnerabilities in the Siemens EN100 Ethernet Communication Module and SIPROTEC 5 relays. These vulnerabilities were reported by Victor Nikitin, Vladislav Suchkov, and Ilya Karpov from ScadaX. Siemens has updates for some of the affected products and continues to work on updates for the remaining products.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to cause a denial-of-service condition of the network functionality of the device, compromising the availability of the system.

NOTE: This advisory was published when Siemens published an update last Tuesday. The original Siemens advisory was reported here back in July, 2018.

Schneider Advisory


This advisory describes three vulnerabilities in the Schneider Electric GUIcon. The vulnerabilities were reported by mdm and rgod of 9SG Security Team. Schneider has a new version that mitigates the vulnerabilities. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Type confusion (2) - CVE-2018-7813 and CVE-2018-7815; and
• Stack-based buffer overflow - CVE-2018-7814

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to execute code with privileges within the context of the application.

NOTE: I briefly reported the Schneider advisory last Saturday.

Medtronic Advisory


This advisory describes a missing encryption of sensitive data vulnerability in the Medtronic 9790 CareLink Programmer, 2090 CareLink Programmer, 29901 Encore Programmer; programmers for Medtronic cardiac devices. The vulnerabilities were reported by Researchers Billy Rios and Jonathan Butts of Whitescope LLC. Medtronic has provided generic workarounds for two of the devices and reports that the 9970 is out of support and all use should be discontinued. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an relatively low-skilled attacker with physical access to the devices could exploit the vulnerability to access PHI or PII stored on the device.

Siemens Update

This update provides additional information for an advisory that was originally published on March 29th, 2018 and updated on April 24th, 2018, June 12th, 2018 and again on November 14th, 2018. The update provides updated affected version information and mitigation links for SIMATIC NET PC-Software.

NOTE: Siemens updated their advisory on Tuesday and then again today. This NCCIC-ICS update reflects the corrected information published by Siemens today.

Philips Update


This update provides additional information for an advisory that was originally published on March 27th, 2018 and subsequently updated on December 11th, 2018. The updated information includes revised affected version data.

More Missing Siemens Updates


Siemens published four more updates today; only one of those was addressed by NCCIC-ICS today. It will be a long blog post here on Saturday. 

Saturday, July 14, 2018

ICS Public Disclosure – Week of 07-07-18


This week we have two vendor disclosures from Siemens and WAGO with a concurrent publication of exploit code for the WAGO vulnerabilities.

Siemens Advisory


This advisory describes two denial of service vulnerabilities in the Siemens EN100 Ethernet communication module and SIPROTEC 5 relays. The vulnerabilities were reported by Victor Nikitin, Vladislav Suchkov, and Ilya Karpov from ScadaX. Siemens recommends blocking access to port 102/tcp e.g. with an external firewall.

WAGO Advisory


This VDE-CERT advisory describes three vulnerabilities in the WAGO e!DISPLAY. The vulnerabilities were reported by SEC Consult. WAGO has a new firmware version that mitigates the vulnerabilities. There is no indication that SEC Consult has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Improper neutralization of input during web page generation - CVE-2018-12981;
• Unrestricted upload of file with dangerous type - CVE-2018-12980; and
Incorrect permission assignment for critical resource - CVE-2018-12979

The day after VDE-CERT released this advisory SEC Consult published exploit code for all three vulnerabilities on their web site and other locations (see here for example).

 
/* Use this with templates/template-twocol.html */