Showing posts with label Schneider Electric. Show all posts
Showing posts with label Schneider Electric. Show all posts

Friday, July 24, 2020

1 Advisory Published – 7-23-20


Yesterday the CISA NCCIC-ICS published a control system security advisory for products from Schneider Electric.

Schneider Advisory

This advisory describes five vulnerabilities in the Schneider Triconex TriStation and Triconex Tricon Communication Module. The vulnerabilities were reported by Reid Wightman of Dragos, Inc. Schneider has new versions that mitigate the vulnerabilities and has pushed notification to customers.

The five reported vulnerabilities are:

• Cleartext transmission of sensitive information - CVE-2020-7483,
• Uncontrolled resource consumption - CVE-2020-7484 and CVE-2020-7486,
• Hidden functionality - CVE-2020-7485, and
• Improper access control - CVE-2020-7491

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to view clear text data on the network, cause a denial-of-service condition, or allow improper access.

Friday, September 13, 2019

6 Advisories Published – 09-12-19


Yesterday the DHS NCCIC-ICS published five control system security advisories for products from 3S and a medical device security advisory for products from Philips.

Communication Server Advisory


This advisory describes a detection of error condition without action vulnerability in the CODESYS V3 products containing a CODESYS communication server. The vulnerability was reported by Martin Hartmann from cirosec GmbH. 3S has a new version that mitigates the vulnerability. There is no indication that Hartmann has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to cause a denial-of-service condition.

OPC UA Server Advisory


This advisory describes a null pointer dereference vulnerability in the CODESYS Control V3 OPC UA Server. The vulnerability is self-reported. 3S has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial-of-service condition.

Online User Management Advisory


This advisory describes an incorrect permission assignment for critical resource vulnerability in the CODESYS Control V3 online user management. The vulnerability is apparently self-reported. 3S has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow unauthorized actors access to unintended functionality and/or information.

Library Manager Advisory


This advisory describes a cross-site scripting vulnerability in the CODESYS V3 Library Manager. The vulnerability was reported by Heinz Füglister of WRH Walter Reist Holding AG. 3S has a new version that mitigates the vulnerability. There is no indication that Füglister has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow malicious content from manipulated libraries to be displayed or executed.

Web Server Advisory


This advisory describes two vulnerabilities in the CODESYS V3 web server. The vulnerability was reported by Ivan Cheyrezy of Schneider Electric. 3S has new versions that mitigate the vulnerability. There is no indication that Cheyrezy has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Path traversal - CVE-2019-13532; and
Stack-based buffer overflow - CVE-2019-13548

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to create a denial-of-service condition, to perform remote code execution, or to access restricted files.

NOTE 1: It is good to see cooperative sharing of vulnerability information between vendors, but I suspect that Schneider reported these vulnerabilities because they found them in their own product that used the CODESYS web server as a third-party component of one or more of their products. It will be interesting to see how long it takes Schneider to report these vulnerabilities.

NOTE 2: 3S has not yet reported any of the vulnerabilities in the above advisories on their web site. They did, however, publish an advisory on another product earlier this week that I will discuss tomorrow.

Philips Advisory


This advisory describes two vulnerabilities in the Philips IntelliVue WLAN, portable patient monitors. The vulnerabilities were reported by Shawn Loveric of Finite State, Inc. One of the affected WLAN versions is out-of-support and will not receive mitigation actions. Philips intends to have a patch available by the end of the year.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerabilities to cause corruption of the IntelliVue WLAN firmware and impact to the data flow over the WLAN Version A and WLAN Version B wireless modules. This would lead to an inoperative condition alert at the device and Central Station. The Phillips Advisory reports that it would take “an unauthorized user with a high skill level and access to the device’s local area network” to exploit the vulnerabilities.

Wednesday, April 17, 2019

Three Advisories Published – 04-16-19


Yesterday the DHS NCCIC-ICS published two control system security advisories for products from WAGO and Delta Industrial Automation, and one for PLC products from multiple vendors.

PLC Advisory


This advisory describes an uncontrolled resource consumption vulnerability in specific PLC products from ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO. The vulnerability was reported by Matthias Niedermaier (Hochschule Augsburg), Jan-Ole Malchow (Freie Universität Berlin), and Florian Fischer (Hochschule Augsburg). The responses range from a firmware update from Schneider, to ‘its not really a vulnerability but here are generic workarounds’, to ‘its not a vulnerability’ from Siemens. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fixes.

NCCIC-ICS reports that a relatively low-skilled attacker could use a publicly available exploit to emotely influence configured cycle times.

NOTE: The Schneider advisory referenced in this advisory was released in February and listed a 2018 CVE number for the reported vulnerability. Neither CVE number is currently available.

WAGO Advisory


This advisory describes a hard-coded credential vulnerability in the WAGO Series 750-88x and 750-87x PLCs. The vulnerability was reported by Jörn Schneeweisz of Recurity Labs. WAGO has new firmware that mitigates the vulnerability. There is no indication that Schneeweisz has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to change the settings or alter the programming of the device.

NOTE: I briefly mentioned this vulnerability last Saturday.

Delta Advisory


This advisory describes three vulnerabilities in the Delta Industrial Automation CNCSoft screen editor software. The vulnerabilities were reported by Natnael Samson and an anonymous researcher via the Zero Day Initiative. Delta has an updated version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

Stack-based buffer overflow - CVE-2019-10947;
Heap-based buffer overflow - CVE-2019-10951; and
Out-of-bounds read - CVE-2019-10949

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to cause buffer overflow conditions that may allow information disclosure, remote code execution, or crash the application.

Saturday, February 23, 2019

Public ICS Disclosures – Week of 02-16-19


This week we have one vendor disclosure for products from CODESYS and two exploits for previously disclosed vulnerabilities for products from NUOO.

CODESYS Advisory


CODESYS has published an advisory that describes a directory traversal vulnerability in their runtime system. This vulnerability was reported by Ivan Cheyrezy of Schneider Electric. 3S has released a new version that mitigates the vulnerability. There is no indication that Cheyrezy has been provided an opportunity to verify the efficacy of the fix.

NOTE: Somehow, I suspect that Schneider identified this vulnerability in one of their products and traced it back to CODESYS code in that product. We may be seeing a Schneider advisory for this vulnerability in the near future.

NUOO Exploits


Pedro Ribeiro published two Metasploit modules for two vulnerabilities (here and here) that he had previously disclosed through NCCIC-ICS for vulnerabilities in the NUOO Central Management Software platform.

The two vulnerabilities for which the Metasploit modules were published are:

• Unrestricted upload of file of dangerous type; and
SQL injection


Saturday, October 6, 2018

Public ICS Disclosures – Week of 09-29-18


This week we have two new vendor notifications for products from Schneider Electric and PTC. We also have a vendor update from BD.

Schneider Advisory


This advisory describes an insufficient verification of data authenticity vulnerability in the Schneider Modicon M221. The vulnerability was reported by Eran Goldstein of CRITIFENCE. Schneider reports on workarounds to mitigate the vulnerability. There is no indication that Goldstein has been provided an opportunity to verify the efficacy of the fix.

PTC Advisory


This advisory describes three vulnerabilities in the PTC ThingWorx Platform. The vulnerability was reported by Matteo Tomaselli from the SEC Consult Vulnerability Lab. PTC has new versions that mitigate the vulnerabilities. There is no indication that Tomaselli has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Disclosure of User Password Hashes to Privileged Users - CVE-2018-17216;
• Disclosure of Encrypted Credentials and Use of Hard-Coded Passwords - CVE-2018-17217; and
Reflected Cross-Site Scripting - CVE-2018-17218

BD Update


This update provides additional information on an advisory that was originally published on May 22, 2018. The update provides previously promised mitigation measures.

Saturday, April 28, 2018

Public ICS Disclosures – Week of 04-21-18


This week we have three vendor disclosures from Schneider Electric and one researcher report for cloud services from Hikvision.

Wiser for KNX Advisory


This advisory describes an FTP access vulnerability in the Schneider Wise for KNX logic controller. The vulnerability was reported by Jokin Guevara. Schneider has an update that mitigates the vulnerability. There is no indication that Guevara has been provided an opportunity to verify the efficacy of the fix.

Schneider reports that an uncharacterized attacker could remotely exploit the vulnerability to gain unauthorized access.

EVlink Charging Station Advisory 


This advisory describes a cookie modification privilege escalation in the Schneider EVlink charging station. This vulnerability was reported by Joakim B. Hellum. Schneider has an update that mitigates the vulnerability. There is no indication that Hellum has been provided an opportunity to verify the efficacy of the fix.

Schneider reports that an uncharacterized attacker could remotely exploit the vulnerability to gain administrative privileges without properly authenticating remote users.

Pelco Sarix Professional Advisory 


This advisory describes three vulnerabilities in the Schneider Pelco Sarix Professional IP cameras. The vulnerabilities were reported by Weapon x, Giri Veeraraghavan Veda, and Gulf Business Machines. Schneider has an update available that mitigates the vulnerabilities. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Buffer overflow - CVE-2018-7780;
• Authenticated password disclosure and privilege escalation - CVE-2018-7781; and
Authenticated password disclosure - CVE-2018-7782

Hikvision Advisory


This advisory describes an authentication vulnerability in the Hikvision hik-connect.com and ezvizlife.com cloud services. The vulnerability was reported by Vangelis Stykas and the hack process reported in depth here (Medium.com registration required). Hikvision has a fix available, but there is no indication that Stykas has been provided an opportunity to verify the fix.

Saturday, March 24, 2018

Public ICS Disclosure – Week of 3-17-18


This week we have seven vendor disclosures for products from Schneider (5) and ABB (2). We also have an exploit announcement for a previously disclosed vulnerability in a product from Hikvision.

MiCOM Px4x Advisory #1


This advisory describes a denial of service vulnerability in the Schneider MiCOM Px4x rejuvenated product. The vulnerability is self-reported. Schneider has provided firmware updates and described work arounds to mitigate the vulnerability.

MiCOM Px4x Advisory #2


This advisory describes a denial of service vulnerability in the Schneider MiCOM Px4x with legacy Ethernet board product. The vulnerability is self-reported. Schneider has described generic work arounds to mitigate the vulnerability.

MiCOM P540D Advisory


This advisory describes a denial of service vulnerability in the Schneider MiCOM P540D with legacy Ethernet board product. The vulnerability is self-reported. Schneider has provided firmware updates and described generic work arounds to mitigate the vulnerability.

MGE Advisory


This advisory describes four vulnerabilities in the Schneider MGE SNMP/Web Card 66074. The vulnerabilities were reported by Ilya Karpov and Evgeny Druzhinin of Positive Technologies. Schneider has replacement NMC kits available for some of the affected products and they describe generic workarounds.

The four reported vulnerabilities are:

• Authorization bypass - CVE-2018-7243;
• Information exposure - CVE-2018-7244;
• Improper authorization - CVE-2018-7245; and
• Clear-text transmission of sensitive information - CVE-2018-7246

Modicon Web Servers Advisory


This advisory describes four vulnerabilities in the Schneider Modicon PLC embedded web server. The vulnerabilities were reported by Positive Technologies. Schneider has described generic workarounds to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Denial of Service - CVE-2018-7759;
• Authorization bypass - CVE-2018-7760;
• Arbitrary code execution - CVE-2018-7761; and
• Buffer overflow - CVE-2018-7762

Modicon FTP Advisory


This advisory describes three vulnerabilities in the Schnedier Modicaon PLC FTP servers. The vulnerability is self-reported. Schneider describes generic workarounds to mitigate the vulnerability.

The three reported vulnerabilities are:

• Arbitrary code execution - CVE-2018-7240;
• Hardcoded accounts - CVE-2018-7241; and
• Vulnerable hash algorithms - CVE-2018-7242

ADMS netCADOPS Advisory


This advisory describes a bounds checking vulnerability. The vulnerability was reported by Ismail Erkek – Barikat. ABB has described generic workarounds to mitigate the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

CCLAS Advisory


This advisory describes three vulnerabilities in the ABB CCLAS laboratory information management system. The vulnerabilities are self-reported. ABB has a new version that mitigates the vulnerabilities.

The three reported vulnerabilities are:

• Path traversal (2); and
• Cross-site scripting

Hikvision Exploit


This announcement describes an exploit for the password in configuration file vulnerability reported last year in a number of Hikvision IP cameras. Hikvision previously reported that the “configuration file is encrypted and is therefore not readable, and protects users’ credentials”, but promised to upgrade the protections in future firmware updates. Neither ICS-CERT nor Hikvision have reported that promised firmware update.

Tuesday, March 6, 2018

ICS-CERT Publishes 3 Advisories and One Siemens Update


Today the DHS ICS-CERT published three new control system security advisories for products from Eaton, Schneider Electric, and Hirschmann Automation. The also updated a previously issued advisory for products from Siemens.

Eaton Advisory


This advisory describes an improper input validation vulnerability in the Eaton ELCSoft programming software. The vulnerability was reported by Ariele Caltabiano (kimiya) and axt working with the Zero Day Initiative. Eaton has produced a new version of the software (ICS-CERT mistakenly refers to ‘firmware’) to mitigate this vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to execute arbitrary code. The Eaton Security Update Advisory [.PDF Download] notes that the vulnerability only affects the Windows® based PCs that run the software, not the programmable logic controllers being programed.

Schneider Advisory


This advisory describes an uncontrolled search path element vulnerability in the Schneider SoMove software and DTM software components. The vulnerability was reported by ADLab of Venustech (NOTE: The Schneider security notification credits Haojun Hou from Adon with reporting the vulnerability). Schneider has produced new software versions that mitigate the vulnerabilities. There is no indication that the researchers have been afforded an opportunity to verify the efficacy of the fix.

ICS-CERT reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerability to execute arbitrary code.

Hirschmann Advisory


This advisory describes multiple vulnerabilities in the Hirschmann Classic Platform Switches. These vulnerabilities were reported by Ilya Karpov, Evgeniy Druzhinin, Mikhail Tsvetkov, and Damir Zainullin of Positive Technologies. Hirschmann provides workarounds to mitigate the vulnerabilities; there is no indication that additional mitigation measures are forthcoming. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Session fixition - CVE-2018-5465;
• Information exposure through query strings in get requests - CVE-2018-546;
• Cleartext transmission of sensitive information - CVE-2018-5471;
• Inadequate encryption strength - CVE-2018-5461; and
Improper restriction of excessive authentication requests - CVE-2018-5469

ICS-CERT reports that a highly-skilled attacker could remotely exploit these vulnerabilities to hijack web sessions, impersonate a legitimate user, receive sensitive information, and gain access to the device.

Siemens Update


This update provides new information on an advisory that was was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th,  November 28th, 2017, and most recently January 18th, 2018, January 25th, 2018, and most recently on January 27th, 2018. The new information is a link to mitigation measures for SCALANCE X-200IRT. ICS-CERT did not update the affected version information for this product to include the latest information in the Siemens security advisory; all versions before V5.4.0 are affected.

Tuesday, March 7, 2017

ICS-CERT Publishes Schneider Advisory

Today the DHS ICS-CERT published a control system security advisory for a credential management vulnerability in the Schneider Electric Wonderware Intelligence application. This is a self-reported vulnerability. Schneider has produced a new version that mitigates the vulnerability.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to escalate its privilege to an administrator and take control over the host machine where Tableau Server is installed.

According to the Schneider security bulletin, the problem is with the third-party program Tableau Server. Schneider provides a link to the Tableau security bulletin. That bulletin notes that: “The Tableau Server installation process leaves an account enabled that can allow an unauthorized remote attacker to gain access and perform administrative functions. This vulnerability does not affect installations that are configured to use Active Directory authentication.”


There is no indication in this ICS-CERT advisory that the Tableau Server is (or is not) used by any other ICS vendor.

Thursday, September 3, 2015

ICS-CERT Publishes 4 New Advisories

This morning the DHS ICS-CERT published four new control system security advisories for products from SMA Solar Technology, Moxa, Schneider Electric, and Cogent.

SMA Advisory

This advisory describes a hard-coded account vulnerability in the SMA Solar Technology Sunny WebBox product. The vulnerability was originally reported by Aleksandr Timorin of PT Security. SMA does not plan of fixing this vulnerability as the product will soon be discontinued. They have provided some mitigation measures but there is no indication that Timorin has been provided the opportunity to verify the efficacy of the fix. This advisory was originally released on the US CERT Secure Portal on June 30th, 2015.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to gain complete access to the system.

ICS-CERT reports that SMA “recommends using port-forwarding or a VPN to access these devices remotely”. ICS-CERT on the other hand recommends that owners remove and replace the system. The public portion of the SMA Solar Technology website contains no mention of this vulnerability.

It is disappointing to see any vendor stop providing security support for a product while it is still being sold even if it is an older system that is in the process of being phased out. Control system products are expected to have a longer useful life than a sales life. Failing to support such systems beyond sales is short sighted and provides a clear indication (IMHO) of a lack of customer focus on the part of the organization. CAVEAT EMPTOR!

Moxa Advisory

This advisory describes three separate vulnerabilities found in the Moxa EDS-405A/EDS-408A series managed Ethernet switches. The vulnerabilities were originally reported by Erwin Paternotte of Applied Risk. Moxa has produced a firmware update to mitigate the vulnerabilities but there is no indication that Paternotte has been given the opportunity to verify the efficacy of the fix.

The three vulnerabilities are:

Improper privilege management, CVE-2015-6464;
Resource exhaustion, CVE-2015-6465; and
Cross-site scripting, CVE-2015-6466

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to elevate access privileges, execute a denial of service attack or inject JavaScript code.

The Moxa firmware release notes for the EDS-405A series does not list the cross-site scripting vulnerability among the fixes, but the release note for the EDS-408A series does. The other two vulnerabilities are listed in both release notes.

NOTE: There is an error in the click-through link to the Moxa update site in the ICS-CERT advisory, but the printed link does work.

Schneider Advisory

This advisory is a follow-up to the ICS-CERT alert published on August 12th. The advisory describes two vulnerabilities on a number of PLC products that were disclosed (with proof of concept exploit code) at DefCon by Aditya K. Sood. ICS-CERT notes that the vulnerabilities had been previously disclosed to Schneider by Juan Francisco Bolivar. Schneider has released a firmware patch to mitigate the vulnerabilities, but there is no indication that either researcher has been provided and opportunity to verify the efficacy of the fixes.

ICS-CERT notes that it would be difficult to craft “a working exploit for these vulnerabilities” even though proof of concept exploit code is publicly available. This reflects the continuing opinion by ICS-CERT that crafting a social engineering attack is difficult. This does not appear (IMHO) to reflect recent history where even security conscious organizations have been successfully attacked by social engineering exploits.

The Schneider security notification also addresses the hard-coded credential vulnerability that was reported in the ICS-Alert (but was not mentioned in this advisory). The Schneider document notes that this vulnerability was previously addressed and provides a link to a recently updated security notification discussing the problem that was reported by Ruben Santamarta in 2011. That document continues to claim that the hard-coded credential is part of a deliberate design decision and Schneider is still considering whether or not it needs to be removed.

There is an interesting additional link to a Schneider document in the ICS-CERT mitigation section of the Advisory. It is a link to the Schneider report on the use of the TOFINO Firewall as a mitigation measure for PLC vulnerabilities. This is a very detailed (55 page) description of how to use this device.

Cogent Advisory

This advisory describes a code injection vulnerability in the Cogent DataHub application. The vulnerability was originally reported by an anonymous researcher via the HP Zero Day Initiative. Cogent has produced a new version that mitigates the vulnerability, but there is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to turn on an insecure processing mode in the web server.


Tuesday, August 11, 2015

ICS-CERT Publishes Schneider Advisory

This afternoon the DHS ICS-CERT published a new advisory for a memory corruption vulnerability in the Schneider Electric IMT25 DTM component. The vulnerability was originally reported by Alexander Bolshev, Gleb Cherbov, and Svetlana Cherkasova of Digital Security. Schneider has produced a patch that mitigates the vulnerability and ICS-CERT reports that the researchers have validated the efficacy of the fix.

ICS-CERT reports that it would be moderately difficult to craft an exploit for this vulnerability and notes that access to an adjacent network is required to exploit this vulnerability. The vulnerability is remotely exploitable.


The Schneider Security Notification for this vulnerability explains that the vulnerability “includes a potential buffer overflow that possibly could lead to memory corruption and cause Denial of Service or permit remote code execution”.

Thursday, April 2, 2015

ICS-CERT Publishes a Schneider Electric Advisory

This afternoon the DHS ICS-CERT published an advisory for a stack-based buffer overflow in the Schneider Electric VAMPSET software. The vulnerability was reported by Ricardo Narvaja and Joaquín Rodríguez of Core Security. Schneider reports (.PDF download) that a new version has been made available that does not have the vulnerability. There is no indication that the researchers have been given the opportunity to verify the efficacy of the fix.


ICS-CERT reports that a social engineering attack would be required to exploit this vulnerability. A successful exploit could result in the execution of arbitrary code.

Thursday, March 26, 2015

ICS-CERT Published Schneider Advisory

Today the DHS ICS-CERT published an advisory for multiple vulnerabilities in two Schneider Electric products, InduSoft WebStudio and InTouch Machine. The vulnerabilities were reported by Gleb Gritsai, Ilya Karpov, and Kirill Nesterov of Positive Technologies Security Lab and independent researcher Alisa Esage Shevcheckno. Schneider has produced patches for the products, but there is no indication that the researchers were provided the opportunity to verify the efficacy of the fix.

The vulnerabilities include:

∙ Hard-coded credentials - CVE-2015-0996;
∙ Authentication - CVE-2015-0997; and
∙ Clear-text transmission of sensitive information - CVE-2015-0998 and CVE-2015-0999.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to execute arbitrary code. They also mention that there may be exploits for these vulnerabilities publicly available.


Schneider published separate advisories for the two product lines (here and here). The two advisories are nearly identical and neither mention publicly available exploits. They were also both published over a month ago. There is no indication about why ICS-CERT only recently got the information.

Tuesday, August 26, 2014

ICS-CERT Publishes Two New Advisories

Today the DHS ICS-CERT published two control system cybersecurity advisories for multiple vulnerabilities in the CG Automation  Substation Gateway and the Schneider Electric Wonderware Information Server.

Wonderware Advisory

This advisory reports on five vulnerabilities reported by Timur Yunusov, Ilya Karpov, Sergey Gordeychik, Alexey Osipov, and Dmitry Serebryannikov of the Positive Technologies Research Team in a coordinated disclosure. ICS-CERT reports that Schneider has produced an update that mitigates these vulnerabilities but there is no indication that Positive Technologies Research has validated that update.

The five reported vulnerabilities are:

• Account encryption and storage - CVE-2014-2381 and CVE-2014-2380;
• Cross site scripting - CVE-2014-5397;
• Improper input validation - CVE-2014-5398; and
• SQL Injections - CVE-2014-5399

ICS-CERT reports that crafting an exploit of these vulnerabilities ‘would be difficult’.

Looking at the CVE numbers it looks like there may have been two different vulnerability reports by Positive Technologies Research separated by a significant amount of time.

CG Automation Advisory


This advisory is the latest Crain-Sistrunk disclosed DNP3 improper input validation vulnerability. This should be the 22nd system report published by ICS-CERT of the reported 30 Crain-Sistrunk DNP3 reports submitted to date, according to the Automatak Robus web site.  CG  Automation has provided an update. ICS-CERT specifically reports that CG Automation has self-validated the efficacy of the fix, not Crain-Sistrunk; something smells there.

Follow-up NOTE (08-27-14 07:46 CDT): Adam reports that he and Chris no longer have access to CG Automation hardware to do the validation testing. So nothing nefarious, but it would have been appropriate (IMHO) for CG Automation to offer access for validation testing.

Thursday, April 3, 2014

Yet Another Schneider Advisory from ICS-CERT

Today the DHS ICS-CERT published yet another advisory for a vulnerability in a product from Schneider Electric. This one is for a buffer overflow vulnerability in the OPC Factory Server (OFS). The vulnerability was reported by Wei Gao, formerly of IXIA. Schneider has produced an update that mitigates the vulnerability and Wei Gao has verified the efficacy of the patch. Interestingly the Schneider published advisory does not mention Wei Gao.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this ActiveX based vulnerability to execute a denial of service attack by causing the device to re-boot.

Schneider reports that the patch includes a patched version of the OLE2T macro from Microsoft. This is also noted in the ICS-CERT advisory. I wonder what other programs are using the vulnerable version of OLE2T?


NOTE: The Schneider security site pointed to by this advisory also includes a link to another update of the Modbus Driver Advisory that I most recently updated on Tuesday.

Tuesday, January 14, 2014

ICS-CERT Publishes 3 Advisories

Today DHS ICS-CERT published three advisories; a unique Crain-Sistrunk DNP3 vulnerability, a mitigation effort update and an advisory from the secure portal.

Schneider Advisory

This advisory addresses an Uncontrolled Resources Consumption Vulnerability in the Schneider Electric ClearSCADA series of products. The vulnerability in the DNP3 system was reported by Crain-Sistrunk in a coordinated disclosure. Schnieder has produced a new software version that mitigates the vulnerability and Adam Crain has verified the efficacy of the fix.

ICS-CERT reports that a moderately skilled attacker could remotely exploit the vulnerability to cause DNP3Driver.exe to hang causing an interruption in the system processing. Essentially this is a denial of service (DOS) attack vector.

According to the Schneider Electric web site – they publicly disclosed this vulnerability on December 5th, 2013.

Sierra Wireless Advisory Update

This advisory update provides additional information about mitigation measures for the vulnerability reported last week. Sierra Wireless provides a vulnerability note dated January 10th suggesting that over-the-air firmware updates should not be done because “the update process, password data is transmitted to the device”. It recommends that the over-the-air programing feature be disabled.

The vulnerability note also as a recommendation for high-security applications:

“For high-security applications such as critical infrastructure monitoring, Sierra Wireless advises customers to deploy cellular devices using a Private Cellular Network or VPN to reduce the risk of an attacker capturing data transferred to/from the device.”

The pages that I reported last week did not mention that the device was discontinued now contain the following product status note: “Discontinued, still supported”.

This new information provides customers with a little more useable information than did the original advisory which essentially just said “Well we’ve discontinued the defective device, its now your problem”.

WellinTech Advisory

This advisory was originally released on the secure portal (on HSIN) last month and is now being released to the public. The advisory describes twin vulnerabilities affecting a variety of the WellinTech SCADA products. The vulnerability was reported by Andrea Micalizzi via the Zero Day Initiative (ZDI) in a coordinated disclosure. I was not able to find the ZDI listing for this vulnerability.

The twin vulnerabilities are:

• Information disclosure vulnerability, CVE-2013-2826; and
• ActiveX remote code execution vulnerability, CVE-2013-2827
NOTE: The CVE links are not yet active.


ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to either obtain system credentials or run arbitrary code in the dll. WellinTech has provided new versions of the affected software that mitigate the vulnerabilities. There is no mention of anyone verifying the efficacy of the new software versions in fixing these vulnerabilities.

Monday, September 23, 2013

ICS-CERT Updates (again) Schneider Advisory

Today the DHS ICS-CERT published a second update for a series of Schneider Electric alerts and advisories dating back to December 2011 (12-12-11 Alert, 1-17-12 Advisory, 3-5-13 Alert, and 6-4-13 Advisory Update). The original alert was based upon a partially coordinated disclosure (we still haven’t heard the whole story on that) by Ruben Santamarta. The second alert was based upon an S4 Conference disclosure by Arthur Gervais.

This advisory update reports that:

• This advisory corrects and expands on the details in the specified alert and subsequent advisory updates;
• ICS-CERT has coordinated with Schneider Electric, and they have produced patches and firmware upgrades for Quantum and other affected products;
• Schneider Electric has created firmware upgrades that resolve the Telnet and Windriver debug port vulnerabilities for all affected products by removing the Telnet and Windriver services from these modules; and
• Schneider has also released a firmware upgrade to address the FTP service vulnerability by allowing the user to disable the FTP service.

The ICS-CERT advisory provides a link to the Schneider Electric download site but I cannot find a reasonably identifiable upgrade that deals with removing the Telnet and Windriver services from the Quantum Ethernet Module. Of course this fix was supposedly developed in 2011 for two of the affected modules so it may take some searching to find these upgrades. Hopefully someone in the Schneider Electric service department will be able to help owners locate the appropriate upgrades.

The advisory notes that the removal of these two services should not impact operations since they were included only for “advance troubleshooting use” and were not intended to be used by customers.


ICS-CERT left language in the updated advisory {pg 5} that would seem to indicate that additional mitigation measures are expected. It is not clear from reading the rest of the updated advisory if this was simply an editorial oversight or if additional work is actually expected from Schneider.

Thursday, August 22, 2013

ICS-CERT Publishes Two Advisories – Schneider and Top Server

Today the DHS ICS-CERT published two control system advisories; one for an encryption vulnerability in the Schneider Electric Trio J-Series Radios and one for an input validation vulnerability in the Software Toolbox TOP Server DNP Master OPC product.

Schneider Vulnerability

This advisory concerns a self-reported hard-coded encryption key vulnerability (NOTE: The Schneider web site reports that this vulnerability was reported by an unnamed security researcher). Some versions of the firmware in the Trio J-Series License Free Ethernet Radio does not properly generate an AES encryption key. Schneider reports that simply upgrading to a newer version of the firmware does not necessarily correct the problem.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to take control of the communications network and the control system attached to it. Schneider reports that they have updated firmware, that properly applied, will mitigate the problem. There is no indication that the original researcher has validated the update.

NOTE: Schneider identified this problem and solution in May and posted it on their web site on August 8th. That delay was almost certainly due to attempting to notify customers of the problem. The delay in the ICS-CERT reporting of this issue is not explained.

TOP Server Vulnerability

This advisory concerns an improper input validation vulnerability on the TOP Server DNP Master OPD product identified by Adam Crain and Chris Sistrunk. Oh, hell, just read my Kepware blog post of last week; this advisory is for the same vulnerability in the same system, it’s just marketed under a different label. Adam pointed this out to ICS-CERT but they would not add it to the earlier advisory. Adam and Chris get credit for another coordinated disclosure because they pushed ICS-CERT to publish this advisory so that the TOP Server owners would understand that this vulnerability applied to them.

This is an ongoing problem with hardware, software and firmware sold under different names or included in other systems. As more of these types of vulnerabilities are reported blackhats will begin to realize that systems are vulnerable because owners don’t realize that available patches and upgrades apply to their equipment. ICS-CERT needs to step up and be proactive in these types of situations and not have to be pressured into acting by concerned researchers.


BTW: The Project Robus web site takes credit for this advisory and reports that there are now 17 disclosures pending.

Tuesday, August 6, 2013

ICS-CERT Publishes Schneider Electric Advisory

Yesterday the DHS ICS-CERT published an advisory for an XML external entity vulnerability in three Schneider Electric products. The vulnerability was reported to Schneider by Timur Yunusov, Alexey Osipov, and Ilya Karpov of Positive Technologies.

ICS-CERT reports that a moderately skilled attacker with local access to affected systems could exploit this vulnerability to gain access to information on the system. Schneider reports that the vulnerability could also lead to a denial of service attack.

Schneider has produced a series of patches for this vulnerability for the affected systems. There is no indication in the Advisory that there has been any outside verification of the efficacy of the patches. Interestingly, the Schneider disclosure document reminds users that if they must re-install or repair the affected products that the “should first uninstall the fix, re-install\repair the affected product(s) and then reinstall the fix”. Hopefully customers will be able to ensure that this information remains prominently available over the lifetime of the product.


NOTE: Schneider publicly released their vulnerability disclosure on July 28th after making it available on their secure portal on May 9th.  The ICS-CERT Advisory does not provide links to either the disclosure document or the vulnerability report.

Wednesday, April 10, 2013

ICS-CERT Publishes Another Schneider Advisory


Today the DHS ICS-CERT published an advisory for an improper authorization vulnerability in the Schneider Electric MiCOM S1 Studio Software. The vulnerability was reported by Michael Toecker of Digital Bond in a coordinated disclosure before Digital Bond’s S-4 Conference and then made a presentation of the vulnerability at the S-4 Conference.

ICS-CERT reports that a highly skilled attacker with network access could exploit this vulnerability to cause the system to run arbitrary code or execute a denial of service attack. Schneider has addressed this vulnerability through a trio of recommended practices which would, according to Schneider, mitigate the vulnerability. Those practices include:

• Standard practices always encourage users to validate the downloaded parameters through the devices’ front panel HMI;
• Schneider Electric recommends users employ best IT practices to secure their computer with authorized user login and password protection;
• On Windows 7 configured computers, use of User Access Control (UAC) can further improve the security of the computer; and
• Users who are not directly using this software on a regular basis are strongly encouraged to delete this application from their computer to reduce the likelihood of attack.

In today’s threat environment these actions hardly seem a prudent method of protecting systems from an insider attack, particularly on systems that are designed to o configure and maintain electronic protective relays
 
/* Use this with templates/template-twocol.html */