Showing posts with label Schweitzer. Show all posts
Showing posts with label Schweitzer. Show all posts

Saturday, August 5, 2023

Review – Public ICS Disclosures – Week of 7-29-23 – Part 1 -

This week in Part 1 we have 80 vendor advisories from Aruba Networks, BD, Broadcom (45), CODESYS (5), Fujitsu, GE Gas Power, HP, HPE, Omron (3), Schweitzer Engineering Laboratory, Setelsa Security, Splunk, Tanzu (16), WAGO (2), and VMware.

For Part 2 I will look at vendor updates and researcher reports.

Advisories

Aruba Advisory - Aruba published an advisory that describes a command injection vulnerability in their CX Switches.

BD Advisory - BD published an advisory that discusses an incorrect authorization vulnerability in multiple products.

Broadcom Advisories - Broadcom published 45 advisories for third-party vulnerabilities in a variety of their products.

CODESYS Advisory #1 - CODESYS published an advisory that describes an improper restriction of excessive authentication attempts vulnerability in their Development System product.

CODESYS Advisory #2 - CODESYS published an advisory that describes an insufficient verification of data authenticity vulnerability in their Development System product.

CODESYS Advisory #3 - CODESYS published an advisory that describes an uncontrolled search path vulnerability in their Development System product.

CODESYS Advisory #4 - CODESYS published an advisory that describes 15 vulnerabilities in their Control V3 runtime systems products.

CODESYS Advisory #5 - CODESYS published an advisory that describes two vulnerabilities in their Control V3 runtime system products.

Fujitsu Advisory - Fujitsu published an advisory that describes an improper credential storage vulnerability in their Software Infrastructure Manager product.

GE Advisory - GE published an advisory that discusses a FortiOS stack-based buffer overflow vulnerability.

HP Advisory - HP published an advisory that describes an elevation of privilege vulnerability in some HP and Samsung Printer software packages.

HPE Advisory - HPE published an advisory that discusses 48 vulnerabilities in their Fibre Channel and SAN Switches.

Omron Advisory #1 - Omron published an advisory that describes three vulnerabilities in their CX-Programmer product.

Omron Advisory #2 - Omron published an advisory that describes an improper validation of specified type of input vulnerability in their CJ Series CJ2 CPU units.

Omron Advisory #3 - Omron published an advisory that discusses the INFRA:HALT vulnerabilities in their Multi-function Compact Inverter 3G3MX2.

SEL Advisory - SEL published an advisory that announces that a new version of their Synchrowave Linux Platform is available to fix an undescribed vulnerability by closing Port 10250 on k3s.

Setelsa Advisory - Incibe-CERT published an advisory that describes an SQL injection vulnerability in the Setelsa ConacWin access control platform.

Splunk Advisory - Splunk published an advisory that describes a log injection vulnerability in their SOAR product.

Tanzu Advisories - Tanzu published 16 advisories, each with multiple vulnerabilities in various products.

WAGO Advisory #1 - VDE-CERT published an advisory that discusses an authentication bypass by capture replay vulnerability in the WAGO 758-918 ETHERNET Gateways.

WAGO Advisory #2 - VDE-CERT published an advisory that discusses 15 vulnerabilities in multiple WAGO products.

VMware Advisory - VMware published an advisory that describes two vulnerabilities in their Horizon Server.

 

For more details on these disclosures, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-4fa - subscription required.

Saturday, June 24, 2023

Review – Public ICS Disclosures – Week of 6-17-23

This week we have twelve vendor disclosures from FortiGuard (2), GE Gas Power, HP, HPE, Sick, Schweitzer Engineering Labs (2), Sierra Wireless, VMware, Western Digital, and Zyxel. There is also an update from GE Gas Power. We also have three researcher reports for products from Dell and an update of the OT:ICEFALL report. Finally, we have an exploit for the HiSECOS from Belden.

Advisories

FortiGuard Advisory #1 - FortiGuard published an advisory that describes a deserialization of untrusted data vulnerability in their FortiNAC.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes a command injection vulnerability in their FortiNAC product

GE Gas Power Advisory - GE published an advisory that discusses five vulnerabilities in their Proficy Historian product.

HP Advisory - HP published an advisory that discusses a Time-of-Check to Time-of-Use (TOCTOU) vulnerability in their PC products using AMI UEFI Firmware.

HPE Advisory - HPE published an advisory that discusses a remote code execution vulnerability in their IceWall product modules.

Sick Advisory - Sick published an advisory that describes vulnerabilities in their SICK EventCam App.

SEL Advisory #1 - SEL announced that a new version of their SEL-5037 SEL Grid Configurator is available that mitigates undescribed cybersecurity vulnerabilities.

SEL Advisory #2 - SEL announced that a new version of their SEL-5030 acSELerator QuickSet Software is available that mitigates undescribed cybersecurity vulnerabilities.

Sierra Wireless Advisory - Sierra Wireless published an advisory that provides additional guidance on a previously disclosed improper authentication vulnerability for their routers using the AirLink Management Service (ALMS).

VMware Advisory - VMware published an advisory that describes five vulnerabilities in their vCenter Server and Cloud Foundation products.

Western Digital Advisory - Western Digital published an advisory that describes two command injection vulnerabilities in their My Cloud OS 5 Firmware.

Zyxel Advisory - Zyxel published an advisory that describes a command injection vulnerability in the NAS products. This vulnerability is listed in the CISA Known Exploited Vulnerabilities Catalog.

Updates

GE Gas Power Update - GE published an update for their Proficy Historian that was originally published on February 3rd, 2023.

Researcher Reports

Dell Reports - Binarly published three reports describing individual vulnerabilities in the Dell Edge Gateway BIOS.

OT:ICEFALL Report - Forescout published an update of their OT:ICEFALL report.

Exploits

Belden Exploit - Dreizehnutters published an exploit for a privilege escalation vulnerability in Belden’s HiSecOS Web Server.

 

For more details on these disclosures, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-7c8 - subscription required.

Tuesday, July 10, 2018

ICS-CERT Publishes 2 Advisory – Updates Spectre Alert


Today the DHS ICS-CERT published two control system security advisories for products from Schweitzer Engineering and Universal Robots. They also updated their alert for Meltdown/Spectre vulnerabilities.

Schweitzer Advisory


This advisory describes three vulnerabilities in the Schweitzer Compass and AcSELerator Architect products. The vulnerabilities were reported by Gjoko Krstic of Applied Risk. The latest versions of the software mitigate the vulnerability. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Incorrect default permissions - CVE-2018-10604;
• Improper restriction of XML external entity reference - CVE-2018-10600; and
Uncontrolled resource consumption - CVE-2018-10608

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability with publicly available exploit code to allow modification/replacement of files within the Compass installation directory, disclosure of information, or denial of service.

Universal Robots Advisory


This advisory describes two vulnerabilities in the Universal Robots Robot Controllers. The vulnerabilities were reported by Davide Quarta, Mario Polino, Marcello Pogliani, and Stefano Zanero from Politecnico di Milano as well as Federico Maggi with Trend Micro Inc. Universal Robots has described generic workarounds to mitigate the vulnerabilities. There is no indication that any of the researchers have been provided with an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Use of hard-coded credentials - CVE-2018-10633; and
• Missing authentication for critical function - CVE-2018-10635

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to run arbitrary code on the device.

Meltdown/Spectre Update


This update provides additional information on an alert that was originally published on January 11th, 2018 and updated on January 16th, 2018, January 17th, 2018, January 30th, 2018, February 20th, 2018, February 22nd, 2018, March 1st, 2018 and again on April 26th, 2018 (typo in ICS-CERT update says 4-27-18). The update provides a link to the new PEPPERL+FUCHS (ecom mobile devices) advisory that I discussed on Saturday.

Tuesday, January 24, 2012

Reader Comment: Basecamp Communications Devices

It took me a while, but I finally got a chance to ‘moderate’ a response to this weekend’s blog post on the Basecamp disclosure process from Dale Peterson; one of the drawbacks to traveling cross country by car is that you can’t do much work on the internet. Dale explains the reasoning for including the Koyo ECOM100 and notes that the Schweitzer alert was for a wireless communications device, the SEL 2032 Communications Processor.

As Dale points out, vulnerabilities in the communications nodes between the PLCs and the control system are essentially major vulnerabilities for the control system and the PLC; they can allow protected access to both. As such they were clearly fair game for analysis.

The only point that I was trying to make about the ECOM100 being a ‘ringer’ (and the same point should have been made about the Schweitzer device) is that the PLC vendors had clear public notice about what was going to happen with the research into their devices. Since they should have known about the disclosed vulnerabilities (especially the ones that were specifically designed into the systems), they have no cause to complain about the ‘uncoordinated disclosures’. They are the ones that put their customers at risk not Project Basecamp.

Unless the Project Basecamp team provided direct notification to Koyo and Schweitzer about their products being included in the evaluation, the same blanket dismissal of concerns does not apply. On the other hand, the process industry really does need to understand that these types of devices (and I assume that the same types of vulnerabilities will show up in many if not most of these types of devices currently in use) may provide a broad avenue of attack on control systems. This clearly needs to be recognized and addressed.

So with the caveat that the following does not apply if they received advanced notification of inclusion in the Project Basecamp investigation, I think that both Koyo and Schweitzer were poorly treated by an uncoordinated disclosure of their vulnerabilities. More importantly their customers may have been unduly put at risk by not allowing these two manufacturers a chance to correct the system defects before the vulnerabilities were made public.

Twenty lashes with an al dente noodle for each of the uncoordinated disclosures for these two manufacturers (again with an immediate pardon if they received advanced notification of inclusion in the process) to Dale Peterson for his unsportsmanlike conduct. On the other hand, I think that it is time to look at all of the devices and systems that we employ to control critical processes, so a small quiet kudo to Dale as a salve to his wounds for his efforts (and of course the hard work of the entire Project Basecamp team and supporters) to bring formal attention to this problem.

Sunday, January 22, 2012

ICS-CERT Publishes Five S4 Based Alerts Plus Two Other Alerts

On Friday the DHS ICS-CERT published 7 separate alerts, five of which referenced vulnerabilities that were publicly discussed at Digital Bond’s SCADA Security Scientific Symposium (S4) in Miami, FL. These alerts, combined with a similar alert published on Thursday, may mark just the tip of the iceberg as Dale Peterson noted on the DigitalBond.com blog that 30 students at a HMI hacking class before the actual symposium “were quickly finding 0days using ActiveX and File Format Fuzzing”.

Oh yes, the two other alerts. They were based upon uncoordinated disclosures by the Digital Security Research Group (DSecRG) for systems produced by WellinTech and WAGO.

S4 Alerts


The five S4 alerts issued Friday included a general alert for disclosures made during the Project Basecamp portion of S4. The alert notes that the reported vulnerabilities in multiple vendor products included “buffer overflows, backdoors, weak authentication and encryption, and other vulnerabilities that could allow an attacker to take control of the device and interfere or halt the process it controls” (page 1). The four other S4 related alerts dealt with specific vulnerabilities in systems from four separate vendors; those vendors were:



Koyo (Note: not a PLC vendor, but an Ethernet vendor that provides communications between PLCs and the actual control system)


Project Basecamp was a detailed search for and reporting of vulnerabilities in various PLC’s used by industrial control systems. Dale has become increasingly vocal over the last six months or so about his dissatisfaction at cybersecurity community’s disregard of the consequences of the insecure design of programmable logic controllers (PLC). In both his blog and in any other venue that would listen (or even pretend to listen) he has made it clear that everyone in the control system vendor and researcher community has known for at least 10 years that the basic PLC design has inherent cyber-security flaws that make them vulnerable to attack. These vulnerabilities were made painfully clear in the design of the Stuxnet virus.

Because the Stuxnet worm exploited vulnerabilities in the Siemens PLC, many of the Siemens security flaws have been publicly documented, while the rest of the industry breathed a sigh of relief that their systems weren’t being used by the Iran’s nuclear program. The whole point of Project Basecamp was to formally tell the world that Siemens was not alone in their ‘insecure by design’ problems.

That the world, at least the security professional side, has taken notice cannot be doubted. There has been significant discussions in a number of forums (on LinkedIn.com and on the SCADASec list for instance) and in the cyber related press. Unfortunately, most of that discussion has been about the public disclosure of the vulnerabilities (along with some Metasploit® modules published to aid in the exploit of those vulnerabilities) rather than on the potential effects of the vulnerabilities on real world control systems. Hopefully, the fait accompli provided by Dale and the Basecamp team will eventually allow for a more detailed discussion of the vulnerabilities and how to protect control systems from attack using those vulnerabilities.

ICS-CERT does make a valuable contribution (with a forgivable sideways slap at Project Basecamp) to that inevitable discussion in the general Basecamp alert. They note (page 2):

“This public release increases the potential for cyber attack on these devices, particularly if the devices are connected to the Internet. ICS-CERT reminds users that the use of readily available and generally free search tools (such as SHODAN and ERIPP) significantly reduces time and resources required to identify Internet facing control systems. In turn, hackers can use these tools combined with the exploit modules to identify and attack vulnerable control systems. Conversely, owners and operators can also use these same tools [emphasis added] to audit their assets for unsecured Internet facing devices.”

But, less anyone forget, the Iranian PLCs that were the Stuxnet target were not connected to the Internet, nor were their control systems. Many of the vulnerabilities reported by the Project Basecamp team will allow an attacker to exploit the vulnerabilities without having to target an internet connected PLC; it will require a higher skill level and more system knowledge. There are loads of attackers with the appropriate skills and system knowledge can be easily obtained via social engineering attacks. Internet-isolated control systems (if there are really such things in existence) are not safe from attacks based upon these vulnerabilities.

WellinTech Alert


The WellinTech alert provides initial information on a reported password encryption vulnerability in the KingSCADA product that could allow an attacker to read and use a user password, thus gaining user level access to a control system. Exploiting this vulnerability requires access to the SCADA server.

WAGO Alert


The WAGO alert concerns multiple vulnerabilities in the I/O System 750. The vulnerabilities include:




Interestingly a DSecRG press release notes that the WAGO disclosure of the 750 series controller vulnerabilities was made in support of Project Basecamp. Additionally the DSecRG web site notes two other control system vulnerabilities released by DSecRG on the same day. One deals with a default password vulnerability on Tecomat PLCs (more Project Basecamp fallout?) and an ActiveX vulnerability on an OPC system. I expect that we’ll see ICS-Alerts on these on Monday.
 
/* Use this with templates/template-twocol.html */