Showing posts with label SecuNinja. Show all posts
Showing posts with label SecuNinja. Show all posts

Saturday, October 3, 2020

Public ICS Disclosures – Week of 9-26-20

This week we have ten vendor disclosures for products from WAGO (3), IBM, Bosch, B&R Automation (2), Moxa, BD, and Philips.

WAGO Advisories

CERT-VDE published an advisory describing an improper authentication and authorization vulnerability in the WAGO 750-8XX series PLCs. The vulnerability was reported by Maxim Rupp. WAGO has new firmware versions that mitigate the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

CERT-VDE published an advisory describing an improper authentication and access control vulnerability in the WAGO 750-36X and WAGO 750-8XX series PLCs. The vulnerability was reported by Maxim Rupp. WAGO has new firmware versions that mitigate the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

CERT-VDE published an advisory describing an improper neutralization of input during web page generation vulnerability in the Web-UI for WAGO 750-88X and WAGO 750-89X series PLCs. This vulnerability was reported by Secuninja. WAGO has new firmware versions that mitigate the vulnerability. There is no indication that Secuninja has been provided an opportunity to verify the efficacy of the fix.

IBM Advisory

IBM published an advisory describing an authentication bypass vulnerability in their Maximo Asset Management product. The vulnerability is being self-reported. IBM has updates that mitigate the vulnerability.

Bosch Advisory

Bosch published an advisory describing three vulnerabilities in their PRAESIDEO Network Controller and the PRAESENSA System Controller products. The vulnerabilities were reported by Gjoko Krstic of Applied Risk. Bosch has software updates for the supported products that mitigate the vulnerabilities. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Cross-site scripting - CVE-2020-6777,

• Cross-site request forgery - CVE-2020-6776, and

• Nonce reuse attack - CVE-2020-15688

NOTE: The last is a third-party vulnerability (GoAhead web server).

B&R Advisories

B&R published an advisory describing four vulnerabilities in their GateManager product. These vulnerabilities were reported by NCCIC-ICS on July 28th as being for the Secomea GateManager.

B&R published an advisory describing six vulnerabilities in their SiteManager and GateManager procucts. These vulnerabilities were reported by NCCIC-ICS last Tuesday, but the B&R advisory was not available when I published my blog post. It is not clear if the Secomea versions of these products are also affected by these vulnerabilities.

Moxa Advisory

Moxa published an advisory describing a device information leak vulnerability in their EDR-810 Series Industrial Secure Routers. The vulnerability was reported by the National Security Agency (yep, that is what the advisory says). Moxa has provided generic workarounds to mitigate the vulnerability.

BD Advisory

BD published an advisory describing a remote code execution vulnerability (CVE-2020-1147) in a third-party component (Microsoft) of a long list of their products. BD is working on testing and validation of the Microsoft patch.

Philips Advisory

Philips published an advisory describing a privilege elevation vulnerability (CVE-220-1472) in a third-party component (Microsoft) of an undisclosed number of Philips products. No mitigation information has been provided.

Saturday, October 13, 2018

Public ICS Disclosures – Week of 10-06-18


This week there was a vendor vulnerability disclosure from Siemens. There were also four exploits published for products from Delta Industrial, WAGO, and Phoenix Contact (2). I am also going to take a quick look at some additional information on an NCCIC-ICS advisory for the Hangzhou XMeye P2P Cloud Server published this week.

Siemens Advisory


Siemens published an advisory on Foreshadow and L1 Terminal Fault (L1TF) in their industrial product line. These are another pair of speculative execution attack vulnerabilities based on processors used in the affected devices. More details on the generic vulnerabilities can be found here. Siemens has some bios updates available to mitigate the vulnerabilities (three separate CVE’s involved) and has provided workarounds for other products.

This advisory was published in the same batch that was covered extensively by NCCIC-ICS on Tuesday. I have no idea why this was not included unless NCCIC-ICS is lumping these new vulnerabilities in with the Spectre and Meltdown problem. Even if that is the case, this would then have deserved an update to their alert on those issues.

Delta Industrial Exploit


A Metasploit module was published for a previously identified stack-based buffer overflow vulnerability in the Delta Industrial COMMGR software.

WAGO Exploit


SecuNinja published an exploit for a cross-site scripting vulnerability in the WAGO 750-881 ethernet controller. There is no CVE number provided so it is possible that this is a 0-day vulnerability being exploited.

Phoenix Contact Exploit


Photubias published two exploits for previously identified vulnerabilities in the Phoenix Contact ILC PLC vis their WebVisit HMI page.

The three reported vulnerabilities covered in these exploits are:

• Cleartext storage of sensitive information - CVE-2016-8366;
• Authentication bypass issues - CVE-2016-8371; and
• Access to critical private variable via public method - CVE-2016-8380.

Hangzhou Advisory


Earlier this week NCCIC-ICS published their advisory for three vulnerabilities in the Hangzhou XMeye P2P Cloud Server. As is typical for these advisories NCCIC-ICS provided summary data on the issue. Since Hangzhou effectively did not respond to the coordination efforts of NCCIC-ICS there was no vendor information provided in the advisory. While NCCIC-ICS did acknowledge the vulnerability reporting effort of SEC Consult, they did not (as is their apparent policy) provide any link to the reporting agency’s information on the vulnerabilities.

Generally speaking this policy of not linking to supporting documentation from researchers is a mistake and, in this instance, it does a gross disservice to the affected community by severely understating the potential problems associated with the affected devices. In particular, it fails to explain that the vulnerabilities affect a large number of vendors that rebrand and sell the affected Hangzhou DVR products.

SEC Consult published an advisory on the vulnerabilities as well as a lengthy blog post. Brian Krebs also did a lengthy blog post on the topic.

 
/* Use this with templates/template-twocol.html */