Showing posts with label Sergey Gordeychik. Show all posts
Showing posts with label Sergey Gordeychik. Show all posts

Thursday, February 15, 2018

ICS-CERT Publishes 4 Advisories and One ABB Update


Today the DHS ICS-CERT published four new control system security advisories for products from Schneider Electric (2), GE and Nortek. Additionally, they provided an update for a previously published advisory for products from ABB.

StructureOn Advisory


This advisory describes an unrestricted upload of file with dangerous type vulnerability in the Schneider StruxureOn Gateway software management program. The vulnerability is being self-reported.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to upload a malicious file to any directory on the device, which could lead to remote code execution. The Schneider security advisory reports that the file must be a .zip file with specifically modified metadata for this vulnerability to be exploited.

IGSS Mobile Advisory


This advisory describes two vulnerabilities in the Schneider IGSS Mobile application (iOS and Android). The vulnerabilities were reported by Alexander Bolshev (IOActive) and Ivan Yushkevich (Embedi). Schneider has produced updates for both versions. There is no indication that either researcher has been provided an opportunity to verify the efficacy of the fix.



The two reported vulnerabilities are:

• Improper certificate validation - CVE-2017-9968; and
Plaintext storage of password - CVE-2017-9969

ICS-CERT reports that a relatively low-skilled attacker with local access (okay they, actually said: “Locally exploitable”; that may not mean ‘local access’) could exploit the vulnerability to execute a man-in-the-middle attack. In addition, passwords can be accessed by unauthorized users.

NOTE: Marc Ayala pointed out to me that anyone can download these apps from the appropriate (iOs/Android) app store. This means that it would be easy to exploit a compromised mobile password. All the attacker needs to do is to get access to the IGSS configuration file on an oh so secure smart phone to compromise the password.

GE Advisory


This advisory describes two vulnerabilities in the GE D60 Line Distance Relay. The vulnerabilities were reported by Kirill Nesterov of Kaspersky Labs. GE has released new firmware that mitigates the vulnerability. There is no indication that Nesterov was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-5475; and
• Improper restriction of operations within bounds of memory buffer - CVE-2018-5473

ICS-CERT reports that relatively low-skilled attacker could remotely exploit the vulnerability to execute arbitrary code on the device.

Nortek Advisory


This advisory describes a command injection vulnerability in the Nortek Linear eMerge E3 Series access control interface. The vulnerability was reported by Evgeny Ermakov and Sergey Gordeychik. Nortek recommends upgrading the system using established procedures. There is no indication that either researcher was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability  to execute malicious code on the system with elevated privileges, allowing for full control of the server.

ABB Update


This update provides additional information on an advisory that was originally published on November 14th, 2017. The update reports that the new update of Mesh OS mitigates the KRACK vulnerability in these devices.

NOTE: The updated ABB security advisory that forms the basis for this ICS-CERT update was published on January 11th, 2018.

Thursday, July 24, 2014

ICS-CERT Publishes Two More Advisories

Some weeks it seems that everyday there is a new set of advisories from DHS ICS-CERT; this is one of those weeks. Today ICS-CERT published advisories for Siemens WinCC and the Morpho Itemizer. Oh, and they missed listing the Morpho advisory on both the landing page and the Advisories page; they did tweet about it though. When you get busy, mistakes happen unless you have good administrative controls in place.

Siemens Advisory

This advisory is based upon coordinated disclosures from an anonymous researcher and a separate report from Sergey Gordeychik, Alexander Tlyapov, Dmitry Nagibin, and Gleb Gritsai of Positive Technologies. Siemens has prepared an update that is reported to mitigate the multiple vulnerabilities, but there is no indication that the researchers have had a chance to verify the efficacy of the fix.

The vulnerabilities include:

• Forced browsing - CVE-2014-4682 – could allow unauthenticated access to data;
• Session fixation - CVE-2014-4683 – could allow remote privilege escalation;
• Improper privilege management - CVE-2014-4684 – could allow database privilege escalation;
• Permissions, privileges and access control - CVE-2014-4685 – could allow local user to escalate their privileges; and
• Hard-coded cryptographic key - CVE-2014-4686 – cold allow privilege escalation.

ICS-CERT reports that a low-to-moderately skilled attacker could remotely (except CVE-2014-4685) exploit these vulnerabilities. Siemens reports that they have produced an update that mitigates the vulnerabilities in WinCC and expect an update for Simatic PCS7 next month. In addition they suggest the following actions be taken until a hard fix can be established:

• Limit the WebNavigator server access to trusted networks/clients only
• Ensure that the WebNavigator clients authenticate themselves against the WebNavigator server (e.g. use client certificates)
• Restrict access to the WinCC database server at port 1433/tcp to trusted entities
• Deactivate all unnecessary OS users on WinCC server
• Run WinCC server and engineering stations within a trusted network, or
• Ensure that the WinCC server and the engineering stations communicate via encrypted channels only (e.g. establish a VPN tunnel).

Morpho Advisory

This advisory looks at a single hard-coded-credential vulnerability reported by Billy Rios and Terry McCorkle. ICS-CERT reports that: “Morpho has decided not to address this vulnerability at this time.” Since the Itemizer® 3 is not strictly speaking an industrial control system (it’s an analytical system controller) it could look like this is no big thing. It could, however, have an effect on police investigations that would rely on these pieces of equipment to identify drug and explosives trace evidence. A cyber savvy defense attorney could use this uncorrected vulnerability to cause a judge to question the validity of test data from this machine and potentially reverse a drug or explosives conviction or the use of the evidence in court.


ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability to gain administrative access to the system. Not much you can’t do once you have that access.


 
/* Use this with templates/template-twocol.html */