Showing posts with label Siemens PLC. Show all posts
Showing posts with label Siemens PLC. Show all posts

Sunday, July 31, 2011

ICS-CERT Updates Siemens PLC Alert

Friday afternoon the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published an update of the alert for Siemens PLCs that had been published the previous weekend. This new information comes from Siemens. They have confirmed the existence of the vulnerability that Beresford found in certain S7-300 PLCs (a list is included in the revised alert) and claim that it does not affect any of the S7-400 PLCs.

A number of bloggers and Tweeters have questioned the timing of this information; it seems that too often the information from ICS-CERT concerning Siemens products comes out late Friday afternoon. It isn’t clear if the timing is ICS-CERT or Siemens driven, but it does look like it is being designed to come out too late for most organizations to react to the release in a timely manner.

It seems odd to me that Siemens started fixing this issue in some version of the S7-300 PLCs as early as June 2009 and has yet failed to let their customers know about the vulnerability so that older versions of the PLC’s could be updated. As recently as earlier this month Siemens was publicly claiming that there were no known security issues with the S7-300 or S7-400 PLCs. Is it any wonder that many people are questioning the truthfulness of the claim in this updated alert that the S7-400 PLCs are not affected by this latest vulnerability?

There is one other oddity about this update. Typically, ICS-CERT issues an alert when it has just some preliminary information about an identified vulnerability. Once the vendor has confirmed the issue and provided mitigation measures, ICS-CERT will then issue an ‘advisory’ to replace the alert. Publishing this new information as an update to the alert rather than publishing it as an advisory would seem to indicate that ICS-CERT has not been able to verify this information.

Friday, June 10, 2011

Two ICS-CERT Vulnerability Notes – Includes Siemens S7-1200 PLC

Today the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published two new control system vulnerability notices on its web site, including the long expected alert on the Siemens S7-1200 PLCs. The other vulnerability was identified in a product from another large ICS vendor – Rockwell.

Siemens S7-1200 PLC

Well the ICS security community has been waiting for this Alert since May 19th when Dillon Beresford pulled his Siemens vulnerability talk at Takedown. We have been hearing talk about an FOUO version of this alert for the last couple of days, but now we have a ‘properly sanitized’ version for public consumption. The Alert notes that “ICS-CERT and Siemens have confirmed that these vulnerabilities [reported by Dillon] could allow an attacker with automation network access to execute various unauthorized commands against the S7-1200 PLC”.

The Alert goes on to say that today Siemens published “a Security Advisory and patch to address a portion of the reported vulnerabilities [emphasis added]”. Both the advisory and patch are available on the Siemens web site. The ICS-CERT Alert also includes the following additional mitigation measures:

• ICS-CERT and Siemens recommend that customers disable the embedded web server in TIA Portal Version 11 if it is not critical to operations.

• ICS-CERT and Siemens recommend that customers apply a properly configured, strong password. The same password should not be reused across the automation network, where possible.

• Apply defense-in-depth strategies for both enterprise and control system networks;

• Restrict connections between the enterprise and control system networks, where possible.

• Restrict remote access to enterprise and control system networks and diligently monitor any remote connections allowed; employ Virtual Private Network (VPN) connections for any remote system access.
There are an awful lot of qualifiers in those recommendations. That seems to indicate that ICS-CERT doesn’t really think that it will probably be practical to implement all of the suggested security measures. Oh well, we didn’t really want secure control systems did we?

More interestingly, this alert does not provide even a general description of the vulnerabilities that were ‘patched’ in this initial Siemens response. I understand the reluctance to describe the un-patched vulnerabilities, but not providing a generic description of the patched vulnerabilities makes one think that the patch is not really that successful.

Rockwell RSLinx Classic Advisory

This Advisory comes via the CERT Coordination Center and it concerns a program bundled with Rockwell’s RSLinx Classic, the Electronic Data Sheet (EDS) Hardware Installation Tool. The buffer overflow vulnerability in that tool could allow an attacker to execute arbitrary code that could be used to “subvert any other security service” (an interesting new phrase for an ICS-CERT advisory).

The Advisory notes that this attack would require an authorized user to load a malformed EDS file. This would, according to the advisory, not allow the attacker to “initiate the exploit from a remote machine”. That may be technically true, except that the spear phishing or other social engineering attack that tricked the user into loading the compromised file could certainly be sent from a remote machine.

Rockwell does have a patch available and ICS-CERT provides links to two documents that contain information about spear phishing and other social engineering attacks.

BTW: The ICS vulnerability numbering system gets a little annoying here. Both of these vulnerabilities have the same number (11-161-01) with different prefixes (‘ICSA’ and ‘ICS – Alert’). With just a quick glance one might assume that they are the same document. We are supposed to be more alert than that, but I wouldn’t have designed the numbering system this way.
 
/* Use this with templates/template-twocol.html */