Showing posts with label Siemens WinCC. Show all posts
Showing posts with label Siemens WinCC. Show all posts

Wednesday, December 10, 2014

ICS-CERT Updates Their Alert on Ongoing Malware Campaign

Today the DHS ICS-CERT published the second update of their alert concerning the BlackEnergy malware campaign. The first update was published on October 29th and the original alert was published the day before.

This update provides a little more information on the probable existence of a Siemens WinCC attack vector involved in the campaign. The original alert only provided the vaguest hint about the use of WinCC which ICS-CERT plainly said they could not confirm. They now say:

“While ICS-CERT lacks definitive information on how WinCC systems are being compromised by BlackEnergy, there are indications that one of the vulnerabilities fixed with the latest update for SIMATIC WinCC [link added] may have been exploited by the BlackEnergy malware. ICS-CERT strongly encourages users of WinCC, TIA Portal, and PCS7 to update their software to the most recent version as soon as possible.”

This version of the alert also updates the Yara Rules that allow organizations to interpret the results of scan conducted with the Yara pattern matching tool. ICS-CERT recommends that organizations running the updated scan and the application of the updated Yara Rules send copies of the results to ICS-CERT for more detailed interpretation of the data if there are any indications of potential compromise in the results.


ICS-CERT does not specifically state in this update that even those organizations that have already run the earlier version should run the updated scan. Since this apparently checks for later versions (or at least different versions) of the malware associated with BlackEnergy, it would seem to me that it would only be prudent to run this latest version and any new versions that ICS-CERT might publish in the future.

Wednesday, November 26, 2014

ICS-CERT Publishes Siemens and MatrikonOPC Advisories

Yesterday the DHS ICS-CERT published two new advisories; one for the Siemens WinCC application and another for the MatrikonOPC for DNP application.

Siemens Advisory

This advisory is for two vulnerabilities in SIMATIC WinCC, both as a stand alone application and as implemented in SIMATIC PCS7 and TIA Portal. These are apparently self-identified vulnerabilities for which Siemens has updates for some of the affected products and is working on updates for the others.

ICS-CERT identifies the vulnerabilities as:

• Remote code execution - CVE-2014-8551; and
• Transfer/extract files - CVE-2014-8552.

Interestingly this tells us what the exploit of the vulnerability is not what the vulnerability is. The Siemens ProductCERT advisory is not any more forthcoming on this topic than is the ICS-CERT Advisory. I suspect that any more detailed description of the actual vulnerability would make it easy for the average hacker to figure out how to exploit these vulnerabilities.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities. ICS-CERT reports that a exploits for these vulnerabilities may already be available and these vulnerabilities “may have been exploited during a recent campaign”. Siemens acknowledges assistance from Symantec Deepsight Intelligence which may substantiate that claim.

Siemens published their advisory on Friday. I noted in a TWEET® on Friday morning the unusual lack of description of the type of vulnerability. With the apparent level of risk involved and the wide spread use of these applications I am very surprised (and disconcerted) that ICS-CERT took this long to publish this advisory.

MatrikonOPC Advisory

This advisory reports an unhandled C++ exception vulnerability in the MatrikonOPC DNP3 application. The vulnerability was reported by Crain-Sistrunk and was discovered under their Project Robus using their Aegis Fuzzer (I ought to charge these guys advertising fees, but I like their chutzpah too much). It looks like this is now 26 reported of 31 disclosed for the DNP3 protocol and this is a different vulnerability than most of those previously reported by this team.

ICS-CERT reports that MatrikonOPC has produced a new version that mitigates this vulnerability but does not say that Crain-Sistrunk have verified the efficacy of that mitigation.

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to effect a denial of service attack that would require a manual reboot of the system. The MatrikonOPC Security Notification that a successful exploit would “require expert knowledge of both the DNP3 protocol and an in-depth understanding of the vulnerability that exists in the affected versions of the MatrikonOPC Server for DNP3”.


MatrikonOPC published their notice on October 22nd, over a month ago. There is no indication in the ICS-CERT advisory that this had been released on the US-CERT Secure Portal, so I wonder why it took so long for this advisory to be published? Could they have been trying to convince MatrikonOPC to allow Crain-Sistrunk to verify that their update worked?

Friday, August 2, 2013

ICS-CERT Issues Three Advisories – Two for Siemens

After a three-week breather advisories start coming hot and heavy from ICS-CERT. There are two Siemens’ advisories (one self-reported) and a coordinated disclosure advisory for IOServer.

Siemens Scalance

The first advisory addresses two Siemens’ reported two vulnerabilities in their Scalance W-7xx product family. They are:

• Key management errors, CVE-2013-4651, hard-coded SSL certificate;
• Improper authentication, CVE-2013-4652, network access required.
NOTE: CVE Links may not be active for a couple of days.

ICS-CERT notes that a relatively low skilled attacker could remotely exploit these vulnerabilities to conduct a man-in-the-middle attack or take over complete control of the system. Siemens has produced an update that mitigates the vulnerability (since they self-reported they get to self-validate). The Siemens-CERT advisory also provides a work-around for the second vulnerability.

Siemens WinCC

The second advisory addresses two vulnerabilities reported by Timur Yunusov and Sergey Bobrov of Positive Technologies in a coordinated disclosure. The vulnerabilities are:

• Cross-site request forgery, CVE-2013-4911,
• Url redirection to untrusted site, CVE-2013-4912,
NOTE: CVE Links may not be active for a couple of days.

According to the Siemens-CERT advisory, both vulnerabilities require that a web be activated on the affected devices during set up. The attacker must then use a social engineering attack to get a user to access a malicious web page.

ICS-CERT notes that a moderately skilled attacker could remotely exploit these vulnerabilities to compromise the integrity (execute arbitrary code?) and availability (DoS attack?). Siemens has produced a product update that mitigates the vulnerabilities and has validated the fix (oops, that should have been the researchers, Yunusov and Borov, doing the validation).

IOServer Advisory

The third advisory of the day reports on an improper input validation vulnerability in the IOServer Master Station product reported by Adam Crain of Automatak and Chris Sistrunk in a coordinated disclosure.


ICS-CERT notes that a moderately skilled attacker could remotely exploit this vulnerability to execute a denial of service attack. IOServer has produced a Beta Driver (beta2042.exe) that mitigates these vulnerabilities. There is no indication that the researchers have validated the efficacy of the updated driver. NOTE: an even more recent Beta Driver is available.

Wednesday, March 20, 2013

ICS-CERT Publishes 4 Advisories


Today ICS-CERT published three new advisories for vulnerabilities in systems from Siemens and Schweitzer Engineering Laboratories (SEL) and updated a very recently published advisory from Schneider Electric.

Schneider Update

This has got to be one of the fastest advisory updates, on Monday ICS-CERT published the advisory and today the published the update. The update provides a reference to the update to the original alert that reported Schneider’s claim that two of the four reported vulnerabilities were not actually vulnerabilities. It goes on to provide some more detailed explanation of Schneider’s reasoning.

This update also addresses an issue I raised in my blog post, the failure of Schneider to produce a patch or update to correct the two acknowledged vulnerabilities, relying instead on recommendations (detailed recommendations to be sure) for the use of a firewall to prevent unauthorized access to the vulnerabilities.

The updated advisory explains that Schneider “does not plan to issue patches because of their complex nature. Schneider Electric says that fixing these vulnerabilities would require significant changes to existing protocols and make any customer solutions currently using these features incompatible” (pg 2).

Now I’m not a software engineer, so I can’t comment on the complexity of fixing the problem, but I know that I’m not alone in thinking that this is a short-sighted response from Schneider. A commenter today on one of the LinkedIn groups where I started a discussion about yesterday’s blog post said:

“Looks like we will be looking at adding Tofino firewalls to their systems. Long term we will be looking at migrating away from hardware with known issues as it is only a matter of time before something gets around the firewall.”

SEL Advisory

This advisory describes an improper authorization vulnerability in the SEL AcSELerator  QuickSet software reported by Michael Toecker of DigitalBond. The vulnerability was initially disclosed to the vendor, but it was then reported at the S4 Conference in January. Since it was a coordinated disclosure, ICS-CERT did not issue an alert on the vulnerability when it was publicly disclosed in January. (NOTE: See Michael’s DigitalBond blog post about vendor responses to disclosures which mentions this vulnerability.)

The advisory reports that a highly skilled attacker could use this vulnerability to replace executables within the SEL Program Files directory. The attacker would require access to the computer as an authorized user to exploit this vulnerability.

SEL has produced a new version of the affected software that only allows an authenticated Administrator to change executables. The advisory does not mention if they or Michael have verified the efficacy of the new version to correct this vulnerability. Does that mean that there has been no verification or that the drafter of this advisory simply failed to mention the fact? Please, let’s have some consistency here.

Siemens WinCC Advisory

This advisory describes multiple vulnerabilities reported by Sergey Gordeychik of Positive Technologies and Siemens ProductCERT in a coordinated disclosure. The vulnerabilities include:

• Missing encryption of sensitive data, CVE-2013-0678;
• Improper authorization, CVE-2013-0676 and CVE-2013-0677;
• Relative path traversal, CVE-2013-0679; and
• Buffer overflow, CVE-2013-0674 and CVE-2013-0675;

ICS-CERT reports that a low to medium skilled attacker could remotely exploit these vulnerabilities to execute a DoS attack, gain read access to files or remotely execute arbitrary code. Siemens has produced an updated version of the software that is available through customer support.

Siemens WinCC TIA Portal Advisory

This advisory describes multiple vulnerabilities affecting the Siemens WinCC TIA Portal (HMI) that were reported by multiple researchers (Billy Rios and Terry McCorkle of Cylance; Gleb Gritsai, Sergey Bobrov, Roman Ilin, Artem Chaykin, Timur Yunusov, and Ilya Karpov from Positive Technologies; and Shawn Merdinger). The vulnerabilities include:

• Insecure password storage, CVE-2011-4515;
• Improper input validation, CVE-2013-0669;
• Cross-site scripting, CVE-2013-0672;
• Directory Traversal, CVE-2013-0671;
• HTTP response splitting, CVE-2013-0670;
• Server-side script injection, CVE-2013-0667 (Note there is a typo in the link printed in the advisory, it has been corrected here); and
• Reflected cross-site scripting, CVE-2013-0668

ICS-CERT reports that a low to medium skilled attacker using a social engineering attack or having valid user credentials could exploit these vulnerabilities to execute a Dos attack, gain access to system files, or execute arbitrary code. Siemens has produced an updated version of the software, but recommends disabling the web server as a work-around for the web based vulnerabilities until the new software can be installed.

Wednesday, September 7, 2011

ICS-CERT Publishes Advisories on Two Industrial Control Systems

Yesterday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published two control system advisories. One dealt with the Siemens WinCC system while the other dealt with the Scadatec Limited Procyon system.

Siemens WinCC


A new set of security researchers, Billy Rios and Terry McCorkle, have reported a memory corruption vulnerability in WinCC Runtime Advanced Loader, a component of both WinCC flexible and TIA Portal. This vulnerability was reported in limited distribution on the US-CERT secure portal on September 1st.

The vulnerability would allow an attacker with basic skills to use a specially crafted packet to execute a denial of service attack and possibly execute arbitrary code remotely. There is no known exploit publicly available for this vulnerability.

Siemens has not developed, nor is it intending to develop a patch for this vulnerability. They advise customers to keep this feature disabled on their systems except when it is being used to update firmware.

Scadatec Limited Procyon


The nSense Vulnerability Coordination Team has reported a buffer overflow vulnerability in the Scadatec Limieted Procyon HMI/SCADA product. This vulnerability was originally reported on the US-CERT secure portal on August 4th.

This vulnerability would allow a moderately skilled attacker to use a specially crafted packet to cause a buffer overflow via the Telnet daemon allowing for a denial of service attack and potentially allow the remote execution of arbitrary code.

Scadatec Limited has produced an updated version of Procyon HMI/SCADA product that is free of this vulnerability. Current customers can download the new version from http://scadatec.co.uk/existing_users.html.

General Comments


The increased visibility of SCADA system vulnerabilities has started to produce the additional attention of security researchers that has been predicted by a number of commentators in the ICS security arena. We must assume that the portion of the Black Hat community actively interested in attacking systems has also increased their attention on industrial control systems. We should start to see apparently random attacks on such systems. Hopefully system owners will report such attacks to ICS-CERT and/or RISI.

It is interesting to see Siemens specifically decline to produce a patch or update to deal with this new vulnerability. It is good to see that the vulnerable system is disabled by default, but it is unreasonable to assume that all users will remember to re-disable the loader when they are done using it to update firmware. They are setting their customers up for failure.

Saturday, July 2, 2011

ICS-CERT Publishes 3 Advisories

Yesterday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published three new advisories for vulnerabilities identified in SCADA systems from two different vendors; Siemens and Iconics. The three advisories address vulnerabilities significantly different than the standard run of HMI vulnerabilities that we have become used to seeing.


Siemens Vulnerabilities

The Siemens advisory deals with exploitable crash vulnerabilities in the WinCC system. These vulnerabilities are not related to those Siemens vulnerabilities identified by Dillon Beresford that caused so much controversy back in May. A restricted access version of this advisory was previously published on the US-CERT site.

According to ICS-CERT this vulnerability could be exploited by a moderately skilled attacker and potentially result in execution of arbitrary code. An attacker would need to employ a social engineering vector to get a user to load a corrupted file.

Siemens has released a patch for the identified vulnerabilities.

ICONICS Vulnerabilities

Two separate advisories were published for vulnerabilities in the ICONICS GENESIS32 and BizViz systems. The first details a vulnerability in the ActiveX control that allows an arbitrary domain to be set to the trusted zone. The second describes a vulnerability in the Security Login Controls that could allow execution of arbitrary code or denial of service. The reason for the separate advisories is that these vulnerabilities are found in different version of the systems.

The trusted zone vulnerability is remotely exploitable. A moderately skilled attacker could create the website required to exploit this vulnerability. There is no known publicly available exploit of this vulnerability. An upgrade is recommended but a patch is also available on the ICONICS web site.

The login control vulnerability requires the creation of a specifically crafted password to exploit. A low skill level attacker could exploit this vulnerability to execute a denial of service attack, but more skill would be required to use the vulnerability to execute arbitrary code. Both types of exploits can be implemented remotely. Again a system upgrade is recommended but a patch is available.

ICONICS has updated their security whitepaper to reflect both of these vulnerabilities. Both patches and the white paper are available on the ICONICS web site.

Coordinated Disclosures

All three of these advisories were based upon vulnerabilities reported by the same pair of independent security researchers; Billy Rios and Terry McCorkle. ICS-CERT received the reports and coordinated their release with the vendors. The researchers have validated the patches.
 
/* Use this with templates/template-twocol.html */