Showing posts with label Sinapsi. Show all posts
Showing posts with label Sinapsi. Show all posts

Tuesday, June 9, 2015

ICS-CERT Publishes Two Advisories

Today the DHS ICS-CERT published two new control system advisories for systems from Sinapsi and N-Tron.

Sinapsi Advisory

This advisory describes a plain text password vulnerability in the Sinapsi eSolar Light application. The vulnerability was disclosed by Maxim Rupp. Sinapsi had produced a new version that mitigates the vulnerability but there is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker with local system access could exploit this vulnerability to gain system passwords.

ICS-CERT reports that the updated version is available by contacting Sinapsi on their web site. ICS-CERT does not provide a link to the web site.

Interestingly an earlier ICS-CERT alert for separate Sinapsi eSolar Light vulnerabilities indicates that this product had also been sold under the names Enerpoint eSolar Light, Schneider Electric Ezylog Photovoltaic Management Server, Gavazzi Eos-Box, and Astrid Green Power Guardian. I suspect that at least some versions of those products might be affected by this vulnerability as well.

N-Tron Advisory

This advisory describes a hard-coded encryption key vulnerability in the N-Tron 702-W Industrial Wireless Access Point device. The vulnerability was reported to ICS-CERT by Neil Smith of ZeroFox. ICS-CERT reports that:


“N-Tron has been notified of this reported vulnerability, and NCCIC/ICS‑CERT has not been able to successfully coordinate this issue with N-Tron or Red Lion because of the vendor’s unresponsiveness. ICS-CERT is unaware of any fix, patch, or update by N-Tron that mitigates this vulnerability. This advisory is being published to inform critical infrastructure asset owners of the risk of using this equipment and for them to increase compensating measures if possible.”

Friday, November 23, 2012

ICS-CERT Publishes Sinapsi eSolar Advisory


Earlier this week the DHS ICS-CERT folks published a follow-up advisory to an earlier alert about multiple vulnerabilities in the Sinapsi eSolar family of devices. The original uncoordinated disclosure was made by Roberto Paleari and Ivan Speziale.

Multiple Vulnerabilities


Four vulnerabilities have been identified and confirmed by the vendor. They are:

• Hard-coded credentials – CVE-2012-5862;

• SQL injection - CVE-2012-5861;

Operating system command injection – CVE-2012-5863; and

Broken session enforcement – CVE-2012-5864

Note: the CVE links are not yet active as of 11-23-12 06:00 EST; they will be in the near future.

A relatively unskilled attacker could use the publicly available exploit code to remotely attack the affected systems. Depending on the vulnerability exploited arbitrary code could be executed or confidentiality could be compromised

Mitigation


Sinapsi has new firmware for the affected devices and it is available via the system menu in the devices Web interface, so these devices are specifically designed to face the internet contrary to the ICS-CERT recommendation made in this advisory (actually in all ICS-CERT publications).

The advisory also notes that: “Sinapsi released the new firmware on Monday, November 19, 2012 directly to the devices.” This implies (I’m being generous) that Sinapsi has designed these devices to specifically be remotely reconfigured by someone other than the owner without the owner’s consent or knowledge.

Device security certainly does not seem to be a matter of concern with this vendor. In fact, this vendor seems to have taken ‘insecure by design’ to a new level; designed to be insecure. Why bother with these patches?

Multiple Vendors


It is only in the Mitigation section of this advisory that we learn that these vulnerabilities may affect devices from other vendors. The advisory would not be expected to list these vendors until they confirm that they have addressed the vulnerabilities. The original alert listed:

• Enerpoint eSolar Light;

• Schneider Electric Ezylog Photovoltaic Management Server;

• Gavazzi Eos-Box; and

• Astrid Green Power Guardian

Actually, the original exploit was developed for the Schneider device.

Wednesday, October 10, 2012

ICS-CERT Publishes Sinapsi Alert


This afternoon the DHS ICS-CERT published an alert on an uncoordinated disclosure of multiple vulnerabilities in the Sinapsi eSolar Light Photovoltaic System Monitor. The disclosure was made by Roberto Paleari and Ivan Speziale, who described the vulnerable system as being  the Schneider Electric Ezylog photovoltaic SCADA management server. ICS-CERT notes that the Italian company produces the system that is used by multiple vendors including Schneider Electric.

The multiple vulnerabilities reported were:

• Hard-coded Credentials

• SQL Injection

• Command Execution

• Broken Session Enforcement

Tomorrow’s ICS-CERT Alerts?


Joel Langill reports on his SCADAHacker Blog that Gleg has released SCADA+ Exploit Pack V 1.18 that includes 0-day exploits for three separate SCADA systems; Elipse E3, Carel PlantVisor, and QNX FTPD. Joel has a brief synopsis of the vulnerabilities. I would expect for ICS-CERT to address these vulnerabilities tomorrow. I suspect that these may be advisories instead of alerts; there were some TWEETS® sometime last month about Gleg related releases on the secure US CERT server.
 
/* Use this with templates/template-twocol.html */