Showing posts with label Sistrunk. Show all posts
Showing posts with label Sistrunk. Show all posts

Tuesday, January 14, 2014

ICS-CERT Publishes 3 Advisories

Today DHS ICS-CERT published three advisories; a unique Crain-Sistrunk DNP3 vulnerability, a mitigation effort update and an advisory from the secure portal.

Schneider Advisory

This advisory addresses an Uncontrolled Resources Consumption Vulnerability in the Schneider Electric ClearSCADA series of products. The vulnerability in the DNP3 system was reported by Crain-Sistrunk in a coordinated disclosure. Schnieder has produced a new software version that mitigates the vulnerability and Adam Crain has verified the efficacy of the fix.

ICS-CERT reports that a moderately skilled attacker could remotely exploit the vulnerability to cause DNP3Driver.exe to hang causing an interruption in the system processing. Essentially this is a denial of service (DOS) attack vector.

According to the Schneider Electric web site – they publicly disclosed this vulnerability on December 5th, 2013.

Sierra Wireless Advisory Update

This advisory update provides additional information about mitigation measures for the vulnerability reported last week. Sierra Wireless provides a vulnerability note dated January 10th suggesting that over-the-air firmware updates should not be done because “the update process, password data is transmitted to the device”. It recommends that the over-the-air programing feature be disabled.

The vulnerability note also as a recommendation for high-security applications:

“For high-security applications such as critical infrastructure monitoring, Sierra Wireless advises customers to deploy cellular devices using a Private Cellular Network or VPN to reduce the risk of an attacker capturing data transferred to/from the device.”

The pages that I reported last week did not mention that the device was discontinued now contain the following product status note: “Discontinued, still supported”.

This new information provides customers with a little more useable information than did the original advisory which essentially just said “Well we’ve discontinued the defective device, its now your problem”.

WellinTech Advisory

This advisory was originally released on the secure portal (on HSIN) last month and is now being released to the public. The advisory describes twin vulnerabilities affecting a variety of the WellinTech SCADA products. The vulnerability was reported by Andrea Micalizzi via the Zero Day Initiative (ZDI) in a coordinated disclosure. I was not able to find the ZDI listing for this vulnerability.

The twin vulnerabilities are:

• Information disclosure vulnerability, CVE-2013-2826; and
• ActiveX remote code execution vulnerability, CVE-2013-2827
NOTE: The CVE links are not yet active.


ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to either obtain system credentials or run arbitrary code in the dll. WellinTech has provided new versions of the affected software that mitigate the vulnerabilities. There is no mention of anyone verifying the efficacy of the new software versions in fixing these vulnerabilities.

Tuesday, December 3, 2013

Yet Another Crain-Sistrunk-Todorski DNP3 ICS-CERT Advisory

This afternoon the DHS ICS-CERT published an improper input validation (DNP3) advisory for the Elecsys Director Gateway application. The vulnerability was reported by Crain-Sistrunk-Todorski (newest member of the team) in a coordinated disclosure. Elecysy has developed a patch to mitigate the vulnerability and the patch has been validated by Adam Crain.

ICS-CERT reports that a moderately skilled attacker could remotely exploit the vulnerability to “to affect the availability of the DNP3 master slave communication in Elecsys Director Gateway
Devices”.

In addition to the patch, ICS-CERT notes that: “Because this vulnerability is identified with fuzzing tools, the researchers suggest developers use extensive negative testing during quality control of products.” Hmm. Adam has been saying this on his web site for about six months now; I wonder why ICS-CERT has now picked up the refrain.


BTW: Adam has not changed the count of advisories on the Robus web page. A tweet today mentioned this as a “mini advisory” so maybe this isn’t included in the count of 25 advisories that have been coordinated to-date. Or maybe Adam just got tired of counting coup; no challenge anymore.

Thursday, November 21, 2013

ICS-CERT Updates Master DNP3 Implementation Vulnerability Advisory

Just a little over a month ago ICS-CERT took the unusual step of posting a master advisory covering 9 separate advisories for essentially the same input validation vulnerability in different systems. Anyone with rudimentary prognostication skills could have predicted that when ICS-CERT published two more advisories in the series, they would be morally required to update the list of included advisories. They did that today; published the –A version and added Catapult Software and GE to the list.

There are going to be at least 14 more advisories according to the Project Robus web site and Adam Crain admits they stopped counting, so it may be 15 or more yet to come. That ‘or more’ comes from the fact that multiple vendors have used the library identified in the Triangle Microworks advisory and they may/should self-report the vulnerability after they apply the fix developed by Triangle Microworks.

Oh yes, and Crain-Sistrunk are supposed to be presenting at Digital Bond’s S4x14 and will be discussing the fuzzing technique they’ve used to identify these vulnerabilities, so who knows how many other people will start looking for, finding and reporting these vulnerabilities.


We just might get to a –AA or –BB version of this advisory yet.

Tuesday, November 19, 2013

Identical Twin ICS-CERT DNP3 Advisories Published

Today the DSH ICS-CERT published two virtually identical DNP3 advisories for twin improper input validation vulnerabilities in Catapult Software DNP3 Drivers and GE Proficy platform. The reason that they are nearly identical is because the Proficy vulnerability is due to the use of the Catapult Software drivers. Since these are familiar DNP3 vulnerabilities, it should come as no surprise that they were first reported by the team of Crain and Sistrunk. Technically, GE self-reported their vulnerability when notified of the problem by Catapult Software.

These are the same IP-based and serial-based validation vulnerabilities that we have seen before in similar Crain-Sistrunk based advisories. ICS-CERT reports that the IP-based vulnerability has a higher CVSS v2 base score (7.1 vs 4.7) but that reflects the fact that the IP-based vulnerability can be more easily exploited remotely. Many cybersecurity commentators (though certainly not all) note that physically accessing the serial connection may actually be easier at remote, low-security sites.

Catapult Software has produced updated software that mitigates both their system vulnerabilities and the Proficy vulnerabilities. The Catapult advisory does report that Crain and Sistrunk have validated the efficacy of the new software version. While that is not specifically mentioned in the GE advisory, I would assume that the same validation applies to the Proficy issues.

The Automatak web site reports these vulnerabilities as numbers 10 and 11 of the 25 vulnerable systems that they have discovered. I wonder how many of the remaining 14 are also based upon either the Catapult system or the earlier Triangle Microworks library. Both have obviously been made available (sold) to other vendors. Of course, it is also possible that Crain and Sistrunk have not yet found all of the system vulnerabilities since they have apparently stopped looking for these vulnerabilities; no challenge left I suppose.

Hopefully, any unidentified DNP3 vendors will take the leads posted by these two and self-correct and self-report their problems without being identified by Project Robus.

NOTE: A quick update from an Adam Crain Tweet® - None of the remaining vulns are catapult related. Should probably read 11/26 now, but we've kinda stopped counting.

 
/* Use this with templates/template-twocol.html */