Showing posts with label SpiderControl. Show all posts
Showing posts with label SpiderControl. Show all posts

Thursday, June 22, 2023

Review – 2 Advisories and 2 Updates Published – 6-22-23

Today, CISA’s NCCIC-ICS published two control system security advisories for products from SpiderControl and Advantech. They also updated two advisories for products from Mitsubishi and Econolite.

Advisories

SpiderControl Advisory - This advisory describes a path traversal vulnerability in the SpiderControl SCADA Webserver.

Advantech Advisory - This advisory describes two vulnerabilities in the Advantech R-SeeNet server monitors.

Updates

Mitsubishi Update - This update provides additional information on an advisory that was originally published on March 2nd, 2023.

Econolite Update - This update provides additional information on an advisory that was originally published on January 26th, 2023.

 

For more details on these advisories, including a discussion about a missing advisory number, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-2-updates-published-c3d - subscription required.

Thursday, December 6, 2018

Two Advisories Published – 12-04-18


Earlier this week the DHS NCCIC-ICS published two control system security advisories for products from SpiderControl and Omron.

SpiderControl Advisory


This advisory describes a cross-site scripting vulnerability in the SpiderControl SCADA WebServer. The vulnerability was reported by Ismail Bulbul. SpiderControl has a new version that mitigates the vulnerability. There is no indication that Bulbul has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to execute JavaScript on the victim’s browser.

Omron Advisory


This advisory describes two vulnerabilities in the Omron CX-One application. The vulnerability was reported by Esteban Ruiz (mr_me) of Source Incite via the Zero Day Initiative. Omron has an update that mitigates the vulnerability. There are no indications that Ruiz has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-18993; and
Use after free - CVE-2018-18989

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to execute code under the privileges of the application.

ODD NOTE: This post was actually written on Tuesday night and I was sure that it had been posted, but it is surely not on the blog. I guess I am getting senile in my middle age.


Saturday, November 4, 2017

Public ICS Disclosure – Week of 10-29-17

This week Karn Ganeshen provided proof of concept (POC) information on three previously published ICS-CERT vulnerabilities and Joel Langill provided a link to an ABB KRACK advisory.

POC Information


Karn continues to use the FullDisclosure web site to provide to provide additional information about control system vulnerabilities that he has previously disclosed through the DHS ICS-CERT. This week he has provided POC information on the following control system vulnerabilities:

Progea Movicon SCADA/HMI – earlier reported here (there was no mention of publicly available POC in the ICS-CERT advisory);
JanTek JTC-200 – earlier reported here (publicly available POC was mentioned in ICS-CERT advisory); and
SpiderControl SCADA Web Server – earlier reported here (there was no mention of publicly available POC in the ICS-CERT advisory)

Based upon past experience, I do not expect ICS-CERT to update their vulnerability reports to reflect the fact that POC information is now available. Given the fact that ICS-CERT has reported that relatively low skilled attackers could exploit these vulnerabilities, I think that it is important that owners of these systems has this information available to help them appropriately assess the risks to their systems.

KRACK Vulnerability


Joel’s post on LinkedIn pointed at a cybersecurity advisory from ABB for their  ABB TropOS wireless mesh products concerning the WPA2 Key Reinstallation Vulnerabilities (also known as the Key Reinstallation Attack – KRACK).

As I pointed out in the resulting LinkedIn conversation this is the second vendor specific advisory on the KRACK vulnerability. Unlike the earlier report, ABB includes 7 of the 10 CVE found in the KRACK report, indicating that they have probably reviewed all 10 of the vulnerabilities in their system.


I continue to be disappointed in ICS-CERT for not having published a control system alert for the KRACK problem since these vulnerabilities will affect almost all ICS products that use WPA2 security for wireless communications in their control system products.

Thursday, October 19, 2017

ICS-CERT Publishes 2 Advisories and 1 Update

Today the DHS ICS-CERT published one medical control system security advisory for a product from Boston Scientific. Additionally, they published an industrial control system advisory for a product from SpiderControl. They also updated a medical control system advisory for a product from Becton, Dickinson and Company.

Boston Scientific Advisory


This advisory describes two vulnerabilities for the Boston Scientific ZOOM LATITUDE Programmer/Recorder/Monitor (PRM). The vulnerabilities were reported by Jonathan Butts and Billy Rios of Whitescope. Boston Scientific has provided mitigating controls. ICS-CERT reports that Boston Scientific will not be fixing the vulnerabilities.

The two reported vulnerabilities are:

• Use of hard-coded cryptographic key - CVE-2017-14014; and
• Missing encryption of sensitive data - CVE-2017-14012

ICS-CERT reports that an uncharacterized attacker with physical access to the device could exploit these vulnerabilities to obtain patient health information (PHI).

SpiderControl Advisory


This advisory describes an uncontrolled search path element vulnerability in the SpiderControl MicroBrowser, a touch panel operating system. The vulnerability was reported by Karn Ganeshen. SpiderControl has provided a new version that mitigates the vulnerability. There is no indication that Ganeshen has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to execute arbitrary code on the target system.

BD Update


This update provides additional information on an advisory that was originally published on February 7th, 2017. The updated information includes:

• The identification of “Researchers at Zingbox” as being involved in the reporting of the vulnerabilities;
• The expansion of the impact statement to include the ability to “compromise the confidentiality, integrity, and availability of the device”;
• The information that an internal removeable flash drive which in some versions provides access to “wireless network authentication credentials and other sensitive technical data on the affected device’s removable flash memories”;
• Updated mitigation measures; and

• A link to the updated BD security bulletin [.PDF download] which provides additional details on the information accessible due to the reported vulnerabilities

Thursday, September 7, 2017

ICS-CERT Publishes 4 Advisories

Today the DHS ICS-CERT published two medical device security advisories for products from Smiths Medical and i-SENS. They also published to control system security advisories for products from PHOENIX CONTACT and SpiderControl.

Smiths Medical Advisory


This advisory describes eight vulnerabilities in the Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump. The vulnerabilities were reported by Scott Gayou. Smiths Medical is developing a new product version to mitigate the vulnerabilities; compensating controls have been developed.

The eight reported vulnerabilities are:

• Buffer copy without checking size of input - CVE-2017-12718;
• Out-of-bounds read - CVE-2017-12722;
• Use of hard-coded credentials - CVE-2017-12725, CVE-2017-12724;
• Improper access control - CVE-2017-12720;
• Use of hard-coded password - CVE-2017-12726;
• Improper certificate validation - CVE-2017-12721; and
• Password in configuration file - CVE-2017-12723

ICS-CERT reports that an uncharacterized attacker could remotely exploit the vulnerabilities to gain unauthorized access and impact the intended operation of the pump. Despite the segmented design, it may be possible for an attacker to compromise the communications module and the therapeutic module of the pump.

No FDA safety communication has been released on these vulnerabilities.

i-SENS Advisory


This advisory describes an uncontrolled search path element vulnerability in the i-SENS SmartLog Diabetes Management Software. The vulnerability was reported by Mark Cross. i-SENS has produced a new version that mitigates the vulnerability. ICS-CERT reports that Cross has been provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that an authorized user with local access could exploit the vulnerability to execute arbitrary code on the target system.

PHOENIX CONTACT Advisory


This advisory describes a null pointer deference vulnerability in the PHOENIX CONTACT mGuard firmware. This vulnerability was self-reported. PHOENIX CONTACT has produced a firmware version that mitigates the vulnerability.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to cause a remote denial of service and force a restart of all IPSec connections.

SpiderControl Advisory


This advisory describes an improper privilege management vulnerability in the SpiderControl SCADA Web Server. The vulnerability was reported by Karn Ganeshen. SpiderControl has produced a new version that mitigates the vulnerability. There is no indication that Ganeshen has been provided an opportunity to verify the efficacy of the fix.


ICS-CERT reports that a relatively low skilled attacker with authorized access could exploit the vulnerability to escalate their privileges under certain conditions.

Tuesday, August 22, 2017

ICS-CERT Publishes 3 Advisories

Today the DHS ICS-CERT published three control system security advisories for products from SpiderControl (2) and Automated Logic Corporation.

SCADA Web Server Advisory 


This advisory describes a path traversal vulnerability in the SpiderControl SCADA Web Server. The vulnerability was reported by Karn Ganeshen via the Zero Day Initiative (ZDI). SpiderControl has produced a new version that mitigates the vulnerability. There is no indication that Ganeshen has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to gain read access to system files through directory traversal.

SCADA MicroBrowser Advisory


This advisory describes a stack-based buffer overflow vulnerability in the SpiderControl SCADA MicroBrowser. The vulnerability was reported by Karn Ganeshen via ZDI. SpiderControl has produced a new version that mitigates the vulnerability. There is no indication that Ganeshen has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to gain access to the system, manipulate system files, and potentially render the system unavailable.

Automated Logic Advisory


This advisory describes three vulnerabilities in the ALC WebCTRL, i-Vu, and SiteScan Web. The vulnerabilities were reported by Gjoko Krstic from Zero Science Lab. ALC has produced patches that mitigate the vulnerabilities. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Unquoted search path or element - CVE-2017-9644;
• Path traversal - CVE-2017-9640; and
• Unrestricted upload of file with dangerous type - CVE-2017-9650


ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerabilities to elevate his or her privileges to execute arbitrary code on the system.
 
/* Use this with templates/template-twocol.html */