Showing posts with label Steven Seeley. Show all posts
Showing posts with label Steven Seeley. Show all posts

Saturday, June 20, 2020

Public ICS Disclosures – Week of 6-13-20


This week we have eight vendor disclosures (3 for the Ripple20 vulnerabilities) for products from Beckhoff, Moxa, Medtronic, GE Health, Draeger (2), Rockwell, and BD. There is also a researcher report of a zero-day for products from Inductive Automation.

Ripple20 Advisories


Medtronic published a Ripple20 advisory reporting no impact.

GE Healthcare published a Ripple20 advisory reporting no impact but advising that there may be possible impact to third party components used in combination with GE Healthcare products.

Draeger published a Ripple 20 advisory reporting no impact.

NOTE: “No impact” reports are valuable information. I think the GE nuanced ‘no impact’ report is important where the vendor software may be running on a machine that includes other non-vendor produced software (perhaps including OS?).

Beckhoff Advisory


CERT-VDE published an advisory describing an information leak vulnerability in the Beckhoff TwinCAT RT network driver. The vulnerability is self-reported. Beckhoff has patches that mitigate the vulnerability.

Moxa Advisory


Moxa published an advisory describing a stack-based buffer overflow vulnerability in their EDR-G902 Series and EDR-G903 Series Secure Routers. The vulnerability was reported by Tal Keren from Claroty. Moxa has new firmware to mitigate the vulnerability. There is no indication that Keren has been provided an opportunity to verify the efficacy of the fix.

Draeger Advisory


Draeger published an advisory describing an improper input validation vulnerability in their Perseus A500 product. The vulnerability is self-reported. Draeger has new software that mitigates the vulnerability.

Rockwell Vulnerability


Rockwell published an advisory describing a path traversal advisory in their FactoryTalk Linx software. This vulnerability was discovered in the ZDI Pwn2Own competition in this year’s S4 Security conference. Rockwell has a patch that mitigates the vulnerability.

NOTE: Rockwell reports that they had previously disclosed this vulnerability in an advisory that was published on June 11th, 2020. I suppose that the Pwn2Own announcement could have been included as an update to that advisory. This may be why NCCIC-ICS has not picked up this advisory.

BD Advisory


BD published an advisory describing a remote code execution vulnerability in a number of BD products that use the Microsoft Windows 10®. This is a third-party (MS) SMBv3 server vulnerability. BD is currently working to test and validate the Microsoft patch on the affected products.

Inductive Automation Advisory


The Zero Day Initiative published an advisory describing a deserialization of untrusted data information disclosure vulnerability in the Inductive Automation Ignition product. The vulnerability was reported by Chris Anastasio (muffin) and Steven Seeley (mr_me) of Incite Team. This vulnerability was discovered in the ZDI Pwn2Own competition in this year’s S4 Security conference and reported to the vendor. The vendor has not been able to provide an estimated fix date to either ZDI or NCCIC-ICS. This is effectively a zero-day vulnerability.

Tuesday, May 26, 2020

2 Advisories Published – 5-26-20

Today the NCCIC-ICS published two control system security advisories for products from Johnson Controls and Inductive Automation.

Johnson Controls Advisory


This advisory describes an improper access control vulnerability in the Johnson Controls Kantech EntraPass software. This vulnerability is self-reported. Johnson Controls has a new version that mitigates the vulnerability.

NCCIC-ICS reports that an relatively low-skilled attacker with uncharacterized access to allow an authorized low-privileged user to gain full system-level privileges.

Inductive Automation Advisory


This advisory describes three vulnerabilities in the Inductive Automation Ignition. The vulnerabilities were reported by Pedro Ribeiro, Radek Domanski, Chris Anastasio (muffin), and Steven Seeley via the Zero Day Initiative. Inductive Automation has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Missing authentication for critical function - CVE-2020-12004, and
• Deserialization of untrusted data (2) - CVE-2020-10644 and CVE-2020-12000

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to obtain sensitive information and perform remote code execution with SYSTEM privileges.

Thursday, May 21, 2020

2 Advisories Published – 5-21-20


Today the CISA NCCIC-ICS published two control system security advisories for products from Schneider Electric and Johnson Controls.

Schneider Advisory


This advisory describes five vulnerabilities in the Schneider EcoStruxure Operator Terminal Expert. The vulnerabilities were reported by Sharon Brizinov and Amir Preminger of Claroty Research (via the Zero Day Initiative), Steven Seeley and Chris Anastasio of Incite Team (via ZDI), and Fredrik Østrem, Emil Sandstø, and Cim Stordal of Cognite. Schneider has an update that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• SQL Injection - CVE-2020-7493,
• Path traversal (3) - CVE-2020-7494, CVE-2020-7495 and CVE-2020-7497, and
• Argument injection - CVE-2020-7496

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could use publicly available code to exploit the vulnerabilities to allow unauthorized write access or remote code execution.

NOTE: I briefly discussed these vulnerabilities last Saturday.

Johnson Controls Advisory


This advisory describes a cleartext storage of sensitive information vulnerability in Sensormatic Electronics (subsidiary of Johnson Controls) video management systems. The vulnerability is self-reported. Johnson Controls has new versions that mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to access credentials used for access to the application.

Saturday, May 16, 2020

Public ICS Disclosures – Week of 5-9-20


This week we have five vendor disclosures for products from Schneider (4) and Rockwell as well as six vendor updates from Schneider (5) and Siemens. We also have two researcher reports of vulnerabilities in products from Advantech.

Schneider Advisories


Schneider published an advisory describing a weak password requirement vulnerability in their Pro-face GP-Pro EX Programming Software product. The vulnerability was reported by Kirill Kruglov of Kaspersky Labs. Schneider has a new version that mitigates the vulnerability. There is no indication that Krublov has been provided an opportunity to verify the efficacy of the fix.


Schneider published an advisory describing a use of hard-coded credentials vulnerability in their Vijeo Designer Basic and Vijeo Designer software products. The vulnerability was reported by Jie Chen of NSFOCUS. Schneider has a HotFix available to mitigate the vulnerability. There is no indication that Jie has been provided an opportunity to verify the efficacy of the fix.


Schneider published an advisory describing two vulnerabilities in their U.motion servers and touch panel products. The vulnerabilities were reported by Rgod and Zhu Jiaqi. Schneider has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper access control - CVE-2020-7499, and
• SQL injection - CVE-2020-7500


Schneider published an advisory describing five vulnerabilities in their EcoStruxure™ Operator Terminal Expert product. The vulnerabilities were reported by Steven Seeley and Chris Anastasio of Incite Team, Sharon Brizinov and Amir Preminger of Claroty Research via the Zero Day Initiative (see here, here, and here), and Fredrik Østrem, Emil Sandstø, and Cim Stordal of Cognite. Schneider has a new version that mitigates four of the five vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• SQL command injection - CVE-2020-7493,
• Path traversal (3) - CVE-2020-7494, CVE-2020-7495, and CVE-2020-7497, and
• Argument injection or modification - CVE-2020-7496

Rockwell Advisory


Rockwell published an advisory describing five vulnerabilities in multiple Rockwell Automation software products. These are third-party vulnerabilities from OSIsoft components used in the Rockwell products. These vulnerabilities are self-identified. Rockwell provides workarounds to mitigate the vulnerabilities.

The five reported vulnerabilities are:

• Local privilege escalation via uncontrolled search path element - CVE-2020-10610,
• Local privilege escalation via improper verification of cryptographic key - CVE-2020-10608,
• Local privilege escalation via incorrect default permissions - CVE-2020-10606,
• Null pointer dereference - CVE-2020-10600, and
• Use of out-of-range pointer offset may lead to remote code execution - CVE-2020-10645

NOTE: These are five of the ten vulnerabilities in the OSIsoft PI System that were reported by NCCIC-ICS earlier this week. The fact that this Rockwell Advisory was published on the same day as the NCCIC-ICS advisory indicates that there was pre-disclosure coordination between OSIsoft and Rockwell, good show.

Advantech Advisories


The Zero Day Initiative published advisories (see links below) describing two vulnerabilities in Advantech WebAccess Node. ZDI published the two advisories as 0-day notifications under their 120-day response rule. NCCIC-ICS was reported involved in the coordination of these vulnerabilities. The vulnerabilities were reported by Z0mb1E.

The two reported vulnerabilities are:

• DATACORE Stack-based Buffer Overflow Remote Code Execution Vulnerability - ZDI-20-654, and
• Incorrect Permission Assignment Privilege Escalation Vulnerability - ZDI-20-655

Schneider Updates


Schneider published an update for the Urgent/11 advisory that was originally published on August 11th, 2019 and most recently updated on April 14th, 2020. The new information includes updated mitigation information for:

• Modicon Network Option Switch,
• Modicon X80 - I/O Drop Adapters,
• Modicon Quantum 140 CRA,
• Modicon Quantum Head 140 CRP,
• Modicon Quantum Ethernet DIO network module - 140NOC78x00 (C),
• SCD6000 Industrial RTU, and
• Pro-face HMI -GP4000H/R/E Series


Schneider published an update for their Andover Continuum System advisory that was originally published on March 10th, 2020 and most recently updated on April 14th, 2020. The new information includes minor updates to overview, vulnerability details, and product information for clarification.


Schneider published an update for their Embedded Web Servers for Modicon advisory that was originally published in November 2018 and most recently updated November 27th, 2019. The new information includes a corrected CVSS vector for CVE-2018-7812.


Schneider published an update for their Modicon Controllers advisory that was originally published on May 14th, 2019 and most recently updated on December 10th, 2019. The new information includes updated fix version information for CVE-2018-7857.


Schneider published an update for their Legacy Triconex advisory that was originally published on April 14th, 2020. Unfortunately, the link on the Schneider web site takes one to the original version of the advisory.

Siemens Update


Siemens published an update for their GNU/Linux advisory that was originally published on November 27th, 2018 and most recently updated on April 14th, 2020. The new information includes the addition of the following CVE’s:

• CVE-2019-9674,
• CVE-2019-18348,
• CVE-2019-20636,
• CVE-2020-8492,
• CVE-2020-11565,
• CVE-2020-11655, and
• CVE-2020-11656

Saturday, April 18, 2020

Public ICS Disclosures – Week of 04-11-20


This week we have five vendor disclosures for products from Schneider (4) and OPC Foundation. We also have nine updated advisories for products from Schneider (4) and Siemens (5).

Schneider Advisories


Schneider published an advisory describing an injection vulnerability in their Modicon M100/M200/M221 controllers, SoMachine Basic and EcoStruxure Machine Expert - Basic products. The vulnerability was reported by Seok Min Lim and Johnny Pan of Trustwave. Schneider has updated software and firmware that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.


Schneider published an advisory describing two vulnerabilities in their Modicon M218/M241/M251/M258 Logic Controllers, SoMachine & SoMachine Motion, and EcoStruxure Machine Expert products. The vulnerabilities were reported by Rongkuan Ma, Shunkai Zhu and Peng Cheng of 307Lab. Schneider has new versions to mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Insufficient verification of data authenticity - CVE-2020-7487; and
• Clear-text transmission of sensitive data - CVE-2020-7488



Schneider published an advisory describing an untrusted search path vulnerability in their Vijeo Designer and Vijeo Designer Basic Software products. The vulnerability was reported by Yongjun Liu of nsfocus. Schneider has a new version that mitigates the vulnerability. There is no indication that Yongjun has been provided an opportunity to verify the efficacy of the fix.


Schneider published an advisory describing four vulnerabilities in their legacy Triconex product. These vulnerabilities are self-reported. Schneider reports that newer versions corrected the vulnerabilities.

The four reported vulnerabilities are:

• Password vulnerability (2) - CVE-2020-7483 and CVE-2020-7484;
• Improper access - CVE-2020-7485; and
• Denial of service - CVE-2020-7486

OPC Foundation Advisory


OPC published an advisory describing an malformed message vulnerability in their UA .NET Standard Stack. The vulnerability was reported by Steven Seeley (mr_me) and Chris Anastasio (muffin) via the Zero Day Initiative. OPC has updates available that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Schneider Updates


Schneider has published an update for their Urgent/11 advisory that was originally published on August 2nd, 2019 and most recently updated on March 11th, 2020. The new information includes updated mitigation information for:

• ION7400 MID; and
• PM8000 MID


Schneider has published an update for their Modicon Controllers advisory that was originally published on November 12th, 2019. The new information includes the addition of a new hard-coded credentials vulnerability - CVE-2019-6859.


Schneider has published an update for their Andover Continuum advisory that was originally published on March 10th, 2020. The updated information includes an explanation that the code injection vulnerability is a third-party MS-XML library vulnerability.


Schneider has published an update for their Modicon Controllers advisory that was originally published on December 10th, 2019. The updated information includes:

• Adding Modicon M340 and M580 to affected product list;
• Adding a hotfix link and adding further details to the mitigation measures;
• Adding updated firmware links; and
• Adding Enrique Murias Fernández of Tecdesoft Automation to the acknowledgements.

Siemens Updates


Siemens published an update for an advisory for Intel CPUs that was originally published on February 11th, 2020 and most recently updated on March 10th, 2020. The new information includes updated version information and mitigation links for SIMATIC ET 200SP Open Controller CPU 1515SP PC2.


Siemens published an update for an advisory for Industrial Products that was originally published on January 14th, 2020. The new information includes explicitly mentioning old versions of SIMATIC NET.


Siemens published an update for their GNU/Linux subsystem vulnerabilities advisory that was originally published on November 27th, 2018 and most recently updated on February 11th, 2020. The new information includes adding the following new vulnerabilities:

• CVE-2015-5895;
• CVE-2019-19447;
• CVE-2019-19603;
• CVE-2019-19645,
• CVE-2019-19646;
• CVE-2019-19880;
• CVE-2019-19923;
• CVE-2019-19924;
• CVE-2019-19925;
• CVE-2019-19926;
• CVE-2019-19959;
• CVE-2019-20218;
• CVE-2020-8428;
• CVE-2020-8492;
• CVE-2020-9327;
• CVE-2020-10029; and
• CVE-2020-10942


Siemens published an update for their SIMATIC advisory that was originally published on July 30th, 2012. The new information includes adding SIPLUS devices to the list of affected devices.

NOTE: ICS-CERT published advisory ICSA-12-212-02 covering this vulnerability, but has not yet updated (and may not update) that advisory.


Siemens published an update for their SIMATIC advisory that was originally published on July 30th, 2012. The new information includes adding SIPLUS devices to the list of affected devices.

NOTE: This advisory was lumped into the ICS-CERT advisory described above.

Wednesday, April 15, 2020

9 Advisories and 5 Updates – 4-14-20


Yesterday the CISA NCCIC-ICS published nine control system security advisories for products from Siemens (6), Triangle MicroWorks (2) and Eaton. They also published updates for five advisories for products from Siemens.

TIM Advisory


This advisory describes an active debug code vulnerability in the Siemens TIM communication modules. This vulnerability was self-reported. Siemens has new versions that mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an unauthenticated attacker with network access to gain full control over the device.

KTK Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the Siemens KTK, SIDOOR, SIMATIC, and SINAMICS products. This vulnerability is self-reported. Siemens has updates available to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to create a denial-of-service condition.

NOTE: This is the third-party, Interniche OS, SegmentSmack vulnerability.

SCALANCE Advisory


This advisory describes a resource exhaustion vulnerability in the Siemens SCALANCE and SIMATIC products. This vulnerability is self-reported. Siemens provided generic work arounds while they continue to work on mitigation measures.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to create a denial-of-service condition.

NOTE: This is the third-party, VX Works OS, SegmentSmack vulnerability.

SIMOTICS Advisory


This advisory describes a business logic error vulnerability in the Siemens SIMOTICS, Desigo, APOGEE, and TALON products. The vulnerability was self-reported. Siemens provided generic workarounds.

NCCIC-ICS reports that a relatively low-skilled attacker on an adjacent network could exploit this vulnerability to allow an attacker to affect the availability and integrity of the device.

Industrial Devices Advisory


This advisory describes two vulnerabilities in the Siemens IE/PB-Link, RUGGEDCOM, SCALANCE, SIMATIC and SINEMA products. The vulnerabilities are self-reported. Siemens has updates that mitigate the vulnerabilities.

The two reported vulnerabilities are:

• Resource exhaustion - CVE-2018-5390; and
• Improper input validation - CVE-2018-5391

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to  to affect the availability of the devices under certain conditions.

NOTE: This is the third-party, Linux OS, SegmentSmack vulnerability.

Climatix Advisory


This advisory describes two vulnerabilities in the Siemens Climatix product line. The vulnerability was reported by Ezequiel Fernandez from Dreamlab Technologies. Siemens has provided generic workarounds.

The two reported vulnerabilities are:

• Cross-site scripting - CVE-2020-7574; and
• Basic XSS - CVE-2020-7575

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow a remote attacker to execute arbitrary code to access confidential information without authentication.

TMW SCADA Advisory


This advisory describes three vulnerabilities in the Triangle Microworks (TMW) SCADA Data Gateway. The vulnerabilities were reported by Incite Team of Steven Seeley and Chris Anastasio, and Tobias Scharnowski, Niklas Breitfeld, and Ali Abbasi via the Zero Day Initiative. TMW has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2020-10615;
• Out-of-bounds read - CVE-2020-10613; and
• Type confusion - CVE-2020-10611

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to execute arbitrary code and disclose on affected installations of Triangle Microworks SCADA Data Gateway with DNP3 Outstation channels. Authentication is not required to exploit these vulnerabilities.

TMW DNP3 Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Triangle Microworks DNP3 Outstation Libraries. The vulnerability was reported by Incite Team of Steven Seeley and Chris Anastasio via ZDI. TMW has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to stop the execution of code on affected equipment.

Eaton Advisory


This advisory describes two vulnerabilities in the Eaton HMiSoft VU3. The vulnerabilities were reported by Natnael Samson (@NattiSamson) via ZDI. The HMiSoft VU3 has reached end-of-life and is no longer supported by Eaton.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2020-10639; and
• Out-of-bounds read - CVE-2020-10637

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to crash the device being accessed and may allow remote code execution or information disclosure.

Industrial Products Update


This update provides additional information for an advisory that was originally published on September 10th, 2019 and most recently updated on March 10th, 2020. The new information includes updated version information and mitigation links for ROX II.

PROFINET Update


This update provides additional information for an advisory that was originally published on October 10th, 2019 and most recently updated on March 10th, 2020. The new information includes updated version information and mitigation links for SIMATIC ET200MP IM155-5 PN HF.

TIA Portal Update


This update provides additional information for an advisory that was originally published on January 14th, 2020. The new information includes updated version information and mitigation links for TIA Portal V16.

SIMATIC PCS 7 Update


This update provides additional information for an advisory that was originally published on February 11th, 2020 and most recently updated on March 10th, 2020. The new information includes updated version information and mitigation links for SIMATIC WinCC (TIA Portal) V16.

SIMATIC S7 Update


This update provides additional information for an advisory that was originally published on February 11th, 2020 and most recently updated on March 10th, 2020. The new information includes adding SIMATIC WinAC RTX to the list of affected products.

Other Siemens Updates


Siemens also updated five other advisories yesterday. I expect that NCCIC-ICS will address at least two of these, probably later this week.

Wednesday, September 12, 2018

ICS-CERT Publishes 5 Advisories and 4 Updates


Yesterday the DHS ICS-CERT published five control system security advisories for products from Siemens (3) and Fuji electric (2). They also updated three previously published advisories for products from Siemens and the Meltdown/Spectre alert.

SCALANCE Advisory


This advisory describes an improper input validation vulnerability in the Siemens SCALANCE X Switches. The vulnerability is being self-reported. Siemens has updates available for two of the three affected products and has identified mitigation measures.

ICS-CERT reports that a relatively low-skilled attacker could use publicly available exploits to remotely exploit the vulnerability to cause a denial-of-service condition.

SIMATIC Advisory


This advisory describes an improper access control vulnerability in the Siemens SIMATIC WinCC OA HMI. The vulnerability is being self-reported. Siemens has an update available to mitigate the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to escalate their privileges in the context of the program.

TD Keypad Designer Advisory


This advisory describes an unprotected search path element vulnerability in the Siemens TD Keypad Designer. The vulnerability is being self-reported. Siemens has identified generic mitigation measures for the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker with local access could exploit the vulnerability  to escalate their privileges.

V-Server Lite Advisory


This advisory describes a classic buffer overflow vulnerability in the Fuji V-Server Lite. The vulnerability was reported by Ariele Caltabiano (kimiya) via the Zero Day Initiative (ZDI). Fuji has a firmware update available to mitigate the vulnerability. There is no indication that Caltabiano has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to view sensitive information and disrupt the availability of the device.

V-Server Advisory


This advisory describes seven vulnerabilities in the Fuji V-Server. The vulnerabilities were reported by Steven Seeley (mr_me) of Source Incite via ZDI. Fuji has a new software version that mitigates the vulnerabilities. There is no indication that Seeley has been provided an opportunity to verify the efficacy of the fix.

The seven reported vulnerabilities are:

• Use after free - CVE-2018-14809;
• Untrusted pointer dereference - CVE-2018-14811;
• Heap-based buffer overflow - CVE-2018-14813;
• Out-of-bounds write - CVE-2018-14815;
• Integer underflow- CVE-2018-14817;
• Out-of-bounds read - CVE-2018-14819; and
Stack-based buffer overflow - CVE-2018-14823

ICS-CERT reports that a relatively low-skilled attacker could use publicly available exploits to remotely exploit the vulnerabilities to allow for remote code execution on the device, causing a denial of service condition or information exposure.

Industrial Products Update


This update provides new information on an advisory that originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th, November 28th, February 27th, 2018, May 3rd, 2018 and most recently on May 15th, 2018. The new information includes revised affected versions data and mitigation measures for:

• SINAMICS DCP w. PN; and
• SINAMICS DCM w. PN

SIMATIC Update


This update provides new information on an advisory that was originally published on May 17th, 2018. The new information includes additional mitigation measures that can be used.

OpenSSL Update


This update provides new information on an advisory that was originally published on August 14th, 2018. The new information includes revised affected versions data and mitigation measures for WinCC OA.

Meltdown/Spectre Update


This update provides new information on an alert that was originally published on January 11th, 2018 and updated on January 16th, 2018, January 17th, 2018, January 30th, 2018, February 20th, 2018, February 22nd, 2018, March 1st, 2018, and most recently on July 10th, 2018. The new information includes a link to a new Meltdown/Spectre advisory from Siemens.

Note: While this newly added advisory from Siemens and another Siemens advisory on the older versions of Meltdown/Spectre address newer versions of the vulnerability, ICS-CERT has failed to provide any information (or links to information) about these new problems.

Tuesday, May 15, 2018

ICS-CERT Publishes Advantech Advisory and Updates Siemens Advisory


Today the DHS ICS-CERT published a control system security advisory for products from Advantech. They also updated a previously issued advisory for products from Siemens.

Advantech Advisory


This advisory describes eleven vulnerabilities in the Advantech WebAccess products. The vulnerabilities were reported by Mat Powell and rgod, working with ZDI; Steven Seeley of Offensive Security, working with ZDI; and Donato Onofri and Simone Onofri of Business Integration Partners S.p.A. Advantech released a new version that mitigates the vulnerabilities. There is no indication that any of the researchers were provided an opportunity to verify the efficacy of the fix.

The eleven reported vulnerabilities are:

• SQL injection - CVE-2018-7501;
• Information exposure through directory listing - CVE-2018-10590;
• Improper authorization - CVE-2018-7505;
• Path traversal (2) - CVE-2018-7503, and CVE-2018-10589;
• Stack-based buffer overflow - CVE-2018-7499;
• Heap-based buffer overflow - CVE-2018-8845;
• Untrusted pointer dereference - CVE-2018-7497;
• External control of file name or path - CVE-2018-7495;
• Origin validation error - CVE-2018-10591; and
Improper privilege management - CVE-2018-8841

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilitie to disclose sensitive information from the host and/or target, execute arbitrary code, or delete files.

Siemens Update


This update provides additional information for an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th, November 28th, February 27th, 2018 and most recently on May 3rd, 2018. The new information includes links to new versions for version 4.7 of:

• SINAMICS G130;
• SINAMICS G150;
• SINAMICS S120; and
• SINAMICS S150

The Siemens security advisory provided undated version information for the same products, but that was not reported in the ICS-CERT advisory

NOTE: Siemens also reported two other updated advisories (here and here) and a new advisory (here) today when they reported this update. Hopefully ICS-CERT will publish their versions later this week.

Wednesday, April 25, 2018

ICS-CERT Publishes 4 Advisories and 2 Siemens Updates


Yesterday the DHS ICS-CERT published three control system security advisories for products from Advantech, Intel and Vecna. They published a medical device security advisory for products from Becton, Dickinson and Company (BD). They also updated two control system security advisories previously published for products from Siemens. I have previously reported these two updates (here and here).

Advantech Advisory


This advisory describes three vulnerabilities in the Advantech WebAccess HMI Designer. The vulnerabilities were reported by Steven Seeley of Source Incite thru the Zero Day Initiative. No mitigation measures have yet been provided.

The three reported vulnerabilities are:

• Heap-based buffer overflow - CVE-2018-8833;
• Double free - CVE-2018-8835; and
Out-of-bounds write - CVE-2018-8837

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to remotely execute arbitrary code.

Intel Advisory


This advisory describes a classic buffer overflow vulnerability in the Intel 2G modem products. The vulnerability was reported by Dr. Ralph Phillip Weinmann and Dr. Nico Golde from Comsecuris. Intel is making firmware updates available to device manufacturers that protect systems from this vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The Intel advisory notes that: “The vulnerability affects Intel® 2G Modem products where the Earthquake Tsunami Warning System (ETWS) feature is enabled in Modem firmware.”

ICS-CERT reports that an uncharacterized attacker could remotely exploit this vulnerability to allow remote code execution.

It will be interesting to see if ICS-CERT provides us a list of the affected vendors as they update their products with the new Intel firmware. Given that this is Intel, I suspect that the list of affected vendors could be extensive.

Vecna Advisory


This advisory describes two vulnerabilities in the Vecna VGo Robot, a mobile robotic assistant. The vulnerability was reported by Dan Regalado from Zingbox. Vecna has released an update that mitigates the vulnerability. There are no indications that Regalado has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• OS command injection - CVE-2018-8866; and
• Clear transmission of sensitive information - CVE-2018-8860

ICS-CERT reports that a relatively low-skilled attacker on an adjacent network could exploit the vulnerability to capture firmware updates through network traffic and could allow remote code execution.

BD Advisory


This advisory describes the KRACK vulnerabilities in the BD BD Pyxis Products. BD is reporting being affected by 9 of the 10 reported KRACK vulnerabilities (not reporting - CVE-2017-13084: Reinstallation of the STK key in the PeerKey handshake). BD has implemented third-party vendor patches through BD's routine patch deployment process that resolves these vulnerabilities for most devices. The BD advisory that for three of the affected products coordination with customers is necessary to properly deploy patches and they are contacting the affected customers.

SIMATIC Update


This update provides new information on an advisory that was originally published on March 29th, 2018. The update provides new affected version information and mitigation measures for SIMATIC BATCH V8.0 and V8.1.

SCALANCE Update


This update provides new information on an advisory that was originally published on November 14th, 2017 and updated on December 5th, 2017, December 19th, 2017 and again on January 25th, 2018. The update provides new affected version information and mitigation measures for SCALANCE W1750D.

Friday, March 23, 2018

ICS-CERT Publishes 2 Advisories and Siemens Update


Yesterday the DHS ICS-CERT published two control system security advisories for products from Beckhoff and Siemens. They also updated a previously published advisory for products from Siemens. The two Siemens products were mentioned in a previous blog post.

Beckhoff Advisory


This advisory describes an untrusted pointer dereference vulnerability in the Beckhoff TwinCAT PLC products. The vulnerability was reported by Steven Seeley of Source Incite. According to the Beckhoff security advisory, the company has updates available that mitigate the vulnerability. There is no indication that Seeley has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to escalate privileges. ICS-CERT reports that Matlab modules need to be recompiled after updating.

Siemens Advisory


This advisory describes an improper access control vulnerability in the Siemens SIMATIC WinCC OA UI mobile app. The vulnerability was reported by Alexander Bolshev from IOActive, and Ivan Yushkevich from Embedi. Siemens has updates available that mitigate the vulnerability. There is no indication that the researchers have verified the efficacy of the fix.

ICS-CERT reports that an uncharacterized attacker on an adjacent network could exploit the vulnerability to read and write data from and to the app’s project cache folder. The Siemens security advisory notes that a social engineering attack is required to convince the App user to connect to an attacker-controlled WinCC OA server

Siemens Update


This update provides new information on an advisory that was originally published on January 25th, 2018 and updated on February 6th. The update removes a product from the affected product list.

Thursday, January 4, 2018

ICS-CERT Publishes 2 Advisories and Siemens Update

Today the DHS ICS-CERT published two control system security advisories for products from Advantech and Delta Electronics. It also updated a previously published advisory for products from Siemens

Advantech Advisory


This advisory describes multiple vulnerabilities in the Advantech WebAccess products. The vulnerabilities were reported by Steven Seeley of Offensive Security, Zhou Yu and Andrea Micalizzi working with the Zero Day Initiative, and Michael Deplante. Advantech has released a new version that mitigates the vulnerabilities. There is no indication that any of the researchers were provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Untrusted pointer deference - CVE-2017-16728;
• Stack-based buffer overflow - CVE-2017-16724;
• Path traversal - CVE-2017-1672;
• SQL injection - CVE-2017-16716; and
• Improper input validation - CVE-2017-16753

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to cause the device to crash, remotely execute arbitrary code or bypass authentication.

Delta Advisory


This advisory describes multiple vulnerabilities in the Delta Industrial Automation Screen Editor. The vulnerabilities were reported by Steven Seeley of Source Incite. The affected product has been discontinued and Delta recommends upgrading to DOPSoft, Version 2. There is no indication that Seeley has verified the efficacy of the fix.

The three reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2017-16751;
• Use after free - CVE-2017-16749; and
• Out-of-bounds write - CVE-2017-16747

ICS-CERT reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to remotely execute arbitrary code.

Siemens Update


This update provides new information on an advisory that was was originally published on July 6th, 2017, and updated on July 18th, on July 28th, on October 10th, and then again on November 30th. Siemens is providing updated version information and mitigation measures for their SIPROTEC 7UT686.


NOTE: This is the update that I mentioned last Saturday.

Tuesday, December 19, 2017

ICS-CERT Publishes 5 Advisories and 2 Updates

Today the DHS ICS-CERT published control system security advisories for products from WECON, Siemens, Ecava, PEPPERL+FUCHS and ABB. They also published updates for two previous published advisories for products from Siemens.

WECON Advisory


This advisory describes a heap-based buffer overflow in the WECON LeviStudio HMI. The vulnerability was reported by Michael DePlante working with the Zero Day Initiative (ZDI). WECON notes that the current version mitigates the vulnerability. There is no indication that DePlante was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to crash the device and a buffer overflow condition may allow remote code execution.

Siemens Advisory


This advisory describes a download of code without integrity check vulnerability in the Siemens LOGO! Soft Comfort engineering software product. The vulnerability was reported by Tobias Gebhardt. Siemens is providing SHA-256 checksums for all LOGO! Soft Comfort software packages via a secured HTTPS channel.

ICS-CERT reports that an uncharacterized attacker could remotely exploit the vulnerability to manipulate a software package during download. The Siemens security advisory reports that a successful exploitation would require that the attacker must be able to gain a privileged network position allowing him to capture and modify the affected system’s network communication.

Ecava Advisory


This advisory describes two SQL injection vulnerabilities in the Ecava IntegraXor. The vulnerabilities were independently reported by Steven Seeley of Source Incite, and Michael DePlante and Brad Taylor (working with ZDI). Ecava reports that a newer version mitigates the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to disclose sensitive information from the database or generate an error in the database log.

PEPPERL+FUCHS Advisory


This advisory describes the key reinstallation attacks (KRACK) vulnerabilities in various WLAN enabled products from PEPPERL+FUCHS. This report lists 9 of the 10 KRACK CVE’s. The vendor is still working on fixes for their Android® based products. For their Windows® based products they are recommending that users apply the security update provided by Microsoft. If users are using WPA-TKIP in their WLAN, users should switch to AES-CCMP immediately.

ABB Advisory


This advisory describes an unprotected transport of credentials vulnerability in the ABB Ellipse. ICS-CERT reports that this vulnerability was self-reported by ABB, but the ABB security advisory notes that ABB had received information about this vulnerability through responsible disclosure from an unnamed researcher. ABB has released product updates to mitigate the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to discover authentication credentials by sniffing the network traffic. ABB notes that local network access is required for the exploit.

NOTE: I reported on this vulnerability earlier this month.

Industrial Products Update


This update provides additional information on an advisory that was originally published on December 5th, 2017. It provides updated affected version information and mitigation information for:

• SIMATIC S7-400 H V6: All versions prior to V6.0.8,
• SIMATIC S7-1500: All versions prior to V2.0,
• SIMATIC S7-1500 Software Controller: All versions prior to V2.0,

SCALANCE Update


This update provides additional information on an advisory that was originally published on November 14th, 2017 and updated on December 5th, 2017. It provides updated affected version information and mitigation information for:

• RUGGEDCOM RX1400 with WLAN interface: All versions prior to V2.11.2
• SIMATIC RF350M: All versions with Summit Client Utility prior to V22.3.5.16
• SIMATIC RF650M: All versions with Summit Client Utility prior to V22.3.5.16.


Note: Siemens has issued a separate security advisory for the last two products listed above. That advisory only lists two of the 10 KRACK CVEs instead of the 10 listed in the original Siemens KRACK advisory. It is not clear why ICS-CERT merged these two advisories.

Friday, November 3, 2017

ICS-CERT Publishes Two Advisories

Yesterday the DHS ICS-CERT published two control system security advisories for products from Advantech and Siemens.

Advantech Advisory


This advisory describes two vulnerabilities in the Advantech WebAccess HMI platform. The vulnerabilities were reported by Steven Seeley via the Zero Day Initiative. Advantech released a new version to mitigate the vulnerability. There is no indication that Seeley has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2017-14016; and
• Untrusted pointer dereference - CVE-2017-12719

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to allow remote code execution.

Siemens Advisory


This advisory describes an improper input validation vulnerability in the Siemens SIMATIC PCS7 distributed control system. The vulnerability was reported by Sergey Temnikov and Vladimir Dashchenko of Kaspersky Labs. Siemens has issued an update for some versions to mitigate the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix. Siemens has provided interim mitigation suggestions pending updates to the other versions.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to crash services on the device. The Siemens security advisory reports that: “The attacker must be member of the group administrators and have network access to an affected system.”


NOTE: Siemens reported this vulnerability on October 18th.

Thursday, February 9, 2017

ICS-CERT Publishes Hanwha Techwin Advisory

Today the DHS ICS-CERT published an industrial control system advisory for products from Hanwha Techwin. The advisory describes two vulnerabilities in the Hanwha Techwin Smart Security Manager. The vulnerabilities were reported by Steven Seeley of Source Incite. Hanwah Techwin has produced a patch to mitigate the vulnerability. There is no indication that Seely has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Path traversal - CVE-2017-5168; and
• Cross-site request forgery - CVE-2017-5169


ICS-CERT only notes that the vulnerabilities are remotely exploitable and reports that a successful exploit could lead to create an arbitrary file on the server with attacker controlled data as well as an attacker gaining root shell access.

Thursday, June 23, 2016

ICS-CERT Publishes Three Advisories

Earlier today the DHS ICS-CERT published three new control system security advisories for products from Meinberg, Unitronics, and Rockwell.

Meinberg Advisory


This advisory describes multiple vulnerabilities in the Meinberg NTP Time Servers Interface. The vulnerabilities were reported by Ryan Wincey. Meinberg has produced a new version that mitigates the vulnerabilities. ICS-CERT reports that Wincey has verified the efficacy of the fix.

The vulnerabilities include:

• Twin stack-based buffer overflows - CVE-2016-3962 and CVE-2016-3988; and
• Privilege escalation - CVE-2016-3989

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to cause a buffer overflow condition that may allow escalation to root privileges.

Unitronics Advisory


This advisory describes a stack-based overflow vulnerability in the Unitronics VisiLogic product. The vulnerability was reported by Steven Seeley of Source Incite via ZDI. Unitronics has produced a new version that mitigates the vulnerability. There is no indication that Seeley has been given an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to remotely execute arbitrary code.

The Unitronics’ CERT Compliance page reports that the vulnerability is in the 'Xceed Zip Compression Library' (the XceedZip.dll), - a 3rd party component from Xceed. Unitronics upgraded to version 6.5.16068.0 in their updated version.

NOTE: Once again a vulnerability in a 3rd party library raises the question of what other control system programs are using the vulnerable version of this .DLL?


Rockwell Advisory


This advisory describes a resource management vulnerability in the Rockwell Allen-Bradley Stratix 5400 and Allen-Bradley Stratix 5410 industrial networking switches. The vulnerability is apparently self-reported.


ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to impact traffic (or packets) transiting the affected device.

Tuesday, May 10, 2016

ICS-CERT Publishes Panasonic Advisory

This morning the DHS ICS-CERT published an advisory for a number of vulnerabilities in the Panasonic FPWIN Pro application. The vulnerabilities were reported through ZDI by Steven Seeley. Panasonic has developed a new version of the software that mitigates the vulnerability. There is no indication that Seeley has been given the opportunity to verify the efficacy of the fix.

The vulnerabilities include:

• Heap-based buffer overflow vulnerabilities - CVE-2016-4499;
• Access of uninitialized pointer - CVE-2016-4498;
• Out-of-bounds write - CVE-2016-4496; and
• Type confusion - CVE-2016-4497

ICS-CERT reports that a social engineering attack would be required to exploit these vulnerabilities.


NOTE: It has now been 11 days since Siemens announced that they had updated their advisory on frame padding in ROS devices. ICS-CERT has not yet updated their advisory on this vulnerability. The updated provides additional information about which products are affected by the vulnerability.

Thursday, April 14, 2016

ICS-CERT Publishes 3 Advisories

This morning the DHS ICS-CERT published three control system advisories for systems from Ecava, Accuenergy, and Sierra Wireless.

Ecava Advisory

This advisory describes multiple vulnerabilities in the Ecava IntegraXor application. The vulnerabilities were independently reported by Steven Seeley of Source Incite and Marcus Richerson. Ecava has produced a new version to mitigate the vulnerabilities. Richerson has tested the new version and verified that it fixed all but one (partially fixed) of the vulnerabilities; Ecava will address that in their next release.

The eight vulnerabilities include:

• Clear text transmission of sensitive information - CVE-2016-2306;
• Cross-site scripting - CVE-2016-2305;
• Improper neutralization of alternate XSS syntax - CVE-2016-2304;
• Improper authorization - CVE-2016-2300;
• SQL injection (2) - CVE-2016-2299 and CVE-2016-2301;
• Information exposure - CVE-2016-2302; and
• Improper neutralization of CLRF sequences in HTTP headers - CVE-2016-2303

ICS-CERT reports that a relatively unskilled attacker could remotely use publicly available exploits to gain complete control of the system.

The Ecava vulnerability note does not mention that one of the vulnerabilities is only partially corrected. Nor does it mention the role of Steven Seeley.

NOTE: There is a minor error in the ICS-CERT advisory. The print version of the link has an incorrect version number (5.0.4522.2 instead of 5.0.4525.2), but the actual link goes to the correct place.

Accuenergy Advisory

This advisory describes twin vulnerabilities in the Accuenergy Acuvim II Series AXM-NET module. The vulnerabilities were reported by Maxim Rupp. Accuenergy has developed suggested user mitigations and there is no indication that a fix is planned for the vulnerabilities.

The vulnerabilities are:

• Authentication bypass issues - CVE-2016-2293; and
• Plain text storage of passwords - CVE-2016-2294

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to execute a denial of service attack on the meter.

The Accuenergy suggested mitigations are very broadly painted instructions designed to deny unauthorized access to the meter. They include the use of firewalls, authentication, and VPN use. No specific information for the use of these techniques with this equipment is provided.

Sierra Wireless Advisory

This advisory describes a file and directory information exposure vulnerability in the Sierra Wireless ACEmanager application. The vulnerability was reported by Maxim Rupp. Sierra Wireless has produced a new version that mitigates the vulnerability, but there is no indication that Rupp has been provided the opportunity to verify the efficacy of the fix.


ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to  learn operational characteristics of the gateway.
 
/* Use this with templates/template-twocol.html */