Showing posts with label TRI. Show all posts
Showing posts with label TRI. Show all posts

Thursday, September 26, 2024

OMB Approves EPA NRPM Adding PFAS to TRI

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice of proposed rulemaking (NPRM) on “Addition of Certain Per- and Polyfluoroalkyl Substances (PFAS) to the Toxics Release Inventory (TRI)”. The NPRM was sent to OIRA on January 16th, 2024.

According to the Spring 2024 Unified Agenda entry for this rulemaking:

“The Environmental Protection Agency (EPA) is developing a proposal to add individually listed per- and polyfluoroalkyl substances (PFAS) and PFAS categories to the Toxics Release Inventory (TRI) list of toxic chemicals subject to reporting under the Emergency Planning and Community Right-to-Know Act (EPCRA) and the Pollution Prevention Act (PPA). EPA also intends to address how PFAS compound categories should be treated and discuss what events may trigger the automatic addition of a PFAS to the TRI. These actions are being proposed to comply with the National Defense Authorization Act for Fiscal Year 2020 (NDAA) [15 USC 8921].”

This NPRM should have been published by December 20th, 2022 according to the UA entry.

I will not be covering this rulemaking in any depth in this blog, but its publication will be reported in the appropriate ‘Short Takes’ post.

Wednesday, November 30, 2022

EPA Publishes Final Rule Adding 12 Chemicals to TRI List

Today, the EPA published a final rule in the Federal Register (87 FR 73475-73488) for “Addition of Certain Chemicals; Community Right-to-Know Toxic Chemical Release Reporting”. The Toxic Release Inventory (TRI) list change is the result of a petition from the Massachusetts Toxics Use Reduction Institute (TURI) to add 25 chemicals to the list.

The chemicals added to the TRI include:

• Dibutyltin dichloride; 683-18-1,

• 1,3-Dichloro-2-propanol; 96-23-1,

• Formamide; 75-12-7,

• 1,3,4,6,7,8-Hexahydro-4,6,6,7,8,8-hexamethylcyclopenta[g]-2-benzopyran; 1222-05-5,

• N-Hydroxyethylethylenediamine; 111-41-1,

• Nitrilotriacetic acid trisodium salt; 5064-31-3,

• p-(1,1,3,3-Tetramethylbutyl)phenol; 140-66-9,

• 1,2,3-Trichlorobenzene; 87-61-6,

• Triglycidyl isocyanurate; 2451-62-9;

• Tris(2-chloroethyl) phosphate; 115-96-8,

• Tris(1,3-dichloro-2-propyl) phosphate; 13674-87-8, and

• Tris(dimethylphenol) phosphate; 25155-23-1.

 

The effective date for this new rule is November 30th, 2022. It will apply to the reporting year beginning January 1, 2023 (reports are due July 1, 2024).


Thursday, June 16, 2022

Review - EPA Publishes TRI Reporting 30-day ICR Revision Notice

Yesterday the EPA published a 30-day information collection request (ICR) revision notice in the Federal Register (87 FR 36123-36124) for their Toxic Chemical Release Reporting ICR. This revision includes an increase in the burden estimate for both the number of reporting facilities and the per-hour burden estimate for non-reporting requirements. The 60-day ICR notice for this revision was published on November 15th, 2021.

Burden Estimate

Current

Proposed

Increase

Facilities

21,876

21,905

29

Responses

76,534

76,579

45

Hours

3,615,128

3,616,827

1699

The EPA is soliciting public comments on this ICR submission. Comments may be submitted on the ORIA web page for this Revision, by clicking on the ‘Comment’ box. Comments should be submitted by July 15th, 2022.

For more details about the change in burden estimate, including exercise of EPA discretionary authority to order TRI reporting, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/epa-publishes-tri-reporting-30-day - subscription required.

Friday, June 28, 2019

6 Advisories Published – 06-27-19


Yesterday the DHS NCCIC-ICS published five control system security advisories for products from Advantech, SICK AG, and ABB (3). They also published a medical device security advisory for products from Medtronic.

Advantech Advisory


This advisory describes six vulnerabilities in the Advantech WebAccess/SCADA software platform. The vulnerabilities were reported by Mat Powell, Natnael Samson (@NattiSamson) and EljahLG via the Zero Day Initiative. Advantech has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

Path traversal - CVE-2019-10985;
Stack-based buffer overflow - CVE-2019-10991;
Heap-based buffer overflow - CVE-2019-10989;
Out-of-bounds read - CVE-2019-10983;
Out-of-bounds write - CVE-2019-10987; and
Untrusted pointer dereference - CVE-2019-10993

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow information disclosure, deletion of files, and remote code execution.

SICK Advisory


This advisory describes a use of hard-coded credentials vulnerability in the SICK MSC800 PLC. The vulnerability was reported by Tri Quach of Amazon’s Customer Fulfillment Technology Security (CFTS) group. SICK has new firmware that mitigates the vulnerability. There is no indication that Quach has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow a low-skilled remote attacker to reconfigure settings and/or disrupt the functionality of the device.

CP 635 Advisory


This advisory describes a use of hard-coded credentials vulnerability in the ABB CP620 and CP635 HMI products. The vulnerability is self-reported. ABB has an update available that mitigates the vulnerability.

The ABB advisory describes two other vulnerabilities with these products and reports that the vulnerabilities were reported by Xen1thLabs. The individual vulnerability reports from Xen1thLabs (see links below) include proof of concept exploits.

The three reported vulnerabilities are:

Out-dated software components – multiple OpenSSL CVE;
Hard-coded credentials - CVE-2019-7225; and
Absence of signature verification - CVE-2019-7229

NCCIC-ICS reports that a relatively low-skilled attacker on an adjacent network could exploit the (single reported?) vulnerability to allow an attacker to prevent legitimate access to an affected system node, remotely cause an affected system node to stop, take control of an affected system node, or insert and run arbitrary code in an affected system node.

CP 651 Advisory


This advisory describes a use of hard-coded credentials vulnerability in the ABB CP651, CP665 and CP676 HMI products. The vulnerability is self-reported. ABB has an update available that mitigates the vulnerability.

The ABB advisory describes the same two other vulnerabilities with these products and reports that the vulnerabilities were discovered based upon the work of Xen1thLabs on the CP 635 vulnerabilities reported above.

NCCIC-ICS reports that a relatively low-skilled attacker on an adjacent network could exploit the (single reported?) vulnerability to allow an attacker to prevent legitimate access to an affected system node, remotely cause an affected system node to stop, take control of an affected system node, or insert and run arbitrary code in an affected system node.

Panel Builder Advisory


This advisory describes seven vulnerabilities in the ABB PB610 Panel Builder 600 engineering tool. The vulnerability was reported by Xen1thLabs. ABB has new versions available that mitigate the vulnerabilities. There is no indication that Xen1thLabs has been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities (with links to the Xen1thLabs reports; reports which contain proof of concept exploit code) are:

Use of hard-coded credentials - CVE-2019-7225;
Improper authentication - CVE-2019-7226;
Relative path traversal - CVE-2019-7227;
Improper input validation (2) - CVE-2019-7228 and CVE-2019-7230; and
Stack-based buffer overflow - CVE-2019-7231

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to prevent legitimate access to an affected system node, remotely cause an affected system node to stop, take control of an affected system node, or insert and run arbitrary code in an affected system node.

Medtronic Advisory


This advisory describes an improper access control vulnerability in the Medtronic MiniMed 508 and Paradigm Series Insulin Pumps. The vulnerability is self-reported, but NCCIC-ICS notes that the internal investigation by Medtronic was guided by previous work from outside researchers on other Medtronic products. Medtronic suggests upgrading to a newer product. The FDA advisory on this product notes that Medtronic is recalling the affected insulin pumps.

NCCIC-ICS reports that an uncharacterized attacker with adjacent access (radio frequency access according to the Medtronic advisory) could exploit this vulnerability to intercept, modify, or interfere with the wireless RF (radio frequency) communications to or from the product. This may allow attackers to read sensitive data, change pump settings, or control insulin delivery.

Saturday, March 1, 2014

EPA Publishes TRI 60-day ICR Notice

The Environmental Protection Agency (EPA) is publishing a 60-day information collection request (ICR) renewal notice in Monday’s Federal Register (79 FR 11783-11787; available on line today) for their Toxic Release Inventory program. The ICR covers the forms that covered facilities are required to use to report information under 42 USC 11023 and 42 USC 13106.

ICR Data

The ICR covers the use of 2 forms; TRI Form R with Schedule 1 and Form A 5-5-2011. The currently approved burden estimate and the new burden being submitted in this ICR are shown in the table below. This ICR notice shows a slight increase in the burden imposed by this collection.

OMB Control No: 2025-0009
Current ICR
Proposed ICR
Responses
73,727
74,869
Time Burden
3,522,736
3,555,998
Cost Burden
$0
$183,418,377

The cost burden is obviously not increasing from $0 to $183 Million. The OMB’s Office of Information and Regulatory Affairs (OIRA) is apparently on-again off-again about how it reports ICR cost burdens. The OIRA web page for the current ICR shows no cost burden, a blatant misrepresentation of facts.

Burden Change

The ICR notes that there are a number of factors that go into their increase in estimated burden associated with this ICR. Those include:

• Change in reporting requirements for hydrogen sulfide;
• Addition of o-nitrotoluene reporting requirements; and
• A slight increase in the number of reporting facilities.

Form Changes

The notice also reports that the EPA is making some changes to the reporting forms, but does not expect that these changes will materially change the time burden in completing the submissions. Those changes include:

• Add an optional extension to all phone numbers;
• Add an optional field to allow facilities to indicate the section of a water body that received the surface water discharge; and
• EPA proposes rewording the heading titles for 5.4.1 and 5.4.2.

Public Input

As required by 44 USC 3506(c)(2) the EPA is soliciting public comments on this ICR renewal. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket #EPA-HQ-OEI-2013-0803). Comments should be submitted by May 2nd, 2014.

Commentary

I must say that this is the most complete and informative ICR (other than the PSP ICR for CFATS which is in an entirely different category) notice that I have seen. In my opinion this is the type of information that should be included in an ICR notice every time that there is any change in the underlying collection. The EPA is to be commended for their exemplary efforts in preparing this document.
 
/* Use this with templates/template-twocol.html */