Showing posts with label TRIPwire. Show all posts
Showing posts with label TRIPwire. Show all posts

Saturday, June 26, 2021

Review - Public ICS Disclosures – Week of 6-19-21

This week we have 16 vendor disclosures from ABB, Aveva, Weidmueller, Draeger, Phoenix Contact (7), QNAP, Sick, SonicWall, and VMware (2). There are exploit reports for products from VMWare and HPE.

Miscellaneous Advisories

ABB Advisory - ABB published an advisory discussing CodeMeter vulnerabilities in their Automation Builder, Drive Application Builder and Virtual Drive products.

Aveva Advisory - Aveva published an advisory describing five vulnerabilities in the AutoBuild service of their System Platform.

Weidmueller Advisory - CERT-VDE published an advisory describing twelve vulnerabilities in the Weidmueller Industrial WLAN devices.

Draeger Advisory - Draeger published an advisory describing an integer overflow or wraparound vulnerability in their Clinical Assistance Package.

QNAP Advisory - QNAP published an advisory describing a command injection vulnerability in their NAS running legacy versions of QTS.

Sick Advisory - Sick published an advisory describing an inadequate SSH configuration vulnerability in their Visionary-S CX product.

SonicWall Advisory - SonicWall published an advisory describing a buffer overflow vulnerability in their SonicOS.

Phoenix Contact Advisories

Phoenix Contact published an advisory describing an undocumented access vulnerability in their AXL F BK and IL BK products.

Phoenix Contact published an advisory describing a denial of service vulnerability in their ILC1x1 Industrial controllers.

Phoenix Contact published an advisory describing a file parsing memory corruption vulnerability in their Automation Worx Software Suite.

Phoenix Contact published an advisory describing a race condition vulnerability in their r PLCNext, SMARTRTU AXC, CHARX control modular and EEM-SB37x products.

Phoenix Contact published an advisory describing two vulnerabilities in their PLCNext, ILC 2050 BI, FL MGUARD DM UNLIMITED, TC ROUTER und CLOUD CLIENT products.

Phoenix Contact published an advisory describing three vulnerabilities in their FL SWITCH SMCS series.

VMware Advisories

VMware published an advisory describing a local privilege escalation vulnerability in their VMware Tools, VMRC and VMware App Volumes products.

VMware published an advisory describing an authentication bypass vulnerability in their Carbon Black App Control product.

Exploits

CHackA0101 published an exploit for an improper privilege management vulnerability in the VMware vCenter Server.

Jeremy Brown published an exploit for a denial of service vulnerability in the HPE Remote Device Access product.

For more detailed information on the advisories see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-73d  (subscription required)


Wednesday, February 27, 2013

NPPD Publishes 60-day ICR Notice for TRIPwire Program


The National Protection and Programs Directorate (NPPD) of DHS published a 60-day information collection request notice in today’s Federal Register (78 FR 13366-13367). This new ICR would support the existing user registration for the Technical Resource for Incident
Prevention (TRIPwire) program operated out of the Office of Bombing Prevention. According to this notice TRIPwire “is OBP's online, collaborative, information-sharing network for bomb squad, law enforcement, and other emergency services personnel to learn about current terrorist improvised explosive device (IED) tactics, techniques, and procedures”.

This is one of those long-standing (since at least 2009 that I know of) programs that has collected voluntary registration information without an OMB ICR program number. Agencies collecting information from State and local governments and the private sector are required to get OMB approval of those information collections to ensure that there is a legitimate governmental need for the information and that the collected information is appropriately used and protected. The Obama Administration has been very proactive in bringing these voluntary programs into coverage of the ICR program, so it is somewhat surprising that this particular program is just now receiving this attention.

The OBP expects that there will be an annual participation in this registration collection by about 3,500 participants and that the average time spent in providing the information will be 10 minutes. This annual time burden of 583 estimated hours will have a total cost burden $11,803 on the information providers.

Public comments on this ICR may be provided via the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2012-0022). Comments need to be submitted by April, 29th, 2013.

Thursday, January 13, 2011

IED Threat Information

The web site that publishes restricted access information from governments around the world, PublicIntelligence.net, recently posted a copy of a set of DHS TRIPwire briefing slides providing an overview of the use of improvised explosive devices by terrorists; “Domestic Improvised Explosive Device (IED) Threat Overview”. As is usual with the publications of the slides from a presentation, much of the detailed explanation that makes up such briefings is missing from this document, but even so it is a valuable compilation of information about Terrorist IED Tactics, Techniques, and Procedures (TTP).

In addition to information about explosives and devices (lacking any details that would allow the uninformed to produce them) there is an interesting section on ‘Domestic Radicalization’. There will be some that object to the inclusion of ‘radical Christian movements’ in the discussion, but the example of Eric Rudolph demonstrates that they are referring to the violent radical fringe, not the just less-mainstream religious groups. They conclude that slide with a very important point;

“To date, most of the perpetrators of terrorist attacks in the United States have been radicalized by non-Islamic movements.”
The slide presentation would almost certainly be more informative if it included the information provided by the presenter, but this is still a good, short reference document on IEDs and their associated tactics.

SECURITY WARNING: Government contractors and members of the federal government should be aware that the document is marked ‘For Official Use Only’ (FOUO) and the fact that you download this from an open source will not exempt you from applying appropriate safeguards for the storage of this document. The last time I looked at FOUO regulations (20+ years ago in the Army) this required the use of an ‘FOUO’ cover sheet and storing in a locked desk drawer or file cabinet.
 
/* Use this with templates/template-twocol.html */