Showing posts with label Timur Yunusov. Show all posts
Showing posts with label Timur Yunusov. Show all posts

Thursday, October 10, 2013

ICS-CERT Publishes Two Advisories

In the midst of a dysfunctional government’s fiscal fiasco the DHS ICS-CERT published two control system security advisories yesterday, one a DNP3 advisory for Alstom e-Terracontrol and another HMI advisory for Wonderware InTouch.

Alstom Advisory

This advisory is for an improper input validation vulnerability reported by Adam Crain and Chris Sistrunk in a coordinated disclosure (#9 of 25 listed on the Project Robus web page). Alstom has produced a patch to mitigate this vulnerability and Adam and Chris have verified the efficacy of that patch.

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to execute a denial of service attack on the system.

Wonderware Advisory

This advisory is for an improper input validation vulnerability reported by Timur Yunusov, Alexey Osipov, and Ilya Karpov of the Positive Technologies Research Team in a coordinated disclosure. Wonderware has produced an updated version of InTouch that mitigates this vulnerability and the team from Positive Technologies has verified the efficacy of the new version. ICS-CERT had released this advisory to the US-CERT secure Portal library on October 03, 2013.

ICS-CERT reports that a relatively low skilled attacker could exploit this vulnerability to gain access to system information or execute a denial of service attack. ICS-CERT says that this vulnerability cannot be remotely exploited; they note that the “exploit is only triggered when a local user runs the vulnerable application and loads the malformed XML files” {page 2}. It seems clear that a remote exploit would be possible through a social engineering attack.

According to the Positive Technologies web site that organization reported this vulnerability to Invensys on 12-16-13 along with three other vulnerabilities in the same system. Those reported vulnerabilities were:

• PT-2013-40: Resource Exhaustion;
• PT-2013-38: Multiple SQL Injection vulnerabilities; and
• PT-2013-37: Multiple Cross Site Scripting (XSS).


Positive Technologies reported that Invensys publicly reported all four vulnerabilities on October 6th. It is not clear why ICS-CERT did not include these other, more serious, vulnerabilities in this advisory especially since Positive Technologies reports that the same Invensys update fixed all four vulnerabilities. The Wonderware notifications are only available to registered system owners so I cannot verify the Positive Technologies claims.

Tuesday, August 6, 2013

ICS-CERT Publishes Schneider Electric Advisory

Yesterday the DHS ICS-CERT published an advisory for an XML external entity vulnerability in three Schneider Electric products. The vulnerability was reported to Schneider by Timur Yunusov, Alexey Osipov, and Ilya Karpov of Positive Technologies.

ICS-CERT reports that a moderately skilled attacker with local access to affected systems could exploit this vulnerability to gain access to information on the system. Schneider reports that the vulnerability could also lead to a denial of service attack.

Schneider has produced a series of patches for this vulnerability for the affected systems. There is no indication in the Advisory that there has been any outside verification of the efficacy of the patches. Interestingly, the Schneider disclosure document reminds users that if they must re-install or repair the affected products that the “should first uninstall the fix, re-install\repair the affected product(s) and then reinstall the fix”. Hopefully customers will be able to ensure that this information remains prominently available over the lifetime of the product.


NOTE: Schneider publicly released their vulnerability disclosure on July 28th after making it available on their secure portal on May 9th.  The ICS-CERT Advisory does not provide links to either the disclosure document or the vulnerability report.

Friday, August 2, 2013

ICS-CERT Issues Three Advisories – Two for Siemens

After a three-week breather advisories start coming hot and heavy from ICS-CERT. There are two Siemens’ advisories (one self-reported) and a coordinated disclosure advisory for IOServer.

Siemens Scalance

The first advisory addresses two Siemens’ reported two vulnerabilities in their Scalance W-7xx product family. They are:

• Key management errors, CVE-2013-4651, hard-coded SSL certificate;
• Improper authentication, CVE-2013-4652, network access required.
NOTE: CVE Links may not be active for a couple of days.

ICS-CERT notes that a relatively low skilled attacker could remotely exploit these vulnerabilities to conduct a man-in-the-middle attack or take over complete control of the system. Siemens has produced an update that mitigates the vulnerability (since they self-reported they get to self-validate). The Siemens-CERT advisory also provides a work-around for the second vulnerability.

Siemens WinCC

The second advisory addresses two vulnerabilities reported by Timur Yunusov and Sergey Bobrov of Positive Technologies in a coordinated disclosure. The vulnerabilities are:

• Cross-site request forgery, CVE-2013-4911,
• Url redirection to untrusted site, CVE-2013-4912,
NOTE: CVE Links may not be active for a couple of days.

According to the Siemens-CERT advisory, both vulnerabilities require that a web be activated on the affected devices during set up. The attacker must then use a social engineering attack to get a user to access a malicious web page.

ICS-CERT notes that a moderately skilled attacker could remotely exploit these vulnerabilities to compromise the integrity (execute arbitrary code?) and availability (DoS attack?). Siemens has produced a product update that mitigates the vulnerabilities and has validated the fix (oops, that should have been the researchers, Yunusov and Borov, doing the validation).

IOServer Advisory

The third advisory of the day reports on an improper input validation vulnerability in the IOServer Master Station product reported by Adam Crain of Automatak and Chris Sistrunk in a coordinated disclosure.


ICS-CERT notes that a moderately skilled attacker could remotely exploit this vulnerability to execute a denial of service attack. IOServer has produced a Beta Driver (beta2042.exe) that mitigates these vulnerabilities. There is no indication that the researchers have validated the efficacy of the updated driver. NOTE: an even more recent Beta Driver is available.

Tuesday, May 7, 2013

ICS-CERT Issues Wonderware Advisory


Earlier today the DHS ICS-CERT published an advisory covering multiple vulnerabilities in Invensys Wonderware Information Server products. The coordinated disclosure was made by Timur Yunusov, Alexey Osipov, and Ilya Karpov of the Positive Technologies Research Team. The multiple vulnerabilities included:

• Cross-site scripting, CVE-2013-0688;
• SQL injection, CVE-2013-0684;
• Inproper input validation, CVE-2013-0686; and
• Resource exhaustion, CVE-2013-0685.

NOTE: These CVE links will not be functional for a couple of days.


ICS-CERT reports that a moderately skilled attacker could remotely exploit these vulnerabilities to execute remote code, disclose information, or perform session credential high jacking. The advisory notes that Invensys has developed a software update (registration required) that has been verified by PTR to mitigate the identified vulnerabilities.

These are old school vulnerabilities that should have been identified a long time back. I think the reason they are just turning up now is that they are in an ICS server. It looks like researchers are expanding the areas in which they are searching for ICS vulnerabilities. How many other types of ICS equipment will have similar vulnerabilities that would allow access to the control system?

BTW: A couple of posts back I noted that ICS-CERT had changed their format for these advisories and that one of the changes was the removal of the Traffic Light Protocol (TLP) markings. I just noticed that this advisory still includes a description of the TLP white marking that shows up near the top of page 3 on the .PDF saved version of the advisory. This is the first time this FAQ has shown up on an advisory since the format change.
 
/* Use this with templates/template-twocol.html */