Showing posts with label Tom Westenberg. Show all posts
Showing posts with label Tom Westenberg. Show all posts

Tuesday, March 19, 2019

2 Advisories Published – 03-19-19


Today the DHS NCCIC-ICS published two control system security advisories for products from Columbia Weather Systems and AVEVA.

Columbia Advisory


This advisory describes six vulnerabilities in the Columbia Weather MicroServer weather monitoring system. The vulnerabilities were reported by John Elder and Tom Westenberg of Applied Risk. Columbia has a firmware update that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Cross-site scripting (2) - CVE-2018-18875 and CVE-2018-18880;
• Path traversal - CVE-2018-18876;
• Improper authentication - CVE-2018-18877;
• Improper input validation - CVE-2018-18878; and
Code injection - CVE-2018-18879

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow disclosure of data, cause a denial-of-service condition, and allow remote code execution.

AVEVA Advisory


This advisory describes an uncontrolled search path element vulnerability in the AVEVA InduSoft Web Studio, InTouch Edge HMI products. The vulnerability is in a third-party component; Gemalto Sentinel UltraPro encryption keys (separately reported last week). The vulnerability was reported by ADLab of Venustech. AVEVA has updates available to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow execution of unauthorized code or commands.

NOTE: I wonder how many other vendors are using the Gemalto product?

Saturday, March 16, 2019

Public ICS Disclosures – Week of 03-09-19


This week we have five vendor notifications for products from Siemens, PEPPERL+FUCHS, and Schneider(3) and four vendor updates of previously published advisories for products from Siemens(3) and Medtronics.

Siemens Advisory


Siemens published an advisory describing a mirror port isolation vulnerability in their SCALANCE X switches. The vulnerability is being self-reported. Siemens has provided generic workarounds to mitigate the vulnerability.

PEPPERL+FUCHS Advisory


VDE CERT published an advisory describing two vulnerabilities in the PEPPERL+FUCHS ecom mobile devices. The vulnerabilities were reported by Ben Seri and Gregory Vishnepolsky of Armis; the armis 2017 Blueborne disclosure includes exploits. PEPPERL+FUCHS points to (no links provided) OEM vendors for updates for some of the affected products.

Schneider Advisories


Schneider published an advisory describing an uncontrolled search path element vulnerability in their Pelco VideoXpert OpsCenter. The vulnerability was reported by Osama Radwan. Schneider has a new version that mitigates the vulnerability. There is no indication that Radwan has been provided an opportunity to verify the efficacy of the fix.

Schneider published an advisory describing an SQL injection vulnerability in their U.motion Builder software product. The vulnerability was reported by Julien Ahrens (RCE Security). Schneider recommends that customers stop using the their U.motion Builder software product as it is no longer supported.

Schneider published an advisory describing an improper check for unusual or exceptional conditions vulnerability in their Triconex TriStation Emulator. The vulnerability was reported by Tom Westenberg – Applied Risk. Schneider plans to have an update available in July and has provided generic workarounds to mitigate the vulnerability in the mean time.

Siemens Updates


Siemens published an update for their advisory on Spectre and Meltdown Vulnerabilities in Industrial Products. They added an updated solution for their SINUMERIK PCU. NCCIC-ICS is not expected to publish and update for their Meltdown/Spectre alert (ICS-ALERT-18-011-01) since the link in that Alert to the Siemens Industrial Products already takes one to this latest update.

Siemens published an update for their advisory on Foreshadow / L1 Terminal Fault Vulnerabilities in Industrial Products. They added an updated solution for their SINUMERIK PCU. NCCIC-ICS has not published any advisories or alerts about the Foreshadow vulnerabilities.

Siemens published an update for their advisory on Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP. They added 14 new CVE’s to the already lengthy list of CVE’s covered in the advisory. NCCIC-ICS has not published an advisories or alerts on this family of Linux vulnerabilities.

Medtronic Update


Medtronic published an update for their advisory on MiniMed™ Paradigm™ Insulin Pumps. They added:

• Two new affected devices available in the US; and
A link to the field safety notification letter issued in August, 2018.

The NCCIC-ICS advisory (ICSMA-18-219-02) was originally published on August 8th, 2018. I suspect that this will be updated in the coming week.

NOTE: It is interesting that the letter (dated August 7th, 2018; the date of the original advisory) includes the two affected devices that are being added to the advisory via this update. The original Medtronic advisory made special note that none of the affected devices were available for sale in the United States.

Thursday, January 17, 2019

Three Advisories Published – 01-17-19


Today the DHS NCCIC-ICS published three control system security advisories for products from ControlByWeb, ABB and Omron.

ControlByWeb Advisory


This advisory describes two vulnerabilities in the ControlByWeb X-320M web-enabled weather station. The vulnerabilities were reported by John Elder and Tom Westenberg of Applied Risk. ControlByWeb has a firmware update that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper authentication - CVE-2018-18881; and
Cross-site scripting - CVE-2018-18882

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow arbitrary code execution and could cause the device being accessed to require a physical factory reset to restore the device to an operational state.

ABB Advisory


This advisory describes an improper input validation vulnerability in the ABB CP400 Panel Builder TextEditor. The vulnerability was reported by Ivan Sanchez of NullCode. ABB has a new version that mitigates the vulnerability. There is no indication that Sanchez has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerability to allow an attacker to execute arbitrary code and cause a denial-of-service condition within the Text Editor application. The ABB security advisory reports that a social engineering attack would be required to get an operator to load a specially crafted file.

NOTE: I briefly discussed this vulnerability back in early December.

Omron Advisory


This advisory describes five vulnerabilities in the Omron CX-Supervisor. The vulnerabilities were reported by Esteban Ruiz (mr_me) of Source Incite via the Zero Day Initiative. Omron has a new version that mitigates the vulnerabilities. There is no indication that Ruiz has been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Code injection - CVE-2018-19011;
• Command injection (2) - CVE-2018-19013 and CVE-2018-19015;
• Use after free - CVE-2018-19017; and
• Type confusion - CVE-2018-19019

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to cause a denial-of-service condition, and/or allow an attacker to achieve code execution with privileges within the context of the application.

NOTE: The Omron release notes for the new version recommended in this NCCIC-ICS advisory lists 8 ZDI reported vulnerabilities (no details currently available on ZDI site) corrected and a couple of other cybersecurity improvements that are included.

 
/* Use this with templates/template-twocol.html */