Showing posts with label Treck. Show all posts
Showing posts with label Treck. Show all posts

Thursday, March 17, 2022

Review – 1 Update and 1 3rd Party Advisory Published

Today CISA’s NCCIC-ICS published an update for an advisory for products from Treck. CISA (separately from NCCIC-ICS) published an advisory for products from OpenSSL that is very likely to show up as a third-party advisory for products from various vendors.

Treck Update - This update provides additional information on an advisory that was originally published on June 16th, 2020 and most recently updated on August 20th, 2020.

NOTE #1: I discussed the ‘new’ PEPPERL+FUCHS advisory on August 21st, 2021

OpenSSL Advisory - CISA briefly reports the OpenSSL advisory which describes an infinite loop vulnerability in the BN_mod_sqrt() function when parsing certificates.

NOTE: With so many industrial control systems using OpenSSL for a variety of security functions, I expect that we will be seeing this vulnerability being reported by multiple vendors as a third-party vulnerability.

 

For more details on these two advisories, including discussion about Ripple20 exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-update-and-1-3rd-party-advisory - subscription required.

Saturday, December 25, 2021

Review - Public ICS Disclosure – Week of 12-18-21 – Part 1

Merry Christmas. This has been another busy week for ICS disclosures. Part 1 today will be normal vulnerabilities and Part 2 (probably tomorrow) will be Log4Shell disclosures.

This week we have six vendor disclosures from ABB, IDEC Corporation, QNAP, Hitachi Energy (2), and Johnson Controls. We also have twelve researcher reports for products from Garrett (7) and Open Design Alliance (5).

ABB Advisory - ABB published an advisory describing an MMS file transfer vulnerability in their Distribution Automation products.

IDEC Advisory - JPCERT published an advisory [link added 18:40 EST 1-6-22] for four vulnerabilities in the IDEC PLCs.

QNAP Advisory - JPCERT published an advisory describing two vulnerabilities in the QNAP VioStar series NVR.

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory describing four vulnerabilities in their LinkOne product.

Hitachi Energy Advisory #2 - Hitachi Energy published an advisor discussing seven vulnerabilities in their Data Manager (SDM600) product.

Johnson Controls Advisory - Johnson Controls published an advisory describing an unspecified vulnerability in their American Dynamics VideoEdge NVR.

NOTE: It looks like this has been reported to NCCIC-ICS, so we may see an advisory from them next week

Garrett Reports - Talos published seven reports covering nine vulnerabilities in the Garrett Metal Detectors used for security screening.

ODA Reports - The Zero Day Initiative published five reports covering vulnerabilities in the ODA Drawings Explorer product.

For more details on these advisories, including links to third-party advisories, see my report at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-12 - subscription required.

Sunday, July 18, 2021

Review – Public ICS Disclosures – Week of 7-10-21 – Part 2

As has become typical for the weekend following the 2nd Tuesday, we have a Part 2 to cover the disclosures and updates from Schneider and Siemens that were not addressed by NCCIC-ICS.

Schneider advisory #1 - Schneider published an advisory describing three vulnerabilities in their Easergy T300 RTU.

Schneider advisory #2 - Schneider published an advisory describing a deserialization of untrusted data vulnerability in their SoSafe Configurable product.

Schneider advisory #3 - Schneider published an advisory describing a missing authentication for critical function vulnerability in their Easergy T200 RTU.

Schneider advisory #4 - Schneider published an advisory describing thirteen vulnerabilities in their EVlink City, Parking and Smart Wallbox products.

Siemens advisory #1 - Siemens published an advisory discussing two buffer over-read vulnerabilities in a number of their products that utilize the WIBU CodeMeter Runtime product.

Siemens advisory #2 – Siemens published an advisory discussing a null pointer dereference vulnerability in a number of their products that utilize OpenSSL.

Siemens advisory #3 - Siemens published an advisory discussing the FragAttacks WiFi vulnerabilities in their SCALANCE product line.

Schneider update #1 - Schneider published an update for their Ripple20 advisory that was originally published on June 23, 2020 and most recently updated on May 11th, 2021.

Schneider update #2 - Schneider published an update for their APC Ripple20 advisory that was  originally published on June 23, 2020 and most recently updated on January 12th, 2021.

Schneider update #3 - Schneider published an update for their EcoStructure advisory that was originally published on December 8th, 2020.

Schneider update #4 - Schneider published an update for their Triconex advisory that was originally published on May 11th, 2021.

Schneider update #5 - Schneider published an update for their Treck TCP/IPv6 advisory that was originally published on December 18th, 2020.

Schneider update #6 - Schneider published an update for their PLC Simulator advisory that was originally published on November 10th, 2020 and most recently updated on June 8th, 2021.

Siemens update - Siemens published an update for their GNU/Linux subsystem advisory advisory that was originally published in 2018 and most recently updated on May 11th, 2021.

For a more detailed look at the advisories, including links to exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-part-2 - subscription required.

Saturday, March 27, 2021

Public ICS Disclosures – Week of 3-20-21

This week we have 27 vendor disclosures from BD (3), Bosch, TRUMPF, GE Grid Systems (19), Mitsubishi Electric, Moxa, and Rockwell Automation. We have a researcher report for products from Ovarro. Finally, there were two exploits published for products from VMWare and Advantech.

BD Advisories

BD published patch advisories for the below listed products. These are the 3rd party patches that have been tested by BD on the listed products.

• BD Care Coordination Engine (CCE),

• Security Patches: BD Pyxis™ Products, and

• Security Patches: BD Alaris™ Systems Manager

Bosch Advisories

Bosch published an advisory describing seven uncontrolled search path element vulnerabilities in multiple Bosch products. The vulnerabilities were reported by Nir Yehoshua, Dhiraj Mishra, and Eli Paz of CyberArk. Bosch has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

TRUMPF Advisory

CERT-VDE published an advisory describing an out-of-bounds write vulnerability in the TRUMPF TruControl laser control software. The vulnerability was reported by Qualys Research Labs. TRUMPF has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

GE Grid Advisories

GE published advisories for the below listed products. These may be updates for previously issued advisories, but only GE customers can access the advisories, so I do not know for sure:

• C30 Controller

• C60 Breaker Management Relay

• C70 Capacitor Bank Protection and Control System

• B30 Bus Differential Relay

• B90 Bus Differential System

• F35 Multiple Feeder Management Relay

• F60 Feeder Management Relay

• G30 Generator Management Relay

• G60 Generator Management Relay

• L30 Line Current Differential Relay

• L60 Line Phase Comparison Relay

• L90 Line Current Differential Relay

• M60 Motor Management Relay

• D30 Line Distance Relay

• D60 Line Distance Relay

• N60 Network Stability and Synchrophasor Measurement System

• T35 Transformer Management Relay

• T60 Transformer Management Relay

• UR Family of Protection Relays

Mitsubishi Advisory

Mitsubishi published an advisory discussing a heap-based buffer overflow vulnerability in a third-party TCP/IP stack (Treck). Mitsubishi is providing generic workarounds to mitigate the vulnerability.

NOTE: Mitsubishi is only reporting one of the four TCP/IP stack vulnerabilities reported by Treck.

Moxa Advisory

Moxa published an advisory describing ten vulnerabilities in their EDR-810 Series Security Routers. The vulnerabilities were reported by the Russian BDU FSTEC. Moxa has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The ten reported vulnerabilities are:

• Improper Input Validation - CVE-2014-2284 (Linux ICMP-MIB implementation),

• Resource Management Errors - CVE-2015-1788 (Open SSL),

• Improper Restriction of Operations within the Bounds of a Memory Buffer - CVE-2016-10012 (Open SSH),

• Exposure of Sensitive Information to an Unauthorized Actor - CVE-2015-3195 (Open SSL),

• Improper Input Validation - CVE-2016-6515 (open SSH, Exploit),

• Improper Input Validation - CVE-2017-17562 (EmbedThis, Exploit),

• Cryptographic Issues - CVE-2013-0169 (TLS Protocol),

• Permissions, Privileges, and Access Controls - CVE-2013-1813 (BusyBox, Exploit), and

• Numeric Errors - CVE-2010-2156 (ISC DHP, Exploit)

Rockwell Advisory

Rockwell published an advisory discussing eight vulnerabilities in their Stratix Switches. These are third-party (Cisco) vulnerabilities. Rockwell has new versions that mitigate the vulnerability.

The eight reported vulnerabilities are:

• Privilege escalation (2) - CVE-2021-1392 and CVE-2021-1442,

• Cross-site web socket hijacking - CVE-2021-1403,

• Denial of service (3) - CVE-2021-1352, CVE-2021-1220, and CVE-2021- 1356, and

• Command injection (2) - CVE-2021-1452 and CVE-2021-1443,

NOTE: Links above are to the Cisco advisories.l

Ovarro Report

Claroty published a report describing the five vulnerabilities that were reported earlier this week in the Ovarro TBox RTUs.

VMWare Exploit

WVU published a Metasploit module for a remote code execution vulnerability in the VMware View Planner. This vulnerability was previously reported by VMware.

Advantech Exploit

Spencer McIntyre published a Metasploit module for a missing authentication for critical function vulnerability in the Advantech iView. This vulnerability was previously reported by Advantech.

Saturday, January 30, 2021

Public ICS Disclosures – Week of 1-23-21

This week we have nine vendor disclosures from Bosch, ZIV Automation (2), Emerson, GE Healthcare, Johnson Controls, Rockwell (2), and Siemens.

Bosch Advisory

Bosch published an advisory describing a stack-based buffer overflow vulnerability in their Rexroth ID 200/C-ETH using EtherNet/IP Protocol. This is a third-party (Real Time Automation) vulnerability. Bosch provides generic mitigation measures.

ZIV Automation Advisories

Incibe-CERT published an advisory describing an uncontrolled resource consumption vulnerability in the ZIV 4CCT Smart Metering Data Concentrator. The vulnerability was reported by Aarón Flecha Menéndez of S21Sec. ZIV has a patch available that mitigates the vulnerability. There is no indication that Menendez has been provided an opportunity to verify the efficacy of the fix.

 

Incibe-CERT published an advisory describing an improper authentication vulnerability in the ZIV 4CCT Smart Metering Data Concentrator. The vulnerability was reported by Aarón Flecha Menéndez of S21Sec. ZIV has a patch available that mitigates the vulnerability. There is no indication that Menendez has been provided an opportunity to verify the efficacy of the fix.

Emerson Advisory

Emerson published an advisory describing the fdtCONTAINER vulnerability in their Rosemont Transmitter Interface Software. Emerson no longer supports that software.

NOTE: This Emerson impact was previously reported by NCCIC-ICS.

GE Healthcare Advisory

GE Healthcare has published an advisory discussing undisclosed vulnerabilities in the VC150 Vital Signs Monitor that they distribute. The Innokas Medical web site simply notes in their software update note for the VC150 that it contains “Cybersecurity enhancements and bug fixes”. GE Healthcare has made the updated software available.

Johnson Controls

Johnson Controls has published an advisory discussing four vulnerabilities in their Sur-Gard System 5 receivers. They are third-party (Treck) vulnerabilities. Johnson Controls has a new version that mitigates the vulnerabilities.

NOTE: This advisory does not specifically name the four vulnerabilities identified by Treck and NCCIC-ICS, it just provides the CVE numbers; CVE-2020-25066,  CVE-2020-27336, CVE-2020-27337, and  CVE-2020-27338.

Rockwell Advisories

Rockwell published an advisory describing the fdtCONTAINER vulnerability in their FactoryTalk AssetCentre. Rockwell has a new version that mitigates the vulnerability.

 

Rockwell published an advisory describing a buffer overflow vulnerability in their MicroLogix 1400 Controller. The vulnerability was reported by Parul Sindhwad and Dr. Faruk Kazi from COE-CNDS. Rockwell provides generic mitigation measures

Siemens Advisory

Siemens published an advisory describing a missing authentication for critical function vulnerability in their SIMATIC HMI Panels. The vulnerability was reported by the Zero Day Initiative. Siemens has new versions that mitigate the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

NOTE: The advisory acknowledges the coordination efforts of CISA, so it is likely that NCCIC-ICS will publish an advisory on this vulnerability next week.

Tuesday, January 26, 2021

1 Advisory and 3 Updates Published – 1-26-21

Today CISA’s NCCIC-ICS published a control system security update for products from Fuji Electric and updated three advisories for products from Mitsubishi, Treck and Eaton.

Fuji Advisory

This advisory describes five vulnerabilities in the Fuji Tellus Lite V-Simulator and V-Server Lite. The vulnerabilities were reported by Kimiya, Khangkito – Tran Van Khang of VinCSS (Member of Vingroup), and an anonymous researcher via the Zero Day Initiative. Fuji has a newer version that mitigates the vulnerabilities. There is no indication that the researchers have been provided with an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

Stack-based buffer overflow - CVE-2021-22637,

Out-of-bounds read - CVE-2021-22655,

Out-of-bounds write - CVE-2021-22653,

Access of uninitialized pointer - CVE-2021-22639, and

Heap-based buffer overflow - CVE-2021-22641

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to execute code under the privileges of the application.

Mitsubishi Update

This update provides additional information on an advisory that was originally published on September 1st, 2020. The new information includes updated affected version and mitigation measures for:

• R12CCPU-V,

• RD55UP06-V,

• RD55UP12-V,

• RJ71GN11-T2,

• Q03UDECPU,

• QnUDEHCPU,

• QnUDVCPU,

• QnUDPVCPU

• LnCPU(-P),

• L26CPU-(P)BT,

• RnSFCPU,

• RnPCPU,

• RnPSFCPU,

• FX5-ENET,

• FX5-ENET/IP,

• FX3U-ENET-ADP,

• FX3GE-**M*/**,

• FX3U-ENET,

• FX3U-ENET-L,

• FX3U-ENET-P502,

• FX5-CCLGN-MS

• FR-A800-E Series,

• FR-F800-E Series,

• FR-A8NCG,

• FR-E800-EPA Series, and

• FR-E800-EPB Series

Treck Update

This update provides additional information on an advisory that was originally published on December 18th, 2020. The new information includes providing the researcher names from Intel that reported the advisory.

Eaton Update

This update provides additional information on an advisory that was originally reported on January 11th, 2021. The new information includes the announcement of the availability of a patch that mitigates the vulnerability.

Friday, December 18, 2020

1 Advisory Published – 12-18-20

Today the CISA NCCIC-ICS published an unusual Friday control system security advisory for products from Treck.

Treck Advisory

This advisory describes four vulnerabilities in the Treck TCP/IP stack. The vulnerabilities were reported by Intel. Treck has a new version that mitigates the vulnerabilities. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Heap-based buffer overflow - CVE-2020-25066,

• Out-of-bounds write - CVE-2020-27337, and

• Out-of-bounds read - CVE-2020-27338 and CVE-2020-27336

NOTE: These vulnerabilities are in a version where the Ripple20 vulnerabilities had already been corrected. I would suspect that just about everyone that was affected by Ripple20 as a third-party vulnerability will be affected by this.

Thursday, August 20, 2020

1 Advisory and 1 Update Published – 8-20-20


Today the CISA NCCIC-ICS published one medical device cybersecurity advisory for products from Philips and updated one control system security advisory for products from Treck.

Philips Advisory


This advisory describes three vulnerabilities in the Philips SureSigns VS4 patient monitor. The vulnerabilities were reported by Cleveland Clinic. Philips has provided generic mitigations for these vulnerabilities. There is no indication that the researchers have been provided with an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Improper input validation - CVE-2020-16237,
• Improper access control - CVE-2020-16241, and
• Improper authentication - CVE-2020-16239

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerabilities to allow an attacker access to administrative controls and system configurations, which could allow changes to system configuration items causing patient data to be sent to a remote destination.. The Philips advisory notes that: “This potential vulnerability does not impact patient safety.”

Treck Update


This update provides additional information on the Ripple20 advisory that was originally published on June 16th, 2020 and most recently updated on July 21st, 2020. The new information includes a link to a vendor advisory from Johnson Controls for their Sur-Gard System 5 receivers.

NOTE: NCCIC-ICS still has not reported the Siemens Ripple20 advisory that I discussed on July 18th, 2020

Tuesday, July 21, 2020

1 Update Published – 7-21-20


Today the CISA NCCIC-ICS published an update for a control system security advisory for products from Treck.

Treck Update


This update provides additional information on an advisory that was originally published on June 16th, 2020 and most recently updated on July 14th, 2020. The new information includes a link to the ABB advisory for the Ripple20 vulnerabilities.

NOTE: NCCIC-ICS has still not included a link to the Siemens advisory for their SPPA-T3000 Solutions distributed control system that I mentioned last Saturday.

Wednesday, July 15, 2020

12 Updates Published – 7-14-20


Yesterday CISA NCCIC-ICS published 11 control system security updates for products from Siemens (10) and Treck. They also published a medical device security update for products from Baxter.

PROFINET Update #1


This update provides additional information on an advisory that was originally published on May 9th, 2017 and most recently updated on October 8th, 2019. The new information includes adding SIMATIC TDC CP51M1 and CPU555 to the list of affected products.

Industrial Products Update #1


This update provides additional information on an advisory that was originally published on December 5th, 2017 and most recently updated on October 8th, 2019. The new information includes adding SIMATIC TDC CP51M1 and CPU555 to the list of affected products.

SCALANCE Update


This update provides additional information on an advisory that was originally published on August 15th, 2019. The new information includes adding mitigation links and updating affected version data for  SCALANCE XB-200, XC-200, XP-200,XF-200BA and XR-300WG.

PROFINET Update #2


This update provides additional information on an advisory that was originally published on October 10th, 2019 and most recently updated on March 14th, 2020. The new information includes adding  SIMATIC TDC CP51M1 and CPU555 to the list of affected products.

S7-1200 Update


This update provides additional information on an advisory that was originally published on November 14th 2019 and most recently updated on December 10th, 2019. The new information includes mitigation links and updated version information for SIMATIC S7-1200 and SIMATIC S7-200 SMART.

SIMATIC Update #1


This update provides additional information on an advisory that was originally published on February 11th, 2020 and most recently updated on May 12th, 2020. The new information includes mitigation links and updated version information for SIMATIC PCS 7 V9.0.

Industrial Products Update #2


This update provides additional information on an advisory that was originally published on February 11th, 2020. The new information includes mitigation links and updated version information for IE/PB LINK PN IO.

SIMATIC Update #2


This update provides additional information on an advisory that was originally published on March 10th, 2020. The new information includes:

• Adding SIMATIC TDC CP51M1 and SIMATIC TDC CPU555 to the list of affected products, and
• Adding mitigation links and updated affected version information for SINUMERIK 840D sl.

SIMATIC Update #3


This update provides additional information on an advisory that was originally published on July 9th, 2020. The new information includes mitigation links and updated version information for SIMATIC PCS 7 V9.0.

SIMATIC Update #4


This update provides additional information on an advisory that was originally published on July 9th, 2020. The new information includes mitigation links and updated version information for:

• SIMATIC STEP 7 V13,
• SIMATIC STEP 7 V16,
• SIMATIC WinCC Runtime Professional V13,
• SIMATIC WinCC Runtime Professional V16, and
• SIMATIC WinCC Runtime Advanced

Treck Update


This update provides additional information on an advisory that was was originally published on June 16th, 2020 and most recently updated on July 7th, 2020. The new information includes links to vendor advisories from DIGI International and Meile.

NOTE 1: I briefly mentioned the Meile advisory last Saturday.

NOTE 2: NCCIC-ICS missed the Siemens' Treck related advisory, more on that this weekend.

Baxter Update


This update provides additional information on an advisory that was was originally reported on June 18th, 2020 and most recently updated on June 23rd, 2020. The new information includes additional mitigation information for one version of Prismaflex.

Other Siemens Updates


There were two additional updated advisories published yesterday by Siemens that were not addressed by NCCIC-ICS. I will look at those on Saturday.

Tuesday, July 7, 2020

2 Advisories and 1 Update Published – 7-7-20


Today the CISA NCCIC-ICS published two control system security advisories for products from Mitsubishi and Grundfos. The also updated an advisory for products from Treck. CISA also started a new control system security initiative.

Mitsubishi Advisory


This advisory describes six vulnerabilities in the Mitsubishi GOT2000. These vulnerabilities are in the third-party CoreOS. The vulnerabilities are self-reported. Mitsubishi provided instructions on how to update the CoreOS version.

The six reported vulnerabilities are:

• Improper restriction of operations within the bounds of a memory buffer - CVE-2020-5595,
• Session fixation - CVE-2020-5596,
• Null pointer dereference - CVE-2020-5597,
• Improper access control - CVE-2020-5598,
• Argument injection - CVE-2020-5599, and
• Resource management errors - CVE-2020-5600

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow a remote attacker to cause a denial-of-service condition or remote code execution.

NOTE 1: I briefly discussed these vulnerabilities last Saturday.

NOTE 2: NCCIC-ICS did not provide a link to the Mitsubishi advisory.

Grundfos Advisory


This advisory describes two vulnerabilities in the Grundfos CIM 500 communications module. The vulnerabilities were reported by Marcin Dudek from CERT.PL. Grundfos has a new firmware version that mitigates the vulnerabilities. There is no indication that Dudek has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Missing authentication for critical function - CVE-2020-10605, and
• Unprotected storage of credentials - CVE-2020-10609

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow access to cleartext credential data.

Treck Update


This update provides new information on the Ripple20 advisory that was originally published on June 16th, 2020 and most recently updated on June 30th, 2020. The new information includes links to vendor advisories:

• Opto22 (includes list of affected products, new firmware pending), and
• Smiths Medical (includes list of affected products, update pending),

NOTE: NCCIC-ICS has not yet identified the Moxa advisory that I mentioned Saturday.

Mitsubishi Update


This update provides new information on an advisory that was originally published on June 23rd, 2020. The new information includes:

• Correcting the CVE number to that originally reported by Mitsubishi, and
• Adding a link for contacting Mitsubishi about the vulnerability.

[Added 9:20 EDT, 7-7-20; Missed email (SIGH)]


ICS Security Initiative 


CISA has released its five-year industrial control systems (ICS) strategy: Securing Industrial Control Systems: A Unified Initiative. This 11-page document is a high-level analysis of the current ICS security problem and an aspirational look at how CISA plans on dealing with the problems associated with securing the wide swath of security systems involved in the National Critical Functions (NCF) recently defined by CISA. Probably more on this tomorrow.

Tuesday, June 30, 2020

2 Advisories and 2 Updates Published – 6-30-20


Today the CISA NCCIC-ICS published two control system security advisories for products from Mitsubishi Electric and Delta Industrial. They also updated two advisories for products from Treck and Inductive Automation.

Mitsubishi Advisory


This advisory describes two vulnerabilities in the Mitsubishi Factory Automation Engineering Software Products. The vulnerabilities are self-reported. Mitsubishi has new versions that mitigate the vulnerabilities.

The two reported vulnerabilities are:

• Improper restriction of XML external entity reference - CVE-2020-5602, and
• Uncontrolled resource consumption - CVE-2020-5603

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow a local attacker to send files outside of the system as well as cause a denial-of-service condition.

NOTE: NCCIC-ICS did not provide a link to the Mitsubishi advisory.

Delta Advisory


This advisory describes two vulnerabilities in the Delta Industrial Automation DOPSoft HMI editing software. The vulnerabilities were reported by Natnael Samson (@NattiSamson) via the Zero Day Initiative. Delta expects to have a new version to mitigate these vulnerabilities available next month (July).

The two reported vulnerabilities are:

• Out-of-bounds read - CVE-2020-10597, and
• Heap-based buffer overflow - CVE-2020-14482

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

Treck Update


This update provides new information on an advisory that was originally published on June 16th, 2020 and most recently updated on June 18th, 2020. The new information includes the addition of links to two new affected vendors’ advisories:

• CareStream and
• Eaton

NOTE: I briefly mentioned the Eaton advisory last Saturday.

Inductive Update


This update provides new information on an advisory that was originally published on May 26th, 2020 and most recently updated on June 2nd, 2020. The new information includes:

• The addition of a new vulnerability – missing authentication for critical function - CVE-2020-14479, and
• A note that it will be corrected in an expected future version update.


NOTE: There is no mention of the two updates listed above on either the CISA Industrial Control Systems landing page or the associated Recently Published page. Fortunately ICS-CERT (ics-cert@ncas.us-cert.gov) sent out email notifications and TWEETS® on the two updates.

Friday, June 19, 2020

11 Advisories and 1 Update Published – 6-18-20


Today the CISA NCCIC-ICS published five control system security advisories for products from Rockwell Automation (2), ICONICS, Mitsubishi Electric, and Johnson Controls; and six medical device security advisories for products from BD, BIOTRONIC and Baxter (6). They also updated the Treck TCP/IP advisory that was published earlier this week.

FactoryTalk View SE Advisory


This advisory describes four vulnerabilities in the Rockwell FactoryTalk View SE. The vulnerabilities were reported by the Zero Day Initiative. Rockwell has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Improper input validation - CVE-2020-12029,
• Improper restriction of operations within a memory buffer - CVE-2020-12031,
• Permissions, privileges, and access control - CVE-2020-12028, and
• Exposure of sensitive information to an unauthorized actor - CVE-2020-12027

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow a remote authenticated attacker to manipulate data of affected devices.

NOTE: These vulnerabilities were discovered in the Pwn-2-Own competition at this year’s S4 Security conference in Miami, Florida.

FactoryTalk Services Platform Advisory


This advisory describes an improper input validation vulnerability in the Rockwell FactoryTalk Services Platform. No vulnerability disclosure information is provided in the advisory. Rockwell provides generic mitigation measures.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an unauthenticated attacker to execute remote COM objects with elevated privileges.

NOTE: These vulnerabilities were discovered in the Pwn-2-Own competition at this year’s S4 Security conference in Miami, Florida.

ICONICS Advisory


This advisory describes five vulnerabilities in the ICONICS GENESIS64 and GENESIS32 products. The vulnerabilities were reported by Tobias Scharnowski, Niklas Breitfeld, Ali Abbasi, Yehuda Anikster of Claroty; Pedro Ribeiro and Radek Domanski of Flashback; Ben McBride of Oak Ridge National Laboratory; and Steven Seeley and Chris Anastasio of Incite. ICONICS has patches that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Out-of-bounds write - CVE-2020-12011,
• Deserialization of untrusted data (3) - CVE-2020-12015, CVE-2020-12009, and CVE-2020-12007, and
• Code injection - CVE-2020-12013

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow remote code execution or denial of service.

NOTE: ICONICS takes an unusual approach to the publication of security advisories. The two separate product advisories for this NCCIC-ICS report (GENESIS64 and GENESIS32) contains summaries of all the vulnerabilities reported to/by NCCIC-ICS (and its predecessor, ICS-CERT) since 2011. If/when new vulnerabilities are reported, they are added to the respective product vulnerability report.

Mitsubishi Advisory


This advisory describes five vulnerabilities in the Mitsubishi MC Works64 MC Works32 products. The vulnerabilities were reported by Tobias Scharnowski, Niklas Breitfeld, Ali Abbasi, Yehuda Anikster of Claroty; Pedro Ribeiro and Radek Domanski of Flashback; Ben McBride of Oak Ridge National Laboratory; and Steven Seeley and Chris Anastasio of Incite. Mitsubishi has patches that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Out-of-bounds write - CVE-2020-12011,
• Deserialization of untrusted data (3) - CVE-2020-12015, CVE-2020-12009, and CVE-2020-12007, and
• Code injection - CVE-2020-12013

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit these vulnerabilities to allow remote code execution, a denial-of-service condition, information disclosure, or information tampering.

NOTE 1: The reporting information and CVE numbers indicate that these are the same vulnerabilities reported in the ICONICS advisory above. It is interesting to note the differing exploit information in the two advisories.

NOTE 2: Mitsubishi now has a publicly available PSIRT page.

Johnson Controls Advisory


This advisory describes an improper verification of cryptographic signature vulnerability in the Johnson Controls exacqVision product. The vulnerability was reported by Michael Norris. Johnson Controls has newer versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow the execution of operating system commands on the system. It would seem that [IMO] a social engineering attack would be required to cause a person with administrative privileges to potentially download and run a malicious executable.

BD Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the BD Alaris PCU. The vulnerability is self-reported. BD provides generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial of service (DoS) on the target system and could cause the BD Alaris PCU to disconnect from the facility’s wireless network.

NOTE: This vulnerability is one of three SACK vulnerabilities reported in the FreeBSD and Linux kernels. It would seem to me that the other two vulnerabilities might also be found in this product.

BIOTRONIK Advisory


This advisory describes five vulnerabilities in the BIOTRONIK CardioMessenger II-S T-Line and CardioMessenger II-S GSM products. The vulnerabilities were reported by Guillaume Bour, Anniken Wium Lie, and Marie Moe. BIOTRONIK has provided generic workarounds to mitigate the vulnerability.

The five reported vulnerabilities are:

• Improper authentication (2) - CVE-2019-18246 and CVE-2019-18252,
• Cleartext transmission of sensitive information - CVE-2019-18248,
• Missing encryption of sensitive data - CVE-2019-18254, and
• Storing passwords in an accessible format - CVE-2019-18256

NCCIC-ICS reports that a relatively low-skilled attacker with physical access to the device could exploit the vulnerabilities to obtain sensitive data, obtain transmitted medical data from implanted cardiac devices with the implant’s serial number or impact Cardio Messenger II product functionality. The same attacker with adjacent access could exploit the vulnerabilities to allow an attacker with adjacent access to influence communications between the Home Monitoring Unit (HMU) and the Access Point Name (APN) gateway network.

NOTE: See this TWITTER thread by Marie Moe about this advisory.

Sigma Spectrum Infusion Pump Advisory


This advisory describes six vulnerabilities in the Baxter Sigma Spectrum Infusion systems. The vulnerabilities are self-reported. Baxter provided generic workarounds to mitigate the vulnerabilities.

The six reported vulnerabilities are:

• Use of hard-coded passwords (3) - CVE-2020-12039, CVE-2020-12045 and CVE-2020-12047,
• Cleartext transmission of sensitive data - CVE-2020-12040,
• Incorrect permission assignment for critical resource - CVE-2020-12041, and
• Operation on a resource after expiration or release - CVE-2020-12043

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow access to sensitive data, alteration of system configuration, and impact to system availability.

NOTE: NCCIC-ICS did not provide a link to the related Baxter advisory.

Phoenix Hemodialysis Advisory


This advisory describes a cleartext transmission of sensitive information vulnerability in the Baxter Phoenix Hemodialysis Delivery System. This vulnerability is self-reported. Baxter provides generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to view sensitive data.

NOTE: NCCIC-ICS did not provide a link to the related Baxter advisory.

PrismaFlex Advisory


This advisory describes three vulnerabilities in the Baxter PrismaFlex and PrisMax medical systems. The vulnerabilities are self-reported. Baxter has new versions that mitigate the vulnerabilities.

The three reported vulnerabilities are:

• Cleartext transmission of sensitive information - CVE-2020-12036;
• Improper authentication - CVE-2020-12035, and
• Use of hard-coded passwords - CVE-2020-12037

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to view and alter sensitive data.

NOTE: NCCIC-ICS did not provide a link to the related Baxter advisory.

ExactaMix Advisory


This advisory describes seven vulnerabilities in the Baxter Baxter ExactaMix systems. The vulnerabilities are self-reported. Baxter has new versions that mitigate the vulnerabilities.

The seven reported vulnerabilities are:

• Use of hard-coded password (2) - CVE-2020-12016 and CVE-2020-12012,
• Cleartext transmission of sensitive information - CVE-2020-12008,
• Missing encryption of sensitive data - CVE-2020-12032,
• Improper access control - CVE-2020-12024,
• Exposure of resource to wrong sphere - CVE-2020-12020, and
• Improper input validation - CVE-2017-0143

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow unauthorized access to sensitive data, alteration of system configuration, alteration of system resources, and impact to system availability.

NOTE: NCCIC-ICS did not provide a link to the related Baxter advisory.

Treck Update


This update provides additional information on an advisory that was originally published on June 16th, 2020. The new information is a link to the Baxter advisory on the issue.

Tuesday, June 16, 2020

1 Advisory and 1 Update Published – 6-16-20


Today the NCCIC-ICS published a control system security advisory for products from Treck. They also updated an earlier advisory for products from Mitsubishi.

Treck Advisory


This advisory describes 19 vulnerabilities in the Treck TCP/IP stack. The vulnerabilities were reported (Ripple20) by Shlomi Oberman and Moshe Kol from JSOF. Treck has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The 19 reported vulnerabilities are:

• Improper handling of length parameter inconsistency (4) - CVE-2020-11896, CVE-2020-11897, CVE-2020-11898, CVE-2020-11907,
• Improper input validation (9) - CVE-2020-11899, CVE-2020-11901, CVE-2020-11902, CVE-2020-11906, CVE-2020-11909, CVE-2020-11910, CVE-2020-11912, CVE-2020-11913, CVE-2020-11914
• Double free - CVE-2020-11900,
• Out-of-bounds read (2) - CVE-2020-11903, CVE-2020-11905,
• Integer overflow or wraparound - CVE-2020-11904,
• Improper null termination - CVE-2020-11908,
• Improper access control - CVE-2020-11911,

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerabilities to allow remote code execution or exposure of sensitive information. NOTE: There is publicly available (registration required) exploit code for two of the vulnerabilities; CVE-2020-11896 RCE, and CVE-2020-11898 Info Leak.

NOTE: The Treck TCP/IP stack is used by a number of vendors. NCCIC reports that the following vendors have prepared advisories for their affected products (no real mitigations available yet):

• B.Braun



Mitsubishi Update


This update provides additional information on an advisory that was originally published on June 9th, 2020. The new information includes revised mitigation instructions.

 
/* Use this with templates/template-twocol.html */