Showing posts with label Tri Quach. Show all posts
Showing posts with label Tri Quach. Show all posts

Friday, November 8, 2019

4 Advisories and 1 Update Published – 11-07-19


Yesterday the CISA NCCIC-ICS published two control system security advisories for products from Fuji Electric and Mitsubishi Electric; and two medical device security advisories for products from Medtronic (2). The also updated a previously published medical device advisory for products from Philips.

Fuji Advisory


This advisory describes a heap-based buffer overflow vulnerability in the Fuji V-Server. The vulnerability was reported by kimiya of 9SG via the Zero Day Initiative. Fuji has a new version that mitigates the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to crash the device being accessed; several heap-based buffer overflows have been identified.

Mitsubishi Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the Mitsubishi MELSEC-Q Series and MELSEC-L Series CPU Modules. The vulnerability was reported by Tri Quach of Amazon’s Customer Fulfillment Technology Security (CFTS) group. Mitsubishi has a new firmware version that mitigates the vulnerability. There is no indication that Tri has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to prevent the FTP client from connecting to the FTP server on MELSEC-Q Series and MELSEC-L Series CPU module. Only FTP server function is affected by this vulnerability.

Medtronic Advisory #1


This advisory describes two RFID security vulnerabilities in the Medtronic Valleylab energy and electrosurgery products. The vulnerabilities are self-reported. Medtronic has a patch available to mitigate the vulnerabilities.

The two reported vulnerabilities are:

• Improper authentication - CVE-2019-13531; and
• Protection mechanism failure - CVE-2019-13535

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to connect inauthentic instruments to the affected products by spoofing RFID security mechanisms. This may lead to a loss of performance integrity and platform availability due to incorrect identification of instrument and associated parameters.

Medtronic Advisory #2


This advisory describes four vulnerabilities in the Medtronic Valleylab energy products. The vulnerabilities are self-reported. Medtronic has patches available to mitigate the vulnerability.

The four reported vulnerabilities are:

• Use of hard-coded credentials - CVE-2019-13543;
• Reversible one-way hash - CVE-2019-13539; and
• Improper input validation (2) - CVE-2019-3464, and CVE-2019-3463.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to  allow an attacker to overwrite files or remotely execute code, resulting in a remote, non-root shell on the affected products. By default, the network connections on these devices are disabled. Additionally, the Ethernet port is disabled upon reboot. However, it is known that network connectivity is often enabled.

Philips Update


This update provides new information for and advisory that was originally reported on April 30th, 2019.
The new information includes:

• Revised (increased) overall CVSS score;
• Information exposure vulnerability added;
• Added Tasy WEbPortal to affected product list;
• Added Trabalho Médico IT Department as a vulnerability reporter; and
• Reported that a new version mitigates the vulnerabilities.

Tuesday, August 20, 2019

1 Advisory, 2 Updates Published – 08-20-19

Today the DHS NCCIC-ICS published a control system security advisory for products from Zebra and two updates for advisories for products from Siemens and Sierra Wireless.

Zebra Advisory

This advisory describes an insufficiently protected credentials vulnerability in the Zebra Industrial Printers. The vulnerability was reported by Tri Quach. Zebra has a new version that mitigates the vulnerability. There is no indication that Tri has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow a remote attacker to send specially crafted packets to a port on the printer, resulting in the retrieval of a front control panel passcode.

Siemens Update

This update provides new information on an advisory that was originally published on August 13th, 2019. NCCIC-ICS changed the vulnerability description from ‘uncontrolled resource consumption’ to ‘insufficient resource pool’. There was no corresponding change in the Siemens advisory; Siemens does not use CWE vulnerability titles or codes in their advisories.

Sierra Wireless Update

This update provides new information on an advisory that was originally published on May 2nd, 2019. The  update reports that the ALEOS 4.12.0 Release Note is now available.

Tuesday, January 29, 2019

5 Advisories Published – 01-29-19


Today the DHS NCCIC-ICS published three control system security advisories for products from AVEVA, Mitsubishi, and Yokogawa. They also published two medical device security advisories for products from BD and Stryker.

AVEVA Advisory


This advisory describes an insufficiently protected credential vulnerability in the AVEVA
Wonderware System Platform. The vulnerability was reported by Vladimir Dashchenko from Kaspersky Lab. AVEVA has an update that mitigates the vulnerability. There is no indication that Daschenko has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow unauthorized access to the credentials for the ArchestrA Network User Account.

NOTE: I briefly discussed this advisory last Saturday.

Mitsubishi Advisory


This advisory describes a resource exhaustion vulnerability in the Mitsubishi MELSEC-Q series PLCs. The vulnerability was reported by Tri Quach of Amazon’s Customer Fulfillment Technology Security (CFTS) group. Mitsubishi has a new firmware version that mitigates the vulnerability. There is no indication that Tri has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a remote attacker to send specially crafted packets to the device, causing Ethernet communication to stop.

Yokogawa Advisory


This advisory describes an unrestricted upload of files with dangerous type vulnerability in the Yokogawa License Manager Service. The vulnerability was reported by Kaspersky Lab. The latest version mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NOTE: I briefly discussed this advisory last Saturday.

BD Advisory


This advisory describes an improper access control vulnerability in the BD FACSLyric. This vulnerability was self-reported. BD will directly apply mitigation measures to the affected systems.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to gain unauthorized access to administrative level privileges on a workstation, which could allow arbitrary execution of commands. This vulnerability does not impact BD FACSLyric flow cytometry systems using the Windows 7 Operating System.

NOTE: This is not the BD advisory that I briefly discussed last Saturday.

Stryker Advisory


This advisory describes a reusing a nonce vulnerability. advisory for the Stryker Secure II MedSurg Bed, S3 MedSurg Bed, and InTouch ICU Bed products. This is for the Key Reinstallation Attack – (KRACK) set of vulnerabilities. This advisory only reports nine of the ten CVE’s for the KRACK vulnerability. Stryker has software updates to mitigate the vulnerability.

 
/* Use this with templates/template-twocol.html */