Showing posts with label Tridium. Show all posts
Showing posts with label Tridium. Show all posts

Saturday, August 22, 2020

Public ICS Disclosures – Week of 8-15-20


This week we have three vendor disclosures for products from Phoenix Contact, Moxa, and Eaton and one update from Rockwell. There are researcher reports for products from WECON. There were two control system exploits published for products from PNPSCADA and Geutebruck.

Phoenix Contact Advisory


Phoenix Contact published an advisory [.PDF download link] describing a synchronous access of remote resource without timeout vulnerability in their Emalytics, ILC 2050 BI and ILC 2050 BI-L products. This is a third-party vulnerability in the Tridium Niagara product that was reported earlier this month by NCCIC-ICS. Phoenix Contact reports that they expect to fix this vulnerability in the next firmware update in October 2020.

Moxa Advisory


Moxa published an advisory describing six vulnerabilities in their NPort IAW5000A-I/O Series Serial Device Servers. The vulnerabilities were reported by Evgeniy Druzhinin and Ilya Karpov of Rostelecom-Solar. Moxa has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Session fixation,
• Improper privilege management,
• Weak password requirements,
• Cleartext transmission of sensitive information,
• Improper restriction of excessive authentication attempts, and
• Information exposure

Eaton Advisory


Eaton published an advisory describing two vulnerabilities in their Secure Connect Android Mobile app. The vulnerability was reported by Vishal Bharad. Eaton has a new version that mitigates the vulnerabilities. There is no indication that Bharad has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Information exposure, and
• Information exposure through log files

Rockwell Update


Rockwell published an update for an advisory that was originally published on July 8th, 2020 and most recently updated on July 23rd, 2020. The new information includes links to additional detections.

WECON Reports


The Zero Day Initiative has published (ZDI-20-1055 thru ZDI-20-1076) 22 reports of 0-day vulnerabilities in the WECON LeviStudioU. The vulnerabilities have been reported to ‘ICS-CERT’ (presumably CISA NCCIC-ICS) which reportedly received no response from WECON. The vulnerabilities were reported by Natnael Samson. The vulnerabilities are all stack-based buffer overflows in various components of the LeviStudioU product. NO CVEs have been reported.

PNPSCADA Exploit


İsmail ERKEK published an exploit for an SQL injection vulnerability in the PNPSCADA. There is no CVE for this vulnerability and there is no indication that ERKEK has contacted the vendor, so this looks like it is a 0-day vulnerability.

Geutebruck Exploit


Davy Douhine published a Metasploit module for an authenticated arbitrary command execution vulnerability in Geutebruck G-Cam and G-Code cameras. This vulnerability was previously reported by NCCIC-ICS.

Wednesday, August 12, 2020

8 Advisories Published – 8-12-20


Yesterday the CISA NCCIC-ICS published eight control system security advisories for products from Siemens (5), Tridium, Schneider, and Yokogawa. There were also 22 updates published but those will be dealt with in a later blog post.

SICAM Advisory


This advisory describes a cross-site scripting vulnerability in the Siemens  SICAM A8000 RTUs. The vulnerability was reported by Emma Good from KTH Royal Institute of Technology. Siemens has a new version that mitigates the vulnerability. There is no indication that Good has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit this vulnerability to compromise the confidentiality, integrity, and availability of the web application.

Automation License Advisory


This advisory describes an improper authorization vulnerability in the Siemens Automation License Manager. The vulnerability was reported by Lasse Trolle Borup of Danish Cyber Defense. Siemens has a new version of ALM6 that mitigates the vulnerability. There is no indication that Borup has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow an attacker to locally escalate privileges and modify files that should be protected against writing.

Desigo Advisory


This advisory describes a code injection vulnerability in the Siemens Desigo CC building management platform. This vulnerability is self-reported. Siemens has patches available that mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to gain remote code execution on the server with SYSTEM privileges.

Simatic Advisory


This advisory describes the kr00k vulnerability in the Siemens SIMATIC and SIMOTICS wi-fi services. This is a third-party vulnerability in the Broadcom Wi-Fi client devices with publicly available exploits. Siemens has provided generic workarounds pending development of updates.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to read a discrete set of traffic over the air after a Wi-Fi device state change. NCCIC-ICS provides no mention of the publicly available exploits.

SCALANCE Advisory


This advisory describes a classic buffer overflow in the Siemens SCALANCE and RUGGEDCOM products. This is the Linux Point-to-Point Protocol Daemon (pppd) Vulnerability reported in March and proof-of-concept exploit code is available. Siemens has updates available to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to gain unauthenticated access to a device and cause a buffer overflow to execute custom code. NCCIC-ICS provides no mention of the publicly available exploits.

Tridium Advisory


This advisory describes a synchronous access of remote resource without timeout vulnerability in the Tridium Niagara product. The vulnerability was self-reported. Tridium has updates that mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker on an adjacent network could exploit the vulnerability to result in a denial-of-service condition.

Schneider Advisory


This advisory describes two path traversal vulnerabilities in the Schneider APC Easy UPS On-Line. The vulnerabilities were reported by rgod via the Zero Day Initiative. Schneider has a new version that mitigates the vulnerability. There is no indication that rgod has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to lead to remote code execution.

NOTE: Schneider also published six other advisories yesterday.

 

Yokogawa Advisory


This advisory describes two vulnerabilities in the Yokogawa CENTUM distributed control system. The vulnerabilities were reported by Nataliya Tlyapova, Ivan Kurnakov, and Positive Technologies. Yokogawa has patches that mitigate the vulnerabilities for products still under support. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper authentication - CVE-2020-5608, and
• Path traversal CVE-2020-5609

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a remote unauthenticated attacker to send tampered communication packets or create/overwrite any file and run any commands.

NOTE: I briefly discussed these vulnerabilities on August 1st.

Thursday, September 19, 2019

1 Advisory and 2 Updates Published – 09-19-19


Today the DHS NCCIC-ICS published one control system security advisory for products from Tridium and updates to two previously published advisories for products from WECON and Rockwell.

Tridium Advisory


This advisory describes two third-party vulnerabilities in the Tridium Niagara product. The vulnerabilies are in the Blackberry QNX operating system. The vulnerabilities were reported by Johannes Eger and Fabian Ullrich of Secure Mobile Networking Lab, and Francisco Tacliad. Tridium has updates that mitigate the vulnerabilities. There is no indication that the researchers have been provided the opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Information exposure - CVE-2019-8998; and
Improper authorization - CVE-2019-13528

NCCIC-ICS reported that a relatively low-skilled attacker with local access could exploit the vulnerabilities to allow a local user to escalate their privileges.

NOTE: Blackberry has published an advisory on the first vulnerability.

WECON Update


This update provides additional information on an advisory that was originally published on February 5th, 2019. The new information includes updated affected versions and mitigation information.

Rockwell Update


This update provides additional information on an advisory that was originally published on August 1st, 2019 and then updated on 09-05-19. The new information is the addition of a new vulnerability; access of uninitialized pointer - CVE-2019-13527.

NOTE: The updated Rockwell security advisory reports that  kimiya of 9SG Security Team has reported 7 additional vulnerabilities, bringing the total to 15 for the Rockwell Arena Simulation Software.



Tuesday, January 22, 2019

Two Advisories Published – 01-22-19


Today the DHS NCCIC-ICS published a control system security advisory for products from Johnson Controls and a medical device security advisory for products from Drager.

Johnson Controls Advisory


This advisory describes two vulnerabilities in the Johnson Controls Facility Explorer. The vulnerabilities were reported by Tridium. Johnson Controls has new versions that mitigate the vulnerabilities. There is no indication that Tridium has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Path traversal - CVE-2017-16744; and
Improper authentication - CVE-2017-16748

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit these vulnerabilities to allow an attacker to read, write, and delete sensitive files to gain administrator privileges in the Facility Explorer system.

Drager Advisory


This advisory describes three vulnerabilities in the Drager Infinity Delta patient monitoring devices. The vulnerabilities were reported by Marc Ruef and Rocco Gagliardi, of scip AG. Drager has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Improper input validation - CVE-2018-19010;
• Information exposure through log files - CVE-2018-19014; and
• Improper privilege management - CVE-2018-19012

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to cause information disclosure of device logs, denial of service through device reboots of the patient monitors, and privilege escalation.

NOTE: The Drager security advisory adds an additional vulnerability for one of the affected products; “Several 3rd party components were found outdated and vulnerable to several published security vulnerabilities.”

Friday, January 11, 2019

Four Advisories and One Update Published – 01-10-19


Yesterday the DHS ICS-CERT published four control system security advisories for products from Tridium, Pilz, Omron and Emerson. They also updated a previously issued advisory for products from Schneider. The Tridium advisory was originally posted to the HSIN ICS-CERT library on November 29, 2018.

Tridium Advisory


This advisory describes a cross-site scripting vulnerability in the Niagara Enterprise Security, Niagara AX, and Niagara 4 products. The vulnerability was reported by Daniel Santos and Elisa Costante of SecurityMatters. Tridium has new versions available that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an authenticated user to inject client-side scripts into some web pages that could then be viewed by other users.

NOTE: The link to the Tridium bulletin is for a .PDF download. Registered users can view the bulletin here.

Pilz Advisory


This advisory describes a clear-text storage of sensitive information vulnerability in the Pilz PNOZmulti Configurator tool. The vulnerability was reported by Gjoko Krstikj of Applied Risk. Pilz has a new version that mitigates the vulnerability. There is no indication that Krstikj was provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow sensitive data to be read from the system.

Omron Advisory


This advisory describes a type confusion vulnerability in the Omron CX-Protocol within CX-One. The vulnerability was reported by Esteban Ruiz (mr_me) of Source Incite via the Zero Day Initiative. Omron has a new version that mitigates the vulnerability. There is no indication that Ruiz has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to execute code under the privileges of the application.

Emerson Advisory


This advisory describes an authentication bypass vulnerability in the Emerson DeltaV Distributed Control System Workstations. The vulnerability was reported by Alexander Nochvay of Kaspersky Lab. Emerson has a patch that mitigates the vulnerability. There is no indication that Nochvay has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to shut down a service, resulting in a denial of service.

Schneider Update


This update provides additional information on an advisory that was originally published on February 23rd, 2017. The new information includes:

• New researcher acknowledgements; and
New products affected.

Friday, August 17, 2018

ICS-CERT Publishes 3 Advisories


Yesterday the DHS ICS-CERT published two control system security advisories for products from Tridium and Emerson and a medical device security advisory for products from Philips. The Tridium advisory was previously published on the HSIN ICS-CERT library on July 10, 2018. For more on this HSIN resource see the final section below.

Tridium Advisory


This advisory describes two vulnerabilities in the Tridium Niagara controller. The vulnerabilities were reported by Johnathan Gains and Leet Cyber Security. Tridium has updates available that mitigate the vulnerability. There is no indication that that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Path traversal - CVE-2017-16744; and
Improper authentications - CVE-2017-16748

ICS-CERT reports that an uncharacterized attacker could remotely exploit these vulnerabilities to crash the device being accessed; a buffer overflow condition may allow remote code execution.

Emerson Advisory


This advisory describes four vulnerabilities in the Emerson DeltaV DCS Workstations. The vulnerabilities were reported by Younes Dragoni of Nozomi Networks, Ori Perez of CyberX. Emerson has a patch available that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Uncontrolled search path element - CVE-2018-14797;
• Relative path traversal - CVE-2018-14795;
• Improper privilege management - CVE-2018-14791; and
• Stack-based buffer overflow - CVE-2018-14793

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow arbitrary code execution, malware injection, or malware to spread to other workstations.

Philips Advisory


This advisory describes two vulnerabilities in the Philips PageWriter Cardiographs. Philips is self-reporting these vulnerabilities to ICS-CERT. Philips has produced generic workarounds and plans to issue updates to mitigate the vulnerabilities in the middle of next year.

The two reported vulnerabilities are:

• Improper input validation - CVE-2018-14799; and
• Use of hard-coded credentials - CVE-2018-14801

ICS-CERT reports that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to allow buffer overflows or allow an attacker to access and modify settings on the device.

HSIN Library


It has been a while since I mentioned the ICS-CERT library on the Homeland Security Information Network. This restricted access, on-line resource provides ICS-CERT a method of sharing information with the user community for vulnerabilities that may affect critical homeland resources. This restricted release is designed to allow owners a chance to implement mitigation measures before the vulnerability becomes public knowledge.

For more information about this program and to request access see this ICS-CERT page.

Friday, May 19, 2017

ICS-CERT Updates WannaCry Alert Again (#4)

For the fourth day in a row the DHS ICS-CERT updated their alert for the WannaCry ransomware. It was originally published on Monday and the latest update was yesterday. Today’s update adds links to WannaCry notifications from the following vendors:

Tridium; and


The update also provides a link to a general WannaCry support document from Siemens Healthineers. This document and a further linked Siemens’ blog post provides a good technical discussion of the WannaCry problem and solutions; including links to Microsoft updates for ‘unsupported’ (outdated?) Windows operating systems still in use by Siemens Healthineer (and too many other industrial control) products.
 
/* Use this with templates/template-twocol.html */