Showing posts with label Trihedral Engineering. Show all posts
Showing posts with label Trihedral Engineering. Show all posts

Tuesday, October 31, 2017

ICS-CERT Publishes Two Advisories

Today the DHS ICS-CERT published two control system security advisories for products from Trihedral Engineering and ABB. The ABB advisory addresses a vulnerability that I addressed ten days ago.

Trihedral Advisory


This advisory describes two vulnerabilities in the Trihedral VTScada. The vulnerabilities were independently reported by Karn Ganeshen and Mark Cross. Trihedral has a new version that mitigates the vulnerabilities. There is no indication that either researcher has been provided the opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper access control - CVE-2017-14031;
• Uncontrolled search path element - CVE-2017-14029

ICS-CERT reports that a relatively low skilled attacker with uncharacterized access could exploit the vulnerability to allow execution of arbitrary code.

NOTE: If one were to look for one possible explanation about why owner/operators are slow to update their ICS software, one would need to look no further than the Trihedral upgrade notes for moving from v11.2 to the current version. Lots of work and lots of tools do not carry over to the newest version.

ABB Advisory


This advisory describes an improper input validation vulnerability in the ABB FOX515T. The vulnerability was reported by Ketan Bali. ABB reports that the device has been phased out and is no longer being supported. The ABB cybersecurity advisory reports that there are no work around available for this vulnerability.

ICS-CERT reports that a relatively low skilled attacker with uncharacterized access could exploit this vulnerability to craft a malicious script that would enable retrieval of any file on the server.

Commentary


Two security researchers independently detecting and reporting the same vulnerabilities is not real common, but I suspect that is more due to the reporting component of that statement rather than the detection component. This is an important concept for security researchers and vendors to remember when they decide whether or not to communicate vulnerabilities.

For vendors trying to determine whether or not to report an in-house detected vulnerability they first have to determine if they are going to (or can) patch/upgrade to mitigate the vulnerability. If they do not patch, they are risking having an independent researcher/team discover the vulnerability and either misuse it or selling it to somewhere.


If the vendor fixes the vulnerability the question arises of whether or not to report the underlying vulnerability or letting the update stand on routine improvements to the device/system. As I have mentioned before, ICS owners are slow to update for any number of reasons; the risk of a security vulnerability un-fixed may be the incentive needed to upgrade to a newer version.

Tuesday, June 7, 2016

ICS-CERT Publishes Two Advisories

This afternoon the DHS ICS-CERT published two control system security advisories for products from KMC Controls and Trihedral Engineering. The KMC Controls advisory was originally published on the US CERT Secure Portal on May 5th, 2016.

KMC Controls Advisory


This advisory describes twin vulnerabilities in the KMC Controls Conquest BACnet routers. The vulnerabilities were reported by Maxim Rupp. KMC has produced a new firmware version to mitigate the vulnerabilities. There is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.

The two vulnerabilities are:

• Cross-site request forgery - CVE-2016-4494; and
• Missing authentication for critical information - CVE-2016-4495.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerabilities to  read the configuration of the target device.

Trihedral Engineering Advisory


This advisory describes multiple vulnerabilities in the Trihedral Engineering VTScada. The vulnerabilities were reported by an anonymous researcher through the Zero Day Initiative (ZDI).

The vulnerabilities include:

• Out-of-bounds read - CVE-2016-45232F;
• Path traversal - CVE-2016-45325F; and
• Authentication bypass issues - CVE-2016-45108F.

NOTE: The CVE numbers listed above were copied directly from the advisory, but are not in the proper format. It is too early to verify the numbers in the CVE database. I suspect that the real numbers end after the first four digits following the final dash.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to download or view arbitrary files, or to cause the server to crash and not come back without being manually relaunched.


The advisory reports that the upgrade notes on the Trihedral web site provide additional help on installing the updates. Unfortunately, the firmware version that mitigates these vulnerabilities is not listed on that page. That may be because the next latest firmware version was published yesterday and the security updated version was published today.
 
/* Use this with templates/template-twocol.html */