Showing posts with label Trihedral. Show all posts
Showing posts with label Trihedral. Show all posts

Thursday, October 27, 2022

Review – 4 Advisories Published – 10-27-22

Today, CISA’s NCCIC-ICS published four control system security advisories for products from Trihedral, Rockwell Automation (2), and SAUTER.

Trihedral Advisory - This advisory describes an improper input validation vulnerability in the Trihedral VTScada.

Rockwell Advisory #1 - This advisory discusses nine vulnerabilities (one with a known exploit) in the Rockwell Stratix Devices.

Rockwell Advisory #2 - This advisory describes an improper access control vulnerability in the Rockwell FactoryTalk Alarm and Events Server.

SAUTER Advisory - This advisory describes a cross-site scripting vulnerability in the SAUTER moduWeb.

 

For more details about these advisories, including links to 3rd party advisories and exploits, see my article in CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/4-advisories-published-10-27-22 - subscription required.

Tuesday, June 13, 2017

ICS-CERT Publishes 3 Advisories

Today the DHS ICS-CERT published three control system security advisories for products from Trihedral and OSIsoft. ICS-CERT continues to have problems with Siemens security advisories and updates.

PI Web API Advisory


This advisory describes cross-site request forgery vulnerability in the OSIsoft Web API. The vulnerability is self-reported. OSIsoft has produced an upgraded version and provides additional mitigation measures.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to access the PI System with the privileges of a legitimate client user (write data).

PI Server Advisory


This advisory describes two improper authentication vulnerabilities in the OSIsoft PI Server. The vulnerability is self-reported. A new version (not currently available) has been developed that mitigates the vulnerability.

ICS-CERT reports that an (uncharacterized skill level) attacker could remotely exploit the vulnerability to spoof a PI Server or cause undefined behavior within the PI Network Manager.

Trihedral Advisory


This advisory describes three vulnerabilities in the Trihedral VTScada product. Karn Ganeshen reported the vulnerability. Trihedral has developed a patch to mitigate the vulnerability. ICS-CERT reports that Ganeshen has verified the efficacy of the fix.

The three reported vulnerabilities are:

• Uncontrolled resource consumption - CVE-2017-6043;
• Cross-site scripting - CVE-2017-6053; and
• Information exposure - CVE-2017-6045

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to result in uncontrolled resource consumption, arbitrary code execution, or information exposure.

NOTE: the VTScada upgrade notes report that “VTScada logo images are now protected by a checksum. VTScada will not start if these files have been removed or modified. If you wish to create a custom-branded application, contact Trihedral Engineering for licensing.” So it is possible that a facility is using a vulnerable system and not know it.

Missing Siemens Advisories and Updates


In addition to the five Siemens’ WannaCry updates I mentioned yesterday, there are six recently reported Siemens’ advisories and updates published that have not been reported by ICS-CERT. They are:

SSA-275839: Denial-of-Service Vulnerability in Industrial Products", June 7th;
SSA-946325: Vulnerabilities in SICAM PAS, June 9th;
SSA-732541: Denial-of-Service Vulnerability in SIPROTEC 4, June 12th;
SSA-293562: Vulnerabilities in Industrial Products, June 13th;
SSA-623229: DROWN Vulnerability in Industrial Products, June 13th; and
SSA-931064: Authentication Bypass in SIMATIC Logon, June 13th

To be fair it is probably too soon to be concerned about the last four, but the other 7 missing Siemens reportings are definite of concern.


As always thanks to the Siemens @ProductCERT for their tweets about security updates on their products.

Tuesday, December 9, 2014

ICS-CERT Publishes OpenSSL Update and 2 New (Almost) Advisories

The afternoon the DHS ICS-CERT updated (up to ‘F’ now) their Situational Awareness Alert for the OpenSSL vulnerability. They also published new advisories for vulnerabilities in systems from Trihedral Engineering and Yokogawa.

HeartBleed

This update adds ABB to the list of vendors with affected products. The Relion 650 series has a patch available to mitigate the vulnerability. There is no explanation as to why this update was so long in coming. The last HeartBleed update was published back in April and ABB published their advisory in July.

Trihedral Advisory

This advisory describes an integer overflow vulnerability in their VTS and VTScada products. The vulnerability was reported by an anonymous researcher through ZDI. ICS-CERT reports that Trihedral has produced a patch that mitigates the vulnerability.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to cause the application to crash.

Interestingly the Trihedral update page says nothing about this vulnerability in their upgrade descriptions. ZDI does report that they notified Trihedral of this vulnerability (ZDI-CAN-2599) on November 19th so this was a very quick response.

Yokogawa Advisory

This advisory reports an XML external entity processing vulnerability in the Yokogawa FAST/TOOLS application. The vulnerability was reported by Timur Yunusov, Alexey Osipov, and Ilya Karpov of Positive Technologies Inc. ICS-CERT reports that Yokogawa has developed a service pack that mitigates this vulnerability, but no mention is made that the researchers have verified the efficacy of the fix.

ICS-CERT reports that it would be difficult to craft an exploit of this vulnerability and local access would be required. Yokogawa also reports (in their CVSS calculation) that local access is required, but note that it can be exploited by an attacker that “intrudes into the WebHMI server in any way”. Something may be lost in translation there because that sounds to me like remote access could be used to exploit this vulnerability.


I mentioned earlier that Yokogawa had publicly reported this vulnerability over a week and a half ago; not very timely reporting by ICS-CERT.
 
/* Use this with templates/template-twocol.html */