Showing posts with label URGENT/11. Show all posts
Showing posts with label URGENT/11. Show all posts

Saturday, June 13, 2020

Public ICS Disclosures – Week of 6-6-12


This week we have seven vendor disclosures from Schneider (3), WAGO (2), Moxa and Medtronic as well as four vendor updates for advisories from Schneider (3) and Siemens. There were three researcher reports about vulnerabilities from Siemens.

Schneider Advisories


Schneider published an advisory describing an out-of-bounds write vulnerability in their Modicon M218 Logic Controller. The vulnerability was reported by CNCERT. Schneider provides generic workarounds to mitigate the vulnerability.


Schneider published an advisory describing a use of hard-coded credentials vulnerability in their Unity Loader and OS Loader Software. The vulnerability was reported by Yang Dong of DingXiang Dongjian Security Lab. Schneider provides workarounds to mitigate the vulnerability, noting that: “Hardcoded credentials are kept for compatibility with legacy products.”


Schneider published an advisory describing a null pointer dereference vulnerability in their Modicon LMC078 Logic Controller. This vulnerability is self-reported. Schneider provides generic workarounds to mitigate the vulnerability.

NOTE: This vulnerability is in a third-party (Wind River) component (IGMP) and was introduced in a patch applied to mitigate the Urgent/11 vulnerabilities. This vulnerability should be able to be found in a large number of products. I expect that we will be seeing more of this one.

WAGO Advisories


CERT-VDE published an advisory describing an improper privilege management vulnerability in the WAGO Web Based Management products. This vulnerability was reported by CISCO Talos; the report includes proof-of-concept code. WAGO provides generic workarounds to mitigate this ‘feature’.


CERT-VDE published an advisory describing a classic buffer overflow vulnerability in the WAGO Series PFC100 and Series PFC200 PLC’s. This vulnerability was reported by BSI. WAGO has new firmware that mitigates the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

NOTE: This is the third-party (LINUX) PPP daemon vulnerability that has been previously reported in other products.

MOXA Advisory


Moxa has published an advisory describing a command injection vulnerability in their VPort 461 Series Industrial Video Servers. The vulnerability was reported by Xinjie Ma from Beijing Chaitin Future Technology Co. Moxa has a patch for this phased-out product. There is no indication that Xinjie has been provided an opportunity to verify the efficacy of the fix.

Medtronic Advisory


Medtronic has published an advisory describing the Bluetooth Impersonation Attacks (BIAS) vulnerabilities in their FA Controller and  Patient Telemetry Module products. Medtronic has not yet determined what mitigation measures it will take.

NOTE: These vulnerabilities may (probably?) affect any medical device or control system component that uses Bluetooth connectivity.

Schneider Updates


Schneider published an update for their Urgent/11 advisory that was originally published on August 2nd, 2020 and most recently updated on May 12th, 2020. The new information includes updated mitigation measures for:

 • Easergy T300 and
• Magelis HMI - HMIGTO Series, HMISCU Series,  HMIGTUX Series, and HMIGTU Series (Except Open BOX) products


Schneider published an update for their EcoStruxure™ Operator Terminal Expert advisory that was originally published on May 12th, 2020. The new information includes an update of CVE-2020-7495.


Schneider published an update for their GoAhead Web Server Vulnerability that was originally published on December 10th, 2015. The new information includes:

• A note that proof-of-concept code is publicly available,
• Updated remediation informtation.

NOTE: ICS-CERT (now NCCIC-ICS) published an advisory for this vulnerability, it will be interesting to see if they get around to updating it.

Siemens Update


Siemens published an update for their Urgent/11 advisory that was originally published on May 12th, 2020. The new information includes updated version data and mitigation measures for Siemens Power Meters Series 9810.

Researcher Reports – Siemens


CISCO Talos published three research reports (here, here and here) describing vulnerabilities in the Seiemens LOGO! Products. The reports each claim CVE# CVE-2020-7589 which was reported by Siemens (and NCCIC-ICS) earlier this week as a single missing authentication for critical function vulnerability. Each Talos report includes separate proof-of-concept code.

Sunday, March 15, 2020

Public ICS Disclosures – Week of 3-7-20 Part II


In addition to the vendor disclosures I discussed yesterday, we have four vendor disclosures from Schneider and three updated disclosures from Schneider and Siemens (2).

Schneider Advisories


Schneider published an advisory describing two vulnerabilities in the Schneider Interactive Graphical SCADA System (IGSS). The vulnerabilities were reported by an anonymous researcher via the Zero Day Initiative. Schneider has a new version that mitigates the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper limitation of a path name to a restricted directory - CVE-2020-7478; and
• Missing authentication for a critical function - CVE-2020-7479


Schneider published an advisory describing an improper check for unusual or exceptional conditions vulnerability in the Schneider Modicon Quantum Ethernet Network module and Quantum / Premium COPRO. The vulnerability was reported by China Information Technology Security Evaluation Centre (CNITSEC). Schneider has a new version for the Quantum Ethernet Network module that mitigates the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.


Schneider published an advisory describing an untrusted search path vulnerability in the Schneider ZigBee Installation Toolkit. The vulnerability was reported by Yongjun Liu of nsfocus. Schneider has a new version that mitigates the vulnerability. There is no indication that Liu has been provided an opportunity to verify the efficacy of the fix.


Schneider published an advisory describing three vulnerabilities in the Schneider Andover Continuum Line of Controllers. The vulnerabilities were reported by Niv Levy. Schneider provided generic mitigation measures for this product that is no longer under service support.

Schneider Update


Schneider has published an update for their Urgent/11 advisory that was originally published on August 2nd, 2019 and most recently updated on February 11th, 2020. The new information includes mitigation measures for:

• HMIGXU;
• Easergy MiCOM P30;
• Tricon Communication Modules; and
• Trident Communication Integration Module

Siemens Updates


Siemens published an update for an advisory for Intel CPUs that was originally published on February 11th, 2020. The new information includes updated version and mitigation data for:

• SIMATIC IPC127El;
• SIMATIC IPC627E;
• SIMATIC IPC647E;
• SIMATIC IPC677E; and
• SIMATIC IPC847E


Siemens published an update for an advisory for their ZombieLoad advisory that was originally published on July 9th, 2019 and most recently updated on February 11th, 2020. The new information includes updated version and mitigation data for:

• SIMATIC IPC127E; and
• SIMATIC IPC527G

Saturday, February 29, 2020

Public ICS Disclosures – Week of 2-22-20


This week we have two vendor disclosures for products from Phoenix Contact and Moxa and an update from Belden. We also have a researcher disclosure for products from Honeywell.

Phoenix Contact Advisory


Phoenix Contact published an advisory [.PDF download link] describing two of the Urgent/11 vulnerabilities in their FL Switch GHS articles. These vulnerabilities are self-reported. Phoenix Contact provides generic workarounds to mitigate the vulnerabilities.

Moxa Advisory


Moxa published an advisory describing twelve vulnerabilities in their AWK-3131A Series Industrial AP/Bridge/Client. The vulnerabilities were reported by Talos Intelligence (CVE links below to individual Talos reports with proof of concept code). Moxa has a security patch to mitigate the vulnerabilities. There is no indication that Talos has been provided an opportunity to verify the efficacy of the fix.

The twelve reported vulnerabilities are:

• Improper access control (2) - CVE-2019-5136 and CVE-2019-5162;
• Use of hard-coded cryptographic key - CVE-2019-5137;
• Improper neutralization of special elements used in an OS command (4) - CVE-2019-5138, CVE-2019-5140, CVE-2019-5141, and CVE-2019-5142;
• Use of hard-coded credentials - CVE-2019-5139;
• Buffer copy without checking size of input - CVE-2019-5143;
• Out-of-bounds read - CVE-2019-5148;
• Stack-based buffer overflow - CVE-2019-5153; and
Authentication bypass using alternate path or channel - CVE-2019-5165

Belden Update


Belden published an update to their HiOS advisory that was originally published on February 14th. The new information includes:

• Revised list of affected products;
• Revised list of available updates; and
• Added workaround

Honeywell Report


Applied Risk published their report on the Honeywell vulnerabilities that were reported earlier this month.

Tuesday, February 18, 2020

4 Advisories and 1 Update Published – 2-18-20


Today the CISA NCCIC-ICS published two control system security advisories for products from Emerson and Honeywell, two medical device security advisories for products from GE and Spacelabs, and 1 update for products from Interpeak.

Emerson Advisory


This advisory describes a heap-based buffer overflow vulnerability in the Emerson OpenEnterprise SCADA Server. The vulnerability was reported by Roman Lozko of Kaspersky ICS CERT. Emerson has an upgrade that mitigates the vulnerability. There is no indication that Lozko has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit this vulnerability to allow an attacker to execute code on an OpenEnterprise SCADA Server.

Honeywell Advisory


This advisory describes a clear-text storage of sensitive information vulnerability in the Honeywell INNCOM INNControl 3 energy management platform. The vulnerability is self-reported. Honeywell has an upgrade available to mitigate the vulnerability.

NCCIC reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to escalate user privileges within the INNControl application.

GE Advisory


This advisory describes a protection measure failure vulnerability in the GE Ultrasound Products. The vulnerability was reported by Marc Ruef and Rocco Gagliardi of scip AG. GE has provided generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with local access could exploit the vulnerability to allow an attacker to gain access to the operating system of affected devices.

Spacelabs Advisory


This advisory describes the BlueKeep vulnerability in the Spacelabs Xhibit Telemetry Receiver. Spacelabs has an updated version that mitigates the vulnerability.

NOTE: A number of other vendors in both the control system and medical device realms issued advisories on this vulnerability (see my blog post here for example) beginning in May of last year. This is the first acknowledgement of vendor actions on this vulnerability from NCCIC-ICS though there was an obscure advisory on the vulnerability published by NCCIC-ICS.

Interpeak Update


This update provides additional information on the Urgent/11 advisory that was originally published on October 1st, 2019 and most recently updated on December 10th, 2019. The new information includes a link to a vendor advisory from Mitsubishi.

Saturday, December 7, 2019

Public ICS Disclosures – Week of 11-30-19


This week we have three vendor disclosures for products from BD, GE and Johnson Controls and an URGENT/11 update from Belden. There are also three exploit code reports for products from Fronius, Salto and YachtControl.

BD Advisory


BD published an advisory describing and anti-virus bypass vulnerability in BD products with workstations running CylancePROTECT®. The third-party vulnerability was originally reported by Skylight. BD recommends updating the CylancePROTECT product.

NOTE: I wonder what other ICS vendors bundle CylancePROTECT as a cybersecurity tool? Since the product does not need to do signature updates it would seem to be a tool designed for control system security.

GE Advisory


GE published an advisory describing two privilege escalation vulnerabilities in the GE Digital HMI/SCADA iFIX product. The vulnerability was reported by Applied Risk. GE provides generic mitigation guidance for the vulnerability.

Johnson Controls Advisory


Johnson Controls published an advisory describing vulnerabilities in a third-party component of their Software House C•CURE 9000 application. The vulnerabilities in the Flexera FlexNet Publisher licensing manage have been previously reported. Johnson Controls has an update that mitigates the vulnerability.

Belden Update


Belden published an update of their URGENT/11 advisory that was originally published July 29th, 2019 and most recently updated on October 30th, 2019. The new information includes update information for Hirschmann HiOS RSPE TSN.

Fronius Expliot


SEC Consult published a report containing exploit code for four vulnerabilities in the solar inverter series of Fronius. This is reportedly a coordinated disclosure. Fronius has a firmware patch that mitigates the vulnerabilities. There is no indication that SEC Consult has been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Unencrypted communication;
• Authenticated path traversal - CVE-2019-19229;
• Backdoor account - CVE-2019-19228; and
• Outdated and vulnerable software components

NOTE: This is the first time that I have seen an easter-egg included in a vulnerability report.

Salto Exploit


SEC Consult published a report containing exploit code for six vulnerabilities in the Salto ProAccess Space management software for an access control system. This is reportedly a coordinated disclosure. Salto has a patch that mitigates the vulnerabilities. There is no indication that SEC Consult has been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Path traversal - CVE-2019-19458;
• Arbitrary file write - CVE-2019-19459;
• Stored cross-site scripting - CVE-2019-19457;
• Webserver running as Windows Service per default - CVE-2019-19460;
• Authorization issues; and
• Cleartext transmission of sensitive data

Yachtcontrol Exploit


Hodorsec published exploit code for a remote code execution vulnerability in the Yachtcontrol web application. The report includes a CVE number so this may be a coordinated disclosure.

Saturday, November 30, 2019

Public ICS Disclosures – Week of 11-23-19


This week we have two vendor disclosures from Drager and Moxa. We also have two possible 0-day exploits for products from AVEVA.

Drager Advisory


Drager published an advisory describing two vulnerabilities in their SC Monitoring product line. The vulnerabilities were reported by Jeroen Slobbe and Max Grim. The products have reached end-of-life and no mitigation measures are being offered by Drager.

The two reported vulnerabilities are:

• Denial of service; and
• Hard-coded credentials

Moxa Advisory


Moxa published an advisory concerning the URGENT/11 vulnerabilities. They report that none of their products are affected.

AVEVA Exploits


Chuyreds published exploit code for a denial of service vulnerability in the AVEVA InTouch Machine. There is no report of a CVE number or vendor coordination in the document so this may be a 0-day vulnerability.

Chuyreds published exploit code for a denial of service vulnerability in the AVEVA InduSoft Web Studio. There is no report of a CVE number or vendor coordination in the document so this may be a 0-day vulnerability.

NOTE: The exploits look very similar, so this probably reflects a common vulnerability in the two products. I do not see an AVEVA advisory for the two products with a similar vulnerability.

Thursday, October 3, 2019

1 Update Published – 10-03-19


Today the DHS NCCIC-ICS published an update to a previously published medical device security advisory for products from Interpeak and vendors who have used their IPnet TCP/IP Stack. The advisory was originally published on 10-01-19. The update adds to additional medical device vendor advisories about the underlying URGENT/11 vulnerabilities. Those two vendors are:

Abbott; and

Tuesday, October 1, 2019

4 Advisories Published – 10-01-19


Today the DHS NCCIC-ICS published three control system security advisories for products from Moxa, Yokogawa and Interpeak and a medical device security advisory for products from Interpeak.

Moxa Advisory


This advisory describes two vulnerabilities in the Moxa Moxa EDR 810 router. According to the Moxa advisory these vulnerabilities was reported by Guillaume Lopes of Randorisec (not included in NCCIC-ICS advisory). Moxa has new firmware that mitigates the vulnerabilities. There is no indication that Lopes was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Improper input validation - CVE-2019-10969; and
Improper access control - CVE-2019-10963

 NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow remote code execution or access to sensitive information.

Yokogawa Advisory


This advisory describes an unquoted search path or element vulnerability in the Yokogawa Exaopc, Exaplog, Exaquantum, Exasmoc, Exarqe, GA10, and InsightSuiteAE products. The vulnerability is self-reported. Yokogawa has revisions or updates for most of the affected products.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow a local attacker to execute malicious files.

NOTE: I briefly reported this vulnerability on Saturday.

Interpeak ICS Advisory


This advisory describes eleven vulnerabilities in Interpeak IPnet stack. These vulnerabilities were previously reported as the Wind River URGENT/11 vulnerabilities. This advisory now reports that the vulnerabilities are also found the following real-time operating systems (RTOS):

ENEA - OSE4 and OSE5;
Green Hills Software - INTREGRITY RTOS;
ITRON; and
IP Infusion – Zebos;

Interpeak Medical Device Advisory


This advisory describes the same URGENT/11 vulnerabilities due to problems in the Interpeak IPnet stack as described above. The only difference is that this version provides links to medical device vendor advisories.

Commentary


The two Interpeak advisories point out (AGAIN) how interconnected software systems are. Vulnerabilities found in one system are frequently found in 3rd party software that is used by vendor instead of writing new code. This is done for a variety of reasons, but frequently it is because a vendor does not have either the resources or the expertise in-house to develop the necessary code. This certainly makes economic sense.

Unfortunately, there does not seem to be a system in place to ensure that other vendors that use the same code are notified in a timely manner so that they can fix the related problems. In some cases, I suspect notifications are made, corrective action is taken, but the vendor never reports the vulnerability. The lack of notification is usually due to not wanting to look bad, but it does little to help owners of the affected products who do not update because their systems are ‘working fine’; their decisions might be made differently (or not) if they knew about the vulnerabilities.

Saturday, September 28, 2019

Public ICS Disclosures – Week of 09-21-19


This week we have four vendor disclosures for products from ABB, Schneider, Sick, and Yokogawa  and one vendor update for products from Schneider.

ABB Advisory


ABB published an advisory reporting that two of the Wind River URGENT/11 vulnerabilities affected their AC 800M controllers. ABB provides generic work arounds while it is working on new versions to mitigate the vulnerabilities.

Schneider Advisory


Schneider published an advisory describing the Microsoft Windows® DejaBlue vulnerabilities in a list of Schneider products. Schneider recommends applying the appropriate Windows updates for some products and provides generic workarounds for others.

Schneider Update


Schneider published an update for their advisory on the effect of the BlueKeep {Microsoft® RDP vulnerability (CVE-2019-0708)} on a list of their products. They added “Conext Control” to list of affected products.

Sick Advisory


Sick published an advisory describing a buffer overflow vulnerability in the Sick FX0-GENT00000 and FX0-GPNT00000 safety controllers. The vulnerability was reported by the security-testlab team of Fraunhofer IOSB. Sick has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Yokogawa Advisory


Yokogawa published an advisory describing an unquoted service path vulnerability in a list of their products. This vulnerability is self-reported. Yokogawa has new versions and patches to mitigate the vulnerability.

Saturday, September 14, 2019

Public ICS Disclosures – Week of 09-07-19


This week we have 11 vendor disclosures for products from Siemens (3), Schneider (3), Bosch (2), 3S, Eaton, and Draeger. We also have 3 vendor updates from Schneider (2) and Siemens.

Siemens Advisories


DejaBlue Advisory

Siemens published an advisory describing the Microsoft Windows® DejaBlue vulnerabilities in the Siemens Healthineers Products. In most of the affected products Siemens is recommending applying the appropriate MS patches.

Siemens repeatedly makes the following observation: “The compatibility of Microsoft security patches with products from Siemens Healthineers that are beyond their End of Support date cannot be guaranteed.”

RUGGEDCOM URGENT/11 Advisory

Siemens published an advisory describing the Wind River URGENT/11 vulnerabilities in the Siemens RUGGEDCOM Win base stations. Siemens provides generic workarounds for the vulnerabilities.

SINEMA Advisory

Siemens published an advisory describing four vulnerabilities in the Siemens r SINEMA Remote Connect Server. The vulnerabilities were reported by Hendrik Derre and Tijl Deneut from HOWEST. Siemens has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

Password guessing - CVE-2019-13918;
Privilege escalation - CVE-2019-13919;
Cross-site request forgery - CVE-2019-13920; and
Password hash - CVE-2019-13922

Siemens Update


Siemens published an update for an advisory that was originally published on June 9th, 2019. This update provides corrected version information and mitigation information for:

FieldPG M4;
FieldPG M5; and
ITP1000

Schneider Advisories


U.Motion Server Advisory

Schneider published an advisory describing six vulnerabilities in the Schneider U.motion din rail and touch panel servers. The vulnerabilities were reported by Zhu Jiaqi and Constantin-Cosmin Craciun. Schneider has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

Cross-site scripting - CVE-2019-6835;
Improper access control (3) - CVE-2019-6836, CVE-2019-6838 and CVE-2019-6839;
Server-side request forgery - CVE-2019-6837; and
Format string - CVE-2019-6840

Modicon Quantum Advisory

Schneider published an advisory describing an improper check for unusual or exceptional conditions vulnerability for the Schneider Modicon Quantum 140 NOE771x1 controllers. The vulnerability is self-reported. Schneider has a new version that mitigates the vulnerability.

TwidoSuite Advisory

Schneider published an advisory describing two vulnerabilities in the Schneider TwidoSuite product. The vulnerability is self-reported. This product is no longer supported.

The two reported vulnerabilities are:

Untrusted search path;
Input validation

Schneider Updates


BlueKeep Update

Schneider published an update for an advisory that was originally published on July 12, 2019. The update includes:

Exploit information; and
Updated affected product versions

 Floating License Manager Update

Schneider published an update for an advisory that was originally published on May 14th, 2019. The update provides updated affected product information.

Bosch Advisories


Bosch published two advisories (here and here) describing vulnerabilities in the Access Professional access control system. The vulnerabilities were reported by Oleksii Orekhov. Bosch has a new version that mitigates the vulnerabilities. There is no indication that Orekhov has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Hard-coded credentials - CVE-2019-11898; and
Improper access control - CVE-2019-11899

3S Advisory


3s published an advisory describing a stack-based buffer overflow vulnerability in the CODESYS V2.3 ENI servers. This vulnerability was reported by Chen Jie from NSFOCUS. 3S has an update that mitigates the vulnerability. There is no indication that Chen has been provided an opportunity to verify the efficacy of the fix.

Eaton Advisory


Eaton published an advisory describing multiple undisclosed vulnerabilities in the Eaton Intelligent Power Protector. The vulnerabilities are apparently self-reported. Eaton has a new version that mitigates the vulnerabilities.

NOTE: Eaton continues to publish unusable security advisories.

Drager Advisory


Drager published an advisory describing the Microsoft Windows® DejaBlue vulnerabilities in Drager products.

Saturday, August 17, 2019

Public ICS Disclosures – Week of 08-10-19


This week we have eight vendor notifications from Schneider (7) and Siemens; updates for four previouls published advisories from Schneider (2) and Siemens (2); as well as two exploit reports for previously published vulnerabilities in products from Wind River, and Cisco.

Schneider Advisories


Magelis Advisory

Schneider published an advisory describing an improper check for unusual or exceptional conditions vulnerability in their Magelis HMI Panel products. The vulnerability was reported by VAPT Team. Schneider provides generic workarounds to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Modicon 340 Advisory

Schneider published an advisory describing an improper check for unusual or exceptional conditions vulnerability in their Modicon M340 controllers. The vulnerability was reported by VAPT Team. Schneider provides generic workarounds to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Modicon Advisory

Schneider published an advisory describing three improper check for unusual or exceptional conditions vulnerabilities in their Modicon Ethernet / Serial RTU Modules. The vulnerability was reported by VAPT Team. Schneider provides generic workarounds to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

SoMachine Advisory

Schneider published an advisory describing an untrusted search path vulnerability in their SoMachine HVAC. The vulnerability was reported by Yongjun Liu of the nsfocus security team. Schneider has a new version that mitigates the vulnerability. There is no indiction that Yonguin has been provided an opportunity to verify the efficacy of the fix.

TelevisGo Advisory

Schneider published an advisory describing 22 vulnerabilities in the third party UltraVNC (remote accesss) software component embedded within the TelevisGo product. The vulnerabilities were reported by Kaspersky Labs. Schneider has a hot-fix available that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The 22 reported vulnerabilities are:

Buffer errors (9) - CVE-2019-8258, CVE-2018-15361, CVE-2019-8262, CVE-2019-8263, CVE-2019-8269, CVE-2019-8271, CVE-2019-8273, CVE-2019-8274, and CVE-2019-8276;
Resource management errors (2) - CVE-2019-8259, and CVE-2019-8277;
Out-of-bounds read (8) - CVE-2019-8260, CVE-2019-8261, CVE-2019-8280, CVE-2019-8264, CVE-2019-8265, CVE-2019-8266, CVE-2019-8267, and CVE-2019-8270;
Incorrect calculation (2) - CVE-2019-8268, CVE-2019-8272; and
Improper access control - CVE-2019-8275.

Software Update Service Advisory

Schneider published an advisory describing a deserialization of trusted data vulnerability in their Software Update (SESU) SUT Service. The vulnerability was reported by Amir Preminger of Claroty. Schneider has a new version that mitigates the vulnerability. There is no indication that Preminger has been provided an opportunity to verify the efficacy of the fix.

spaceLYnk Advisory


Schneider published an advisory describing an authentication vulnerability in their  spaceLYnk and Wiser for KNX controllers. The vulnerability was reported by Sumedt Jitpukdebodin. Schneider has new versions that mitigate the vulnreabilty. There is no indication that Jitpukdebodin has been provided an opportunity to verify the efficacy of the fix.

Schneider Updates


Modicon Controllers Update

Schneider published an update that was originally published on May 14th, 2019.  New information includes:
Added mitigation measures for M340;
Added four new vulnerabilities (links for reports w/exploits from Talos):
Denial of service vulnerability - CVE-2019-6809;
Denial of service vulnerability - CVE-2019-6828;
Denial of service vulnerability - CVE-2019-6829; and
Denial of service vulnerability - CVE-2019-6830

SCADAPack Update

Schneider published an update for an advisory that was originally published on May 24th, 2017. New information includes:

Updated researcher acknowledgement section;
Corrected CVE ID from CVE-2017-6028 to CVE-2017-6034; and
Corrected vulnerability description

Siemens Advisory


Siemens published an advisory describing two vulnerabilities in their SIMATIC S7-1200 and SIMATIC
S7-1500 CPU families.  The vulnerabilities were reported by Eli Biham, Sara Bitan, Aviad Carmel, and Alon Dankner, Uriel Malin, and Avishai Woo. Siemens has generic workarounds that mitigate the vulenrabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Man-in-the-middle vulnerability - CVE-2019-10929; and
Code change vulnerability - CVE-2019-10943

Siemens Updates


ZombieLoad Update

Siemens published an update for an advisory that was originally published on July 9th, 2019. New information includes:

SIMATIC IPCs 427D, 477D, 627D, 627E, 647D, 647E, 677D, 677E, 827D, 847D, 847E; and
FieldPG M6

GNU/Linux Update

Siemens published an update for an advisory that was originally published on November 27th, 2019. New information includes:

Added CVE-2018-19591, CVE-2019-11360, CVE-2019-13272; and
Moved CVE2018-16862 from buildtime to runtime relevant

Cisco Exploit


Angelo Ruwantha published a Metasploit module for a vulnerability in the Cisco Adaptive Security Appliance; Cisco published an advisory on this vulnerability on June 6thy, 2018. NCCIC-ICS published an advisory for Rockwell Automation Allen-Bradley Stratix 5950 listing this vulnerability.

WindRiver (Urgent/11) Exploit


Zhou Yu published an exploit for an integer overflow vulnerability in the Wind River VxWorks (one of the Urgent/11 vulnerabilities).

Saturday, August 10, 2019

Public ICS Disclosures – Week of 08-03-19


This week we have three new vendor disclosures concerning the VxWorks URGENT/11 vulnerabilities and three researcher announcements of vulnerabilities in products from Reliable Controls (2) and VISAM

URGENT/11 Advisories


Three new vendors have published advisories related to the VxWorks URGENT/11 vulnerabilities reported by Amis Labs; Bosch, Omron and Philips. Below I have listed links to all of the vendor disclosures that I have discovered to date:

Rockwell,
Xerox, and
Siemens (in an out-of-cycle report);
Schneider; and
• ABB, in:
AC 800PEC;
Belden
Omron (not affected)
Philips

It is great to see that Omron is reporting no exposure to the vulnerabilities. That is as valuable to their customers as the advisories being published by affected vendors.

Reliable Controls Advisories


MACH-ProWeb Advisory

Applied Risk published a report describing a relflected XSS vulnerability in the Reliable Controls MACH-ProWeb BACnet Building Controller. Applied Risk reports that they have not received a response from the vendor to their January 29th, 2019 report on this vulnerability.

Reliable Controls LicenseManager Advisory

Applied Risk published a report describing a privilege escalation vulnerability in the Reliable Controls RC-LicenseManager in the Reliable Controls RC-Studio (MACH-System) software. Applied Risk reports that they have not received a response from the vendor to their January 29th, 2019 report on this vulnerability.

VISAM Advisory


Applied Risk has publihsed a report describing five vulnerabilities in the VISAM Automation Base (VBASE) HMI / SCADA. Applied Risk reports that as of July 8th, 2019 (apparently the date of last communication from VISAM) no mitigation has been made available for these vulnerabilities.

The five reported vulnerabilities are:

• Information disclosure via directory traversal;
• Insecure file permissions privilege escalation;
• Password protection security bypass;
• Cryptographic key disclosure; and
• Buffer overflow

 
/* Use this with templates/template-twocol.html */