Showing posts with label Vladimir Dashchenko. Show all posts
Showing posts with label Vladimir Dashchenko. Show all posts

Friday, May 17, 2019

9 Advisories and 4 Updates Published – 05-14-19


Tuesday the DHS NCCIC-ICS published nine control system security advisories for products from Siemens (8) and Omron and updated four previously published advisories for Siemens (3) and WIBU-Key.

SIMATIC Panels Advisory


This advisory describes three vulnerabilities in the Siemens SIMATIC WinCC Runtime Advanced, WinCC Runtime Professional, WinCC (TIA Portal); HMI Panels. The vulnerabilities are self-reported. Siemens has updates available for many of the affected products.

The three reported vulnerabilities are:

Use of hard-coded credentials - CVE-2019-6572;
Insufficiently protected credentials - CVE-2019-6576; and
Cross-site scripting - CVE-2019-6577

NCCIC-ICS reports that a relatively low-skilled attacker with network access could remotely exploit these vulnerabilities to allow an attacker with network access to the device to read/write variables via SNMP.

NOTE: The NCCIC-ICS advisory references the incorrect Siemens advisory, it should have been SSA-804486. The incorrect advisory listed is for a different vulnerability in a similar list of products.

SIMATIC PCS7 Advisory


This advisory describes three vulnerabilities in the Siemens SIMATIC PCS 7, WinCC Runtime Professional, WinCC (TIA Portal) products. The vulnerabilities were reported by Vladimir Dashchenko and Sergey Temnikov from Kaspersky Lab, CNCERT/CC, and ChengBin Wang from Guoli Security Technology. Siemens has an update for one of the affected products and has provided generic workarounds for the remainder pending mitigation development. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

SQL injection - CVE-2019-10916;
Uncaught exception - CVE-2019-10917; and
Exposed dangerous method or function - CVE-2019-10918

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to execute arbitrary commands on the affected system.

SCALANCE Advisory


This advisory describes five vulnerabilities in the Siemens SCALANCE W1750D. The vulnerability is self-reported. Siemens has a new version that mitigates the vulnerability.

The five reported vulnerabilities are:

Command injection (2) - CVE-2018-7084 and CVE-2018-7082;
Information exposure (2) - CVE-2018-7083 and CVE-2018-16417; and
Cross-site scripting - CVE-2018-7064

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker execute arbitrary commands within the underlying operating system, discover sensitive information, take administrative actions on the device, or expose session cookies for an administrative session.

Perfect Harmony Advisory


This advisory describes an improper input validation vulnerability in the Siemens SINAMICS PERFECT HARMONY GH180 medium voltage converter. The vulnerability is self-reported. Siemens has an upgrade available to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial-of-service condition.

NXG I and II Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the Siemens SINAMICS PERFECT HARMONY GH180 Drives with NXG I and NXG II controls. The vulnerability is self-reported. Siemens has an upgrade available to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with access to the Ethernet Modbus Interface could exploit the vulnerability to cause a denial-of-service condition exceeding the number of available connections.

LOGO!8 Advisory


This advisory describes three vulnerabilities in the Siemens LOGO!8 BM programmable logic controller. The vulnerability was reported by Manuel Stotz and Matthias Deeg from SySS GmbH. Siemens has provided generic mitigation measures for the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

Missing authentication for critical function - CVE-2019-10919;
Improper handling of extra values - CVE-2019-10920; and
Plain-text storage of a password - CVE-2019-10921

NCCIC-ICS reports that a relatively low-skilled attacker with access to port 10005/tcp could remotely exploit the vulnerability to allow device reconfiguration, access to project files, decryption of files, and access to passwords.

SIMATIC WinCC Advisory


This advisory describes a missing authentication for critical function vulnerability in the Siemens SIMATIC WinCC and SIMATIC PCS 7 products. The vulnerability was reported by Vladimir Dashchenko and Sergey Temnikov from Kaspersky Lab. Siemens has newer versions that along with enabling ‘encrypted communications’ mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an unauthenticated attacker with access to the affected devices to execute arbitrary code.

Omron Advisory


This advisory describes an untrusted search path vulnerability in the Omron Network Configurator for DeviceNet. The vulnerability was anonymously reported by n0b0dy. Omron is working on an update to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to achieve arbitrary code execution under the privileges of the application.

Industrial Products with OPC Update


This update provides additional information on an advisory that was originally published on April 9th, 2019. The new information includes:

Clarifying product names for SIMATIC HMI Products;
Adding solution for SIMATIC S7-1500 CPU family; and
Modifying affected versions for SIMATIC Net PC Software

SIMATIC Update


This update provides additional information on an advisory that was originally published on April 9th, 2019. The new information from Siemens included:

Specification for SINAMICS products;
Adding solution for SIMATIC S7-1500 CPU family; and
Adding solution for SIMATIC S7-PLCSIM Advanced

NCCIC-ICS also added a number of affected products that were missing from their original advisory.

WIBU Key Update


This update provides additional information on an advisory that was originally published on February 12th, 2019 and updated on March 12th, 2019 and again on April 9th, 2019. The new information includes:

A reference to a new Siemens Advisory;
Adding new affected products from Siemens.

S7-400 Update


This update provides additional information on an advisory that was originally published on November 13th, 2018. The new information includes:

Adding the names of the researchers who reported the vulnerabilities; and
Adding solution for S7-400H V6.

Tuesday, January 29, 2019

5 Advisories Published – 01-29-19


Today the DHS NCCIC-ICS published three control system security advisories for products from AVEVA, Mitsubishi, and Yokogawa. They also published two medical device security advisories for products from BD and Stryker.

AVEVA Advisory


This advisory describes an insufficiently protected credential vulnerability in the AVEVA
Wonderware System Platform. The vulnerability was reported by Vladimir Dashchenko from Kaspersky Lab. AVEVA has an update that mitigates the vulnerability. There is no indication that Daschenko has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow unauthorized access to the credentials for the ArchestrA Network User Account.

NOTE: I briefly discussed this advisory last Saturday.

Mitsubishi Advisory


This advisory describes a resource exhaustion vulnerability in the Mitsubishi MELSEC-Q series PLCs. The vulnerability was reported by Tri Quach of Amazon’s Customer Fulfillment Technology Security (CFTS) group. Mitsubishi has a new firmware version that mitigates the vulnerability. There is no indication that Tri has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a remote attacker to send specially crafted packets to the device, causing Ethernet communication to stop.

Yokogawa Advisory


This advisory describes an unrestricted upload of files with dangerous type vulnerability in the Yokogawa License Manager Service. The vulnerability was reported by Kaspersky Lab. The latest version mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NOTE: I briefly discussed this advisory last Saturday.

BD Advisory


This advisory describes an improper access control vulnerability in the BD FACSLyric. This vulnerability was self-reported. BD will directly apply mitigation measures to the affected systems.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to gain unauthorized access to administrative level privileges on a workstation, which could allow arbitrary execution of commands. This vulnerability does not impact BD FACSLyric flow cytometry systems using the Windows 7 Operating System.

NOTE: This is not the BD advisory that I briefly discussed last Saturday.

Stryker Advisory


This advisory describes a reusing a nonce vulnerability. advisory for the Stryker Secure II MedSurg Bed, S3 MedSurg Bed, and InTouch ICU Bed products. This is for the Key Reinstallation Attack – (KRACK) set of vulnerabilities. This advisory only reports nine of the ten CVE’s for the KRACK vulnerability. Stryker has software updates to mitigate the vulnerability.

Thursday, December 6, 2018

Three Advisories Published – 12-06-18


Today the DHS NCCIC-ICS published two control system security advisories for products from Rockwell and GE. Additionally they published a medical device security advisory for products from Philips. The Rockwell advisory was originally published on the HSIN ICS-CERT library on November 6, 2018 to allow owner/operators to mitigate the vulnerability before it was made public on the NCCIC-ICS site.

I also think that it is worth mentioning that yesterday Siemens announced changes in the way they were publishing security advisories for their products.

Rockwell Advisory


This advisory describes a missing authentication for critical function vulnerability in the Rockwell MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules. The vulnerability was reported by David Noren. Rockwell reports that a newer firmware version mitigates the vulnerability. There is no indication that Noren was provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an unauthenticated attacker to modify system settings and cause a loss of communication between the device and the system.

I briefly discussed the Rockwell notice for this vulnerability in a post on November 10th, 2018.

GE Advisory


This advisory describes an XXE vulnerability in the GE Proficy GDS service. The vulnerability was reported by Vladimir Dashchenko of Kaspersky Lab. GE reports that a newer version mitigates the vulnerability. There is no indication that Dashchenko has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to initiate an OPC UA session and retrieve an arbitrary file.

The GE security notification for this vulnerability notes that this is an underlying OPC issue that was addressed in an OPC security bulletin.

Philips Advisory


This advisory describes an inadequate encryption strength vulnerability in the Philips Philips HealthSuite Health Android App. The vulnerability was reported by an unnamed (by Philips) security researcher. Philips has provided a generic workaround pending a release of a new version next quarter.

NCCIC-ICS reports that a relatively low-skilled attacker with physical access to the device to impact confidentiality and integrity of the product.

Siemens Announcement


Yesterday Siemens announced on TWITTER that they would be block publishing advisories for security vulnerabilities on the 2nd Tuesday of every month. This policy has obviously been in place for a couple of months (see here for example). They did note that: “In case we have reasons to publish advisories out of band (e.g. due to criticality), we will still do so.” We have also recently seen that.

There are some obvious plusses and minuses to this policy. On a personal note, it makes for some long blog post for these 2nd Tuesday releases. More realistically it helps owners with the making of decisions about patching when all of the advisories for a product release at the same time. Unfortunately, it may allow for longer effective 0-day openings when an attacker discovers a vulnerability that has been ‘fixed’ by Siemens, but the advisory has not been released. This is where we have to rely on Siemens’ judgement about criticality, but we have always had to do that anyway.

Tuesday, August 14, 2018

ICS-CERT Publishes 4 Advisories


Today the DHS ICS-CERT published three control system security advisories for products from Siemens and one medical device security advisory for products from Philips. The three Siemens advisories were briefly discussed here over the weekend.

Automation License Manager Advisory


This advisory describes two vulnerabilities in the Siemens Automation License Manager. The vulnerabilities were reported by Vladimir Dashchenko from Kaspersky Lab. Siemens has updates available to mitigate the vulnerability. There is no indication that Dashchenko was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Relative path traversal - CVE-2018-11455; and
Improper input validation - CVE-2018-11456

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow remote code execution or allow an attacker to determine port status on another remote system.

OpenSSL Advisory


This advisory describes a cleartext transmission of sensitive information vulnerability in the Siemens Industrial Products. The vulnerability is being self-reported by Siemens. Siemens has updates for some of the affected products and continues to work on the remainder.

ICS-CERT reports that an uncharacterized attacker could remotely exploit this vulnerability to result in unencrypted data being transmitted by the SSL/TLS record layer.

SIMATIC Advisory


This advisory describes two incorrect default permissions vulnerabilities in the Siemens SIMATIC STEP 7 (TIA Portal) and SIMATIC WinCC (TIA Portal). The vulnerabilities were reported by Younes Dragoni from Nozomi Network. Siemens has updates that mitigate the vulnerabilities. There is no indication that Dragoni has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker with local access could exploit the vulnerability to manipulate files and cause a denial-of-service-condition, or execute code both on the manipulated installation as well as devices configured using the manipulated installation.

Philips Advisory


This advisory describes two vulnerabilities in the Philips Philips’ IntelliSpace Cardiovascular (ISCV)/Xcelera server products. Philips identified the problem due to a customer complaint. Philips has produced a work around pending publication of an updated version.

The two reported vulnerabilities are

• Improper privilege management - CVE-2018-14787; and
• Unquoted search path or element - CVE-2018-14789

ICS-CERT reports that a relatively low-skilled attacker with local access and users privileges to the ISCV/Xcelera server to escalate privileges on the ISCV/Xcelera server and execute arbitrary code.

Saturday, August 11, 2018

Public ICS Disclosures – Week of 08-04-18


This week we have four vendor advisories from Siemens (3) and ABB and an update of a vendor advisory from Siemens. There were also a number of BlackHat Briefings this week that touched on control system security issues.

Automation License Manager Advisory


Siemens reported two vulnerabilities in their Automation License Manager. The vulnerabilities were reported by Vladimir Dashchenko from Kaspersky Lab. Siemens has updates available to mitigate the vulnerabilities. There is no indication that Dashchenko was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Directory traversal - CVE-2018-11455; and
Network canning vulnerability - CVE-2018-11456

OpenSSL Advisory


Siemens reported an ‘open error state’ vulnerability in the OpenSSL implementation in a number of Siemens Industrial Products. This third-party software vulnerability is being self-reported by Siemens. Siemens has developed updates for some of the affected products (additional work is ongoing) to mitigate the vulnerability.

As always with third-party software issues, there is always the possibility that this vulnerability may affect control system products from other vendors.

SIMATIC Advisory


Siemens reported two improper file permission vulnerabilities in their SIMATIC Step 7 and WinCC products. The vulnerabilities were reported by Younes Dragoni from Nozomi Networks. Siemens has updates for some of the affected products and has reported work arounds.

NOTE: Siemens notes that this vulnerability was coordinated through ICS-CERT so we will probably see this reported by ICS-CERT next week.

ABB Advisory


ABB reported (registration required) an  LDAP authentication vulnerability in their eSOMS product. The vulnerability was reported by an undisclosed researcher. ABB is working on a new version to mitigate the vulnerability and has reported a work around.

Siemens Update


Siemens updated their Spectre/Meltdown advisory. This advisory was last updated on June 26th, 2018. This latest update adds update information for SIMATIC IPC6x7C, SIMAITC IPC8x7C, SIMOTION P320-4S, and SIMOTION P320-4E.

BlackHat Briefings


The latest BlackHat conference was held in Las Vegas this week. There were six briefings that the conference web site identifies as touching on Smart Grid/Industrial Security. There were:



Speaker: Thomas Roth

Speaker: Justin Shattuck


Speaker: Balint Seeber

Wednesday, April 4, 2018

ICS-CERT Publishes Siemens Advisory


Yesterday the DHS ICS-CERT published a control system advisory for products from Siemens. These are the vulnerabilities I reported on Saturday.

This advisory describes eight vulnerabilities in the Siemens Building Technologies Products. These are Gemalto Sentinel LDK RTE vulnerabilities that have been previously reported by Siemens in other products. The vulnerabilities were reported by Sergey Temnikov and Vladimir Dashchenko from Kaspersky Labs. Siemens has a newer version of the License Management System (LMS) that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The eight reported vulnerabilities are:

• Stack-based buffer overflow (2) - CVE-2017-11496, CVE-2017-11497;
• Security features - CVE-2017-12819;
• Improper restriction of operations within the bounds of a memory buffer - CVE-2017-12821;
• Null pointer dereference - CVE-2017-11498;
• XML entity expansion - CVE-2017-12818;
• Heap-based buffer overflow - CVE-2017-12820; and
Improper access control - CVE-2017-12822

Again, Siemens is not reporting all 14 of the Gemalto vulnerabilities. I would suspect that this is because the Siemens implementation of the license manager does not include the features affected by the other vulnerabilities.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow arbitrary code execution, NTLM-relay attacks, denial of service of the remote process, remote denial of service, and/or allow the administrative interface to be remotely enabled and disabled without authentication.

NOTE: Siemens announced that it had updated this advisory yesterday. The update includes a link to download the LMS.

Saturday, March 31, 2018

Public ICS Disclosures – Week of 03-24-18


This week we have one vendor notification from Siemens and two exploits for previously disclosed vulnerabilities in products from Hikvision and Advantech.

Siemens Advisory


This advisory describes 8 vulnerabilities in Siemens Building Technologies Products. The vulnerabilities were reported by Sergey Temnikov and Vladimir Dashchenko from Kaspersky Lab. The newest version of the license management systems for the affected products mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

These reported vulnerabilities are the Gemalto Sentinel LDK RTE vulnerabilities that have been previously reported by Siemens in other products.

Hikvision Exploit


This exploit provides proof-of-concept code for an attack on IP cameras from Hikvision. The backdoor vulnerability was previously disclosed on May 4th, 2017. The exploit was published by Matamorphosis on Exploit-DB.com.


Advantech Exploit


This exploit provides proof-of-concept code for an attack on the WebAccess products from Advantech. The stack-based buffer overflow vulnerability was previously disclosed on January 14th, 2016. The exploit was published by Chris Lyne on Expoit-DB.com.

Commentary


I noted in an earlier post that this set of Gemalto vulnerabilities probably effects a wide range of ICS products (including products from at least three other major ICS vendors) and suggested that ICS-CERT should have done an alert on these vulnerabilities. It is not too late to do so.

While both of the exploited vulnerabilities describe above were previously reported by ICS-CERT as not having publicly available exploits, ICS-CERT does not make a practice of removing that language from their advisories when exploits do become publicly available. It would probably be valuable to the ICS security community if that practice were changed.

Friday, March 30, 2018

ICS-CERT Publishes Four Advisories


Yesterday the DHS ICS-CERT published three control system security advisories for products from Siemens (2) and WAGO as well as a medical device security advisory for products from Phillips.

SIMATIC Advisory


This advisory describes an improper input validation vulnerability in the Siemens SIMATIC product line. The vulnerability was reported by Vladimir Dashchenko from Kaspersky Lab and independent researcher cdev1. A new version is available for one product that mitigates the vulnerability and activating an existing control mitigates the vulnerability in others. There is no indication that either of the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial-of-service condition on the remote and local communication functionality of the affected products. A system reboot is required to recover.

TIM 1531 Advisory


This advisory describes an incorrect implementation of an algorithm vulnerability in the Siemens TIM 1531 IRC communications modules. The vulnerability is self-reported. A new version is available that mitigates the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to enter a denial-of-service condition, or allow the attacker to read and manipulate data and configuration settings of the affected device.

WAGO Advisory


This advisory describes an improper shutdown or release vulnerability in the WAGO 750 Series PLC. The vulnerability was reported by Younes Dragoni of Nozomi Networks. WAGO has released new firmware that mitigates the vulnerability. There is no indication that Dragoni has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a denial-of-service condition affecting the ability of the device to establish connections to commissioning and service software tools. The WAGO security advisory notes that the vulnerability only affects the WAGO communication via WAGO Ethernet TCP/IP driver and that communications are still possible via the 3S TCP/IP level 2 driver and WAGO Service
Communication over TCP/IP.

Phillips Advisory


This advisory describes a large (indeterminate) number of vulnerabilities in the Phillips  iSite and IntelliSpace picture archiving communications systems (PACS). The vulnerabilities are self-reported. Phillips has provided multiple options for mitigating up to 99.9% of the vulnerabilities.

The reported vulnerabilities include:

• Improper restrictions of operations within the bounds of a memory buffer (#?);
• Code/source code vulnerabilities (at least 18);
• Information exposure (#?);
• Improper control of generation of code (#?);
• Weaknesses in OWASP to ten (at least 6);
• Improper restriction of XML external entity reference;
Other 3rd party component vulnerabilities (#?)

ICS-CERT reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to provide unexpected input into the application, execute arbitrary code, alter the intended control flow of the system, access sensitive information, or potentially cause a system crash.

Comment: This is a really flakey advisory and it certainly does not appear to be a problem at ICS-CERT. I am pretty sure that the authors of this advisory wanted to say that: “These products are just screwed up.” Unfortunately, that type of broad characterization is even less helpful than this report. Oh, and Phillips? The comment on their product security web page is priceless: “Philips will continue to add cybersecurity vulnerability remediation improvements through our Secure Development Lifecycle (SDL) as threats continue.” At least they did self-report this fiasco.

NOTE: These vulnerabilities were not reported on the FDA Medical Device Safety Communications page.

Missing Siemens Update


On Tuesday (the same day that Siemens announced the two advisories above) Siemens announced that they had updated their advisory on the improper input validation vulnerability in the Siemens SIMATIC, SINUMERIK, and PROFINET IO products reported last week by ICS-CERT. The update removed a product from the affected product list.

Thursday, January 18, 2018

ICS-CERT Publishes an Advisory and an Update for Siemens Products

Today the DHS ICS-CERT published a new control system security advisory and an updated advisory for products from Siemens.

Siemens Advisory


This advisory describes multiple vulnerabilities in the Siemens SIMATIC WinCC Add-On (license manager software). The vulnerabilities were reported by Sergey Temnikov and Vladimir Dashchenko from Kaspersky Lab. Siemens reports that a third party supplier (Gemalto) has released an updated installer that mitigates the vulnerabilities. The Siemens security advisory reports that SIMATIC WinCC Add-Ons released in 2015 and earlier include a vulnerable version of Gemalto Sentinel LDK RTE. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Stack-based buffer overflow (2) - CVE-2017-11496 and CVE-2017-11497; and
• Improper input validation - CVE-2017-11498

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow remote code execution or a denial of service condition.

NOTE: Looking at the Gemalto product page, it looks like they may have sold this product to multiple vendors. It will be interesting to see if other vendors come forward to recommend installing the same (or similar) updates to their systems.

Siemens Update


This update provides new information for an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th, and most recently November 28th. The update provides new version information and mitigation links for:

• SIMOCODE pro V PROFINET: All versions prior to V2.0.0

NOTE: The latest version of this Siemens security advisory is in their new format which makes checking against previous versions potentially tedious. Fortunately, Siemens (as opposed to ICS-CERT) annotates the specific changes made (as opposed to noting the section in which the changes were made) to their advisories.

Other Siemens Notes



Siemens also published two other advisory documents today that did not make it into the ICS-CERT publication schedule. One was a new advisory and one was an update. Since tomorrow is Friday and ICS-CERT seldom publishes advisories on Friday, I suspect that we will see these two next week.

Friday, November 3, 2017

ICS-CERT Publishes Two Advisories

Yesterday the DHS ICS-CERT published two control system security advisories for products from Advantech and Siemens.

Advantech Advisory


This advisory describes two vulnerabilities in the Advantech WebAccess HMI platform. The vulnerabilities were reported by Steven Seeley via the Zero Day Initiative. Advantech released a new version to mitigate the vulnerability. There is no indication that Seeley has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2017-14016; and
• Untrusted pointer dereference - CVE-2017-12719

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to allow remote code execution.

Siemens Advisory


This advisory describes an improper input validation vulnerability in the Siemens SIMATIC PCS7 distributed control system. The vulnerability was reported by Sergey Temnikov and Vladimir Dashchenko of Kaspersky Labs. Siemens has issued an update for some versions to mitigate the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix. Siemens has provided interim mitigation suggestions pending updates to the other versions.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to crash services on the device. The Siemens security advisory reports that: “The attacker must be member of the group administrators and have network access to an affected system.”


NOTE: Siemens reported this vulnerability on October 18th.

Thursday, March 9, 2017

ICS-CERT Publishes Schneider Advisory

Today the DHS ICS-CERT published a control system security advisory for the Schneider Electric ClearSCADA product. It describes an improper input validation vulnerability. The vulnerability was reported by Sergey Temnikov and Vladimir Dashchenko of Kaspersky Lab’s Critical Infrastructure Defense Team. Schneider has produced new updates to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to cause the ClearSCADA server process and communications driver processes to terminate.


Friday, July 29, 2016

ICS-CERT Publishes Four Advisories

Earlier this week the DHS ICS-CERT published four advisories for industrial control system vulnerabilities in products from Rockwell and Siemens.

Rockwell Advisory


This advisory describes two authentication vulnerabilities in the Rockwell Automation FactoryTalk EnergyMetrix application. These vulnerabilities were self-reported. This advisory was originally released on the US CERT Secure Portal on June 21, 2016.

The two vulnerabilities are:

• Insufficient session expiration - CVE-2016-4531; and
• SQL injection - CVE-2016-4522

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to gain unauthenticated access to the affected system.

Siemens SINEMA Advisory


This advisory describes a cross-site scripting vulnerability in the Siemens SINEMA Remote Connect Server (VPN) application. The vulnerability was reported by Antonio Morales Maldonado of INNOTEC SYSTEM, and Alexander Van Maele and Tijl Deneut of Howest. Siemens has produced an update to mitigate the vulnerability but there is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to gain ongoing access to these devices, but a social engineering attack would be required.

Siemens SIMATIC Net PC Advisory


This advisory describes a denial-of-service vulnerability in the Siemens SIMATIC NET PC-Software. The vulnerability was reported by Vladimir Dashchenko and Sergey Temnikov from Kaspersky Labs. Siemens has produced a new version to mitigate the vulnerability but there is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to cause a denial-of-service of the OPC-Unified Architecture (UA) service. Siemens reports that the attacker would require network access to exploit this vulnerability.

Siemens SIMATIC WinCC Advisory


This advisory describes two separate input validation vulnerabilities in the Siemens SIMATIC WinCC, PCS 7, and WinCC Runtime Professional applications. The vulnerabilities were reported by Sergey Temnikov and Vladimir Dashchenko from Kaspersky Lab. Siemens has produced updates to mitigate these vulnerabilities, but there is no indication that the researchers have been provided an opportunity to verify the efficacy of the fixes.


ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to extract arbitrary files or remotely execute arbitrary code. Siemens reports that the attacker would require network access to exploit this vulnerability.

Tuesday, May 26, 2015

ICS-CERT Publishes Rockwell Advisory

Today the DHS ICS-CERT published an advisory for a password encryption vulnerability in the Rockwell Automation RSView32 application. The vulnerability was reported by Vladimir Dashchenko and Dmitry Dementjev of the Ural Security System Center. Rockwell has produced a software patch to mitigate the vulnerability, but there is no indication that the researchers have been given the opportunity to verify the efficacy of the fix. This advisory was originally released on the US CERT Secure Server on May 12th.

ICS-CERT reports that this vulnerability would be difficult to exploit as it would require access to the file in which the user names and passwords was stored, reverse engineering the encryption and then using a social engineering attack for the exploit.


Once again we have ICS-CERT taking a vulnerability with a reported low exploitability to the Secure Server while they publicly release vulnerabilities that can be exploited by attackers with relatively low skills. Something is amiss here.
 
/* Use this with templates/template-twocol.html */