Showing posts with label Vyacheslav Moskvin. Show all posts
Showing posts with label Vyacheslav Moskvin. Show all posts

Tuesday, December 17, 2019

2 Advisories Published – 12-17-19


Today the CISA NCCIC-ICS published two control system security blogs for products from Siemens and GE.

Siemens Advisory


This advisory describes 54 vulnerabilities in the Siemens SPPA-T3000 servers. The vulnerabilities were reported by Gleb Gritsai, Eugenie Potseluevskaya, Sergey Andreev, and Radu Motspan from Kaspersky Lab; Vyacheslav Moskvin, and Ivan B from Positive Technologies; and Can Demirel from Biznet Bilisim Sistemleri ve Danışmanlık. Siemens has an update that mitigates three of the vulnerabilities on one of the affected products. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

Sorry, I am not going to list the 54 vulnerabilities.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to execute arbitrary code on the server, cause a denial-of-service condition, view and modify passwords, gain root privileges, access sensitive information, and read and write arbitrary files on the local system.

NOTE: This is the new vulnerability of the Siemens monthly drop from last week. I briefly discussed these vulnerabilities last Saturday.

GE Advisory


This advisory describes a cross-site scripting vulnerability in the GE S2020/S2020G Fast Switch 61850, a managed Ethernet switch. The vulnerability was reported by Murat Aydemir of Biznet Bilisim A.S.. GE has a new version that mitigates the vulnerability. There is no indication that Aydemir has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to inject arbitrary code and allow disclosure of sensitive data.

Tuesday, February 26, 2019

One Advisory Published – 02-26-19


Today the DHS NCCIC-ICS published a control system security advisory for products from Moxa. The advisory describes ten vulnerabilities in the Moxa IKS and EDS industrial switches. The vulnerabilities were reported by Ivan B, Sergey Fedonin, and Vyacheslav Moskvin of Positive Technologies Security. Moxa has a firmware patch that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The ten reported vulnerabilities are:

• Classic buffer overflow - CVE-2019-6557;
• Cross-site request forgery - CVE-2019-6561;
• Cross-site scripting - CVE-2019-6565;
• Improper access control - CVE-2019-6520;
• Improper restriction of excessive authentication request - CVE-2019-6524;
• Missing encryption of sensitive data - CVE-2019-6526;
• Out-of-bounds read - CVE-2019-6522;
• Unprotected storage of credentials - CVE-2019-6518;
• Predictable from observable state - CVE-2019-6563; and
Uncontrolled resource consumption - CVE-2019-6559

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow the reading of sensitive information, remote code execution, arbitrary configuration changes, authentication bypass, sensitive data capture, reboot of the device, device crash, or full compromise of the device.

Thursday, January 31, 2019

Two Advisories and Two Updates Published – 01-31-19


Today the DHS NCCIC-ICS published two control system security advisories for products from Schneider and IDenticard. They also updated two previously published advisories for products from Omron and Siemens

Schneider Advisory


This advisory describes three vulnerabilities in the Schneider EVLink Parking product. The vulnerabilities were reported by Vladimir Kononovich and Vyacheslav Moskvin of Positive Technologies. Schneider has an update available that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Use of hardcoded credentials - CVE-2018-7800;
• Code injection - CVE-2018-7801; and
SQL injection - CVE-2018-7802

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to stop the device and prevent charging, execute arbitrary commands, and access the web interface with full privileges.

NOTE: I briefly discussed these vulnerabilities in December just as the Federal Funding Fiasco started.

IDenticard Advisory


This advisory describes three vulnerabilities in the IDenticard PremiSys WCF Service access control system. The vulnerabilities were reported by Jimi Sebree working with Tenable. IDenticard has a software update that mitigates two of the three vulnerabilities. There is no indication that Sebree has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Hard-coded credentials - CVE-2019-3906;
• Inadequate encryption strength - CVE-2019-3907; and
• Use of hard-coded password - CVE-2019-3908

NCCIC-ICS reports that a relatively low-skilled attacker could use a publicly available information to exploit the vulnerability to view sensitive information via backups, obtain access to credentials, and/or obtain full access to the system with admin privileges.

NOTE: The Tenable report on these vulnerabilities add a four vulnerability; default database credentials - CVE-2019-3909.

Omron Update


This update provides additional information on an advisory that was originally published on October 18th, 2018. The update added Esteban Ruiz (mr_me) of Source Incite as one of the researchers reporting the vulnerabilities.

Siemens Update


This update provides additional information on an advisory that was originally published on June 14th, 2018. The update added affected version information and provided a mitigation link for RUGGEDCOM WiMAX.

NOTE: I briefly discussed this update (and six other Siemens updates published on the same day) earlier this month.

Friday, December 21, 2018

Public ICS Disclosure – Week of 12-15-18


This week we have five vendor notifications for products from Schneider Electric (3), Yokogawa and 3S (5).

Schneider Advisories


Schneider published an advisory for three vulnerabilities in their EVLink Parking product. The vulnerabilities were reported by Vladimir Kononovich and Vyacheslav Moskvin (Positive
Technologies). Schneider has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three vulnerabilities are:

• Hard-coded credentials - CVE-2018-7800;
• Code injection - CVE-2018-7801; and
SQL injection - CVE-2018-7802

Schneider published an advisory for an input validation vulnerability in their Pro-Face GP-Pro EX product. The vulnerability was reported by Yu Quiang (ADLab of Venustech). Schneider has a new version that mitigates the vulnerability. Schneider has an update that mitigates the vulnerability. There is no indication that Yu has been provided an opportunity to verify the efficacy of the fix.

Schneider published an advisory for three vulnerabilities in their IIoT Monitor product. The vunlerabilities were reported by rgod via the Zero Day Initiative. Schneider has a new product that mitigates the vulnerability. There is no indication that rgod has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Path traversal - CVE-2018-7835;
• Unrestricted upload of file with dangerous type - CVE-2018-7836; and
• Improper restriction of XML esternal reference entity reference - CVE-2018-7837

NOTE: I expect that we will see these three advisories reported by NCCIC-ICS next week if they are allowed to continue to report during the upcoming financial idiocy. NCCIC will operate, but the ICS reporting function might not be allowed to continue until a funding bill is signed by the President.

Yokogawa Advisory


Yokogawa published an advisory for a denial of service vulnerability in their  Vnet/IP Open
Communication Driver. The vulnerability appears to be self-reported. Yokogawa has a patch for many of the products to mitigate the vulnerability, but many of the affected products are no longer supported.

3S Advisories


3S published an advisory for an information exposure vulnerability in their CODESYS Development System V3. The vulnerability was reported by Heinz Füglister of WRH Walter Reist Holding AG. 3S has a new version that mitigates the vulnerability. There is no indication that Füglister has been provided an opportunity to verify the efficacy of the fix.

3S published an advisory for two denial of service vulnerabilities in their CODESYS V3 products. The vulnerabilities were reported by ABB Switzerland Ltd. and Jérôme Vialle of Schneider Electric. 3S has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

3S published an advisory for two denial of service vulnerabilities in their CODESYS Development System V3 Alarm configuration application. These vulnerabilities are being self-reported. 3S has a new version that mitigates the vulnerabilities.

3S published an advisory for two denial of service vulnerabilities in their CODESYS Control V3 TLS socket communication application. These vulnerabilities were reported by an unidentified OEM customer. 3S has new versions that mitigate the vulnerabilities. There is no indication that the customer was provided an opportunity to verify the efficacy of the fix.

3S published an advisory for two denial of service vulnerabilities in the CODESYS Control V3 Trace Manager application. These vulnerabilities were reported by an unidentified OEM customer. 3S has new versions that mitigate the vulnerabilities. There is no indication that the customer was provided an opportunity to verify the efficacy of the fix.

NOTE: As is obvious from the researchers who identified most of the 3S vulnerabilities, 3S software is used by a number of ICS vendors. It will be interesting to see how many of those vendors self-identify these vulnerabilities in their products. Since 3S does not report CVE numbers for any of these vulnerabilities, it will be hard to track.


Thursday, May 17, 2018

ICS-CERT Publishes 4 Advisories and 2 Siemens Updates


Today the DHS ICS-CERT published three control system security advisories for products from Delta Electronics, Siemens, Phoenix Contact, and Medtronic. They published on medical device security advisory for products from Medtronic. They also updated two previously issued control system security advisories for products from Siemens.

The three Siemens advisories/updates are the ones I mentioned in passing earlier this week.

Delta Advisory


This advisory describes a heap-based buffer overflow vulnerability in the Delta Industrial Automation TPEditor. The vulnerability was reported by ThePotato working with ZDI. Delta has released a new version that mitigates the vulnerability. There is no indication that the researcher was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to crash the accessed device, resulting in a buffer overflow condition that may allow remote code execution.


Siemens Advisory


This advisory describes an improper input validation vulnerability in the Siemens S7-400 CPU. The vulnerability is being self-reported. Siemens has updates that mitigate the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial-of-service condition of the CPU. The CPU will remain in DEFECT mode until a manual restart is performed. The Siemens security advisory notes that:

“Successful exploitation requires an attacker to be able to send a specially crafted S7 communication packet to a communication interface of the CPU. This includes Ethernet, PROFIBUS, and Multi Point Interfaces (MPI). No user interaction or privileges are required to exploit the security vulnerability”

Phoenix Contact Advisory


This advisory describes four vulnerabilities in the Phoenix FL SWITCH 3xxx/4xxx/48xx Series. The vulnerabilities were reported by  Vyacheslav Moskvin, Semen Sokolov, Evgeniy Druzhinin, Georgy Zaytsev and Ilya Karpov of Positive Technologies working through CERT@VDE. Newer firmware mitigates the vulnerability. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Command injection - CVE-2018-10730;
• Information exposure - CVE-2018-10729; and
Stack-based buffer overflow (2) - CVE-2018-10728, and CVE-2018-10731

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow for remote code execution and information disclosure.

GE Advisory


This advisory describes an improper input validation vulnerability n the GE PACSystems, an industrial Internet controller. The vulnerability was reported by Younes Dragoni of Nozomi Networks. GE has released new firmware to mitigate the vulnerability. There is no indication that Dragoni was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause the device to reboot and change its state, causing the device to become unavailable.

Medtronic Advisory


This advisory describes a missing encryption of sensitive data vulnerability in the Medtronic N’Vision Clinician Programmer. The vulnerability was reported by Billy Rios of Whitescope LLC. Medtronic has mitigated the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker with physical access to the card could exploit the vulnerability to access personal health information (PHI) or personally identifiable information (PII).

NOTE: This vulnerability was not reported on the FDA Medical Device Safety Communications page.

SIPROTEC Update #1


This update provides additional information on an advisory that was originally reported by ICS-CERT on May 19th, 2016 and updated on July 5th, 2016. This update removes 7SD80 from list of affected products.

SIPROTEC Update #2


This update provides additional information on an advisory that was was originally published on March 8th, 2018 and updated on April 19th, 2018. This update provides updated effected version information and mitigation measures for 7SD80.

 
/* Use this with templates/template-twocol.html */