Showing posts with label WellinTech. Show all posts
Showing posts with label WellinTech. Show all posts

Monday, July 27, 2026

Looking Back – 3-8-2011 – KingView Exploit

Nearly every morning I start my computer time by looking at information from Google about what happened in my blog in the previous 24 hours. Google, and blogspot.com is a Google service, provides interesting pieces of analytical data about my blog readership. One item of particular interest is the top ten blog posts each day. As you would expect, most of those posts were from the last couple of days, but with 16 years of publishing this blog, every once-in-a-while, a blog post from ancient history rises into that list. 

Today, a blog post from March 8th, 2011, ICS-CERT Alert for WellinTech KingView, made the list. The ICS Alert briefly describes a vulnerability in the WellinTech KingView v6.53. Not much in the way of details about the vulnerability beyond the fact that it affected KVWebSvr.dll and an exploit was available. Interestingly, neither the alert nor the follow-up advisory provide a CVE for the vulnerability.  

It turns out that the supporting CVE (CVE-2011-3142) was not published until August 16th, 2011, and MITRE was the CNA not ICS-CERT (they became a CNA in 2012). Two separate exploits are listed in the NVD.NIST.gov record, but neither link works. In fact, none of the links referenced on the NVD site work. Ancient history, so I guess it really is not important.... 

Tuesday, July 18, 2023

Review – 7 Advisories Published – 7-18-23

Today, CISA’s NCCIC-ICS published seven control system security advisories for products from WellinTech, GE, GeoVision, Weintek, Iagona, Keysight, and Rockwell Automation.

Advisories

WellinTech Advisory - This advisory describes two vulnerabilities in the WellinTech KingHistorian.

GE Advisory - This advisory describes a heap-based buffer overflow vulnerability in the GE Digital CIMPLICITY product.

GeoVision Advisory - This advisory describes an improper authentication vulnerability in the GeoVision GV-ADR2701 cameras.

Weintek Advisory - This advisory describes four vulnerabilities in the Weintek Weincloud product.

Iagona Advisory - This advisory describes four vulnerabilities in the Iagona ScrutisWeb ATM monitoring product.

Keysight Advisory - This advisory describes two vulnerabilities in the Keysight Geolocation Server.

Rockwell Advisory - This advisory describes an uncontrolled resource consumption vulnerability in the Rockwell Kinetix 5700 DC Bus Power Supply Series A.

 

For more details about the advisories, including links to exploits and researcher reports as well as a discussion about missing vulnerabilities, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-published-7-18-23 - subscription required.

Tuesday, April 8, 2014

ICS-CERT Publishes 4 Advisories

This afternoon the DHS ICS-CERT published advisories for vulnerabilities in four different control systems. The vendors include: Advantech, Siemens, WellinTech and OSISoft. All were coordinated disclosures.

Advantech Advisory

This advisory is for multiple vulnerabilities in Advantech WebAcess product. The vulnerabilities were coordinated through the ZDI initiative (still on the ‘Upcoming’ ZDI page) by Andrea Micalizzi (aka rgod), Tom Gallagher, and an independent anonymous researcher. ICS-CERT reports that Advantech has produced a new version of the software that corrects the problem but does not say that anyone had verified the efficacy of the update.

The vulnerabilities are:

• SQL injection, CVE-2014-0763;
• Stack based buffer overflow (5), CVE-2014-0764, CVE-2014-0765, CVE-2014-0766, CVE-2014-0767, CVE-2014-0768;
• Information disclosure (2), CVE-2014-0771, CVE-2014-0772; and
• Command injection, CVE-2014-0773

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to execute arbitrary code or read files stored on the target machine.

Siemens Advisory

This advisory is for a Browser Exploit Against SSL/TLS (BEAST) vulnerability (Note: this is not associated with the HeartBleed SSL/TLS bug) in the Ruggedcom Win product line. The vulnerability was reported to Siemens ProductCERT by Dan Frein and Paul Cotter of West Monroe Partners. Siemens has produced a firmware update that resolves the incompatibility issue. The Siemens ProductCERT Advisory describes additional mitigation techniques.

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to access the session ID of the current user. That could be used to read traffic exchanged between the user and the device.

WellinTech Advisory

This advisory describes a stack-based buffer overflow vulnerability in the KingSCADA application that was reported by an anonymous researcher through ZDI. WellinTech has produced a patch that mitigates the vulnerability, though there is nothing in the advisory that indicates that the mitigation has been independently verified.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to execute arbitrary code.

According to the WellinTech web site, the patch was made available on March 27th, 2014.

OSISoft Advisory

This advisory is a Crain-Sistrunk reported vulnerability in the PI Interface for DNP3 and it the typical improper input validation vulnerability in both the IP and serial communication modes of the device.

ICS-CERT reports that while a moderately skilled attacker could remotely exploit the IP vulnerability, that it would take a more skilled attacker with physical access to exploit the serial interface vulnerability. As I have said on previous occasions I disagree with the term ‘skilled attacker’ to describe the exploit requirements for plugging in a serial cable in an unmanned facility.

It has been almost two months since the last Crain-Sistrunk vulnerability was reported by ICS-CERT. According to the Project Robus web site, only 17 of 28 (it should now read 18 of 28) DNP3 vulnerable systems have been reported by ICS-CERT. I asked Adam Crain about this in a Twitversation today and he explained that most of the remaining vendors are not talking to ICS-CERT.


Given their adamant stand on coordinated disclosures, it is unlikely that Adam or Chris will out any of these vendors any time soon. So, if you have an DNP3 system that has not yet been outed by ICS-CERT then you might want to download the Crain-Sistrunk fuzzer and check your system for yourself.

Tuesday, January 14, 2014

ICS-CERT Publishes 3 Advisories

Today DHS ICS-CERT published three advisories; a unique Crain-Sistrunk DNP3 vulnerability, a mitigation effort update and an advisory from the secure portal.

Schneider Advisory

This advisory addresses an Uncontrolled Resources Consumption Vulnerability in the Schneider Electric ClearSCADA series of products. The vulnerability in the DNP3 system was reported by Crain-Sistrunk in a coordinated disclosure. Schnieder has produced a new software version that mitigates the vulnerability and Adam Crain has verified the efficacy of the fix.

ICS-CERT reports that a moderately skilled attacker could remotely exploit the vulnerability to cause DNP3Driver.exe to hang causing an interruption in the system processing. Essentially this is a denial of service (DOS) attack vector.

According to the Schneider Electric web site – they publicly disclosed this vulnerability on December 5th, 2013.

Sierra Wireless Advisory Update

This advisory update provides additional information about mitigation measures for the vulnerability reported last week. Sierra Wireless provides a vulnerability note dated January 10th suggesting that over-the-air firmware updates should not be done because “the update process, password data is transmitted to the device”. It recommends that the over-the-air programing feature be disabled.

The vulnerability note also as a recommendation for high-security applications:

“For high-security applications such as critical infrastructure monitoring, Sierra Wireless advises customers to deploy cellular devices using a Private Cellular Network or VPN to reduce the risk of an attacker capturing data transferred to/from the device.”

The pages that I reported last week did not mention that the device was discontinued now contain the following product status note: “Discontinued, still supported”.

This new information provides customers with a little more useable information than did the original advisory which essentially just said “Well we’ve discontinued the defective device, its now your problem”.

WellinTech Advisory

This advisory was originally released on the secure portal (on HSIN) last month and is now being released to the public. The advisory describes twin vulnerabilities affecting a variety of the WellinTech SCADA products. The vulnerability was reported by Andrea Micalizzi via the Zero Day Initiative (ZDI) in a coordinated disclosure. I was not able to find the ZDI listing for this vulnerability.

The twin vulnerabilities are:

• Information disclosure vulnerability, CVE-2013-2826; and
• ActiveX remote code execution vulnerability, CVE-2013-2827
NOTE: The CVE links are not yet active.


ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to either obtain system credentials or run arbitrary code in the dll. WellinTech has provided new versions of the affected software that mitigate the vulnerabilities. There is no mention of anyone verifying the efficacy of the new software versions in fixing these vulnerabilities.

Tuesday, October 22, 2013

ICS-CERT Updates Earlier WellinTech Alert

Today the DHS ICS-CERT published an advisory that updated a September alert issued for twin ActiveX vulnerabilities in the WellinTech KingView application. The earlier alert and this advisory respond to uncoordinated disclosures made by Blake (here and here).

ICS-CERT describes these vulnerabilities as:

• Insecure ActiveX control - CVE-2013-6127 (a flaw in the SuperGrid.ocx ActiveX control); and
• ActiveX Remote File Creation/Overwrite - CVE-2013-6128 (a flaw in the KChartXY.ocx ActiveX control}

NOTE: CVE links are not yet active.

ICS-CERT notes that a moderately skilled attacker could remotely execute the publicly available exploits to overwrite files and copy them from one location to another on the target machine. WellinTech has developed new versions of the affected files that hopefully (my word not ICS-CERT’s) mitigate the vulnerabilities. Bruce, being a non-cooperative researcher, does not get the chance to publicly verify the efficacy of the updates nor is there any mention that ICS-CERT has done so.

While ICS-CERT does now give credit to Bruce as the discoverer of the vulnerabilities it does not give credit to OSVDB.ORG for the two workarounds provided in this advisory. Those two workarounds (here and here) were on the OSVDB.org web site the day the initial alert was published. It is not clear from that site if the workarounds were developed by OSVDB or by Bruce.

Wednesday, March 27, 2013

ICS-CERT Publishes Two Metasploit Updated Advisories


Late this afternoon ICS-CERT published two updated advisories that were issued earlier this year; one for multiple vulnerabilities in CoDeSys Gateway-Web Servers and the other for a single vulnerability in the WellinTech KingView product. Both updates were necessary because the organization initially reporting the vulnerability had recently released a Metasploit module for exploiting the identified vulnerabilities.

Both Exodus Intelligence and Ioactive have produced Metasploit modules for the vulnerabilities that they reported in coordinated disclosures. EI explains on their web page that it is their intention to provide their customers with exploit tools for vulnerabilities that they discover. Apparently Ioactive has the same policy. This is becoming a more common approach as security researchers explore a variety of business models to make their security research worthwhile.

In both of these cases the exploit modules were published well after the ICS-CERT advisories were published. Thus the vendors had time to produce and distribute patches or updates to fix the vulnerabilities before the exploit tools became publicly available. Of course, no one really knows how many of the system owners actually knew about the vulnerabilities or if they did know actually had a chance to update their systems.

Wednesday, February 13, 2013

ICS-CERT Publishes Two More Buffer Overflow Advisories


Yesterday (lost in the cybersecurity EO and State of the Union hoopla) the DHS ICS-CERT published two advisories addressing buffer overflow vulnerabilities in industrial control systems. The advisories addressed vulnerabilities in products from Schneider and WellinTech.

Schneider Advisory

This advisory addresses a heap-based buffer overflow in the Accutech Manager application from Schneider. The vulnerability was reported by Aaron Portnoy of Exodus Intelligence in a coordinated disclosure (more about this later) and according to the advisory Aaron has verified that the update provided by Schneider effectively mitigates the vulnerability.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability using publicly available code and it could allow the attacker to execute arbitrary code on the system.

The advisory also notes that Schneider recommends closing Accutech Manager when not actually using it. ICS-CERT (apparently) also recommends ensuring that the vulnerable port (2537/TCP) is not accessible from the internet

WellinTech Advisory

This advisory addresses a memory corruption buffer overflow in the kingMess application within the KingView product. The vulnerability was reported by Lucas Apa and Carlos Mario Penagos Hollman of IOActive in a coordinated disclosure. They have also verified that the patch produced by WellinTech fixes the vulnerability.

ICS-CERT reports that a highly skilled attacker could remotely exploit this vulnerability to execute arbitrary code on the system.

It’s interesting to note that WellinTech reportedly released the patch on November 15th of last year and ICS-CERT is just now publishing the advisory. This may be because WellinTech did not disclose the vulnerability to ICS-CERT until recently.

New Twist on Coordinated Disclosure

The Schneider advisory has something that I don’t recall seeing in a coordinated disclosure advisory before, a report that there is publicly available exploit code for the vulnerability. Typically the researcher keeps any exploit code they developed tightly held, only sharing it with the vendor. There is nothing specific about who has released the exploit, so I can’t tell from the advisory if it was Aaron who released the exploit code or some other researcher who independently discovered the vulnerability.

A look at the Exodus Intelligence (Aaron’s employer) web site sheds some light on the situation. Exodus Intelligence offers their customer two different types of ‘vulnerability intelligence data feeds’. A ‘Zero-day Feed’ offers to their customers information on vulnerabilities (including exploit code) just after Exodus notifies the vendor of the vulnerability. I’m assuming that there is some sort of non-disclosure agreement that goes along with this feed.

A separate (and presumably cheaper) ‘Day of Disclosure Feed’ provides the same information to Exodus customers the same day as the vendor publicly announces the availability of the mitigation for the vulnerability. Again this includes a copy of the exploit code for the vulnerability. I’m assuming that this is the exploit code for the Schneider vulnerability that is referenced in the advisory.

It is interesting to me to see how many different business models are beginning to grow out of the white hat side the cybersecurity universe. Researchers need to make money to support their nasty habits like eating and bathing and these varied business models will make it easier for these folks to keep plying their trade keeping software vendors on their toes.

Wednesday, October 10, 2012

ICS-CERT Publishes WellinTech and Siemens Advisories


Yesterday ICS-CERT published two ICS advisories; a follow-up to an earlier alert concerning a vulnerability in WellinTech KingView application and a Siemens S7-1200 PLC vulnerability.

WellinTech Advisory


The WellinTech advisory is an update of an earlier alert on an uncoordinated disclosure made by Dr. Wesley McGrew of Mississippi State University. Dr. McGrew reported at DEFCON 20 that user credentials were not securely hashed, allowing usernames and passwords to decrypted using a simple mathematical algorithm.

This advisory reports that a relatively low skilled attacker with access to the publicly available exploit can obtain usernames and passwords to gain access to systems. WellinTech has created a patch that increases the complexity of the password encryption algorithm. The advisory does not report that ICS-CERT or Dr. McGrew has confirmed the efficacy of the patch.

Siemens Advisory


Monday Siemens published an advisory based upon a coordinated disclosure by Positive Technologies of a cross-site scripting vulnerability in the S7-1200 Web Application Module; today ICS-CERT published their advisory based upon the Siemens report.

According to Siemens the S7-1200 PLCs have an embedded web server that can be enabled by the user. If a social engineering attack convinces a user to access a malicious web site the attacker “could manipulate what the browser displays when viewing the S7-1200’s web pages, steal session cookies, or redirect the user’s browser to a malicious web site”.

Siemens has developed a firmware update that is available through their regional Technical Support Centers. The ICS-CERT advisory does not confirm that the update mitigates the vulnerability.

Another Siemens Vulnerability


The Siemens security website lists another vulnerability published yesterday. It refers to a buffer overflow vulnerability in the SiPass integrated access control system. I would suppose the reason that this was not reported by ICS-CERT is that the system is not a ‘real’ control system in that it doesn’t control any industrial processes. Owners of such systems would, however, certainly be interested in a vulnerability that would allow an attacker to conduct a denial of service attack on a security system. Siemens has produced a hot fix for this vulnerability that is available through customer service.

Thursday, August 2, 2012

ICS-CERT Has Been Busy


With the Senate debating a cybersecurity bill that actually includes control system coverage, the folks at ICS-CERT have been hard at work trying to keep the control system community up to date on just how vulnerable our systems are. This week they have published, so far, three alerts, four advisories and their Monthly Monitor.

Alerts



The DEFCON 20 conference last week was the source of the disclosure for two of the alerts, both reported by Dr. Wesley McGrew of Mississippi State University. Both deal with credential type issues and neither are remotely executable. The only thing of real  interest here (other than to owners of the affected systems) is that these are the only vulnerabilities to be reported at DEFCON 20 that ICS-CERT has been concerned about.

The third alert comes from an uncoordinated disclosure from Luigi. It’s a directory traversal vulnerability. It is remotely exploitable and Luigi has, as always, published proof of concept code on his web site. As expected, ICS-CERT did not include a link to Luigi’s disclosure, but I will. According to Luigi’s web site this disclosure was made back in June, hardly a timely notification by ICS-CERT.

It turns out that Luigi is also a composer. If you like techno type instrumentals, check out some of his tracks. 

Advisories



Siemens has self-reported vulnerabilities in two separate systems; it seems that they have gotten on the identifying-correcting-reporting bandwagon. Two versions of  SIMATIC S7-400 CPU have DOS vulnerabilities. Siemens has provided a firmware update for the V6.03 CPU but not the V5 as it has reached end-of-life and has been discontinued. Of course everyone has replaced the older version so it isn’t really a problem (SARCASM alert).

The second Siemens advisory deals with a default password in their Synco OZW Web Server device used for building automation systems. This would allow access to the building automation network which may (not mentioned in the ICS-CERT Advisory) include security systems. A firmware update is available, but changing the default passwords is a simpler option.

Dr. McGrew (mentioned above) was responsible for the coordinated disclosure of the authentication by-pass vulnerability in the ICONICS  GENESIS32 and BIZVIS Security Configurator. ICONICS is releasing a patch that disables the backdoor security login in some versions (no word on the others) and plans to implement a “more secure encryption algorithm” in the future. There is a publicly available exploit for this vulnerability. HMMM… did Dr. McGrew talk about this at DEFCON as well? Maybe this should have been an alert instead of an advisory.

The Sielco Sistemi advisory closes out two ICS-CERT Alerts for the Winlog SCADA system (one from a Luigi disclosure and another by Michael Messner). Sielco Sistemi has provided a software update that has been verified by Messner (oops, I guess Luigi is on the outs again).

Monthly Monitor


The latest two-month issue of the Monthly Monitor is, as always, a worthwhile read. They provide an interesting update to their previous report on the apparently on-going phishing attacks on pipeline companies. In my opinion the most important part of that discussion is found in the second paragraph on the first page:

“Recent reports and analysis conducted by ICS-CERT indicate that information pertaining to the ICS/SCADA environment, including data that could facilitate remote unauthorized operations, has been exfiltrated as part of this campaign. Despite this, ICS-CERT has not received any reports of unauthorized access into the ICS environment; however, this may be due to limited monitoring and intrusion detection capabilities in the targeted companies control networks. The intent of the attackers remains unknown.”

While this spear phishing campaign appears to be solely directed at pipeline companies, owners of all control systems need to pay attention to this. It is a classroom lesson in how to go about a systematic attack on control systems; infiltrate the system to gain the knowledge necessary to formulate an effective attack on the system. Much the same thing must have been done to prepare the Stuxnet attack.

There is also an interesting snippet about what may be the ‘next’ systemic vulnerability, inadequate keys or certificates in embedded devices. It is apparent that ICS-CERT is concerned about this apparently wide-spread vulnerability. They note that:

“ICS-CERT is currently coordinating with multiple vendors that could be affected by this vulnerability.”

Typically I would expect silence about a vulnerability that is this important until the vendors either have a chance to fix it, or ICS-CERT gives up on their cooperation. Either ICS-CERT is changing their policy (maybe because this is so important) or the level of cooperation that they are receiving leaves much to be desired. We’ll be watching for advisories on this topic and will wonder when people like Luigi start to look for these on their own.

Wednesday, July 4, 2012

ICS-CERT Publishes New WellinTech Advisory


Yesterday the DHS ICS-CERT published a new advisory concerning multiple vulnerabilities reported in two applications provided by WellinTech; KingView and KingHistorian. These vulnerabilities were reported by Carlos Mario Penagos Hollman and Dillon Beresford in a coordinated disclosure.

The Vulnerabilities


The vulnerabilities are remotely exploitable and can be exploited by a moderately skilled attacker. The Advisory notes that four of the vulnerabilities could result in execution of arbitrary code and the fifth (path traversal) would allow access to process information. The vulnerabilities include:

• Stack-based buffer overflow;

• Heap-based buffer overflow;

• Out-of-bounds read;

• Path traversal; and

• Improper restriction of operation within the bounds of a memory buffer.

WellinTech has produced separate patches for KingView and KingHistorian. ICS-CERT reports that Hollman and Beresford have validated the patches.

Information Sharing


There is one small oddity in this advisory. Typically when ICS-CERT reports on a coordinated disclosure it posts the information initially on the US-CERT limited access server so that owner/operators have a chance to patch their systems before the vulnerability becomes public knowledge. ICS-CERT usually reports that this has happened in the overview section of the advisory; it did not do so in this case. It is not clear whether this was just an omission of the comment (inadvertent or otherwise) or if ICS-CERT did not post this advisory on the restricted access server for some reason.

If it is the later, I’m not sure that it would be a significant change in process. We have no idea how many control system owners have applied to obtain (or been approved to obtain) access to that US-CERT server, but I would be very surprised if it were a significant fraction of the actual owners in the US. Even those that do have access probably don’t utilized it often enough to be assured of the early warning being made available through these restricted releases.

There has to be some way to push this information to the user level. I’m not sure how well vendors do in this regard (and I would assume that some do it better than others and some don’t do it at all), but from an infrastructure protection point of view this is at least partially a responsibility of DHS and thus, by default, ICS-CERT. To be fair ICS-CERT does make an effort; just recently they started Tweeting (@ICS-CERT) about these vulnerability advisories, but they only currently have 93 followers and most of those are commentators like me.

For critical infrastructure control systems, there needs to be some sort of registration requirement where ICS-CERT maintains a registry of control system owners that allows them to push these alerts and advisories directly to security managers at the facility level. Then the owners could make a timely decision on how to address the vulnerabilities in their systems.

Sunday, January 22, 2012

ICS-CERT Publishes Five S4 Based Alerts Plus Two Other Alerts

On Friday the DHS ICS-CERT published 7 separate alerts, five of which referenced vulnerabilities that were publicly discussed at Digital Bond’s SCADA Security Scientific Symposium (S4) in Miami, FL. These alerts, combined with a similar alert published on Thursday, may mark just the tip of the iceberg as Dale Peterson noted on the DigitalBond.com blog that 30 students at a HMI hacking class before the actual symposium “were quickly finding 0days using ActiveX and File Format Fuzzing”.

Oh yes, the two other alerts. They were based upon uncoordinated disclosures by the Digital Security Research Group (DSecRG) for systems produced by WellinTech and WAGO.

S4 Alerts


The five S4 alerts issued Friday included a general alert for disclosures made during the Project Basecamp portion of S4. The alert notes that the reported vulnerabilities in multiple vendor products included “buffer overflows, backdoors, weak authentication and encryption, and other vulnerabilities that could allow an attacker to take control of the device and interfere or halt the process it controls” (page 1). The four other S4 related alerts dealt with specific vulnerabilities in systems from four separate vendors; those vendors were:



Koyo (Note: not a PLC vendor, but an Ethernet vendor that provides communications between PLCs and the actual control system)


Project Basecamp was a detailed search for and reporting of vulnerabilities in various PLC’s used by industrial control systems. Dale has become increasingly vocal over the last six months or so about his dissatisfaction at cybersecurity community’s disregard of the consequences of the insecure design of programmable logic controllers (PLC). In both his blog and in any other venue that would listen (or even pretend to listen) he has made it clear that everyone in the control system vendor and researcher community has known for at least 10 years that the basic PLC design has inherent cyber-security flaws that make them vulnerable to attack. These vulnerabilities were made painfully clear in the design of the Stuxnet virus.

Because the Stuxnet worm exploited vulnerabilities in the Siemens PLC, many of the Siemens security flaws have been publicly documented, while the rest of the industry breathed a sigh of relief that their systems weren’t being used by the Iran’s nuclear program. The whole point of Project Basecamp was to formally tell the world that Siemens was not alone in their ‘insecure by design’ problems.

That the world, at least the security professional side, has taken notice cannot be doubted. There has been significant discussions in a number of forums (on LinkedIn.com and on the SCADASec list for instance) and in the cyber related press. Unfortunately, most of that discussion has been about the public disclosure of the vulnerabilities (along with some Metasploit® modules published to aid in the exploit of those vulnerabilities) rather than on the potential effects of the vulnerabilities on real world control systems. Hopefully, the fait accompli provided by Dale and the Basecamp team will eventually allow for a more detailed discussion of the vulnerabilities and how to protect control systems from attack using those vulnerabilities.

ICS-CERT does make a valuable contribution (with a forgivable sideways slap at Project Basecamp) to that inevitable discussion in the general Basecamp alert. They note (page 2):

“This public release increases the potential for cyber attack on these devices, particularly if the devices are connected to the Internet. ICS-CERT reminds users that the use of readily available and generally free search tools (such as SHODAN and ERIPP) significantly reduces time and resources required to identify Internet facing control systems. In turn, hackers can use these tools combined with the exploit modules to identify and attack vulnerable control systems. Conversely, owners and operators can also use these same tools [emphasis added] to audit their assets for unsecured Internet facing devices.”

But, less anyone forget, the Iranian PLCs that were the Stuxnet target were not connected to the Internet, nor were their control systems. Many of the vulnerabilities reported by the Project Basecamp team will allow an attacker to exploit the vulnerabilities without having to target an internet connected PLC; it will require a higher skill level and more system knowledge. There are loads of attackers with the appropriate skills and system knowledge can be easily obtained via social engineering attacks. Internet-isolated control systems (if there are really such things in existence) are not safe from attacks based upon these vulnerabilities.

WellinTech Alert


The WellinTech alert provides initial information on a reported password encryption vulnerability in the KingSCADA product that could allow an attacker to read and use a user password, thus gaining user level access to a control system. Exploiting this vulnerability requires access to the SCADA server.

WAGO Alert


The WAGO alert concerns multiple vulnerabilities in the I/O System 750. The vulnerabilities include:




Interestingly a DSecRG press release notes that the WAGO disclosure of the 750 series controller vulnerabilities was made in support of Project Basecamp. Additionally the DSecRG web site notes two other control system vulnerabilities released by DSecRG on the same day. One deals with a default password vulnerability on Tecomat PLCs (more Project Basecamp fallout?) and an ActiveX vulnerability on an OPC system. I expect that we’ll see ICS-Alerts on these on Monday.

Thursday, December 22, 2011

New ICS-CERT Monitor and 2 Advisories

Yesterday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published the December edition of their Monthly Monitor and two new Advisories for control system vulnerabilities affecting WellinTech’s KingView and 7-Technologies IGSS SCADA systems.

Monthly Monitor


ICS-CERT continues to produce a brief but valuable monthly newsletter that should be widely read in the control system community. The latest issue contains:

• A neat new logo (okay that’s not so important, but it is good graphics design);

• Another overview of the ‘Water System Hack’;

• A good summary of generic malware analysis and mitigation techniques;

• A summary of the ‘latest’ Gleg Agora SCADA release (probably more appropriate here than as an alert)

• A lengthier listing of control system security articles and blog posts (including one by SCADAHacker, a nice response to my comment last month about the lack of bloggers); and

• Their standard listing of Alerts and Advisories and plug for Coordinated Vulnerability Disclosure

WellinTech


This Advisory describes a heap based buffer overflow vulnerability reported by Luigi through ZDI (so it was coordinated) in the WellinTech KingView system. It appears to be a common remotely exploitable vulnerability that allows execution of arbitrary code by an attacker with an intermediate skill level. WellinTech has a patch available. The CVE number provided in the Advisory is not yet active.

Two interesting things here. First ICS-CERT includes a link to the Chinese language instructions for the patch in addition to the English language instructions (multiculturalism at its best). More importantly the Advisory notes that there are no known exploits available. Luigi typically develops and publishes exploit code, though I can’t find a reference to this vulnerability on his web page. Since this is part of the ZDI project I wonder if he provided them with the code and they just haven’t released it.

7-Technologies


7-Technologies seems to be catching it this week. Earlier there was an advisory for their data server and yesterday a new advisory for similar buffer overflow vulnerability discovered by a separate researcher Celil Unuver (SignalSEC LLC). It appears that the same product update will solve both problems. The CVE file on this vulnerability is also not yet active.

Tuesday, March 8, 2011

ICS-CERT Alert for WellinTech KingView

Yesterday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published a brief alert concerning an Active X vulnerability  [updated link added 4-21-26] in WellinTech’s KingView 6.53. No details on the vulnerability are available, other than the fact that there is reportedly an exploit publicly available for the vulnerability. ICS-CERT is working with WellinTech to verify the vulnerability and develop applicable mitigation measures.

Tuesday, January 11, 2011

DHS ICS-CERT Reports WellinTech Vulnerability

Earlier today the DHS Industrial Control System Cyber Emergency Response Team issued an alert about a reported vulnerability in the WellinTech KingView v6.3. The publicly reported buffer overflow vulnerability would allow a remote attacker to crash an affected application or execute arbitrary code.

DHS reports that they have not confirmed the vulnerability but is reporting it because alleged exploit code is publicly available. I have seen this vulnerability discussed on a couple of different sites (sorry I failed to copy pages or links) and I understand that the researcher who discovered the vulnerability tried to report it to WellinTech, a Chinese company, but received no response. The researcher went public this last weekend.
 
/* Use this with templates/template-twocol.html */