Showing posts with label WinCC. Show all posts
Showing posts with label WinCC. Show all posts

Wednesday, June 19, 2013

ICS-CERT Publishes 3 Siemens Advisories

Today the DHS ICS-CERT published advisories for multiple vulnerabilities in three separate products from Siemens; Scalance, WinCC and COMOS. While the vulnerabilities in WinCC were reported by Alexander Tlyapov of Positive Technologies, the remaining vulnerabilities were identified internally.

Multiple Vulnerabilities

The vulnerabilities include (Note: links on product names are to the respective Siemens ProductCERT report):

Scalance

• Permissions, privileges, and access controls: CVE-2013-3633 and CVE-2013-3634;

WinCC

• SQL injection:  CVE-2013-3957;
• Hard-coded credentials: CVE-2013-3958;
• Forced browsing: CVE-2013-3959; and

COMOS

• Permissions, privileges, and access controls: CVE-2013-3927

Exploitability

ICS-CERT reports that a relatively low skilled attacker could exploit these vulnerabilities. The Scalance and WinCC vulnerabilities could be exploited remotely, but the COMOS vulnerability requires local access by an authenticated user. The Scalance vulnerabilities would allow an attacker to execute arbitrary commands. The WinCC vulnerabilities could allow an attacker to gain full system access. The COMOS vulnerability would allow an attacker to gain full access to information stored in the COMOS library.

Mitigation

Software updates have been developed by Siemens for all three products. Siemens ProductCERT has verified that the modifications mitigate the vulnerabilities (Note: I would have been happier to hear that Alexander Tlyapov had been asked to validate the WinCC update) . The updates can be found at the below listed links:

Scalance;
WinCC; and
COMOS

Delayed Notification


The Siemens’ ProductCERT web page provides data on when these vulnerabilities were published by that organization (Scalance 5-24-13; Win CC 6-14-13; and COMOS 6-18-13). The same day publication of the COMOS vulnerability by ICS-CERT is pretty impressive; the three week delay for the Scalance program is not so much.

Thursday, June 7, 2012

ICS-CERT Issues WinCC Advisory


Yesterday DHS ICS-CERT published an advisory for multiple vulnerabilities in the Siemens’ WinCC application. The vulnerabilities were reported in a coordinated disclosure by a number of researchers from Positive Technologies. In a twist that is to be encouraged, Siemens reported an additional related vulnerability that is being covered in this Advisory.

The vulnerabilities disclosed in this Advisory include:

Cross-site scripting, CVE-2012-2595 and CVE-2012-3003;

Xml (xpath) injection, CVE-2012-2596;

Directory traversal, CVE-2012-2597; and

Buffer overflow, CVE-2012-2598.

NOTE: These links may not be active for a couple of days.

The vulnerabilities are all remotely exploitable by a relatively unskilled attacker. Successful exploits could lead to a number of problems, but none are reported to lead directly to execution of arbitrary code.
Siemens has a security advisory addressing the issues and an update that address all but one of the vulnerabilities. The buffer overflow vulnerability is associated with DiagAgent, a utility that is no longer supported. Siemens suggests disabling DiagAgent and replacing it with SIMATIC Diagnostics Tool or SIMATIC Analyser.

Monday, January 30, 2012

Siemens – The Big ICS-CERT Advisory

Today the DHS ICS-CERT folks published an unusual advisory. They combined reports of vulnerabilities from four separate researchers; Billy Rios, Terry McCorkle, Shawn Merdinger, and Luigi Auriemma; and combined them into one big (eleven separate vulnerabilities) advisory on the Siemens WinCC application. Not only is the big from the number of vulnerabilities, but the potential consequences of the exploitation of these vulnerabilities is really big. ICS-CERT notes that:

“Successful exploitation of these vulnerabilities could allow an attacker to log on to a vulnerable system as a user or administrator with the ability to execute arbitrary code or obtain full access to files on the system.”

Given the wide range of facilities that this Siemens application is used, an attacker would have a wide range of potential targets that could essentially be exploited at will, shutting down electrical transmission facilities, water treatment facilities, chemical plants, even automotive manufacturing facilities. Simultaneous attacks on a number of targets across a number of manufacturing and utility sectors could have a catastrophic impact on local, state, national, or even world economies.

The catalogue of vulnerabilities includes:

• Insecure authentications;
• Weak default passwords;
• Cross-site scripting;
• Header injection;
• Client-side attack;
• Lack of telnet daemon authentication;
• String stack overflow;
• Directory traversal (two separate vulnerabilities);
• Denials of Service; and
• Arbitrary memory read access.

The good news (and I’m really having to stretch here to call this ‘good news’) is that ONE of the vulnerabilities requires user interaction to exploit. Fortunately for Siemens’ customers there have been so few successful social engineering attacks over the last year or so (pardon the gross sarcasm). The bad news (and it doesn’t come much worse than this) is that there are publicly available exploits for 7 of the 11 (Oh Craps, I know, pardon the pun) vulnerabilities.

The good news (another stretch) is that Siemens has dealt with each of these vulnerabilities. They have

• Patched 5;

• Changed product documentation to explain how to correct one during set up;

• Recommended deactivation of transport mode for four others; and

• Explained that users have the option of disabling the final vulnerability.

The bad news is that no one outside of Siemens has verified if any of the above actions prevent the exploit of any of the eleven vulnerabilities included in this report.

The final good thing is that ICS-CERT put all of these vulnerabilities into a single advisory, making it easier to keep track of what has been fixed or not. It might be a good idea to do the same sort of thing for Siemen’s PLCs.

Monday, January 16, 2012

WinCC vs MS Security Patches

I ran across an interesting Tweet today from @siemensindustry about Microsoft security patch compatibility with WinCC. It points us at a page on the Siemens web site that is kind of scary at first glance, but is actually quite valuable for owner/operators of Siemens WinCC control systems.

The Scary


The article on this Siemens page starts out with a warning:

In response to current events (new Trojan horse / virus), [emphasis added] we recommend consulting the Microsoft Security Bulletin MS10-046 - Critical.”

Now I don’t keep up with MS security bulletins real closely (I do automatic updates on my personal computer to avoid that necessity), but that number did seem kind of familiar. I clicked on the link provided and it became obvious why I remembered that particular bulletin number; the title of the bulletin is “Vulnerability in Windows Shell Could Allow Remote Code Execution (2286198)” and is dated August 24th, 2010. Yes, it is the update for one of the Stuxnet ‘0-day’ vulnerabilities.

The date for this page is 2012-01-09 (translated from European to American – 01-09-12) so I immediately jumped to the conclusion that Siemens was just now dealing with this basic Stuxnet related vulnerability. A little closer reading would seem to indicate that this is a long standing Siemens page that has just been updated for the latest (December) Microsoft Windows patches.

I would like to think that all Siemens WinCC owner/operators have already installed this particular security patch, making this confusing note on this Siemens page superfluous. That is probably a dangerous assumption on my part and Siemens is playing it safe, but I do wish they would re-word that opening paragraph to make it seem less timely. Oh, and Siemens could at least mention the name of the Trojan (Stuxnet).

The Valuable


Siemens does provide a valuable service to their customers on this web page (and there is a similar page for their PCS 7 system. There is a link to a spread sheet that provides a list of the Microsoft security patches that Siemens has tested for compatibility with their WinCC system. This is important because a minor incompatibility problem between a Windows update and a control system program can shut a manufacturing facility down or even damage equipment.

The latest Microsoft release covered on this spread sheet is the December 13th release and the earliest is 6-8-2004. At first glance it looks like all of the patches are compatible, but close examination shows some problems (See MS11-025). Siemens does note that a newer version of the patch does work on their system.

Siemens is to be commended on providing this service to their customers and I’m glad to see that they are also using TWITTER to help push this information out to the user community.

I do have a minor concern about the delay (December 13th to January 9th) in the publication of the compatibility information, but I do realize that the type of comprehensive system testing that is required takes some time. It would be nice if Siemens and Microsoft could work out some sort of arrangement where Microsoft could give Siemens some type of advance notification on their patches to allow Siemens to begin the testing process earlier.

A Concern


There is a link on this Microsoft Patch Compatibility page to a separate page entitled: “Why should you not install the Microsoft security patches KB2467174, KB2467175, KB2465361 and KB2465367 in WinCC, PCS 7 and WinCC Professional V11?” This is apparently a follow-up to the incompatible patches (MS11-025) that I mentioned above. The page explains that:

“Installation of one of the Microsoft security patches KB2467174, KB2467175, KB2465361 or KB2465367 causes a massive drain on resources (increase in handles) in WinCC Runtime (OS Runtime, WinCC Runtime Professional V11). This consumption of resources can lead to a standstill of WinCC Runtime.”

That certainly is not a good thing for a control system and owner/users would apparently be well advised not to install these patches.

Unfortunately, the vulnerabilities corrected by these patches would still exist in the Windows operating systems and thus make the Siemens control systems vulnerable to attack through those Windows problems (See Stuxnet). There is nothing on this page that indicates what other mitigating steps an owner/operator could take to protect their control systems from the vulnerabilities now made public by Microsoft.

Since Siemens does make the information available on their spread sheet, it is not a total loss, but a mention here would be appropriate. Also there must have been some lag time before those newer patches became available. There must have been some sort of partial mitigation steps that could have been employed to protect the control systems in the interim.
 
/* Use this with templates/template-twocol.html */