Showing posts with label Younes Dragoni. Show all posts
Showing posts with label Younes Dragoni. Show all posts

Thursday, July 30, 2020

5 Advisories Published – 7-30-20

Today the CISA NCCIC-ICS published four control system security advisories for products from Mitsubishi Electric (3) and Inductive Automation. They also published a medical device security advisory for products from Philips.

 

Factory Automation Advisory #1

 

This advisory describes an unquoted search path or element vulnerability in the Mitsubishi Factory Automation Engineering products. The vulnerability was reported by Mashav Sapir of Claroty. Mitsubishi has new versions that mitigate the vulnerability. There is no indication that Sapir has been provided an opportunity to verify the efficacy of the fix.

 

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to obtain unauthorized information, modify information, and cause a denial-of-service condition.

 

Factory Automation Advisory #2

 

This advisory describes a path traversal vulnerability in the Mitsubishi Factory Automation products. The vulnerability was reported by Mashav Sapir of Claroty. Mitsubishi has new versions that mitigate the vulnerability. There is no indication that Sapir has been provided an opportunity to verify the efficacy of the fix.

 

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to may allow an attacker to obtain unauthorized information, tamper the information, and cause a denial-of-service condition.

 

Factory Automation Advisory #3

 

This advisory describes a permissions issue vulnerability in the Mitsubishi Factory Automation Engineering Software products. The vulnerability was reported by Younes Dragoni of Nozomi Networks, the Applied Risk research team, and Mashav Sapir of Claroty. Mitsubishi has new versions that mitigate the vulnerability. There is no indication that researchers have been provided an opportunity to verify the efficacy of the fix.

 

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to enable the reading of arbitrary files, cause a denial-of-service condition, and allow execution of a malicious binary.

 

Inductive Automation Advisory

 

This advisory describes a missing authorization vulnerability in the Inductive Automation Ignition 8 product. The vulnerability was reported by Mashav Sapir of Claroty. Inductive Automation has a new version that mitigates the vulnerability. There is no indication that Sapir has been provided an opportunity to verify the efficacy of the fxi.

 

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to gain access to sensitive information.

 

Philips Advisory

 

This advisory describes an insertion of sensitive information into log file vulnerability in the Philips DreamMapper mobile application. The vulnerability was reported by Lutz Weimann, Tim Hirschberg, Issam Hbib, and Florian Mommertz of SRC Security Research & Consulting. Philips plans a new release to mitigate the vulnerability by June of next year.

 

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker access to the log file information containing descriptive error messages.


Tuesday, August 13, 2019

1 Alert, 3 Advisories and 4 Updates Published – 08-13-19


Today the DHS NCCIC-ICS published a control system security alert for products from Mitsubishi Electric; three control system security advisories for products from Siemens, OSIsoft, and Delta Industrial; and four control system advisory updates for products from Siemens.

Mitsubishi Alert


This alert describes a report of seven vulnerabilities in the Mitsubishi smartRTU and INEA ME-RTU. The vulnerabilities were reported (with exploit code) by Mark Cross (@xerubus) (NCCIC-ICS did provide the link to the report, a first). Cross disclosed the vulnerabilities to CISA and published the public disclosure under the 45-day disclosure policy.

The seven reported vulnerabilities are:

OS command injection - CVE-2019-14931;
Unauthenticated download of configuration file - CVE-2019-14927;
Stored cross-site script - CVE-2019-14928;
Use of hard-coded cryptographic keys - CVE-2019-14926;
Hard-coded user passwords - CVE-2019-14930;
Plaintext password storage - CVE-2019-14929; and
Incorrect default permissions - CVE-2019-14925


Siemens Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the Siemens SCALANCE X switches. The vulnerability was reported by Younes Dragoni from Nozomi Networks. Siemens has provided generic workarounds. There is no indication that Dragoni has been provided an opportunity to verity the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial-of-service condition.

OSIsoft Advisory


This advisory describes two vulnerabilities in the OSIsoft PI Web API. The vulnerabilities are self-reported. OSIsoft has an update to mitigate the vulnerability.

The two reported vulnerabilities are:

Inclusion of sensitive information in log files - CVE-2019-13515; and
Protection mechanism failure.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerabilities to allow direct attacks against the product and disclose sensitive information.

Delta Advisory


This advisory describes two vulnerabilities in the Delta DOPSoft Human Machine Interface (HMI) editing software. The vulnerability was reported by kimiya of 9SG Security Team via the Zero Day Initiative. Delta has a new version that mitigates the vulnerabilities. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Out-of-bounds read - CVE-2019-13513; and
Use after free - CVE-2019-13514

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow information disclosure, remote code execution, or crash of the application.

SIMATIC WinCC Update


This update provides additional information on an advisory that was originally reported on July 11th, 2019. The update provides new affected version information and mitigation links for:

SIMATIC WinCC V7.3;
SIMATIC PCS 7 V8.1, and
SIMATIC WinCC Runtime Professional V14

Spectrum Power Update


This update provides additional information on an advisory that was originally reported on July 9th, 2019. The update provides corrected version information for Spectrum Power 5.

SIPROTEC Update


This update provides additional information on an advisory that was originally reported on July 9th, 2019. The update provides additional mitigation information.

SIMATIC PCS7 Update


This update provides additional information on an advisory that was originally reported on July 9th, 2019. The update provides corrected version information and mitigation links for:

SIMATIC WinCC V7.3; and
SIMATIC PCS 7 V8.1
NOTE: Siemens published an additional two advisories and two updates today that were not reported by NCCIC-ICS. They may be reported on Thursday, if not, I will report on them on Saturday.

Tuesday, May 21, 2019

Two Advisories Published – 05-21-19


Today the DHS NCCIC-ICS published two control system security advisories for products from Mitsubishi Electric and Computrols.

Mitsubishi Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the Mitsubishi MELSEC-Q series Ethernet module. The vulnerability was reported by Younes Dragoni and Alessandro Di Pinto of Nozomi Networks. Mitsubishi has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to render the device unresponsive, requiring a physical reset of the PLC (Programmable Logic Controller).

Computrols Advisory


This advisory describes nine vulnerabilities in the Computrols CBAS Web, a Web Building Management System (BMS). The vulnerabilities were reported by Gjoko Krstic of Applied Risk. Computrols has new firmware versions that mitigate the vulnerabilities. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

The nine reported vulnerabilities are:

Cross-site request forgery - CVE-2019-10847;
Information exposure through discrepancy - CVE-2019-10848;
Cross-site scripting - CVE-2019-10846;
Command injection - CVE-2019-10854;
Information exposure through source code - CVE-2019-10849;
Hard-coded encryption key - CVE-2019-10851;
SQL injection - CVE-2019-10852;
Authentication bypass using alternate path or channel - CVE-2019-10853; and
Inadequate encryption strength - CVE-2019-10855

NOTE: the Applied Risk report and the Computrols advisory also include an additional vulnerability; default credentials - CVE-2019-10850.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow unauthorized actions with administrative privileges, disclosure of sensitive information, execution of code within a user’s browser, execution of unauthorized OS commands, unauthorized access to the database, execution of unauthorized SQL commands, authentication bypass, or decryption of passwords.

NOTE: I briefly discussed these vulnerabilities on Saturday.

Wednesday, May 1, 2019

Two Advisories Published – 04-30-19


Yesterday the DHS NCCIC-ICS published a control system security advisory for products from Rockwell and a medical device security advisory for products from Philips.

Rockwell Advisory


This advisory describes two vulnerabilities in the Rockwell CompactLogix 5370 programmable automation controllers. The vulnerabilities were reported by Younes Dragoni of Nozomi Networks and George Lashenko of CyberX respectively. Rockwell has firmware updates to mitigate the vulnerabilities. There is no indication that either researcher was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Uncontrolled resource consumption - CVE-2019-10952; and
Stack-based buffer overflow - CVE-2019-10954

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow a remote attacker to render the web server unavailable and/or place the controller in a major non-recoverable faulted state (MNRF).

Philips Advisory


This advisory describes a cross-site scripting vulnerability in the Philips Tasy EMR workflow based information system. The vulnerability was reported by Rafael Honorato. Phillips has provided generic workarounds to mitigate the vulnerability. There in no indication that Honorato has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with site or VPN access could exploit the vulnerability to provide unexpected input into the application, execute arbitrary code, alter the intended control flow of the system, and access sensitive information.

Wednesday, November 14, 2018

8 Advisories and 5 Updates (all Siemens) Published


Yesterday the DHS NCCIC-ICS published eight control system security advisories and updated five previously published advisories; all for products from Siemens.

SIMATIC Panels Advisory


This advisory describes two vulnerabilities in the Siemens SIMATIC HMI and WinCC. The vulnerabilities were reported by Hosni Tounsi from Carthage Red Team. Siemens has newer versions that mitigate the vulnerability. There is no indication that Tounsi has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Path traversal - CVE-2018-13812; and
Open redirect - CVE-2018-13813

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow download of arbitrary files from the device, or allow URL redirections to untrusted websites.

SIMATIC IT Advisory


This advisory describes an improper authentication vulnerability in the Siemens SIMATIC IT Production Suite. The vulnerability is self-reported. Siemens has updated to mitigate the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow an attacker to compromise confidentiality, integrity and availability of the system.

SIMATIC Step 7 Advisory


This advisory describes an unprotected storage of credential in the Siemens SIMATIC STEP 7 (TIA Portal). This vulnerability is self-reported. Siemens has updates available that mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to reconstruct passwords.

SIMATIC S7 Advisory


This advisory describes a resource exhaustion vulnerability in the Siemens SIMATIC S7. The vulnerability was reported by Younes Dragoni of Nozomi Networks. Siemens has a new version for the S7-1500 that mitigates the vulnerability. There is no indication that Dragoni was provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial-of-service condition that could result in a loss of availability of the affected device.

SCALANCE S Advisory


This advisory describes a cross-site scripting vulnerability in the Siemens SCALANCE S firewalls. The vulnerability was reported by Nelson Berg of Applied Risk. Siemens has a new version that mitigates the vulnerability. There is no indication that Berg has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker using social engineering could remotely exploit this vulnerability to allow arbitrary script injection (XSS).

SIMATIC WinCC Advisory


This advisory describes a code injection vulnerability in the Siemens SIMATIC Panels and SIMATIC WinCC (TIA Portal). The vulnerability is self-reported. Siemens has updates available for all but one of the affected devices.

NCCIC reports that a relatively low-skilled attacker with network access could exploit the vulnerability to perform a HTTP header injection attack.

S7-400 Advisory


This advisory describes two improper input validation vulnerabilities in the Siemens S7-400 CPUs. The vulnerability was reported by CNCERT/CC. Siemens has provided specific workarounds to mitigate the vulnerabilities.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to crash the device being accessed which may require a manual reboot or firmware re-image to bring the system back to normal operation.

IEC 61850 Advisory


This advisory describes an improper access control vulnerability in the Siemens IEC 61850 system configurator, DIGSI 5, DIGSI 4, SICAM PAS/PQS, SICAM PQ Analyzer, and SICAM SCC. The vulnerability is self-reported. Siemens has updates to mitigate the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to exfiltrate limited data from the system or execute code with operating system user permissions.

Industrial Products Update


This update provides additional information on an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th, November 28th, February 27th, 2018, May 3rd, 2018 May 15th, 2018, September 11th, 2018 and most recently on October 9th, 2018. The update provides new affected version and mitigation information for:

• SINAMICS S120;
• PN/PN Coupler;
• SIMATIC ET200 SP;
• SIMATIC S7-400 V; and
• SIMOCODE pro V PROFINET

SCALANCE Update


This update provides additional information on an advisory that was originally published on November 14th, 2017 and updated on December 5th, 2017, December 19th, 2017, January 25th, 2018 and again on April 24th, 2018. The update changed the update information for SCALANCE W-700 (IEEE 802.11n).

PROFINET Update


This update provides additional information on an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th,  November 28th, 2017January 18th, 2018, January 25th, 2018, January 27th, 2018, March 6th, 2018 and most recently on May 3rd, 2018. The update provides new affected version and mitigation information for:

• SINAMICS S120;
• SIMATIC ET 200SP (except IM155-6 PN ST); and
• SIMATIC Panels

OpenSSL Update


This update provides additional information on an advisory that was originally published on August 14th, 2018 and updated on September 11th, 2018 and again on October 9th, 2018. The update provides new affected version and mitigation information for:

• SIMATIC HMI WinCC Flexible; and
• SIMATIC IPC DiagMonitor

SIMATIC S7 Update


This update provides additional information on an advisory that was originally published on March 29th, 2018 and updated on April 24th, 2018, and again on June 12th, 2018. The update provides new affected version and migitagion information for:

• SIMATIC BATCH V8.2;
• OpenPCS 7 V8.2; and
• SIMATIC Route Control V8.2

NOTE: I will address the other four updates that Siemens published on Saturday.

Friday, August 17, 2018

ICS-CERT Publishes 3 Advisories


Yesterday the DHS ICS-CERT published two control system security advisories for products from Tridium and Emerson and a medical device security advisory for products from Philips. The Tridium advisory was previously published on the HSIN ICS-CERT library on July 10, 2018. For more on this HSIN resource see the final section below.

Tridium Advisory


This advisory describes two vulnerabilities in the Tridium Niagara controller. The vulnerabilities were reported by Johnathan Gains and Leet Cyber Security. Tridium has updates available that mitigate the vulnerability. There is no indication that that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Path traversal - CVE-2017-16744; and
Improper authentications - CVE-2017-16748

ICS-CERT reports that an uncharacterized attacker could remotely exploit these vulnerabilities to crash the device being accessed; a buffer overflow condition may allow remote code execution.

Emerson Advisory


This advisory describes four vulnerabilities in the Emerson DeltaV DCS Workstations. The vulnerabilities were reported by Younes Dragoni of Nozomi Networks, Ori Perez of CyberX. Emerson has a patch available that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Uncontrolled search path element - CVE-2018-14797;
• Relative path traversal - CVE-2018-14795;
• Improper privilege management - CVE-2018-14791; and
• Stack-based buffer overflow - CVE-2018-14793

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow arbitrary code execution, malware injection, or malware to spread to other workstations.

Philips Advisory


This advisory describes two vulnerabilities in the Philips PageWriter Cardiographs. Philips is self-reporting these vulnerabilities to ICS-CERT. Philips has produced generic workarounds and plans to issue updates to mitigate the vulnerabilities in the middle of next year.

The two reported vulnerabilities are:

• Improper input validation - CVE-2018-14799; and
• Use of hard-coded credentials - CVE-2018-14801

ICS-CERT reports that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to allow buffer overflows or allow an attacker to access and modify settings on the device.

HSIN Library


It has been a while since I mentioned the ICS-CERT library on the Homeland Security Information Network. This restricted access, on-line resource provides ICS-CERT a method of sharing information with the user community for vulnerabilities that may affect critical homeland resources. This restricted release is designed to allow owners a chance to implement mitigation measures before the vulnerability becomes public knowledge.

For more information about this program and to request access see this ICS-CERT page.

Tuesday, August 14, 2018

ICS-CERT Publishes 4 Advisories


Today the DHS ICS-CERT published three control system security advisories for products from Siemens and one medical device security advisory for products from Philips. The three Siemens advisories were briefly discussed here over the weekend.

Automation License Manager Advisory


This advisory describes two vulnerabilities in the Siemens Automation License Manager. The vulnerabilities were reported by Vladimir Dashchenko from Kaspersky Lab. Siemens has updates available to mitigate the vulnerability. There is no indication that Dashchenko was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Relative path traversal - CVE-2018-11455; and
Improper input validation - CVE-2018-11456

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow remote code execution or allow an attacker to determine port status on another remote system.

OpenSSL Advisory


This advisory describes a cleartext transmission of sensitive information vulnerability in the Siemens Industrial Products. The vulnerability is being self-reported by Siemens. Siemens has updates for some of the affected products and continues to work on the remainder.

ICS-CERT reports that an uncharacterized attacker could remotely exploit this vulnerability to result in unencrypted data being transmitted by the SSL/TLS record layer.

SIMATIC Advisory


This advisory describes two incorrect default permissions vulnerabilities in the Siemens SIMATIC STEP 7 (TIA Portal) and SIMATIC WinCC (TIA Portal). The vulnerabilities were reported by Younes Dragoni from Nozomi Network. Siemens has updates that mitigate the vulnerabilities. There is no indication that Dragoni has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker with local access could exploit the vulnerability to manipulate files and cause a denial-of-service-condition, or execute code both on the manipulated installation as well as devices configured using the manipulated installation.

Philips Advisory


This advisory describes two vulnerabilities in the Philips Philips’ IntelliSpace Cardiovascular (ISCV)/Xcelera server products. Philips identified the problem due to a customer complaint. Philips has produced a work around pending publication of an updated version.

The two reported vulnerabilities are

• Improper privilege management - CVE-2018-14787; and
• Unquoted search path or element - CVE-2018-14789

ICS-CERT reports that a relatively low-skilled attacker with local access and users privileges to the ISCV/Xcelera server to escalate privileges on the ISCV/Xcelera server and execute arbitrary code.

Saturday, August 11, 2018

Public ICS Disclosures – Week of 08-04-18


This week we have four vendor advisories from Siemens (3) and ABB and an update of a vendor advisory from Siemens. There were also a number of BlackHat Briefings this week that touched on control system security issues.

Automation License Manager Advisory


Siemens reported two vulnerabilities in their Automation License Manager. The vulnerabilities were reported by Vladimir Dashchenko from Kaspersky Lab. Siemens has updates available to mitigate the vulnerabilities. There is no indication that Dashchenko was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Directory traversal - CVE-2018-11455; and
Network canning vulnerability - CVE-2018-11456

OpenSSL Advisory


Siemens reported an ‘open error state’ vulnerability in the OpenSSL implementation in a number of Siemens Industrial Products. This third-party software vulnerability is being self-reported by Siemens. Siemens has developed updates for some of the affected products (additional work is ongoing) to mitigate the vulnerability.

As always with third-party software issues, there is always the possibility that this vulnerability may affect control system products from other vendors.

SIMATIC Advisory


Siemens reported two improper file permission vulnerabilities in their SIMATIC Step 7 and WinCC products. The vulnerabilities were reported by Younes Dragoni from Nozomi Networks. Siemens has updates for some of the affected products and has reported work arounds.

NOTE: Siemens notes that this vulnerability was coordinated through ICS-CERT so we will probably see this reported by ICS-CERT next week.

ABB Advisory


ABB reported (registration required) an  LDAP authentication vulnerability in their eSOMS product. The vulnerability was reported by an undisclosed researcher. ABB is working on a new version to mitigate the vulnerability and has reported a work around.

Siemens Update


Siemens updated their Spectre/Meltdown advisory. This advisory was last updated on June 26th, 2018. This latest update adds update information for SIMATIC IPC6x7C, SIMAITC IPC8x7C, SIMOTION P320-4S, and SIMOTION P320-4E.

BlackHat Briefings


The latest BlackHat conference was held in Las Vegas this week. There were six briefings that the conference web site identifies as touching on Smart Grid/Industrial Security. There were:



Speaker: Thomas Roth

Speaker: Justin Shattuck


Speaker: Balint Seeber

Thursday, May 17, 2018

ICS-CERT Publishes 4 Advisories and 2 Siemens Updates


Today the DHS ICS-CERT published three control system security advisories for products from Delta Electronics, Siemens, Phoenix Contact, and Medtronic. They published on medical device security advisory for products from Medtronic. They also updated two previously issued control system security advisories for products from Siemens.

The three Siemens advisories/updates are the ones I mentioned in passing earlier this week.

Delta Advisory


This advisory describes a heap-based buffer overflow vulnerability in the Delta Industrial Automation TPEditor. The vulnerability was reported by ThePotato working with ZDI. Delta has released a new version that mitigates the vulnerability. There is no indication that the researcher was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to crash the accessed device, resulting in a buffer overflow condition that may allow remote code execution.


Siemens Advisory


This advisory describes an improper input validation vulnerability in the Siemens S7-400 CPU. The vulnerability is being self-reported. Siemens has updates that mitigate the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial-of-service condition of the CPU. The CPU will remain in DEFECT mode until a manual restart is performed. The Siemens security advisory notes that:

“Successful exploitation requires an attacker to be able to send a specially crafted S7 communication packet to a communication interface of the CPU. This includes Ethernet, PROFIBUS, and Multi Point Interfaces (MPI). No user interaction or privileges are required to exploit the security vulnerability”

Phoenix Contact Advisory


This advisory describes four vulnerabilities in the Phoenix FL SWITCH 3xxx/4xxx/48xx Series. The vulnerabilities were reported by  Vyacheslav Moskvin, Semen Sokolov, Evgeniy Druzhinin, Georgy Zaytsev and Ilya Karpov of Positive Technologies working through CERT@VDE. Newer firmware mitigates the vulnerability. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Command injection - CVE-2018-10730;
• Information exposure - CVE-2018-10729; and
Stack-based buffer overflow (2) - CVE-2018-10728, and CVE-2018-10731

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow for remote code execution and information disclosure.

GE Advisory


This advisory describes an improper input validation vulnerability n the GE PACSystems, an industrial Internet controller. The vulnerability was reported by Younes Dragoni of Nozomi Networks. GE has released new firmware to mitigate the vulnerability. There is no indication that Dragoni was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause the device to reboot and change its state, causing the device to become unavailable.

Medtronic Advisory


This advisory describes a missing encryption of sensitive data vulnerability in the Medtronic N’Vision Clinician Programmer. The vulnerability was reported by Billy Rios of Whitescope LLC. Medtronic has mitigated the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker with physical access to the card could exploit the vulnerability to access personal health information (PHI) or personally identifiable information (PII).

NOTE: This vulnerability was not reported on the FDA Medical Device Safety Communications page.

SIPROTEC Update #1


This update provides additional information on an advisory that was originally reported by ICS-CERT on May 19th, 2016 and updated on July 5th, 2016. This update removes 7SD80 from list of affected products.

SIPROTEC Update #2


This update provides additional information on an advisory that was was originally published on March 8th, 2018 and updated on April 19th, 2018. This update provides updated effected version information and mitigation measures for 7SD80.

Friday, March 30, 2018

ICS-CERT Publishes Four Advisories


Yesterday the DHS ICS-CERT published three control system security advisories for products from Siemens (2) and WAGO as well as a medical device security advisory for products from Phillips.

SIMATIC Advisory


This advisory describes an improper input validation vulnerability in the Siemens SIMATIC product line. The vulnerability was reported by Vladimir Dashchenko from Kaspersky Lab and independent researcher cdev1. A new version is available for one product that mitigates the vulnerability and activating an existing control mitigates the vulnerability in others. There is no indication that either of the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial-of-service condition on the remote and local communication functionality of the affected products. A system reboot is required to recover.

TIM 1531 Advisory


This advisory describes an incorrect implementation of an algorithm vulnerability in the Siemens TIM 1531 IRC communications modules. The vulnerability is self-reported. A new version is available that mitigates the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to enter a denial-of-service condition, or allow the attacker to read and manipulate data and configuration settings of the affected device.

WAGO Advisory


This advisory describes an improper shutdown or release vulnerability in the WAGO 750 Series PLC. The vulnerability was reported by Younes Dragoni of Nozomi Networks. WAGO has released new firmware that mitigates the vulnerability. There is no indication that Dragoni has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a denial-of-service condition affecting the ability of the device to establish connections to commissioning and service software tools. The WAGO security advisory notes that the vulnerability only affects the WAGO communication via WAGO Ethernet TCP/IP driver and that communications are still possible via the 3S TCP/IP level 2 driver and WAGO Service
Communication over TCP/IP.

Phillips Advisory


This advisory describes a large (indeterminate) number of vulnerabilities in the Phillips  iSite and IntelliSpace picture archiving communications systems (PACS). The vulnerabilities are self-reported. Phillips has provided multiple options for mitigating up to 99.9% of the vulnerabilities.

The reported vulnerabilities include:

• Improper restrictions of operations within the bounds of a memory buffer (#?);
• Code/source code vulnerabilities (at least 18);
• Information exposure (#?);
• Improper control of generation of code (#?);
• Weaknesses in OWASP to ten (at least 6);
• Improper restriction of XML external entity reference;
Other 3rd party component vulnerabilities (#?)

ICS-CERT reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to provide unexpected input into the application, execute arbitrary code, alter the intended control flow of the system, access sensitive information, or potentially cause a system crash.

Comment: This is a really flakey advisory and it certainly does not appear to be a problem at ICS-CERT. I am pretty sure that the authors of this advisory wanted to say that: “These products are just screwed up.” Unfortunately, that type of broad characterization is even less helpful than this report. Oh, and Phillips? The comment on their product security web page is priceless: “Philips will continue to add cybersecurity vulnerability remediation improvements through our Secure Development Lifecycle (SDL) as threats continue.” At least they did self-report this fiasco.

NOTE: These vulnerabilities were not reported on the FDA Medical Device Safety Communications page.

Missing Siemens Update


On Tuesday (the same day that Siemens announced the two advisories above) Siemens announced that they had updated their advisory on the improper input validation vulnerability in the Siemens SIMATIC, SINUMERIK, and PROFINET IO products reported last week by ICS-CERT. The update removed a product from the affected product list.

Wednesday, February 28, 2018

ICS-CERT Publishes 5 Advisories and 5 Siemens Updates


Yesterday the DHS ICS-CERT published two medical device security advisories for products from Philips and Medtronic. They published three industrial control system security advisories for products from Emerson, Delta Electronics and Siemens. They also updated five previously published control system security advisories for a variety of products from Siemens.

NOTE: The Siemens advisory and five updates were briefly mentioned here last week. There was another advisory and another update (both 3rd party vendor problems affecting Siemens products) that Siemens announced at the same time that ICS-CERT has apparently decided not to address.

ICS-CERT also recently announced a call for abstracts for the Spring 2018 meeting of the ICSJWG in Albuquerque, NM on April 10 - 12, 2018. Abstracts need to be submitted by March 13th, 2018.

Philips Advisory


This advisory describes a relatively large number of vulnerabilities in the Philips Intellispace Portal ISP visualization and image analysis system. The vulnerabilities are apparently being self-reported. There is no report about these vulnerabilities on the FDA medical device safety page. Philips will be issuing an updated version in the coming months to mitigate the vulnerabilities.

NOTE: Apparently at least some of these vulnerabilities are 3rd party vendor issues that have seen publicly available exploits in other products.

The 35 reported vulnerabilities include:

• Improper input validation (13) - CVE-2018-5474, CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, CVE-2017-0148, CVE-2017-0272, CVE-2017-0277, CVE-2017-0278, CVE-2017-0279, CVE-2017-0269, CVE-2017-0273, and CVE-2017-0280;
• Information exposure (8) - CVE-2017-0147, CVE-2017-0267, CVE-2017-0268, CVE-2017-0270, CVE-2017-0271, CVE-2017-0274, CVE-2017-0275, and CVE-2017-0276;
• Permissions, privileges and access controls (4) - CVE-2018-5472, CVE-2018-5468, CVE-2017-0199, and CVE-2005-1794;
• Unquoted search path element - CVE-2018-5470;
• Left over debug code - CVE-2018-5454; and
Cryptographic issues (8) - CVE-2018-5458, CVE-2018-5462, CVE-2018-5464, CVE-2018-5466, CVE-2011-3389, CVE-2004-2761, CVE-2014-3566, and CVE-2016-2183

ICS-CERT reports that an uncharacterized attacker could remotely exploit these vulnerabilities  to gain unauthorized access to sensitive information, perform man-in-the-middle attacks, create denial of service conditions, or execute arbitrary code.

Medtronic Advisory


This advisory describes two vulnerabilities in the Medtronic 2090 CareLink Programmers. The vulnerabilities were reported by Billy Rios and Jonathan Butts of Whitescope LLC. There is no report about these vulnerabilities on the FDA medical device safety page. Medtronics has identified compensating controls that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Strong password in a recoverable format - CVE-2018-5446; and
• Relative path traversal - CVE-2018-5448

ICS-CERT reports that an uncharacterized attacker with access to a CareLink Programmer could exploit the vulnerability to obtain per-product credentials to the software deployment network. These credentials grant access to the software deployment network, but access is limited to read-only versions of device software applications. No write capability exists with the credentials.

Emerson Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Emerson ControlWave Micro Process Automation Controller. The vulnerability was reported by Younes Dragoni of Nozomi Networks. Emerson has a new firmware version that mitigates the vulnerability. There is no indication that Dragoni has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to execute a denial of service attact.

Delta Advisory


This advisory describes three vulnerabilities in the Delta WPLSoft PLC programming software. The vulnerability was reported by Axt via the Zero Day Intitiative. The newest version of the software mitigates the vulnerability. There is no indication that Axt has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-7494;
• Heap-based buffer overflow - CVE-2018-7507; and
• Out-of-bounds write - CVE-2018-7509

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow remote code execution or cause the software the attacker is accessing to crash.

Siemens Advisory


This advisory describes a cryptographic vulnerability in the Siemens SIMATIC Industrial PCs. This is a 3rd party vulnerability in RSA key generation allowing for a potential ROCA attack. The vulnerability is being self-reported by Siemens. Siemens has produced firmware updates that mitigate the vulnerability.

ICS-CERT reports that an uncharacterized attacker [probably pretty skilled IMO] could remotely exploit the vulnerability to conduct cryptographic attacks against the key material.

NOTE: This is going to be a widespread vulnerability, potentially affecting any control system using Infineon’s Trusted Platform Module for the generation of RSA keys. It is also another vulnerability that it would have been helpful if ICS-CERT had published an alert on the topic last fall.

SIMATIC Update


This update provides additional information on an advisory that was was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14thNovember 28th, and most recently January 18, 2018. The update adds five new vulnerabilities to the advisory:

• Improper restrictions of operations within the bounds of a memory buffer (3) - CVE-2017-12818, CVE-2017-12820, and CVE-2017-12821;
• Security features - CVE-2017-12819; and
• Improper access control - CVE-2017-12822

Industrial Products Update


This update provides additional information on an advisory that was originally published on December 5th, 2017 and updated on December 19th, 2017 and again on January 23rd, 2018. The new information includes new affected version data and mitigation links for:

• SIMATIC ET 200MP IM155-5 PN ST: All versions prior to V4.1;
• SIMOTION P V4.4 and V4.5: All versions prior to V4.5 HF5;
• DK Standard Ethernet Controller: All versions prior to V4.1.1 Patch 05; and
• EK-ERTEC 200 PN IO: All versions prior to V4.5

PROFINET 1 Update


This update provides additional information on an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, 2017, November 14th, 2017, and most recently on January 23rd, 2018. The update provides updated affected version information and mitigation links for:

• SIMATIC WinCC flexible 2008: All versions prior to flexible 2008 SP5

PROFINET 2 Update


This update provides additional information on an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th,  November 28th, 2017, and most recently January 18th, 2018, and most recently on January 25th, 2018. The new information includes new affected version data and mitigation links for:

• SIMATIC ET 200MP-IMI55-5 PN ST: All versions prior to V4.1

Ruggedcom Update


This update provides additional information on an advisory that was was originally published on September 28th, 2017, and updated on October 17th, 2017. The new information adds corrected version information and mitigation links for:

• SCALANCE XR-500/XM-400: All versions between v6.1 and 6.1.1; and
• SCALANCE XB-200/XC-200/XP-200/XR300-WG: All versions between v3.0 and v3.0.2

 
/* Use this with templates/template-twocol.html */