Showing posts with label Z0mb1E. Show all posts
Showing posts with label Z0mb1E. Show all posts

Tuesday, June 9, 2020

6 Advisories and 4 Updates Published


Today the CISA NCCIC-ICS published six control system security advisories for products from Siemens (4), Mitsubishi Electric and Advantech. They also updated four advisories for products from Philips, Siemens (2) and OSIsoft.

SINUMERIK Advisory


This advisory describes 22 vulnerabilities in the Siemens SINUMERIK products. The vulnerabilities are self-reported. Siemens has updates that mitigate the vulnerabilities.

The 22 reported vulnerabilities are:

• Buffer underflow - CVE-2018-15361,
• Heap-based buffer overflow (5) - CVE-2019-8258, CVE-2019-8262, CVE-2019-8271, CVE-2019-8273, and CVE-2019-8274,
• Improper initialization - CVE-2019-8259,
• Out-of-bounds read (3) - CVE-2019-8260, CVE-2019-8267, and CVE-2019-8270,
• Stack-based buffer overflow (3) - CVE-2019-8263, CVE-2019-8269, and CVE-2019-8276,
• Access of memory location after ends of buffer (4) - CVE-2019-8264, CVE-2019-8265, CVE-2019-8266, and CVE-2019-8280,
• Off-by-one error (2) - CVE-2019-8268, and CVE-2019-8272,
• Improper null determination - CVE-2019-8275,
• Improper initialization - CVE-2019-8277,

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow remote code execution, information disclosure, and denial-of-service attacks under certain conditions.

Note: according to the Siemens advisory these are third-party vulnerabilities (in this case, UltraVNC, a remote access system) – that were reported by Kaspersky. A number of other VNC systems were included in that report.

SIMATIC Advisory #1


This advisory describes two vulnerabilities in the Siemens SIMATIC and SINAMICS products. The vulnerabilities were reported by Nadav Erez of Claroty. Siemens has new versions that mitigate the vulnerabilities. There is no indication that Erez has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Uncontrolled search path - CVE-2020-7585, and
• Heap-based buffer overflow - CVE-2020-7586

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to affect the availability of the devices under certain conditions.

NOTE: According to the Siemens advisory the vulnerabilities were reported by Uri Katz of Claroty.

SIMATIC Advisory #2


This advisory describes an unquoted search path or element vulnerability in the Siemens SIMATIC, SINAMICS, SINEC, SINEMA and SINUMERIK products. This vulnerability was reported by Ander Martinez of Titanium Industrial Security via INCIBE. Siemens has some updates that mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with authorized local access could exploit the vulnerability to execute custom code with SYSTEM level privileges.

LOGO! Advisory


This advisory describes a missing authentication for critical function vulnerability in the Siemens LOGO! Product. The vulnerability was reported by Alexander Perez-Palma of Cisco Talos and Emanuel Almeida of Cisco Systems. Siemens has provided generic mitigation measures for this vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to read and modify device configurations and obtain project files from affected devices.

NOTE: The Siemens advisory says that an attacker would have to have access to port 135/tcp to exploit this vulnerability.

Mitsubishi Advisory


This advisory describes a resource exhaustion vulnerability in the Mitsubishi MELSEC iQ-R series modules. The vulnerability was reported by Yossi Reuven of SCADAfence. Mitsubishi has provided generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause the Ethernet port to enter a denial-of-service condition.

Advantech Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Advantech WebAccess Node. The vulnerability was reported by Z0mb1E via the Zero Day Initiative. Advantech has a patch that mitigates the vulnerability. There is no indication that Z0mb1E has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to crash the application being accessed; a buffer overflow condition may allow remote code execution.

Philips Update


This update provides additional information on an advisory that was originally published on August 16th, 2018. The new information includes:

• Extending the expected update publication from mid-2019 to 3rd Quarter 2020, and
• Change mitigation instructions for PageWriter TC50 and TC70,

SIMATIC Update


This update provides additional information on an advisory that was was originally published on December 10th, 2019 and most recently updated on March 10th, 2020. The new information includes:

• Revised version and mitigation information for  SIMOCODE pro V PN, and
• Clarified update version information for SINAMICS G130/G150/S150 and SINAMICS S120

Industrial Products Update


This update provides additional information on an advisory that was originally published on September 10th, 2019 and most recently updated April 14th, 2020. The new information includes:

• Added products SIMATIC NET CP 443-1 OPC UA, CP 443-1 RNA, CP 442-1 RNA, CP 443-1, CP 443-1 Advanced and CP 343-1 Advanced,
• Included additional information to CP 1623 and CP 1628 regarding affected CVE,
• Added new vulnerability: Excessive data query operations in large data table - CVE-2019-8460

Other Siemens Update


There was one other Siemens update that was published today. I will cover it this weekend.

OSIsoft Update


This update provides additional information on an advisory that was originally published on May 12th, 2010. The new information includes:

• Four new affected products:
PI Connector for IEC 60870-5-104,
PI Connector for OPC-UA,
PI Connector for Siemens Simatic PCS 7, and
PI Connector for UFL
• Major change to mitigation measures

Saturday, May 16, 2020

Public ICS Disclosures – Week of 5-9-20


This week we have five vendor disclosures for products from Schneider (4) and Rockwell as well as six vendor updates from Schneider (5) and Siemens. We also have two researcher reports of vulnerabilities in products from Advantech.

Schneider Advisories


Schneider published an advisory describing a weak password requirement vulnerability in their Pro-face GP-Pro EX Programming Software product. The vulnerability was reported by Kirill Kruglov of Kaspersky Labs. Schneider has a new version that mitigates the vulnerability. There is no indication that Krublov has been provided an opportunity to verify the efficacy of the fix.


Schneider published an advisory describing a use of hard-coded credentials vulnerability in their Vijeo Designer Basic and Vijeo Designer software products. The vulnerability was reported by Jie Chen of NSFOCUS. Schneider has a HotFix available to mitigate the vulnerability. There is no indication that Jie has been provided an opportunity to verify the efficacy of the fix.


Schneider published an advisory describing two vulnerabilities in their U.motion servers and touch panel products. The vulnerabilities were reported by Rgod and Zhu Jiaqi. Schneider has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper access control - CVE-2020-7499, and
• SQL injection - CVE-2020-7500


Schneider published an advisory describing five vulnerabilities in their EcoStruxure™ Operator Terminal Expert product. The vulnerabilities were reported by Steven Seeley and Chris Anastasio of Incite Team, Sharon Brizinov and Amir Preminger of Claroty Research via the Zero Day Initiative (see here, here, and here), and Fredrik Østrem, Emil Sandstø, and Cim Stordal of Cognite. Schneider has a new version that mitigates four of the five vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• SQL command injection - CVE-2020-7493,
• Path traversal (3) - CVE-2020-7494, CVE-2020-7495, and CVE-2020-7497, and
• Argument injection or modification - CVE-2020-7496

Rockwell Advisory


Rockwell published an advisory describing five vulnerabilities in multiple Rockwell Automation software products. These are third-party vulnerabilities from OSIsoft components used in the Rockwell products. These vulnerabilities are self-identified. Rockwell provides workarounds to mitigate the vulnerabilities.

The five reported vulnerabilities are:

• Local privilege escalation via uncontrolled search path element - CVE-2020-10610,
• Local privilege escalation via improper verification of cryptographic key - CVE-2020-10608,
• Local privilege escalation via incorrect default permissions - CVE-2020-10606,
• Null pointer dereference - CVE-2020-10600, and
• Use of out-of-range pointer offset may lead to remote code execution - CVE-2020-10645

NOTE: These are five of the ten vulnerabilities in the OSIsoft PI System that were reported by NCCIC-ICS earlier this week. The fact that this Rockwell Advisory was published on the same day as the NCCIC-ICS advisory indicates that there was pre-disclosure coordination between OSIsoft and Rockwell, good show.

Advantech Advisories


The Zero Day Initiative published advisories (see links below) describing two vulnerabilities in Advantech WebAccess Node. ZDI published the two advisories as 0-day notifications under their 120-day response rule. NCCIC-ICS was reported involved in the coordination of these vulnerabilities. The vulnerabilities were reported by Z0mb1E.

The two reported vulnerabilities are:

• DATACORE Stack-based Buffer Overflow Remote Code Execution Vulnerability - ZDI-20-654, and
• Incorrect Permission Assignment Privilege Escalation Vulnerability - ZDI-20-655

Schneider Updates


Schneider published an update for the Urgent/11 advisory that was originally published on August 11th, 2019 and most recently updated on April 14th, 2020. The new information includes updated mitigation information for:

• Modicon Network Option Switch,
• Modicon X80 - I/O Drop Adapters,
• Modicon Quantum 140 CRA,
• Modicon Quantum Head 140 CRP,
• Modicon Quantum Ethernet DIO network module - 140NOC78x00 (C),
• SCD6000 Industrial RTU, and
• Pro-face HMI -GP4000H/R/E Series


Schneider published an update for their Andover Continuum System advisory that was originally published on March 10th, 2020 and most recently updated on April 14th, 2020. The new information includes minor updates to overview, vulnerability details, and product information for clarification.


Schneider published an update for their Embedded Web Servers for Modicon advisory that was originally published in November 2018 and most recently updated November 27th, 2019. The new information includes a corrected CVSS vector for CVE-2018-7812.


Schneider published an update for their Modicon Controllers advisory that was originally published on May 14th, 2019 and most recently updated on December 10th, 2019. The new information includes updated fix version information for CVE-2018-7857.


Schneider published an update for their Legacy Triconex advisory that was originally published on April 14th, 2020. Unfortunately, the link on the Schneider web site takes one to the original version of the advisory.

Siemens Update


Siemens published an update for their GNU/Linux advisory that was originally published on November 27th, 2018 and most recently updated on April 14th, 2020. The new information includes the addition of the following CVE’s:

• CVE-2019-9674,
• CVE-2019-18348,
• CVE-2019-20636,
• CVE-2020-8492,
• CVE-2020-11565,
• CVE-2020-11655, and
• CVE-2020-11656

Thursday, May 7, 2020

1 Advisory Published – 5-7-20


Today the CISA NCCIC-ICS published a control system security advisory for products from Advantech.

Advantech Advisory

This advisory describes eight vulnerabilities in the Advantech WebAccess Node. The vulnerabilities were reported by Natnael Samson and Z0mb1E via the Zero Day Initiative. Advantech has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The eight reported vulnerabilities:

• Improper validation of array index - CVE-2020-12022,
• Relative path traversal - CVE-2020-12010, CVE-2020-12006,
• SQL injection - CVE-2020-12014,
• Stack-based buffer overflow - CVE-2020-12002,
• Heap-based buffer overflow - CVE-2020-10638, and
• Out-of-bounds read - CVE-2020-12018

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow information disclosure, remote code execution, and compromise system availability.

Thursday, December 12, 2019

3 Advisories and 2 Updates Published – 12-12-19


Today the CISA NCCIC-ICS published three control system security advisories for products from Omron (2) and Advantech. They also updated a medical device advisory for products from Philips and a multi-vendor advisory.

Omron Advisory #1


This advisory describes and improper restriction of excessive authentication attempts vulnerability in the Omron CJ, CS and NJ Series PLCs. The vulnerability was reported by n0b0dy. Omron provides generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to brute force login credentials, obtain unauthorized access of the system, and may allow an attacker unauthorized access to the FTP interface.

Omron Advisory #2


This advisory describes three vulnerabilities in the Omron CJ and CS Series PLCs. The vulnerabilities were reported by Wang Zhibei and n0b0dy. Omron provides generic workarounds to mitigate the vulnerabilities.

The three reported vulnerabilities are:

• Authentication bypass by spoofing - CVE-2019-18259;
• Authentication bypass by capture/replay - CVE-2019-13533; and
• Unrestricted externally accessible lock - CVE-2019-18269

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to pose as an authorized user to obtain the status information of the PLC.

Advantech Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Advantech DiagAnywhere Server. The vulnerability was reported by Z0mb1E via the Zero Day Initiative. The device is no longer supported.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to may allow remote code execution.

Philips Update


This update provides additional information on an advisory that was originally published on November 14th, 2019. The new information is an additional generic workaround to mitigate the vulnerability.

PLC Cycle Time Influences Update


This update provides additional information on an advisory that was originally published on April 16th, 2019. The new information is the addition of another affected product from Phoenix Contact.

Interesting Twitter Thread


An interesting Twitter® thread today about record number of vulnerabilities in a single advisory. Spoiler alert: Siemens is not the record holder.

Friday, January 24, 2014

ICS-CERT Publishes GE Proficy Advisory

Yesterday the DHS ICS-CERT published an advisory for twin path traversal vulnerabilities reported in the GE Proficy CIMPLICITY application by amisto0x07 and Z0mb1E. The disclosure was coordinated through the Zero Day Initiative (ZDI). A patch has been developed by GE for one of the vulnerabilities and a configuration change has been suggested for the other. There is no indication that the researchers have validated the efficacy of these mitigation measures.

ICS-CERT notes that a moderately skilled attacker could remotely exploit either of these vulnerabilities to execute arbitrary code on the system.

GE has published two advisories (GEIP13-05 and GEIP13-06) that discuss the vulnerabilities in more detail and explain the mitigation measures.

GEIP13-05 – No Patch

This GE Advisory notes that the vulnerability is due to a single component (gefebt.exe) and recommends that ‘all copies’ of the file be deleted. The advisory provides information about where copies of the file should be found in the server directories and on the server web pages.

The advisory notes that making these changes will disable links on the default home page on the CIMPLICITY system that allow users to “to browse CIMPLICITY projects and view alarms, points, screens and objects”. To regain this functionality, the default home pages will have to be re-created using the “Create Webpage” option.

This could be a very complex remediation.

GEIP13-06 – Patch Available

The second advisory provides a link for a patch to CIMPLICITY version 8.2. It notes that users of versions earlier than 8.2 should upgrade to version 8.2. Interestingly, versions 4.0 and earlier are not affected by either of these vulnerabilities.

GE provides two other mitigation options as alternatives to updating or applying the patch to version 8.2. If web –based HMI functionality is not need, they provide the option of disabling that functionality. If that functionality is required there is the option of using an alternative web server, IIS web server instead of the vulnerable CimWebServer.exe.

Delayed ICS-CERT Notification

Joel Langill notes that OSVDB has been reporting this vulnerability since the middle of December. The GE advisories are also dated from the same point in time and both note that public disclosure of the vulnerabilities was expected by December 31st.


There is no explanation in the ICS-CERT advisory as to why it has taken them so long to report this vulnerability. These delays are becoming increasingly common with ICS-CERT advisories. More importantly it is becoming more common for ICS-CERT to ignore or miss reports of ICS vulnerabilities all together. Perhaps it is time for Congress to exercise their oversight responsibility and look into the operations of ICS-CERT.
 
/* Use this with templates/template-twocol.html */