Showing posts with label Zero Day Initiative. Show all posts
Showing posts with label Zero Day Initiative. Show all posts

Tuesday, September 17, 2019

3 Advisories Published – 09-17-19


Today the DHS NCCIC-ICS published three control system security advisories for products from Honeywell, Siemens and Advantech.

Honeywell Advisory


The advisory describes an information exposure vulnerability in the Honeywell  Performance IP Series cameras and Performance Series NVRs are affected. The vulnerability was reported by Ismail Bulbil. Honeywell has an update that mitigates the vulnerability. There is no indication that Bulbil has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to view device configuration information.

NOTE 1: The Honeywell advisory for this vulnerability was published on April 30th, 2019. Two additional advisories were published last Friday. I will discuss these on Saturday unless NCCIC-ICS publishes their advisories later this week.

NOTE 2: The link to the Honeywell advisory in this advisory does not work.

Siemens Advisory


The advisory describes four vulnerability in the Siemens SINEMA Remote Connect Server. The vulnerabilities were reported by Hendrik Derre and Tijl Deneut from HOWEST. Siemens has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

Improper restriction of excessive authentication attempts - CVE-2019-13918;
Information exposure - CVE-2019-34623;
Cross-site request forgery - CVE-2019-13920; and
Use of password hash with insufficient computational effort - CVE-2019-13922

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerabilities to allow an attacker unauthorized access to the web interface, improper access to privileged user and device information, and may allow successful CSRF attacks.

NOTE: I briefly reported on these vulnerabilities last Saturday.

Advantech Advisory


The advisory describes four vulnerabilities in the Advantech WebAccess HMI platform. The vulnerabilities were reported by Peter Cheng of Elextec Security Tech. Co., and Mat Powell of the Zero Day Initiative. Advantech has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported advisories are:

Code injection (2) - CVE-2019-13558, and CVE-2019-13552;
Stack-based buffer overflow - CVE-2019-13556; and
Improper authorization - CVE-2019-13550

Thursday, August 9, 2018

ICS-CERT Publishes Two Advisories


Today the DHS ICS-CERT published two control system security advisories for products from NetComm and Crestron.

NetComm Advisory


This advisory describes four vulnerabilities in the NetComm 4G LTE Light Industrial M2M Router. The vulnerabilities were reported by Aditya K. Sood. NetComm has new firmware that mitigates the vulnerabilities. There is no indication that Sood has been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Information exposure - CVE-2018-14782;
• Cross-site request forgery - CVE-2018-14783;
• Cross-site scripting - CVE-2018-14784; and
Information exposure through directory listing - CVE-2018-14785

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow for the exposure of sensitive information.

Crestron Advisory


This advisory describes four vulnerabilities in the Crestron TSW-X60 and MC3 products. The vulnerabilities were independently reported by Jackson Thuraisamy (via Security Compass) and Ricky “HeadlessZeke” Lawshae (via the Zero Day Initiative). Crestron has firmware versions available that mitigate the vulnerabilities. There is no indication that either researcher has been offered an opportunity to verify efficacy of the fix.

The four reported vulnerabilities are:

• OS command injection (2) - CVE-2018-11228 and CVE-2018-11229);
• Improper access control - CVE-2018-10630; and
• Insufficiently protected credentials - CVE-2018-13341

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow remote code execution with escalated system privileges.

NOTE: Is it just me or does it seem odd that the same vulnerabilities are found in a touch-screen device and a control system processor controller?

Tuesday, August 7, 2018

ICS-CERT Publishes 3 Advisories


Today the DHS ICS-CERT published one control system security advisory for products from Delta Electronics and two medical device security advisories for products from Medtronic.

Delta Advisory


This advisory describes two vulnerabilities in the Delta CNCSoft and ScreenEditor products. The vulnerability was reported by Mat Powell via the Zero Day Initiative. Delta has an updated version of CNCSoft that mitigates the vulnerabilities. There is no indication that Powell was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-10636; and
Out-of-bounds read - CVE-2018-10598

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to gain remote code execution with administrator privileges.

MiniMed Advisory


This advisory describes two vulnerabilities in the Medtronic MiniMed 508 Insulin Pump. The vulnerabilities were reported by Billy Rios, Jesse Young, and Jonathan Butts of Whitescope LLC. Medtronic does not intend to develop a mitigation for these vulnerabilities (see note below).

The two reported vulnerabilities are:

• Cleartext transmission of sensitive information - CVE-2018-10634; and
• Authentication bypass by capture replay - CVE-2018-14781

ICS-CERT reports that an uncharacterized attacker could remotely exploit these vulnerabilities to allow an attacker to replay captured wireless communications and cause an insulin (bolus) delivery.

NOTE: The Medtronic security advisory reports that the following must occur for these vulnerabilities to be exploited:

1. The remote option for the pump would need to be enabled. This is not a factory-delivered default, and a user must choose this option.
2. The user’s remote controller ID needs to be registered to the pump.
3. The easy bolus option would need to be turned on and easy bolus step size programmed in the pump.
4. An unauthorized individual would need to be within close proximity to the user, with
necessary equipment to copy the RF signals activated, when the user is delivering a bolus
using the remote controller.
5. The unauthorized individual would need to be within the vicinity of the userto play back the RF signals to deliver a malicious remote bolus.
6. The user would need to ignore the pump alerts, which indicates that a remote bolus is being delivered.

MyCareLink Advisory


This advisory describes two vulnerabilities in the Medtronic MyCareLink Patient Monitor. The vulnerabilities were reported by Billy Rios, Jesse Young, and Jonathan Butts of Whitescope LLC. Medtronic is making (has made for one of the vulnerabilities) server side updates to mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Insufficient verification of data authenticity - CVE-2018-10626; and
• Storing passwords in a recoverable format - CVE-2018-10622

ICS-CERT reports that an uncharacterized attacker with physical access to the device could exploit the vulnerabilities to obtain per-product credentials that are utilized to authenticate data uploads and encrypt data at rest. Additionally, an attacker with access to a set of these credentials and additional identifiers can upload invalid data to the Medtronic CareLink network.

Tuesday, July 31, 2018

ICS-CERT Publishes 5 Advisories


Today the DHS ICS-CERT published five control system security advisories for products from AVEVA (2), WECON, Johnson Controls and Davolink.

Wonderware Advisory


This advisory describes an improper restriction in operations within the bounds of a memory buffer vulnerability in the AVEVA Wonderware License Server; the vulnerability is in the 3rd party  Flexera FlexNet Publisher software. The vulnerability was reported to AVEVA by an anonymous researcher. AVEVA has an update that mitigates the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability to effect remote code execution with administrative privileges.

NOTE: This vulnerability was also reported in the Rockwell Factory Talk Activation Manager earlier this year. There is an interesting blog post from 2016 about this vulnerability over at Security Mumblings.

InTouch Advisory


This advisory describes a cross-site scripting vulnerability in the AVEVA InTouch Access Anywhere product. The vulnerability was reported by Google’s Security Team. AVEVA has an update that mitigates the vulnerability. The AVEVA security advisory indicates that the researchers have verified the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability to obtain sensitive information and/or execute Javascript or HTML code.

WECON Advisory


This advisory describes two buffer overflow vulnerabilities in the WECON LeviStudioU. The vulnerabilities were reported by NSFOCUS security team, Ghirmay Desta and Mat Powell via the Zero Day Initiative.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-10602; and
Heap-based buffer overflow - CVE-2018-10606

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to execute remote code.

NOTE: Reading between the lines of the advisory, it looks like ICS-CERT did not get much cooperation from WECON on these vulnerabilities.

Johnson Controls Advisory


This advisory describes an information exposure through an error message vulnerability in the Johnson Controls Metasys and BCPro products. The vulnerability was reported by Dan Regalado of Zingbox. Newer versions mitigate the vulnerability. There is no indication that Regalado was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker on an adjacent network could exploit the vulnerability to obtain technical information about the Metasys or BCPro server, allowing an attacker to target a system for attack.

Davolink Advisory


This advisory describes a use of password hash with insufficient computational effort vulnerability in the Davolink DVW-3200N network switch. The vulnerability was reported by Ankit Anubhav of NewSky Security. There is new firmware for the device that mitigates the vulnerability. There is no indication that Anubhav was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to obtain the password to the device.

Friday, August 11, 2017

ICS-CERT Publishes 5 Advisories

Yesterday the DHS ICS-CERT published five control system security advisories for products from ABB, Fuji Electric, Solar Controls (2), and SIMPlight.

ABB Advisory


This advisory describes a relative path traversal vulnerability in the ABB SREA-01 and SREA-50 remote monitoring tools. The vulnerability was reported by Bertin Jose and Fernandez Ezequiel. HMS Industrial Networks Ab provided a patch to correct the issue, but ABB has only tested it on the SREA-01. These are unsupported legacy products. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could use publicly available exploits to remotely exploit the vulnerability to access files on the affected products’ file systems, view data, change configuration, retrieve password hash codes, and potentially insert and send commands to connected devices without authorization.

NOTE: ABB reports that exploit code was published on github by the researchers.

Fuji Advisory


This advisory describes multiple vulnerabilities in the Fuji Monitouch V-SFT screen configuration software. The vulnerabilities were reported by Fritz Sands and kimiya via the Zero Day Initiative. Fuji has released a new version to mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2017-9659;
• Heap-based buffer overflow - CVE-2017-9660; and
• Improper privilege management - CVE-2017-9662

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerabilities to allow remote code execution or cause the software that the attacker is accessing to crash. The improper privilege management vulnerability could allow an attacker with local access to escalate privileges.

WATTConfig Advisory


This advisory describes an uncontrolled search path element vulnerability in the Solar Controls WATTConfig M Software. The vulnerability was reported by Karn Ganeshen. ICS-CERT reports that Solar Controls has not responded to requests to coordinate with NCCIC/ICS-CERT.

ICS-CERT reports that a relatively low skilled attacker with uncharacterized access could exploit the vulnerability to allow arbitrary code execution.

HCDownloader Advisory


This advisory describes an uncontrolled search path element vulnerability in the Solar Controls Heating Control Downloader (HCDownloader). The vulnerability was reported by Karn Ganeshen. ICS-CERT reports that Solar Controls has not responded to requests to coordinate with NCCIC/ICS-CERT.

ICS-CERT reports that a relatively low skilled attacker with uncharacterized access could exploit the vulnerability to allow arbitrary code execution.

SIMPlight Advisory


This advisory describes an uncontrolled search path element vulnerability in the the SIMPlight SCADA Software. ). The vulnerability was reported by Karn Ganeshen. ICS-CERT reports that Solar Controls has not responded to requests to coordinate with NCCIC/ICS-CERT.


ICS-CERT reports that a relatively low skilled attacker with uncharacterized access could exploit the vulnerability to allow arbitrary code execution.

Tuesday, August 2, 2016

ICS-CERT Publishes Two Advisories

This morning the DHS ICS-CERT published two industrial control system security advisories for products from Siemens and Moxa.

Siemens Advisory


This advisory describes a privilege escalation vulnerability in the Siemens SINEMA Server. The vulnerability was reported by rgod via the Zero Day Initiative. Siemens has developed a temporary fix for the vulnerability while a new version is being developed. There is no indication that rgod has been provided an opportunity to verify the efficacy of the temporary fix.

ICS-CERT reports that a relatively low skilled attacker with local access could exploit the vulnerability with a social engineering attack to escalate their privileges.

Moxa Advisory


This advisory describes an SQL injection vulnerability in the Moxa SoftCMS. The vulnerability was reported by Zhou Yu of Acorn Network Security via the Zero Day Initiative. Moxa has produced an update to mitigate the vulnerability, but there is no indication that Yu has been provided the opportunity to verify the efficacy of the fix.


ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to execute arbitrary commands on the target system.
 
/* Use this with templates/template-twocol.html */