Showing posts with label fdtCONTAINER. Show all posts
Showing posts with label fdtCONTAINER. Show all posts

Saturday, March 6, 2021

ICS Public Disclosures – Week of 2-27-21

This week we have eight public disclosures from Bosch, Carestream, ENDRESS+HAUSER, Dell, Draeger, GE Healthcare, Pulse Secure, and VMWare. An update is available for products from Rockwell. There is an end-of-life notice from Honeywell. Finally, there is an exploit for products from VMware.

Bosch Advisory

Bosch published an advisory describing a side-channel key extraction vulnerability in the Bosch cameras and encoders built on platforms CPP-ENC, CPP3, CPP4, CPP5, CPP6, CPP7 and CPP7.3.  This is a third-party vulnerability (NXP). Since this is a chip-based vulnerability, Bosch is only able to provide generic workarounds. The original NinjaLab report on the NXP vulnerability contains proof-of-concept code.

NOTE: This third-party vulnerability was reported earlier in products from Rockwell, other vendors will probably also be affected.

Carestream Advisory

Carestream published an advisory discussing the Google heap-based buffer overflow vulnerability. Carestream provides a list of affected and unaffected products. Carestream will update Chrome in the next product release for the affected products.

ENDRESS+HAUSER Advisory

CERT-VDE published an advisory discussing the fdtCONTAINER vulnerability in a number of their products. ENDRESS+HAUSER provides generic workarounds pending development of appropriate mitigation measures in future versions of the product.

Dell Advisory

Dell published an advisory describing two vulnerabilities in their EMC OpenManage Server Administrator. The vulnerabilities were reported by David Yesland from Rhino Security Labs and Tenable. Dell has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Authentication bypass - CVE-2021-21513, and

• Path traversal - CVE-2021-21514

NOTE: The Tenable report contains proof-of-concept code for the

Draeger Advisory

Draeger published an advisory describing an out-of-bounds write vulnerability in their CC-Vision Basic and CC-Vision E-Cal Software. The vulnerability was reported by Mario Ceballos. Draeger had new versions that mitigate the vulnerability. There is no indication that Ceballos has been provided an opportunity to verify the efficacy of the fix.

GE Healthcare Advisory

GE Healthcare has published an advisory discussing the Microsoft Windows TCP/IP vulnerabilities. GE Healthcare reports that they are actively assessing products to see if they are affected.

Pulse Secure Advisory

Pulse Secure has published an advisory discussing the Trickboot vulnerability in their PSA-Series Hardware. Pulse Secure has a BIOS patch available that mitigates the vulnerability.

VMWare Advisory

VMWare published an advisory describing a remote code execution vulnerability in their View Planner product. The vulnerability was reported by Mikhail Klyuchnikov of Positive Technologies. VMware has a security patch that mitigates the vulnerability. There is no indication that Klyuchnikov has been provided an opportunity to verify the efficacy of the fix.

Rockwell Update

Rockwell published an update for their Logix Controllers advisory that was originally published on February 25th, 2021. The advisory was re-written for clarity.

NOTE: I suspect the NCCIC-ICS will update their advisory on this vulnerability this coming week.

Honeywell EOL Notice

Honeywell published an end-of-life notice for their Pro-Watch 4.3 and Pro-Watch 4.35 products. The products will no longer be supported after September 30th, 2021.

VMWare Exploit

Photubias published an exploit for an unauthenticated file upload vulnerability in the VMware vCenter Server 7.0. The vulnerability was previously reported by VMWare.

Tuesday, February 16, 2021

3 Advisories and 1 Update Published – 2-16-21

Today CISA’s NCCIC-ICS published two control system security advisories for products from Rockwell and Open Design Alliance, as well as a medical device security advisory for products from Hamilton Medical. They also updated an advisory from M&M Software (WAGO).

Rockwell Advisory

This advisory describes an improper handling of length parameter inconsistency vulnerability in the Allen-Bradley MicroLogix 1100 Programmable Logic Controller. The vulnerability was reported by Talos. Rockwell advises upgrading to the Micrologic 1400, firmware v21.006 or higher.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to result in denial-of-service conditions.

NOTE: I briefly discussed this vulnerability on Saturday.

Open Design Alliance Advisory

This advisory describes six vulnerabilities in the Open Design Alliance Drawings SDK software development kit. The vulnerabilities were reported by Michael DePlante and rgod via the Zero Day Initiative. ODA has a newer version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2021-25178,

• Type confusion - CVE-2021-25177,

• Untrusted pointer dereference - CVE-2021-25176,

• Incorrect type conversion or cast - CVE-2021-25175, and

• Memory allocation with excessive size value (2) - CVE-2021-25174 and CVE-2021-25173

NCCIC-ICS reported that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to allow code execution in the context of the current process or cause a denial-of-service condition.

NOTE: These vulnerabilities were reported last week in NCCIC’s Siemens JT2Go and Teamcenter Visualization (ICSA-21-040-06) advisory and the Siemens advisory (SSA-663999) upon which it was based. Both advisories provided links to the ODA advisory. It will be interesting to see what other vendors use this ODA tool.

Hamilton Advisory

This advisory describes three vulnerabilities in the Hamilton-T1 Ventilator. The vulnerabilities were reported by Julian Suleder, Raphael Pavlidis, Nils Emmerich and Dr. Oliver Matula of ERNW Research. Hamilton recommends updating to newer versions to mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Use of hard-coded credentials - CVE-2020-27278,

• Missing XML validation - CVE-2020-27282, and

• Exposure of sensitive information - CVE-2020-27290

NCCIC-ICS reports that a relatively low-skilled attacker with physical access to the device could exploit the vulnerability to obtain sensitive information or crash the device being accessed.

NOTE: For those that are interested, here is the German BSI’s report on a whole slew of these vulnerabilities that were reported by ERNW Research for this BSI project. Not a lot of detail, but there are a lot of vulnerable devices.

WAGO Update

This update provides additional information on an advisory that was originally published on January 21st, 2021 and most recently updated on February 4th, 2021. The new information includes adding the Mitsubishi Electric MELSOFT FieldDeviceConfigurator as an affected product with a link to the Mitsubishi advisory.

Saturday, January 30, 2021

Public ICS Disclosures – Week of 1-23-21

This week we have nine vendor disclosures from Bosch, ZIV Automation (2), Emerson, GE Healthcare, Johnson Controls, Rockwell (2), and Siemens.

Bosch Advisory

Bosch published an advisory describing a stack-based buffer overflow vulnerability in their Rexroth ID 200/C-ETH using EtherNet/IP Protocol. This is a third-party (Real Time Automation) vulnerability. Bosch provides generic mitigation measures.

ZIV Automation Advisories

Incibe-CERT published an advisory describing an uncontrolled resource consumption vulnerability in the ZIV 4CCT Smart Metering Data Concentrator. The vulnerability was reported by Aarón Flecha Menéndez of S21Sec. ZIV has a patch available that mitigates the vulnerability. There is no indication that Menendez has been provided an opportunity to verify the efficacy of the fix.

 

Incibe-CERT published an advisory describing an improper authentication vulnerability in the ZIV 4CCT Smart Metering Data Concentrator. The vulnerability was reported by Aarón Flecha Menéndez of S21Sec. ZIV has a patch available that mitigates the vulnerability. There is no indication that Menendez has been provided an opportunity to verify the efficacy of the fix.

Emerson Advisory

Emerson published an advisory describing the fdtCONTAINER vulnerability in their Rosemont Transmitter Interface Software. Emerson no longer supports that software.

NOTE: This Emerson impact was previously reported by NCCIC-ICS.

GE Healthcare Advisory

GE Healthcare has published an advisory discussing undisclosed vulnerabilities in the VC150 Vital Signs Monitor that they distribute. The Innokas Medical web site simply notes in their software update note for the VC150 that it contains “Cybersecurity enhancements and bug fixes”. GE Healthcare has made the updated software available.

Johnson Controls

Johnson Controls has published an advisory discussing four vulnerabilities in their Sur-Gard System 5 receivers. They are third-party (Treck) vulnerabilities. Johnson Controls has a new version that mitigates the vulnerabilities.

NOTE: This advisory does not specifically name the four vulnerabilities identified by Treck and NCCIC-ICS, it just provides the CVE numbers; CVE-2020-25066,  CVE-2020-27336, CVE-2020-27337, and  CVE-2020-27338.

Rockwell Advisories

Rockwell published an advisory describing the fdtCONTAINER vulnerability in their FactoryTalk AssetCentre. Rockwell has a new version that mitigates the vulnerability.

 

Rockwell published an advisory describing a buffer overflow vulnerability in their MicroLogix 1400 Controller. The vulnerability was reported by Parul Sindhwad and Dr. Faruk Kazi from COE-CNDS. Rockwell provides generic mitigation measures

Siemens Advisory

Siemens published an advisory describing a missing authentication for critical function vulnerability in their SIMATIC HMI Panels. The vulnerability was reported by the Zero Day Initiative. Siemens has new versions that mitigate the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

NOTE: The advisory acknowledges the coordination efforts of CISA, so it is likely that NCCIC-ICS will publish an advisory on this vulnerability next week.

Sunday, January 24, 2021

Reader Comments – Instrument Vulnerabilities

Earlier this week Jake Brodsky left a comment on my blog post about the Thursday batch of control system security advisories. It is not a long comment, but it is certainly worth reading. He makes the point that: “If you exploit FDT [fdtCONTAINER vulnerability] on an instrument to get it to execute arbitrary code, you can also get it to report incorrect values FROM THE INSTRUMENT.”

As a person that has spent thousands of hours monitoring chemical processes in a manufacturing environment for both safety and quality issues, I can tell you that the prospect of not being able to trust the numbers being provided by your control system was what scared me most about Stuxnet and caused my interest in control system cybersecurity.

Instrument level data is probably the most critical data used in an industrial control system. That is the data the software relies upon to make process decisions. Being able to manipulate that data means that you can effectively manipulate the process (with the caveat that you must understand the process and how the control system responds to various instrument inputs if you are going to be able to drive the process in a specific upset direction). If you are just trying to disrupt the process (shut it down or adversely affect product quality) then less process knowledge would be needed.

Jake also made the point that Joe Weiss has been harping on the vulnerability of sensors for quite some time now. I have talked to Joe about this on a couple of occasions and I agree with many of his concerns. But I also know that smart process engineers understand the criticality of sensor data, this is the reason that there are frequently multiple sensors measuring the same data with protocols in place to deal with disagreements in sensor data.

As a process chemist I spent a lot of my process-upset investigation time looking for sensor failures by examining other process indicators; changes in pressure when valves opened or closed, changes in tank levels when pumps started and the like. Perhaps it is time to start building such data checks into our process controls, especially when safety-critical process changes are involved.

Finally, it would be helpful if the people writing these advisories were a little clearer about the processes that could be affected by the vulnerabilities. I would be surprised if many security managers understood that the fdtCONTAINER vulnerability had specific implications for process sensors. Only a very close reading of the NCCIC-ICS advisory would point you at that fact unless you were involved in process engineering (the key tell for non-engineers like myself was the involvement of Emerson and the RTIS).

 
/* Use this with templates/template-twocol.html */