Showing posts with label iDefense Labs. Show all posts
Showing posts with label iDefense Labs. Show all posts

Wednesday, October 3, 2018

Three Advisories and Three Updates Published


Yesterday the DHS NCCIC-ICS published three control system security advisories for products from Entes, GE and Delta Electronics. They also updated previously published advisories for products from Phillips, WECOM and ABB.

Entes Advisory


This advisory describes two vulnerabilities in the Entes EMG 12, an Ethernet Modbus Gateway. The vulnerability was reported by Can Demirel of Biznet Bilisim. Entes has a new firmware version that mitigates the vulnerabilities. There is no indication that Demirel has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper authentication - CVE-2018-14826; and
Information exposure in query strings in get request - CVE-2018-14822

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to gain unauthorized access and could allow the ability to change device configuration and settings.

GE Advisory


This advisory describes a heap based buffer overflow in the GE Communicator application. The vulnerability was reported by kimiya, working with iDefense Labs. Newer versions of the application mitigate the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to execute arbitrary code or create a denial-of-service condition.

Delta Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Delta ISPSoft, a PLC program development tool. The vulnerability was reported by Ariele Caltabiano (kimiya) via ZDI. Newer versions of the tool mitigate the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to execute code under the context of the application.

Phillips Update


This update provides additional information on an advisory that was originally published on March 29th, 2018. The update adds the phrase “and/or system information” to the description provided for ‘information exposure’ vulnerabilities.

WECON Update


This update provides additional information on an advisory that was originally published on July 31st, 2018. The updated information includes:

• Two new vulnerabilities added, and
• Added a third reporting security researcher.

I would have normally expected this to be a separate advisory, but since the original advisory was based upon information provided via the Zero Day Initiative, I suspect that there was an issue on that end of the process that is being corrected here.

ABB Update


This update provides additional information on an advisory that was originally published on August 28th, 2018. The update provides new mitigation information.

Thursday, October 12, 2017

ICS-CERT Publishes 5 Advisories and 1 Update

Today the DHS publishes five control system security updates for products from ProMinent, WECON, Envitech, NXP Semiconductor, and Siemens. They also updated a previously published control system security advisory for products from Marel Food Processing Systems.

Siemens Advisory


This advisory describes two vulnerabilities in the Siemens BACnet Field Panels. The vulnerabilities are self-reported. Siemens has developed a new firmware version that mitigates the vulnerabilities.

The two reported vulnerabilities are:

• Authentication bypass using an alternate path or channel - CVE-2017-9946; and
• Path traversal - CVE-2017-9947

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to allow unauthenticated attackers with access to the integrated webserver to download sensitive information. The Siemens security advisory notes that the first vulnerability requires network access to exploit.

NXP Advisory


This advisory describes two vulnerabilities in the NXP MQX real time operating system (RTOS). The vulnerability was reported by Scott Gayou. ICS-CERT reports that NXP intends to issue a new version in January to mitigate the vulnerabilities. NXP provides a work around for the first vulnerability in the latest version (the second does not exist in that version) and recommends that users upgrade to that newer version pending the January update.

The two reported vulnerabilities are:

• Classic buffer overflow – CVE-2017-12718; and
• Out-of-bounds read – CVE-2017-12722

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerabilities to cause a buffer overflow condition that may, in turn, cause remote code execution or out-of-bounds read conditions, resulting in a denial of service.

Envitech Advisory


This advisory describes an improper authentication vulnerability in the Envitech EnviDAS Ultimate web application. The vulnerability was reported by Can Demirel and Deniz Çevik of Biznet Bilisim. Envitech has a new version that mitigates the vulnerability. ICS-CERT reports that the researchers have verified the efficacy of the fix.

ICS-CERT reports that relatively low skilled attacker could remotely exploit the vulnerability  to view and edit settings without authenticating and execute code remotely.

WECON Advisory


This advisory describes a stack-based buffer overflow vulnerability in the WECON LeviStudio HMI Editor. The vulnerability was reported by Andrea “rgod” Micalizzi, working with iDefense Labs. WECON has developed a new version that mitigates the vulnerability. There is no indication that Micalizzi was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to effect a denial of service and arbitrary code execution.

ProMinent Advisory


This advisory describes multiple vulnerabilities in the ProMinent MultiFLEX M10a Controller. The vulnerabilities were reported by Maxim Rupp. ICS-CERT reports that ProMinent has not mitigated the vulnerabilities.

The reported vulnerabilities are:

• Client-side enforcement of server-side security - CVE-2017-14013l;
• Insufficient session expiration - CVE-2017-14007;
• Cross-site request forgery - CVE-2017-14011;
• Information exposure - CVE-2017-14009; and
• Unverified password change - CVE-2017-14005

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerabilities  to bypass protection mechanisms, assume the identity of authenticated users, and change the device configuration.

Marel Update


This update provides additional information on an advisory originally published on April 4th, 2017 and updated on August 17th. This update provides information on the firewall update for the Pluto platform that Marel has released.


The advisory still states that “Marel has created an update for Pluto-based applications, which was scheduled for release in October, 2017. This update will restrict remote access by implementing SSH authentication”.

Thursday, July 13, 2017

ICS-CERT Publishes 3 Advisories

Today the DHS ICS-CERT published three control system security advisories for products from Siemens (2) and GE. They also published the latest version of the ICS-CERT Monitor and a new FY 2016 Assessment Report.

SIMATIC Advisory


This advisory describes two vulnerabilities in the Siemens SIMATIC Sm@rtClient Android App. The vulnerabilities were reported by Karsten Sohr and Timo Glander from the TZI at the University of Bremen. Siemens has released a new version to mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two vulnerabilities are:

• Channel accessible by non-endpoint - CVE-2017-6870; and
• Authentication bypass using alternative bypass or channel - CVE-2017-6871

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to read and modify data within a Transport Layer Security TLS session. The Siemens security bulletin reports that the second vulnerability requires “physical access to an unlocked mobile device”.

GE Advisory


This advisory describes a heap-based buffer overflow vulnerability in the GE Communicator application. The vulnerability was reported by Kimiya, working with iDefense Labs. GE recommends upgrading to the newst version that mitigates the vulnerability. There is no indication that Kimiya was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to execute arbitrary code or create a denial-of-service condition.

Comment: Once again a previously released version (revision date 02-18-17) fixes a security issue that was not identified in the Release notes. Remarkably lucky programmers that could fix an unidentified problem. Those release notes did identify another vulnerability in earlier versions that was corrected but has not apparently been reported to ICS-CERT; an unused software graphic library which was identified as a potential Microsoft® ActiveX security vulnerability.

SiPass Advisory


This advisory describes multiple vulnerabilities in the Siemens SiPass integrated access control system. Siemens is self-reporting the vulnerabilities. Siemens has produced a new version that mitigates the vulnerabilities.

The reported vulnerabilities are:

• Improper authentication - CVE-2017-9939;
• Improper privilege management - CVE-2017-9940;
• Channel accessible by non-endpoint - CVE-2017-9941; and
• Storing passwords in a recoverable format - CVE-2017-9942

ICS-CERT reports that a relatively low skilled attacker with unauthenticated network access could remotely exploit these vulnerabilities to perform administrative operations.

ICS-CERT Monitor


The ICS-CERT Monitor for May-June 2017 provides a little more useful information than we have been seeing in this publication of late. There are two brief but informative articles that should be read by all facility security managers:

• Data Classification for Recovery Planning (pg 2); and
• Cybersecurity Defense (pg 2)

The first outlines the risk assessment process used to determine backup rates for data. The second briefly discusses the importance of wet-ware (personnel) training to aid the security process. Both could have been fleshed out quite a bit, but given the glossy corporate report format that really is not practical. It would be helpful if ICS-CERT (or someone) did a fact sheet or white paper on both of these important topics. If someone knows of one, please point me at it.

FY 2016 Assessment Report


Well, the FY 2016 Assessment Report is not be published quite as late in the year as the 2015 report was, but you have to wonder why it took so long to publish such an uninformative 20 page report. If you read my review of the 2015 report, you already know most of the problems with this version.

One disheartening fact did jump off the page a scream at me, ‘Physical Access Control’ jumped back onto the ‘Top Six Weakness’ categories reported in the 130 assessments conducted last year. Again, you have to be careful of the numbers here because it is quite possible that some of the facilities had more than one assessment (three different assessment types) conducted.


Oh well, read it. Be careful of how much respect you give for the individual numbers (and those will be much hyped in the main stream and cybersecurity press), but look for the small pieces of valuable information (for example on page 11 “Keys allowing physical access may be out of the facilities’ control, possibly allowing unauthorized personnel to access critical or sensitive areas.”).

Friday, April 14, 2017

ICS-CERT Publishes Two Advisories

Yesterday the DHS ICS-CERT published two control system security advisories for products from Schneider Electric and Wecon Technologies.

Schneider Advisory


This advisory describes two vulnerabilities in the Schneider Modicon M221 PLCs and SoMachine Basic. The vulnerabilities were reported by Simon Heming, Maik Brüggemann, Hendrik Schwartke, and Ralf Spenneberg of Open Source Security. Schneider has announced an encryption work around and that they will introduce a new version of SoMachine Basic in June.

The two reported vulnerabilities are:

• Use of Hard-Coded Cryptographic Key – CVE-2017-7574; and
• Protection Mechanism Failure – CVE-2017-7575

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities using a publicly available exploit to extract a protected project file from the controller to obtain sensitive project information, or allow a user with access to a protected project file to decrypt it in order to obtain sensitive information without authorization.

Interestingly, the Schneider security notification only addresses the vulnerability in their SoMachine Basic; ignoring the vulnerability in their Modicon M221 PLCs. Could that vulnerability be a ‘design feature’?

NOTE: These are the vulnerabilities that I reported on last weekend. OpenSource published the vulnerabilities on their web site (here and here) a week ago last Tuesday.

Wecon Advisory


This advisory describes two buffer overflow vulnerabilities in the Wecon LEVI Studio HMI Editor. The vulnerabilities were reported by Andrea (rgod) Micalizzi, working with iDefense Labs. Wecon has developed a new version that mitigates the vulnerabilities. There is no indication that rgod has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Heap-based buffer overflow – CVE-2017-6037; and
• Stack-based buffer overflow – CVE-2017-6035


ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to cause the device to become unresponsive; a buffer overflow condition may allow remote code execution.
 
/* Use this with templates/template-twocol.html */