Showing posts with label iRZ. Show all posts
Showing posts with label iRZ. Show all posts

Friday, December 23, 2016

ICS-CERT Publishes Two Advisories and Updates Five

Yesterday the DHS ICS-CERT published two control system security advisories for products from Wago and Fidelix. It also published updates for previously issued advisories for products from Moxa (2), iRZ, Resource Data Management, Environmental Systems and Siemens.

Wago Advisory


This advisory describes an authentication bypass vulnerability in the WAGO Ethernet Web-based Management products. The vulnerability was reported by Maxim Rupp. WAGO has produced a firmware update and workarounds to mitigate the vulnerability. There is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled hacker could remotely exploit this vulnerability to view and edit settings without authenticating.

Fidelix Advisory


This advisory describes a path traversal vulnerability in the Fidelix FX-20 series controllers. The vulnerability was reported by Semen Rozhkov of Kaspersky Lab. Fidelix has produced a new software version that mitigates the vulnerability. There is no indication that Rozhkov has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability  to read data from the device.

Moxa EDR-G903 Update  


This update provides additional information on an advisory that was originally published on May 17th, 2016.  It changes the name of one of the vulnerabilities from ‘memory leak’ to ‘information exposure’. On the unauthenticated download vulnerability, the CVE vector string has a change in the ‘A’ component at the end from ‘H’ to ‘N’.

iRZ Update


This update provides additional information on an advisory that was originally published on May 17th, 2016. It changes the CVSS v3 base score from 6.1 to 7.2 and changes two components of the CVE vector string; ‘UI’ from ‘R’ to ‘N’ and ‘C’ from ‘N’ to ‘H’.

Resource Data Management Update


This update provides additional information on an advisory that was originally published on May 19th, 2016. It changes the CVSS v3 base score on the cross-site request forgery vulnerability from 6.5 to 8.0 and changes three components of the CVE vector string for the same vulnerability; ‘UI’ from ‘N’ to ‘R’, ‘C’ from ‘N’ to ‘H’, and ‘I’ from ‘N’ to ‘H’.

Moxa MiiNePort Update


This update provides additional information on an advisory that was originally published on May 24th, 2016. It changes the CVSS v3 base score on the cross-site request forgery vulnerability from 6.1 to 9.6 and changes three components of the CVE vector string for the same vulnerability; ‘UI’ from ‘R’ to ‘N’, ‘C’ from ‘L’ to ‘H’, and ‘I’ from ‘N’ to ‘H’.

Environmental Systems Update


This update provides additional information on an advisory that was originally published on May 26th, 2016, and then updated on June 2nd, 2016. It changes the CVSS v3 base score on the authentication bypass vulnerability from 7.5 to 9.1.

Siemens Update


This update provides additional information on an advisory that was originally published on November 8th, 2016 and then updated on November 22nd, 2016. It updates both the affected version and mitigation information for SIMIT V9.0 SP1 and SecurityConfiguration Tool (SCT) V4.3 HF1. Siemens has updated their security advisory and reported this update via a tweet on Wednesday.

Commentary


This cluster of incorrect CVE v3 base scores and vector strings from May of this year is interesting. As of this date it does not apparently affect all the advisories produced during that period and only affects one of the reported vulnerabilities in multiple vulnerability advisories. This would seem to indicate that it was not a systemic problem, but rather human error. While we would like to think that the folks at ICS-CERT were perfect, alas they are only human.


I am impressed with the four updates addressing these CVE related errors. I’m not sure what instigated the review of these advisories, but their publication does demonstrate a high level of integrity and attention to detail. ICS-CERT is to be commended on publishing them.

Tuesday, May 17, 2016

ICS-CERT Publishes Two Advisories

This morning the DHS ICS-CERT published two control system advisories for products from Moxa and iRZ. The Moxa advisory was previously published on the US-CERT Secure Portal. I also mention some additional vulnerability news.

Moxa Advisory


This advisory describes five vulnerabilities in the Moxa ECRG903 secure routers. The vulnerabilities were reported by Maxim Rupp. Moxa had developed a new firmware version that mitigates the vulnerabilities. There is no indication that Rupp was provided the opportunity to verify the efficacy of the fix.

The five vulnerabilities include:

• Privilege escalation - CVE-2016-0875;
• Plaintext storage of password - CVE-2016-0876;
• Memory leak - CVE-2016-0877;
• Denial of service - CVE-2016-0878; and
• Unauthenticated file download - CVE-2016-0879

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to escalate privileges, initiate a denial-of-service condition, and execute arbitrary code.

iRZ Advisory


This advisory describes a firmware overwrite vulnerability in the iRZ RUH2 serial-to-Ethernet interface. Apparently this is a self-reported vulnerability though ICS-CERT reports that an exploit is publicly available. iRZ no longer supports this device so no mitigation measures will be forth coming.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to upload new firmware to the device.

Other Vulnerability Notes


I had an interesting TWEET directed my way this morning by Brandon Workentin. He said: “Full Disclosure has email by Meteocontrol vuln reporter saying ICS-CERT advisory ‘not complete and accurate.’ Not on FD archive yet”. ICS-CERT published that vulnerability advisory last week.

When I looked on Full Disclosure to see if that report had been published yet (it hasn’t) I was surprised to find another Moxa vulnerability report from early this month that hasn’t been reported by ICS-CERT yet. This is unusual in that Karn Ganeshen, the apparent reporter, has done numerous coordinated disclosures, so there should be an interesting story here.


BTW: Karn was also the reporter on the Meteocontrol Advisory. I’ll be watching Full Disclosure for this reported email.
 
/* Use this with templates/template-twocol.html */