Showing posts with label mdm. Show all posts
Showing posts with label mdm. Show all posts

Thursday, July 9, 2020

2 Advisories and 1 Update Published – 7-9-20


Today the CISA NCCIC-ICS published two control system security advisories for products from Rockwell Automation and Phoenix Contact. They also updated an advisory for products from Rockwell.

Rockwell Advisory


This advisory describes an improper restriction of XML external entity reference vulnerability in the Rockwell Logix Designer Studio 5000. The vulnerability was reported by the Incite Team during PWN2OWN competition during the S4x20 Security Conference. Rockwell provides generic mitigation measures.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an unauthenticated attacker to craft a malicious file, which when parsed, could lead to some information disclosure of hostnames or other resources from the program.

NOTE: NCCIC-ICS does not provide the link to the Rockwell advisory.

Phoenix Contact Advisory


This advisory describes two vulnerabilities in the Phoenix Contact Automation Worx Software Suite. The vulnerabilities were reported by Natnael Samson and mdm via the Zero Day Initiative. Phoenix Contact provides generic mitigation measures pending development of a new version.

The two reported vulnerabilities were:

• Stack-based buffer overflow - CVE-2020-12497, and
• Out-of-bounds read -  CVE-2020-12498

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to execute arbitrary code under the privileges of the application.

NOTE #1 – NCCIC-ICS does not provide the link to the Phoenix Contact advisory.

NOTE #2 – I briefly described these vulnerabilities last Saturday.

Rockwell Update


This update provides additional information on an advisory that was originally published on June 11th, 2020. The new information includes the removal of RSLinx Classic from the list of affected products.

Friday, July 12, 2019

7 Advisories Published – 07-11-19


Yesterday the DHS NCCIC-ICS published six industrial control system advisories for products from Schneider Electric (2), AVEVA, Siemens (3) and Delta Industrial. They also published a medical device security advisory for products from Philips.

Interactive Graphical SCADA Advisory


This advisory describes an out-of-bounds write vulnerability in the Schneider Interactive Graphical SCADA System (IGSS). The vulnerability was reported by mdm and rgod of 9SG Security Team via the Zero Day Initiative. Schneider has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerability to  allow an attacker to achieve arbitrary code execution or crash the software.

Floating License Manager Advisory


This advisory describes four vulnerabilities in the Schneider Floating License Manager. The vulnerabilities are self-reported. According to the Schneider advisory, the vulnerabilities are in a third-party component (Flexera FlexNet Publisher) of their product. Schneider has a patch available that mitigates the vulnerability.

The four reported vulnerabilities are:

Improper input validation (3) - CVE-2018-20031, CVE-2018-20032, and CVE-2018-20034; and
Memory corruption - CVE-2018-20033

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to deny the acquisition of a valid license for legal use of the product.

NOTE: There are still three other advisories published by Schneider on Tuesday that have not been reported by NCCIC-ICS; all for Modicon controllers. I will address these on Saturday.;

AVEVA Advisory


This advisory describes the same four vulnerabilities reported above, this time in the AVEVA Vijeo Citect and Citect SCADA Floating License Manager. These vulnerabilities have not yet been reported by AVEVA. A new version is available from Schneider to mitigate the vulnerabilities.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to deny the acquisition of a valid license for legal use of the product.

SIMATIC Advisory


This advisory describes three vulnerabilities in the Siemens SIMATIC RF6XXR. The vulnerabilities are in older, third-party SSL and TLS applications still in use by these products. The vulnerabilities were reported by Wendy Parrington from United Utilities. Siemens reports that newer versions mitigate the vulnerabilities.

The three reported vulnerabilities are:

Improper input validation - CVE-2011-3389; and
Cryptographic issues (2) - CVE-2016-6329 and CVE-2013-0169

NCCIC-ICS reports that an uncharacterized attacker could use publicly available exploits (two of these are older, well recognized vulnerabilities) to remotely exploit the vulnerabilities to allow access to sensitive information.

TIA Portal Advisory


This advisory describes an improper access control vulnerability in the Siemens TIA Administrator (TIA Portal). The vulnerability was reported (with proof of concept code) by Joseph Bingham of Tenable. Siemens has an update that mitigates the vulnerability. There is no indication that Bingham has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an execution of some commands without proper authentication.

SIMATIC WinCC Advisory


This advisory describes an unrestricted upload of file with dangerous type vulnerability in the Siemens SIMATIC WinCC and SIMATIC PCS7 devices. The vulnerability was reported by Xuchen Zhu from ZheJiang Guoli Security Technology. Siemens has updates available that mitigates the vulnerability. There is no indication that Xuchen has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to cause a denial-of-service condition on the affected service or device. The Siemens advisory notes that the attacker has to be authenticated with a valid user account.

NOTE: There is still one new advisory that Siemens published on Tuesday that has not been reported by NCCIC-ICS. I will cover it tomorrow.

Delta Industrial Advisory


This advisory describes two vulnerabilities in the Delta Electronics CNCSoft ScreenEditor. The vulnerability was reported by Natnael Samson (@NattiSamson) via ZDI. Delta has a new version that mitigates the vulnerabilities. There is no indication that Samson was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Heap-based buffer overflow - CVE-2019-10982; and
Out-of-bounds read - CVE-2019-10992

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause buffer overflow conditions that may allow information disclosure, remote code execution, or crash the application.

Philips Advisory


This advisory describes a use of obsolete function vulnerability in the Philips Holter 2010 Plus, a 12-lead EKG analysis software program. The vulnerability is self-reported. Philips provides generic measures to mitigate the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit this vulnerability to lead to a product feature escalation.

Tuesday, January 8, 2019

2 Advisories and an Update Published – 01-08-19


Today the DHS NCCIC-ICS published two control system security advisories and an update for a previously published advisory; all for products from Schneider Electric.

IIoT Monitor Advisory


This advisory describes three vulnerabilities in the Schneider IIoT Monitor monitoring platform. The vulnerabilities were reported by rgod via the Zero Day Initiative. Schneider has new software available that mitigates the vulnerabilities. There is no indication that rgod has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Path traversal - CVE-2018-7835;
• Unrestricted upload of a file with dangerous type - CVE-2018-7836; and
XXE - CVE-2018-7837

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to

Zelio Soft 2 Advisory


This advisory describes a use after free vulnerability in the Schneider Zelio Soft programing platform. The vulnerability was reported by rgod and mdm of 9SG Security Team via ZDI. Schneider has a new version that mitigates the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow for remote code execution when opening a specially crafted project file.

NOTE: I briefly discussed this vulnerability last Saturday.

U.motion Builder Update


This update provides additional information on an advisory that was originally published on June 29th, 2017. The new information includes:

• Adding the other 17 vulnerabilities that I mentioned in the original post; and
• Report of a firmware update that mitigates ‘most of these vulnerabilities’;

NOTE: The latest revised Schneider advisory (v5) that was published on November 20th, 2018 reports that the firmware update only mitigates six of the vulnerabilities.

Siemens Update


This is the second Tuesday in January and Siemens published five new advisories and seven updates this morning. None made it to the NCCIC-ICS site today. I expect that we should start seeing most of them tomorrow.

Saturday, December 29, 2018

Public ICS Disclosures – Week of 12-22-18


This week we have one vendor disclosure from Schneider Electric and there is of course the federal funding fiasco.

Schneider Advisory


Schneider published an advisory for a use after free vulnerability in their Zelio Soft software product. The vulnerability was reported by mdm and rgod, of the 9SG Security Team. Schneider has an update available to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Federal Funding Fiasco


This is the first week of the FFF and it looks like it could last for a while. The NCCIC-ICS landing page does not include the FFF banner that is found on web sites for other Cybersecurity and Infrastructure Security Agency (CISA) organizations. I would like to think that that would mean that NCCIC-ICS is up and functioning like the main National Cybersecurity and Communications Integration Center (NCCIC) presumably is.

Unfortunately, the lack of publication of any advisories this week leads me to conclude that if NCCIC-ICS is functioning, it is doing so in a limited fashion. It would be helpful if NCCIC-ICS were to delineate which of its functions were deemed to be essential enough to continue during the FFF.

Saturday, December 8, 2018

Public ICS Disclosures – Week of 12-01-18


This week we have vendor notifications for products from OSIsoft and Schneider Electric and a researcher report of vulnerabilieis in products from Pilz. We also have two exploit publications for products from Rockwell Automation (one may be a 0-day).

OSIsoft Vulnerabilities


In their Release Notes for the latest version of PIProcessbook OSIsoft reports that there are three vulnerabilities being corrected by this release. Those vulnerabilities are related to an included older version of Microsoft’s VBA 6.5. A separate security advisory is being (was?) released to provide further details on these ‘high impact’ vulnerabilities. If it has been released, then my limited (non-customer) access to the OSIsoft site does not provide access to the advisory. The Release Notes do credit the Australian Energy Market Operator (AEMO) with reporting the vulnerabilities.

Schneider Advisory


This advisory describes three vulnerabilities in the Eurotherm by Schneider Electric GUIcon product. The vulnerabilities were reported by mdm and rgod (9SG Security Team). Schneider has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fixes.

The three reported vulnerabilities are:

• Type confusion (2) - CVE-2018-7813 and CVE-2018-7815; and
Stack-based buffer overflow - CVE-2018-7814

Pilz Advisory


Applied Risk has published an advisory for a clear-text storage of sensitive information vulnerability in the Pilz Pilz PNOZmulti Configurator, a safety system tool. This is a coordinated disclosure. Pilz has a new version that mitigates the vulnerability.

Rockwell Exploits


Luca.Chiou published an exploit for an incorrect access control authentication bypass vulnerability in the Rockwell Allen-Bradley PowerMonitor 1000. A CVE has been reserved for this vulnerability (CVE-2018-19616, no further information available) which may indicate that Rockwell has been notified of this vulnerability.

Luca.Chiou published an exploit for a cross-site scripting vulnerability in the Rockwell Allen-Bradley PowerMonitor 1000. No CVE is provided in the exploit documentation. This may indicate that this is a 0-day vulnerability.

 
/* Use this with templates/template-twocol.html */