Showing posts with label rgod. Show all posts
Showing posts with label rgod. Show all posts

Thursday, October 15, 2020

2 Advisories and 1 Update Published – 10-15-20

Today the CISA NCCIC-ICS published two control system security advisories for products from Advantech and updated one advisory for products from Wibu-Systems.

R-SeeNet Advisory

This advisory describes an SQL injection vulnerability in the Advantech  R-SeeNet monitoring application. The vulnerability was reported by rgod via the Zero Day Initiative (ZDI). Advantech has a new version that mitigates the vulnerability. There is no indication that rgod has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reported that a relatively low-skilled attacker could remotely exploit this vulnerability to allow remote attackers to retrieve sensitive information from the R-SeeNet database.

NOTE: NCCIC-ICS provides a link to the Advantech advisory for this vulnerability. This is the first time that I have seen an advisory published by Advantech (actually, Advantech Czech s.r.o.) and they also have a security notifications web page which apparently only covers their cellular routers and gateways. Interestingly, they make Common Vulnerability Reporting Framework (CVRF) v1.1 files on identified vulnerabilities available to their customers.

WebAccess Advisory

This advisory describes an external control of file name or path vulnerability in the Advantech WebAccess/SCADA software package. The vulnerability was reported by Sivathmican Sivakumaran via ZDI. Advantech has newer versions that mitigate the vulnerability. There is no indication that Sivakumaran has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to control or influence a path used in an operation on the filesystem and remotely execute code as an administrator.

NOTE: This vulnerability was not reported on the web site I discussed for the earlier vulnerability, nor was there an Advantech advisory available.

CodeMeter Update

This update provides additional information on an advisory that  was originally published on September 8th, 2020 and most recently updated on October 1st, 2020 (the advisory incorrectly refers back to an earlier version from September 17th). The new information includes links to two new vendor advisories from Schneider and WEIDMUELLER.

Wednesday, August 12, 2020

8 Advisories Published – 8-12-20


Yesterday the CISA NCCIC-ICS published eight control system security advisories for products from Siemens (5), Tridium, Schneider, and Yokogawa. There were also 22 updates published but those will be dealt with in a later blog post.

SICAM Advisory


This advisory describes a cross-site scripting vulnerability in the Siemens  SICAM A8000 RTUs. The vulnerability was reported by Emma Good from KTH Royal Institute of Technology. Siemens has a new version that mitigates the vulnerability. There is no indication that Good has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit this vulnerability to compromise the confidentiality, integrity, and availability of the web application.

Automation License Advisory


This advisory describes an improper authorization vulnerability in the Siemens Automation License Manager. The vulnerability was reported by Lasse Trolle Borup of Danish Cyber Defense. Siemens has a new version of ALM6 that mitigates the vulnerability. There is no indication that Borup has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow an attacker to locally escalate privileges and modify files that should be protected against writing.

Desigo Advisory


This advisory describes a code injection vulnerability in the Siemens Desigo CC building management platform. This vulnerability is self-reported. Siemens has patches available that mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to gain remote code execution on the server with SYSTEM privileges.

Simatic Advisory


This advisory describes the kr00k vulnerability in the Siemens SIMATIC and SIMOTICS wi-fi services. This is a third-party vulnerability in the Broadcom Wi-Fi client devices with publicly available exploits. Siemens has provided generic workarounds pending development of updates.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to read a discrete set of traffic over the air after a Wi-Fi device state change. NCCIC-ICS provides no mention of the publicly available exploits.

SCALANCE Advisory


This advisory describes a classic buffer overflow in the Siemens SCALANCE and RUGGEDCOM products. This is the Linux Point-to-Point Protocol Daemon (pppd) Vulnerability reported in March and proof-of-concept exploit code is available. Siemens has updates available to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to gain unauthenticated access to a device and cause a buffer overflow to execute custom code. NCCIC-ICS provides no mention of the publicly available exploits.

Tridium Advisory


This advisory describes a synchronous access of remote resource without timeout vulnerability in the Tridium Niagara product. The vulnerability was self-reported. Tridium has updates that mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker on an adjacent network could exploit the vulnerability to result in a denial-of-service condition.

Schneider Advisory


This advisory describes two path traversal vulnerabilities in the Schneider APC Easy UPS On-Line. The vulnerabilities were reported by rgod via the Zero Day Initiative. Schneider has a new version that mitigates the vulnerability. There is no indication that rgod has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to lead to remote code execution.

NOTE: Schneider also published six other advisories yesterday.

 

Yokogawa Advisory


This advisory describes two vulnerabilities in the Yokogawa CENTUM distributed control system. The vulnerabilities were reported by Nataliya Tlyapova, Ivan Kurnakov, and Positive Technologies. Yokogawa has patches that mitigate the vulnerabilities for products still under support. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper authentication - CVE-2020-5608, and
• Path traversal CVE-2020-5609

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a remote unauthenticated attacker to send tampered communication packets or create/overwrite any file and run any commands.

NOTE: I briefly discussed these vulnerabilities on August 1st.

Saturday, July 18, 2020

Public ICS Disclosures – Week of 7-11-20


This week we have four Ripple20 vendor disclosures from Siemens, ABB, Rockwell, Carestream and Schneider Electric; two SigRed vendor disclosures from Philips and GE Healthcare; and three other vendor disclosures from HMS and Schneider (2). Four vendor updates from Schneider (2) and Siemens (2) and  two researcher disclosures for products from Siemens and Advantech round out the weeks’ offerings.

Ripple20 Disclosures and Updates


Siemens published a Ripple20 advisory for their SPPA-T3000 Solutions distributed control system. Siemens provides generic mitigation measures for these vulnerabilities.

NOTE: Siemens published a note at the top of their Security Publications page noting that:

“No Siemens product is known to use Treck Inc.'s TCP/IP stack, or otherwise be affected by the reported vulnerabilities.
“Note that Siemens products and systems might interact with products from other manufacturers which are affected by the reported vulnerabilities. In such cases Siemens recommends that owners of operational infrastructures verify if these products are affected and evaluate the potential impact of the Ripple20 vulnerabilities.”

Since the SPPA-T3000 advisory also contains two Intel Server Platform Services vulnerabilities, I suspect that the Ripple20 vulnerabilities come with the Intel server upon which the T-3000 is built.

ABB published a Ripple20 advisory. The advisory contains a list of affected products and generic mitigation measures pending further work to address the vulnerabilities.

Rockwell updated their Ripple20 advisory. The new information includes an updated table of affected products.

Carestream updated their Ripple20 advisory (.PDF download link). The new information includes adding 20 products that were on the ‘still evaluating list’ to the not affected list. The list of affected products has not changed.

Schneider updated their Ripple20 advisory. The new information includes removing the “Smartlink ELEC” from the list of affected products.

SigRed Disclosures


SigRed is the ‘cute’ name given to the Microsoft ‘wormable’ remote code execution DNS vulnerability (CVE-2020-1350).

Phillips published a SigRed advisory noting that: “Philips is currently in the process of evaluating the Microsoft patch and vendor recommended mitigation options.”


GE Healthcare published a SigRed advisory noting that: “GE Healthcare is actively assessing products that utilize impacted Microsoft Operating Systems.”

Neither of these advisories provide much in the way of information beyond noting that a vague ‘some’ of their products may be affected.

Vendor Disclosures


HMS published an advisory describing a remote code execution vulnerability in their eCatcher product. The vulnerability was reported by Claroty. HMS has an update that mitigates the vulnerability. There is no indication that Claroty was provided an opportunity to verify the efficacy of the fix.

Schneider published an advisory describing an open redirect vulnerability in their Schneider Electric Software Update (SESU). The vulnerability was reported by Amir Preminger of Claroty. Schneider has a new version that mitigates the vulnerability. There is no indication that Preminger has been provided an opportunity to verify the efficacy of the fix.

Schneider published an advisory describing two denial of service vulnerabilities in their Floating License
Manager. These are third-party vulnerabilities in the Flexera FlexNet Publisher (reported here and here). Schneider has a new version that mitigates these vulnerabilities.

NOTE: Flexera is also reporting three other vulnerabilities (CVE-2019-8963, CVE-2020-12080, and CVE-2020-12081) that could potentially affect the Schneider Floating License Manager and a variety of other vendor ‘license manager’ products based upon the Flexera product.

Vendor Updates


Schneider updated their ZombieLoad advisory. The new information includes updated mitigation measures for the HMI products.

Schneider updated their BlueKeep advisory. The new information includes updated mitigation measures for the HMI products.

Siemens updated their Vulnerabilities in Intel CPUs advisory. The new information includes:

• Updated mitigation and affected version information for SIMATIC ITP1000, and
• Removed SIMATIC IPC827E from list of affected devices

Siemens updated heir GNU/Linux advisory. The new information includes adding:

CVE-2020-12114,
• CVE-2020-12659,
• CVE-2020-13630,
• CVE-2020-13631, and
• CVE-2020-13632

Researcher Disclosures


Talos published a report on the Siemens LOGO web server vulnerability that was reported earlier this week. The Talos report includes proof-of-concept code for the vulnerability.

The Zero Day Initiative published 43 reports, all based upon research by rgod, about the Advantech iView vulnerabilities that were reported earlier this week. Most of the reports provided more details on the three CVE’s listed in the NCCIC-ICS advisory. One of the reports, however, described an input validation vulnerability that was not reported by NCCIC-ICS.

Tuesday, July 14, 2020

9 Advisories Published – 7-14-20


Today the CISA NCCIC-ICS published eight control system security advisories for products from Siemens (6), Moxa and Advantech. They also published one medical device security advisory for products from Capsule Technologies.

NOTE: NCCIC-ICS also published 12 updates, but I will not try to get a report done on those this evening. Look for it tomorrow morning

Logo Advisory


This advisory describes a classic buffer overflow vulnerability in the Siemens LOGO! Web Server. The vulnerability was reported by Alexander Perez-Palma and Dave McDaniel from Cisco Talos and Emanuel Almeida from Cisco Systems. Siemens has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to  allow remote code execution..

Opcenter Advisory


This advisory describes three vulnerabilities in the Seiemens  Opcenter Execution Core. The vulnerabilities are self-reported. Siemens has a new version that mitigates the vulnerabilities.

The three reported vulnerabilities are:

• Cross-site scripting - CVE-2020-7576,
• SQL injection - CVE-2020-7577, and
• Improper access control - CVE-2020-7578
NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to obtain session cookies, read and modify application data, read internal information, and perform unauthorized changes. Should the attacker gain access to the session cookies, they could then hijack the session and perform arbitrary actions in the name of the victim.

SIMATIC S7 Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the Siemens SIMATIC S7-200 SMART CPU family. The vulnerability was reported by Ezequiel Fernandez. Siemens has a new version that mitigates the vulnerability. There is no indication that Fernandez has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to cause a denial-of-service condition.

UMC Stack Advisory


This advisory describes three vulnerabilities in the Siemens UMC Stack. The vulnerabilities were reported by Victor Fidalgo of INCIBE and Reid Wightman of Dragos. Siemens has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Unquoted search path or element - CVE-2020-7581,
• Uncontrolled resource consumption - CVE-2020-7587, and
• Improper input validation - CVE-2020-7588

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to cause a partial denial-of-service condition on the UMC component of the affected devices under certain circumstances. This could also allow an attacker to locally escalate privileges from a user with administrative privileges to execute code with SYSTEM level privileges.

SIMATIC HMI Advisory


This advisory describes a cleartext transmission of sensitive information in the Siemens SIMATIC HMI Panels. The vulnerability was reported by Richard Thomas and Tom Chothia of the University of Birmingham.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to access sensitive information under certain circumstances.

SICAM Advisory


This advisory describes nine vulnerabilities in the Seimens SICAM MMU, SICAM T and SICAM SGU products. The vulnerabilities were reported by Luca Simbürger, Luca Hofschuster, Lukas Kahnert, Jakob Lachermeier, Christian Costa, Simon Huber, Lukas Sas Brunschier, Florian Freiberger, Florian Burger, Marie-Louise Oostveen, Magdalena Thomeczek, and Johann Uhrmann from Landshut University of Applied Sciences and Max Hirschberger, Simon Hofmann, and Peter Knauer from Augsburg University of Applied Sciences. Siemens has updates that mitigate the vulenrabilites. There is no indication that researchers have been provided an opportunity to verify the efficacy of the fix.

The nine reported vulnerabilities are:

• Out-of-bounds read - CVE-2020-10037,
• Missing authentication for critical function - CVE-2020-10038,
• Missing encryption of sensitive data - CVE-2020-10039,
• Use of password has with insufficient computational effort - CVE-2020-10040,
• Cross-site scripting - CVE-2020-10041,
• Classic buffer overflow - CVE-2020-10042,
• Basic XSS - CVE-2020-10043, and
• Authentication bypass by capture replay - CVE-2020-10045

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to affect the availability, read sensitive data, and gain remote code execution on the affected devices.

Moxa Advisory


This advisory describes a stack-based buffer overflow in the Moxa EDR-G902 and EDR-G903 Series Routers. The vulnerability was reported by Tal Keren of Claroty. Moxa has a firmware patch that mitigates the vulnerability. There is no indication that Keren has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to  crash the device being accessed; a buffer overflow condition may allow remote code execution.

NOTE 1: NCCIC-ICS did not publish a link to the Moxa advisory.

NOTE 2: I briefly discussed this vulnerability last month.

Advantech Advisory


This advisory describes six vulnerabilities in the Advantech iView device management application. The vulnerabilities were reported by rgod via the Zero Day Initiative. Advantech has a new version that mitigates the vulnerability. There is no indication that rgod has been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• SQL injection - CVE-2020-14497,
• Path traversal - CVE-2020-14507,
• Command injection - CVE-2020-14505,
• Improper input validation - CVE-2020-14503,
• Missing authentication for critical function - CVE-2020-14501, and
• Improper access control -CVE-2020-14499

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to read/modify information, execute arbitrary code, limit system availability, and/or crash the application.

Capsule Technologies Advisory


This advisory describes protection mechanism failure in the Capsule Technologies SmartLinx Neuron 2 medical device platform. The vulnerability was reported by Patrick DeSantis of Cisco Talos (NOTE: Talos report includes exploit code). Capsule Technologies has a new version that mitigates the vulnerability. There is no indication that DeSantis has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could use publicly available code to exploit the vulnerability to provide an attacker with full control of a trusted device on a hospital’s internal network.

Saturday, May 16, 2020

Public ICS Disclosures – Week of 5-9-20


This week we have five vendor disclosures for products from Schneider (4) and Rockwell as well as six vendor updates from Schneider (5) and Siemens. We also have two researcher reports of vulnerabilities in products from Advantech.

Schneider Advisories


Schneider published an advisory describing a weak password requirement vulnerability in their Pro-face GP-Pro EX Programming Software product. The vulnerability was reported by Kirill Kruglov of Kaspersky Labs. Schneider has a new version that mitigates the vulnerability. There is no indication that Krublov has been provided an opportunity to verify the efficacy of the fix.


Schneider published an advisory describing a use of hard-coded credentials vulnerability in their Vijeo Designer Basic and Vijeo Designer software products. The vulnerability was reported by Jie Chen of NSFOCUS. Schneider has a HotFix available to mitigate the vulnerability. There is no indication that Jie has been provided an opportunity to verify the efficacy of the fix.


Schneider published an advisory describing two vulnerabilities in their U.motion servers and touch panel products. The vulnerabilities were reported by Rgod and Zhu Jiaqi. Schneider has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper access control - CVE-2020-7499, and
• SQL injection - CVE-2020-7500


Schneider published an advisory describing five vulnerabilities in their EcoStruxure™ Operator Terminal Expert product. The vulnerabilities were reported by Steven Seeley and Chris Anastasio of Incite Team, Sharon Brizinov and Amir Preminger of Claroty Research via the Zero Day Initiative (see here, here, and here), and Fredrik Østrem, Emil Sandstø, and Cim Stordal of Cognite. Schneider has a new version that mitigates four of the five vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• SQL command injection - CVE-2020-7493,
• Path traversal (3) - CVE-2020-7494, CVE-2020-7495, and CVE-2020-7497, and
• Argument injection or modification - CVE-2020-7496

Rockwell Advisory


Rockwell published an advisory describing five vulnerabilities in multiple Rockwell Automation software products. These are third-party vulnerabilities from OSIsoft components used in the Rockwell products. These vulnerabilities are self-identified. Rockwell provides workarounds to mitigate the vulnerabilities.

The five reported vulnerabilities are:

• Local privilege escalation via uncontrolled search path element - CVE-2020-10610,
• Local privilege escalation via improper verification of cryptographic key - CVE-2020-10608,
• Local privilege escalation via incorrect default permissions - CVE-2020-10606,
• Null pointer dereference - CVE-2020-10600, and
• Use of out-of-range pointer offset may lead to remote code execution - CVE-2020-10645

NOTE: These are five of the ten vulnerabilities in the OSIsoft PI System that were reported by NCCIC-ICS earlier this week. The fact that this Rockwell Advisory was published on the same day as the NCCIC-ICS advisory indicates that there was pre-disclosure coordination between OSIsoft and Rockwell, good show.

Advantech Advisories


The Zero Day Initiative published advisories (see links below) describing two vulnerabilities in Advantech WebAccess Node. ZDI published the two advisories as 0-day notifications under their 120-day response rule. NCCIC-ICS was reported involved in the coordination of these vulnerabilities. The vulnerabilities were reported by Z0mb1E.

The two reported vulnerabilities are:

• DATACORE Stack-based Buffer Overflow Remote Code Execution Vulnerability - ZDI-20-654, and
• Incorrect Permission Assignment Privilege Escalation Vulnerability - ZDI-20-655

Schneider Updates


Schneider published an update for the Urgent/11 advisory that was originally published on August 11th, 2019 and most recently updated on April 14th, 2020. The new information includes updated mitigation information for:

• Modicon Network Option Switch,
• Modicon X80 - I/O Drop Adapters,
• Modicon Quantum 140 CRA,
• Modicon Quantum Head 140 CRP,
• Modicon Quantum Ethernet DIO network module - 140NOC78x00 (C),
• SCD6000 Industrial RTU, and
• Pro-face HMI -GP4000H/R/E Series


Schneider published an update for their Andover Continuum System advisory that was originally published on March 10th, 2020 and most recently updated on April 14th, 2020. The new information includes minor updates to overview, vulnerability details, and product information for clarification.


Schneider published an update for their Embedded Web Servers for Modicon advisory that was originally published in November 2018 and most recently updated November 27th, 2019. The new information includes a corrected CVSS vector for CVE-2018-7812.


Schneider published an update for their Modicon Controllers advisory that was originally published on May 14th, 2019 and most recently updated on December 10th, 2019. The new information includes updated fix version information for CVE-2018-7857.


Schneider published an update for their Legacy Triconex advisory that was originally published on April 14th, 2020. Unfortunately, the link on the Schneider web site takes one to the original version of the advisory.

Siemens Update


Siemens published an update for their GNU/Linux advisory that was originally published on November 27th, 2018 and most recently updated on April 14th, 2020. The new information includes the addition of the following CVE’s:

• CVE-2019-9674,
• CVE-2019-18348,
• CVE-2019-20636,
• CVE-2020-8492,
• CVE-2020-11565,
• CVE-2020-11655, and
• CVE-2020-11656

Tuesday, April 7, 2020

5 Advisories and 1 Update Published


Today the CISA NCCIC-ICS published five control system security advisories for products from KUKA, Fuji Electric, HMS Networks, GE Digital and Advantech. They also updated an advisory for products from Synergy.

KUKA Advisory


This advisory describes an improper enforcement of message integrity in a communications channel vulnerability in the KUKA Sim Pro. The vulnerability was reported by Federico Maggi of Trend Micro. KUKA has an upgrade that mitigates the vulnerability. There is no indication that Maggi has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to result in a loss of integrity in external 3D models fetched from remote servers. When tested on real machines, this effect is unpredictable.

Fuji Advisory


This advisory describes a heap-based buffer overflow vulnerability in the Fuji V-Server Lite. The vulnerability was reported by kimiya via the Zero Day Initiative. Fuji has a new version that mitigates the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reported that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a remote attacker to gain elevated privileges for remote code execution.

HMS Advisory


This advisory describes a cross-site scripting vulnerability in the HMS eWON Flexy and Cosy. The vulnerability was reported by Ander Martínez of Titanium Industrial Security. HMS has a firmware update that mitigates the vulnerability. There is no indication that Martinez has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit this vulnerability to initiate a password change.

NOTE: I briefly discussed this vulnerability back in February.

GE Advisory


This advisory describes an improper privilege management vulnerability in the GE Digital CIMPLICITY HMI/SCADA product. The vulnerability was reported by Sharon Brizinov of Claroty. GE has a new version that mitigates the vulnerability. There is no indication that Brizinov has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an adversary to modify the systemwide CIMPLICITY configuration, leading to the arbitrary execution of code.

NOTE: I briefly discussed this vulnerability last weekend.

Advantech Advisory


This advisory describes eight vulnerabilities in the Advantech WebAccess/NMS network management system. The vulnerability was reported by rgod of 9sg via ZDI. Advantech has a new version that mitigates the vulnerability. There is no indication that rgod was provided an opportunity to verify the efficacy of the fix.

The eight reported vulnerabilities are:

• Unrestricted upload of file with dangerous type - CVE-2020-10621;
• SQL injection (2) - CVE-2020-10617 and CVE-2020-10623;
• Relative path traversal (2) - CVE-2020-10619 and CVE-2020-10631;
• Missing authentication for critical function - CVE-2020-10625;
• Improper restriction of XML external entity reference -CVE-2020-10629; and
• OS command injection - CVE-2020-10603

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to gain remote code execution, upload files, delete files, cause a denial-of-service condition, and create an admin account for the application.

Synergy Update


This update provides new information on an advisory that was originally published on February 11th, 2020. The new information includes:

• Four new vulnerabilities:
Missing authentication for critical function - CVE-2019-16879;
Improper check for unusual or exceptional conditions - CVE-2020-7800;
Exposure of sensitive information to an unauthorized actor - CVE-2020-7801; and
Incorrect default permissions - CVE-2020-7802
• Links to three associated advisories from SSS (here, here and here)

Thursday, February 20, 2020

4 Advisories Published – 2-20-20


Today the CISA NCCIC-ICS published four control system security advisories for products from Auto-Maskin, Honeywell, Rockwell Automation and B&R Industrial Automation.

Auto-Maskin Advisory


This advisory describes six vulnerabilities in the Auto-Maskin RP 210E Remote Panels, DCU 210E Control Units, and Marine Observer Pro (Android App). The vulnerability is apparently self-reported. Auto-Maskin has new firmware that mitigates the vulnerability.

The six reported vulnerabilities are:

• Cleartext transmission of sensitive information (2) - CVE-2018-5402 and CVE-2018-5401;
• Origin validation error - CVE-2018-5400;
• Use of hard-coded credentials - CVE-2018-5399;
• Weak password recovery mechanism for forgotten password - CVE-2019-6560; and
• Weak password requirements - CVE-2019-6558

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a remote attacker to gain root access to the underlying operating system of the device and may allow read/write access.

Honeywell Advisory


This advisory describes two vulnerabilities in the Honeywell NOTI-FIRE-NET Web Server (NWS-3). The vulnerabilities were reported by Gjoko Krstikj. Honeywell has a firmware update that mitigates the vulenrabilities. There is no indication that Krstiki has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Authentication bypass by capture-replay - CVE-2020-6972; and
• Path traversal - CVE-2020-6974

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to bypass web server authentication methods.

Rockwell Advisory


This advisory describes a deserialization of untrusted data vulnerability in the Rockwell FactoryTalk Diagnostics. The vulnerability was reported by rgod via the Zero Day Initiative. Rockwell has provided generic workarounds pending the development of updated software.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow a remote unauthenticated attacker to execute arbitrary code with SYSTEM level privileges.

B&R Advisory


This advisory describes an improper authorization vulnerability in the SNMP implementation in the B&R Automation Studio and Automation Runtime. The vulnerability was reported by Yehuda Anikster and Amir Preminger of Claroty. B&R is not able to fix the underlying SNMP vulnerability and has provided generic workarounds.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a remote attacker to modify the configuration of affected devices.

Thursday, October 31, 2019

4 Advisories Published – 10-31-19


Today the CISA NCCIC-ICS published four control system security advisories for products from Honeywell (3) and Advantech.

Cameras and Recorder Advisory


This advisory describes an authentication bypass by capture-replay vulnerability in the Honeywell equIP series and Performance series IP cameras and recorders. The vulnerability is self-reported. Honeywell has a firmware update that mitigates the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to result in unauthenticated access.

NOTE: I briefly reported on this vulnerability on September 14th, 2019.

Cameras Advisory


This advisory describes a missing authentication for critical function vulnerability in the Honewell equIP series and Performance series IP cameras. The vulnerability is self-reported. Honeywell has a firmware update that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to could result in unauthenticated access.

 

equip Advisory


This advisory describes an improper input validation vulnerability in the Honeywell equIP series IP cameras. This vulnerability is self-reported. Honeywell has a firmware update that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to result in a denial of service.

NOTE: I briefly reported on this vulnerability on September 14th, 2019.

Advantech Advisory


This advisory describes four vulnerabilities in the Advatech WISE-PaaS/RMM IoT device remote monitoring and management platform. The vulnerabilities were reported by rgod of 9sg Security Team and trendytofu via the Zero Day Initiative (ZDI). The product is out-of-support and Advantech recommends replacing the product with EdgeSense and DeviceOn.

The four reported vulnerabilities are:

Path traversal - CVE-2019-13551;
Missing authorization - CVE-2019-13547;
Improper restriction of an XML external entity reference - CVE-2019-18227; and
SQL injection - CVE-2019-18229

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow information disclosure, remote code execution, and compromise system availability.

Friday, July 12, 2019

7 Advisories Published – 07-11-19


Yesterday the DHS NCCIC-ICS published six industrial control system advisories for products from Schneider Electric (2), AVEVA, Siemens (3) and Delta Industrial. They also published a medical device security advisory for products from Philips.

Interactive Graphical SCADA Advisory


This advisory describes an out-of-bounds write vulnerability in the Schneider Interactive Graphical SCADA System (IGSS). The vulnerability was reported by mdm and rgod of 9SG Security Team via the Zero Day Initiative. Schneider has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerability to  allow an attacker to achieve arbitrary code execution or crash the software.

Floating License Manager Advisory


This advisory describes four vulnerabilities in the Schneider Floating License Manager. The vulnerabilities are self-reported. According to the Schneider advisory, the vulnerabilities are in a third-party component (Flexera FlexNet Publisher) of their product. Schneider has a patch available that mitigates the vulnerability.

The four reported vulnerabilities are:

Improper input validation (3) - CVE-2018-20031, CVE-2018-20032, and CVE-2018-20034; and
Memory corruption - CVE-2018-20033

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to deny the acquisition of a valid license for legal use of the product.

NOTE: There are still three other advisories published by Schneider on Tuesday that have not been reported by NCCIC-ICS; all for Modicon controllers. I will address these on Saturday.;

AVEVA Advisory


This advisory describes the same four vulnerabilities reported above, this time in the AVEVA Vijeo Citect and Citect SCADA Floating License Manager. These vulnerabilities have not yet been reported by AVEVA. A new version is available from Schneider to mitigate the vulnerabilities.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to deny the acquisition of a valid license for legal use of the product.

SIMATIC Advisory


This advisory describes three vulnerabilities in the Siemens SIMATIC RF6XXR. The vulnerabilities are in older, third-party SSL and TLS applications still in use by these products. The vulnerabilities were reported by Wendy Parrington from United Utilities. Siemens reports that newer versions mitigate the vulnerabilities.

The three reported vulnerabilities are:

Improper input validation - CVE-2011-3389; and
Cryptographic issues (2) - CVE-2016-6329 and CVE-2013-0169

NCCIC-ICS reports that an uncharacterized attacker could use publicly available exploits (two of these are older, well recognized vulnerabilities) to remotely exploit the vulnerabilities to allow access to sensitive information.

TIA Portal Advisory


This advisory describes an improper access control vulnerability in the Siemens TIA Administrator (TIA Portal). The vulnerability was reported (with proof of concept code) by Joseph Bingham of Tenable. Siemens has an update that mitigates the vulnerability. There is no indication that Bingham has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an execution of some commands without proper authentication.

SIMATIC WinCC Advisory


This advisory describes an unrestricted upload of file with dangerous type vulnerability in the Siemens SIMATIC WinCC and SIMATIC PCS7 devices. The vulnerability was reported by Xuchen Zhu from ZheJiang Guoli Security Technology. Siemens has updates available that mitigates the vulnerability. There is no indication that Xuchen has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to cause a denial-of-service condition on the affected service or device. The Siemens advisory notes that the attacker has to be authenticated with a valid user account.

NOTE: There is still one new advisory that Siemens published on Tuesday that has not been reported by NCCIC-ICS. I will cover it tomorrow.

Delta Industrial Advisory


This advisory describes two vulnerabilities in the Delta Electronics CNCSoft ScreenEditor. The vulnerability was reported by Natnael Samson (@NattiSamson) via ZDI. Delta has a new version that mitigates the vulnerabilities. There is no indication that Samson was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Heap-based buffer overflow - CVE-2019-10982; and
Out-of-bounds read - CVE-2019-10992

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause buffer overflow conditions that may allow information disclosure, remote code execution, or crash the application.

Philips Advisory


This advisory describes a use of obsolete function vulnerability in the Philips Holter 2010 Plus, a 12-lead EKG analysis software program. The vulnerability is self-reported. Philips provides generic measures to mitigate the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit this vulnerability to lead to a product feature escalation.

Tuesday, January 8, 2019

2 Advisories and an Update Published – 01-08-19


Today the DHS NCCIC-ICS published two control system security advisories and an update for a previously published advisory; all for products from Schneider Electric.

IIoT Monitor Advisory


This advisory describes three vulnerabilities in the Schneider IIoT Monitor monitoring platform. The vulnerabilities were reported by rgod via the Zero Day Initiative. Schneider has new software available that mitigates the vulnerabilities. There is no indication that rgod has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Path traversal - CVE-2018-7835;
• Unrestricted upload of a file with dangerous type - CVE-2018-7836; and
XXE - CVE-2018-7837

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to

Zelio Soft 2 Advisory


This advisory describes a use after free vulnerability in the Schneider Zelio Soft programing platform. The vulnerability was reported by rgod and mdm of 9SG Security Team via ZDI. Schneider has a new version that mitigates the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow for remote code execution when opening a specially crafted project file.

NOTE: I briefly discussed this vulnerability last Saturday.

U.motion Builder Update


This update provides additional information on an advisory that was originally published on June 29th, 2017. The new information includes:

• Adding the other 17 vulnerabilities that I mentioned in the original post; and
• Report of a firmware update that mitigates ‘most of these vulnerabilities’;

NOTE: The latest revised Schneider advisory (v5) that was published on November 20th, 2018 reports that the firmware update only mitigates six of the vulnerabilities.

Siemens Update


This is the second Tuesday in January and Siemens published five new advisories and seven updates this morning. None made it to the NCCIC-ICS site today. I expect that we should start seeing most of them tomorrow.

Saturday, December 29, 2018

Public ICS Disclosures – Week of 12-22-18


This week we have one vendor disclosure from Schneider Electric and there is of course the federal funding fiasco.

Schneider Advisory


Schneider published an advisory for a use after free vulnerability in their Zelio Soft software product. The vulnerability was reported by mdm and rgod, of the 9SG Security Team. Schneider has an update available to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Federal Funding Fiasco


This is the first week of the FFF and it looks like it could last for a while. The NCCIC-ICS landing page does not include the FFF banner that is found on web sites for other Cybersecurity and Infrastructure Security Agency (CISA) organizations. I would like to think that that would mean that NCCIC-ICS is up and functioning like the main National Cybersecurity and Communications Integration Center (NCCIC) presumably is.

Unfortunately, the lack of publication of any advisories this week leads me to conclude that if NCCIC-ICS is functioning, it is doing so in a limited fashion. It would be helpful if NCCIC-ICS were to delineate which of its functions were deemed to be essential enough to continue during the FFF.

Friday, December 21, 2018

Public ICS Disclosure – Week of 12-15-18


This week we have five vendor notifications for products from Schneider Electric (3), Yokogawa and 3S (5).

Schneider Advisories


Schneider published an advisory for three vulnerabilities in their EVLink Parking product. The vulnerabilities were reported by Vladimir Kononovich and Vyacheslav Moskvin (Positive
Technologies). Schneider has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three vulnerabilities are:

• Hard-coded credentials - CVE-2018-7800;
• Code injection - CVE-2018-7801; and
SQL injection - CVE-2018-7802

Schneider published an advisory for an input validation vulnerability in their Pro-Face GP-Pro EX product. The vulnerability was reported by Yu Quiang (ADLab of Venustech). Schneider has a new version that mitigates the vulnerability. Schneider has an update that mitigates the vulnerability. There is no indication that Yu has been provided an opportunity to verify the efficacy of the fix.

Schneider published an advisory for three vulnerabilities in their IIoT Monitor product. The vunlerabilities were reported by rgod via the Zero Day Initiative. Schneider has a new product that mitigates the vulnerability. There is no indication that rgod has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Path traversal - CVE-2018-7835;
• Unrestricted upload of file with dangerous type - CVE-2018-7836; and
• Improper restriction of XML esternal reference entity reference - CVE-2018-7837

NOTE: I expect that we will see these three advisories reported by NCCIC-ICS next week if they are allowed to continue to report during the upcoming financial idiocy. NCCIC will operate, but the ICS reporting function might not be allowed to continue until a funding bill is signed by the President.

Yokogawa Advisory


Yokogawa published an advisory for a denial of service vulnerability in their  Vnet/IP Open
Communication Driver. The vulnerability appears to be self-reported. Yokogawa has a patch for many of the products to mitigate the vulnerability, but many of the affected products are no longer supported.

3S Advisories


3S published an advisory for an information exposure vulnerability in their CODESYS Development System V3. The vulnerability was reported by Heinz Füglister of WRH Walter Reist Holding AG. 3S has a new version that mitigates the vulnerability. There is no indication that Füglister has been provided an opportunity to verify the efficacy of the fix.

3S published an advisory for two denial of service vulnerabilities in their CODESYS V3 products. The vulnerabilities were reported by ABB Switzerland Ltd. and Jérôme Vialle of Schneider Electric. 3S has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

3S published an advisory for two denial of service vulnerabilities in their CODESYS Development System V3 Alarm configuration application. These vulnerabilities are being self-reported. 3S has a new version that mitigates the vulnerabilities.

3S published an advisory for two denial of service vulnerabilities in their CODESYS Control V3 TLS socket communication application. These vulnerabilities were reported by an unidentified OEM customer. 3S has new versions that mitigate the vulnerabilities. There is no indication that the customer was provided an opportunity to verify the efficacy of the fix.

3S published an advisory for two denial of service vulnerabilities in the CODESYS Control V3 Trace Manager application. These vulnerabilities were reported by an unidentified OEM customer. 3S has new versions that mitigate the vulnerabilities. There is no indication that the customer was provided an opportunity to verify the efficacy of the fix.

NOTE: As is obvious from the researchers who identified most of the 3S vulnerabilities, 3S software is used by a number of ICS vendors. It will be interesting to see how many of those vendors self-identify these vulnerabilities in their products. Since 3S does not report CVE numbers for any of these vulnerabilities, it will be hard to track.


Saturday, December 8, 2018

Public ICS Disclosures – Week of 12-01-18


This week we have vendor notifications for products from OSIsoft and Schneider Electric and a researcher report of vulnerabilieis in products from Pilz. We also have two exploit publications for products from Rockwell Automation (one may be a 0-day).

OSIsoft Vulnerabilities


In their Release Notes for the latest version of PIProcessbook OSIsoft reports that there are three vulnerabilities being corrected by this release. Those vulnerabilities are related to an included older version of Microsoft’s VBA 6.5. A separate security advisory is being (was?) released to provide further details on these ‘high impact’ vulnerabilities. If it has been released, then my limited (non-customer) access to the OSIsoft site does not provide access to the advisory. The Release Notes do credit the Australian Energy Market Operator (AEMO) with reporting the vulnerabilities.

Schneider Advisory


This advisory describes three vulnerabilities in the Eurotherm by Schneider Electric GUIcon product. The vulnerabilities were reported by mdm and rgod (9SG Security Team). Schneider has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fixes.

The three reported vulnerabilities are:

• Type confusion (2) - CVE-2018-7813 and CVE-2018-7815; and
Stack-based buffer overflow - CVE-2018-7814

Pilz Advisory


Applied Risk has published an advisory for a clear-text storage of sensitive information vulnerability in the Pilz Pilz PNOZmulti Configurator, a safety system tool. This is a coordinated disclosure. Pilz has a new version that mitigates the vulnerability.

Rockwell Exploits


Luca.Chiou published an exploit for an incorrect access control authentication bypass vulnerability in the Rockwell Allen-Bradley PowerMonitor 1000. A CVE has been reserved for this vulnerability (CVE-2018-19616, no further information available) which may indicate that Rockwell has been notified of this vulnerability.

Luca.Chiou published an exploit for a cross-site scripting vulnerability in the Rockwell Allen-Bradley PowerMonitor 1000. No CVE is provided in the exploit documentation. This may indicate that this is a 0-day vulnerability.

Tuesday, May 15, 2018

ICS-CERT Publishes Advantech Advisory and Updates Siemens Advisory


Today the DHS ICS-CERT published a control system security advisory for products from Advantech. They also updated a previously issued advisory for products from Siemens.

Advantech Advisory


This advisory describes eleven vulnerabilities in the Advantech WebAccess products. The vulnerabilities were reported by Mat Powell and rgod, working with ZDI; Steven Seeley of Offensive Security, working with ZDI; and Donato Onofri and Simone Onofri of Business Integration Partners S.p.A. Advantech released a new version that mitigates the vulnerabilities. There is no indication that any of the researchers were provided an opportunity to verify the efficacy of the fix.

The eleven reported vulnerabilities are:

• SQL injection - CVE-2018-7501;
• Information exposure through directory listing - CVE-2018-10590;
• Improper authorization - CVE-2018-7505;
• Path traversal (2) - CVE-2018-7503, and CVE-2018-10589;
• Stack-based buffer overflow - CVE-2018-7499;
• Heap-based buffer overflow - CVE-2018-8845;
• Untrusted pointer dereference - CVE-2018-7497;
• External control of file name or path - CVE-2018-7495;
• Origin validation error - CVE-2018-10591; and
Improper privilege management - CVE-2018-8841

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilitie to disclose sensitive information from the host and/or target, execute arbitrary code, or delete files.

Siemens Update


This update provides additional information for an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th, November 28th, February 27th, 2018 and most recently on May 3rd, 2018. The new information includes links to new versions for version 4.7 of:

• SINAMICS G130;
• SINAMICS G150;
• SINAMICS S120; and
• SINAMICS S150

The Siemens security advisory provided undated version information for the same products, but that was not reported in the ICS-CERT advisory

NOTE: Siemens also reported two other updated advisories (here and here) and a new advisory (here) today when they reported this update. Hopefully ICS-CERT will publish their versions later this week.

Tuesday, April 10, 2018

ICS-CERT Publishes Two Advisories


Today the DHS ICS-CERT published two control system security advisories for products from Omron and ATI Systems.

Omron Advisory


This advisory describes three vulnerabilities in the Omron CX-One. The vulnerabilities were reported by rgod via the Zero Day Initiative. Omron has released new versions that mitigate the vulnerabilities. There is no indication that rgod was provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Heap-based buffer overflow - CVE-2018-8834;
• Stack-based buffer overflow - CVE-2018-7514; and
Type confusion - CVE-2018-7530

ICS-CERT reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow remote code execution (which sounds like ‘remote access’ to me).

ATI Systems Advisory


This advisory describes two vulnerabilities in the ATI Emergency Mass Notification Systems. The vulnerabilities were reported by Balint Seeber of Bastille. ATI will be making a patch available to mitigate the vulnerability.

The two reported vulnerabilities are:

• Improper authentication - CVE-2018-8862; and
• Missing encryption of sensitive data - CVE-2018-8864

ICS-CERT reports that an uncharacterized attacker could remotely exploit the vulnerabilities to trigger false alarms.

NOTE: While Seeber notified ICS-CERT of this vulnerability in a coordinated disclosure, he also apparently notified a number of reporters (not me, sigh-grin) because articles about this vulnerability have appeared today at Wired, Gizmodo, and SecurityWeek; they all have more (but not all) details about the vulnerability and its discovery than you would expect to see in an ICS-CERT advisory. Interestingly, none of these articles mentions this ICS-CERT advisory. Oh, and the Bastille web site has a ‘white paper’ that will supposedly be available on the ‘SirenJack’ vulnerability. I have requested my copy and am waiting….

 
/* Use this with templates/template-twocol.html */