Showing posts with label t4rkd3vilz. Show all posts
Showing posts with label t4rkd3vilz. Show all posts

Saturday, July 7, 2018

Public ICS Disclosures – Week of 06-30-18


This week we have four vendor reports of vulnerabilities {Siemens, ABB, and PEPPERL+FUCHS (2)} and exploits for two previously reported vulnerabilities (Cisco and Delta Industrial)

Siemens Advisory


This advisory describes six vulnerabilities in the Siemens SICLOCK TC devices. These vulnerabilities are being self-reported. The products are at end-of-life and thus Siemens is just providing workarounds for these vulnerabilities (and probably explains why they have not reported this to ICS-CERT).

Siemens reports that the vulnerabilities could be exploited by an attacker with network access to the device to allow an attacker to cause Denial-of-Service conditions, bypass the authentication, and modify the firmware of the device or the administrative client.

ABB Advisory


This advisory describes a file parser vulnerability in the ABB Panel Builder 800 products. The vulnerability was reported by Michael DePlante of Leahy Center for Digital Investigation and Michael Flanders of Trend Micro. ABB is working on an update for this product, but has provided workarounds to mitigate the vulnerability.

ABB notes that a social engineering attack is required to exploit the product. A successful exploit would allow the attacker to insert and run arbitrary code on a computer where the affected product is used.

NOTE: There was a second advisory reported on the ABB web site for their Sentinel HASP/LDK License Manager, but the some sort of problem with the link provided.

PEPPERL+FUCHS Advisories


The first advisory addresses the Spectre and Meltdown vulnerabilities in their ecom mobile devices. This is separate from their previously reported Spectre/Meltdown advisory for their HMI products. That other advisory is listed in the most recent ICS-CERT alert update.

The advisory notes that firmware updates will be released for the affected products.

The second advisory describes a remote code execution vulnerability in the PEPPERL+FUCHS HMI products. The vulnerability was reported by Eyal Karni, Yaron Zinar, Roman Blachman @ Preempt, Research Labs. This vulnerability is in a third-party product, Microsoft's Credential Security Support Provider. PEPPERL+FUCHS has provided updates for some of the affected products and recommended using the Microsoft Windows update for the remaining Windows 7 or Windows 10 based systems.

Cisco Exploit


Yassine Aboukir published exploit code on ExploitDB.com for a path traversal vulnerability in the Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software. This vulnerability was most recently reported by ICS-CERT as a third party vulnerability in the Rockwell Allen-Bradley Stratix 5950.

Delta Industrial Exploit


t4rkd3vilz published exploit code on ExploitDB.com for a stack-based buffer overflow vulnerability in the Delta Industrial Automation COMMGR. This vulnerability was reported by ICS-CERT on June 21st, 2018.

Saturday, June 2, 2018

Public ICS Disclosure – Week of 5-26-18


This week we have a vendor update of a previously released advisory, a coordinated disclosure of multiple vulnerabilities in a medical device, and an exploit for a previously disclosed vulnerability. In passing, there was a new advisory from Schneider (U.Motion Builder) that was released on Thursday that may yet be reported by ICS-CERT.

Spectre Update


This week Siemens updated their advisory on the Spectre vulnerabilities in Industrial Products to add mitigation measures for:

• RUGGEDCOM APE;
• RUGGEDCOM VPE1400;
• SINEMA Remote Connect;
• SIMATIC S7-1518-4 PN/DP ODK;
• SIMATIC S7-1518F-4 PN/DP ODK; and
SIMATIC HMI Panels

ICS-CERT does not update their multi-vendor advisories to reflect vendor updates as the links provided generally point to the new information. From an ICS-CERT administrative point of view, this makes a certain amount of sense.

Siemens also updated their general Spectre advisory to reflect information on the next generation Spectre. It will be sometime yet before the Spectre NG will be reflected in the product specific advisories as we are still waiting on the chip-level mitigations to be produced.

Medical Device Disclosure


This week Talos published three reports (here, here and here) of vulnerabilities in the  Natus Xltek NeuroWorks software; these are coordinated disclosures. The three reported vulnerabilities are:

• Invalid key entry denial of service - CVE-2017-2860;
• Deserialization denial of service - CVE-2017-2852; and
• Traversal denial of service - CVE-2017-2858

NOTE: These have not been reported on the FDA Medical Device Safety Communications page.

Siemens Exploit


This week we have another exploit report from t4rkd3vilz on Exploit-DB.com. This one is for a Siemens SIMATIC S7-300 that was originally reported in 2015. While ICS-CERT will note if a publicly available exploit exists at the time of publication of their advisories, they do not generally provide updates that report new exploits.

Saturday, May 19, 2018

ICS Public Disclosure – Week of 5-12-18


This week we have two vendor disclosures (ABB), two exploits published for previously disclosed vulnerabilities (Rockwell and Schneider) and two reports of vulnerabilities in a third-party service (Calamp) used by various automotive automation systems. There is also a third vendor (Philips) disclosure that is probably being reported by ICS-CERT next week that I am just mentioning in passing.

ABB Disclosures


ABB reports three vulnerabilities in the Welcome IP-Gateway product. The vulnerabilities were reported by Florian Grunow of ERNW GmbH. ABB has a new version that mitigates the vulnerabilities. There is no indication that Grunow has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Remote code injections – no CVE reported; and
Missing session management (2) - CVE-2017-7931, and CVE-2017-7906

ABB reports an exploitable RSS function in their Elipse Application. This vulnerability is self-reported. ABB has new versions that mitigate the vulnerability by removing the RSS service.

Rockwell Exploit


t4rkd3vilz published an exploit on ExploitDB.com for the Rockwell CompactLogix SCADA system. The vulnerability that this exploit uses was reported by ICS-CERT in March of 2016.

Schneider Exploit


t4rkd3vilz published an exploit on ExploitDB.com for the Schneider Electric IONXXXX Series Power Meter. The vulnerability that this exploit uses was reported by ICS-CERT in November of 2016.

Calamp Vulnearbilities


Vangelis Stykas has two posts (here and here) and a blog post on two vulnerabilities in backend services provided by Calamp that are used by automotive vendors such as Viper SmartStart and Directed SmartStart. These were coordinated disclosures, patches have been made to the system and Stykas has verified the efficacy of the fix.

 
/* Use this with templates/template-twocol.html */