Friday, October 18, 2013

ICS-CERT Publishes DNP3 Summary Advisory

Today the DHS ICS-CERT took the unusual step of issuing an advisory very briefly summarizing the information that had already been summarized in 9 earlier DNP3 system advisories based upon the work of Adam Crain and Chris Sistrunk. I have addressed the individual advisories here in this blog.

What has undoubtedly driven this unusual publication is the recent discussion about the very real potential consequences of the vulnerabilities that have been taking place over the last couple of days in various cybersecurity venues on the internet. A good example can be found at DigitalBond.com where Dale Peterson describes how easily these vulnerabilities could be used to shut down much of the electrical distribution system in the US.

ICS-CERT does not acknowledge these discussions as the reason for the issuance of this advisory. In fact, they completely ignore the scope of the problem that is being discussed quite widely in the control system security community. If one were to read just this advisory, it would seem that this is just the common, garden-variety denial of service advisory that we have been seeing for the last couple of years.

Part of this is due to the lack of grandstanding by Adam and Chris. Because of their professional backgrounds, I am sure that they are fully aware of how easily these vulnerabilities could be exploited to bring down electrical (or gas, or water, or whatever SCADA controlled distribution system is using DNP3 based devices) transmission systems. Instead of yelling from the mountain top, they have calmly gone through the coordinated disclosure process and worked with ICS-CERT and the vendors to get patches developed for these systems.

BTW: Have I mentioned lately that there are still 15 Crain-Sistrunk vulnerabilities that have yet to see the light of day? They are still wending their way through the disclosure process, and some of them may do for Modbus what has already been done for DNP3.

So it has taken public discussions by other members of the control system community to get ICS-CERT to react to the real scale of the potential problem. Unfortunately, while ICS-CERT has stepped up to the plate, they waited until the pitched ball was in the catcher’s mitt to feebly wuff the bat vaguely over the plate. This is real surprising from an organization that annually exaggerates the number of attacks on control systems (equating IT attacks on corporate networks as attacks on control systems owned by those companies).

It would have been nice if this advisory had even mentioned that the lax physical security at remote transmission sites would make it easy for an attacker to gain access to the whole SCADA network or shut down key nodes of that network. Then maybe readers of the advisory would begin to see the scale of this vulnerability and why it really did justify a summary advisory that ICS-CERT pretended to issue today.


Looking at the last two advisories to come out of ICS-CERT it is clear that, while ICS-CERT understands the microcosmic aspects of control system security, they either fail to grasp or just plain ignore the macrocosmic scope of control system security problems. Somebody needs to readjust their focus and it won’t be a former DOD lawyer and political crony of the President.

Plug-and-Play ICS

There is an interesting adverticle (my blog, I can makeup words) over on ChemicalProcessing.com that advertises a wireless control system device with what is described as ‘plug-and-play technology’. This is hardly a new concept as the Windows® environment has been using this type of device linkage to make home (and business) computers much easier to expand. It also lowered the computer skill level necessary to operate these more complex computer systems.

Now I don’t know anything about the device described in this article so I can’t make any statements about this particular implementation of the ‘plug-and-play’ concept in industrial control systems. It does raise an interesting question, however; do we really want to lower the skill level required to implement an expansion of an industrial control system? Won’t this just aggravate the existing control system security problem?

We already have a situation where there are not enough control system engineers available to ensure that there is someone on-site at critical infrastructure facilities to make reasonable decisions about security issues with control systems, to test and validate patches, or to monitor systems for potential attacks. With plug-and-play expansions of the control system technology we will be allowing the expansion of already complex systems without the necessary technical oversight to ensure that such expansions don’t make existing security and safety problems more common.

Emerson is certainly a respected control system manufacturer and has only had a few security issues identified by ICS-CERT (here, here, here and here) so I would like to assume that they have created a module here that is free from any readily identifiable security concerns. But if they do discover a subsequent problem, will a plug-and-play facility have the expertise to identify the need to patch the device firmware, be able to test the patch to ensure that it does not create more problems than it solves, or even be able to implement the patching process.

And, of course, if plug-and-play becomes the next ICS have-to-have sales gimmick (and management will have to love this for reducing engineering overhead) then we will have to contend with the problems associated with other vendors that do not have Emerson’s level of security design and implementation expertise.


I know that I am a voice crying in the wilderness here, but until we get the industrial control system security situation under control, we really don’t need to be making it easier to deploy or expand such systems without adequate in-house control system expertise.

Post Start Up Congressional Recess

As I reported earlier, both the House and Senate are taking a break now that they have gotten the government temporarily funded. They both passed S Con Res 24 on Wednesday and a copy of that resolution is now available on the GPO web site.  I was correct in reporting that the House will return to session next week, but the Senate is not scheduled to return until Monday of the following week. Both Houses missed scheduled time in their districts (recesses) before and during the federal funding fiasco.

Thursday, October 17, 2013

House Passes HR 2775 to End Shutdown

This evening the House accepted the Senate amendment to HR 2775, the newly renamed Continuing Appropriations Act, 2014, by a bipartisan vote of 285-144 (all 144 noes were Republicans). Shortly thereafter, the House adopted S Con Res 24 providing for a one week break for the two bodies. The House will be back in session on October 22nd.

ICS-CERT Publishes Cisco Advisory

The earlier problem has now been corrected and the ICS-CERT link now takes one to the current multiple vulnerability advisory affecting either the Firewall Service Module (FWSM) Software or the Adaptive Security Appliance (ASA) software for Cisco switches and routers. These vulnerabilities are self-reported vulnerabilities identified during customer support operations.

The FWSM vulnerabilities include:

• Cisco FWSM Command Authorization Vulnerability (CVSS Base Score – 6.8); and
• SQL*Net Inspection Engine Denial of Service Vulnerability (CVSS Base Score – 7.1)

The ASA vulnerabilities include:

• IPsec VPN Crafted ICMP Packet Denial of Service Vulnerability (CVSS Base Score – 7.1);
• SQL*Net Inspection Engine Denial of Service Vulnerability (CVSS Base Score – 7.1);
• Digital Certificate Authentication Bypass Vulnerability (CVSS Base Score – 10.0);
• Remote Access VPN Authentication Bypass Vulnerability (CVSS Base Score – 5.0);
• Digital Certificate HTTP Authentication Bypass Vulnerability (CVSS Base Score – 10.0);
• HTTP Deep Packet Inspection Denial of Service Vulnerability (CVSS Base Score – 7.8);
• DNS Inspection Denial of Service Vulnerability (CVSS Base Score – 7.1);
• AnyConnect SSL VPN Memory Exhaustion Denial of Service Vulnerability (CVSS Base Score – 7.1); and
• Clientless SSL VPN Denial of Service Vulnerability (CVSS Base Score – 7.8)

It is odd that ICS-CERT combines the vulnerabilities for these two separate software packages into the same advisory, especially since Cisco provides two separate advisories (FWSM and ASA). Also, neither ICS-CERT nor Cisco provide some of the details that we have come to expect from ICS-CERT advisories; CVE links for example.  The CVSS base scores for the vulnerabilities are missing from the ICS-CERT document. This makes it more difficult to assess the relative severity of these vulnerabilities.

The Cisco advisories provide much more detail than this unusually brief ICS-CERT advisory. ICS-CERT simply advises that the exploitation of the various vulnerabilities could result in either a denial of service or authentication bypass. Missing is the usual assessment of the skill level necessary to exploit the vulnerabilities or even a statement of whether or not the vulnerabilities are remotely accessible. Furthermore, ICS-CERT fails to mention that Cisco has developed work-arounds for a number of the vulnerabilities

ICS-CERT does note that Cisco has provided software updates that address the vulnerabilities. Since these are self-reported vulnerabilities there is indication of whether or not some outside agency has validated the efficacy of the updates.


BTW: It is interesting to note that ICS-CERT does report the vulnerabilities in these security devices (and are not actually control systems) but fails to report the more numerous Check Point vulnerabilities that I discussed in an earlier blog. Just another hole in the coverage of control system security by ICS-CERT.

Wednesday, October 16, 2013

Senate Passes Bill to End Fiscal Fiasco and Extend Debt Limit

This afternoon the Senate passed a revised version of HR 2775 that would act as a continuing resolution to put a temporary stop to the federal funding fiasco and would also extend the current debt limit. It would not put an end to either problem; it is just a short term band aid to get the government operating while Congress continues to battle over the final spending bill for FY 2014. The bill passed in the Senate by a necessary bipartisan vote of 81 to 18.

Bill Provisions

The new language would generally extend the FY 2013 spending limits (with sequester) until January 15, 2014 and has a an effective date of October 1st. This provision {§118} provides continuity for  programs like CFATS that operate on an authorization that is specifically tied to a spending bill.

The CFATS authorization extension is specifically addressed §131 using the standard language for spending bills. In this case the CFATS authority would be extended until January 15th, 2014.

A lot of other things have been added to this bill that were missing from the various versions and counter-versions of HJ Res 59. This isn’t unusual; there is still horse trading going on the get people to sign-off on the revised language.

House Response

News reports earlier in the day indicated that Rep. Boehner had told the Senate leadership that he would allow a straight-up vote on this measure if it passed in the Senate. There has not yet been a notice of a meeting of the House Rules Committee to formulate the rule (obviously a closed rule with limited debate and no amendments) for the consideration of this bill and there is not yet any mention of this specific bill on the Majority Leader’s web site. The bill was added, however, to the Clerk of the House’s Bills to be Considered page.

BTW: Selection of HR 2775 as the vehicle for the Senate bill is just a tad bit sarcastic. The bill was originally the No Subsidies Without Verification Act that was passed in the House last month. Thus the bill was one of a large numbers of bills that the House Republicans used to try to gut the Obamacare legislation.

Moving Forward


Stripping it of its insurance provisions and effectively not including any of the demands of the conservative faction of the Republican Party is a real slap in the face to those who engineered the government shutdown. No we will just have to wait and see how it is received in the House; too  close to call at this point.

ICS-CERT Tries to Publish Cisco Advisory

The ICS-CERT web site says that they have posted “ICSA-13-289-01 : Cisco ASA and FWSM Security Advisories This Advisory provides information reported by Cisco about vulnerabilities in Cisco ASA and FWSM software.” This has a “10/16/2013 - 10:48” time stamp. Unfortunately the link takes one to an empty page. I wonder if this was supposed to have been posted to the Secure Portal. Oh well, watch the site for further developments. It should be interesting. 
 
/* Use this with templates/template-twocol.html */