Tuesday, August 2, 2016

ICS-CERT Publishes Two Advisories

This morning the DHS ICS-CERT published two industrial control system security advisories for products from Siemens and Moxa.

Siemens Advisory


This advisory describes a privilege escalation vulnerability in the Siemens SINEMA Server. The vulnerability was reported by rgod via the Zero Day Initiative. Siemens has developed a temporary fix for the vulnerability while a new version is being developed. There is no indication that rgod has been provided an opportunity to verify the efficacy of the temporary fix.

ICS-CERT reports that a relatively low skilled attacker with local access could exploit the vulnerability with a social engineering attack to escalate their privileges.

Moxa Advisory


This advisory describes an SQL injection vulnerability in the Moxa SoftCMS. The vulnerability was reported by Zhou Yu of Acorn Network Security via the Zero Day Initiative. Moxa has produced an update to mitigate the vulnerability, but there is no indication that Yu has been provided the opportunity to verify the efficacy of the fix.


ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to execute arbitrary commands on the target system.

ISCD Updates CFAT FAQ – 08-02-16

Today the DHS Infrastructure Security Compliance Division (ISCD) updated the response to one of the frequently asked questions found in the CFATS Knowledge Center. The updated FAQ response was for FAQ #1627; “Can I have multiple Preparers or Reviewers for the Site Security Plan (SSP)?”

The answer provided when this FAQ was first published in May of 2009 was brief and somewhat stilted: “Yes, but this is a unique feature of the SSP, designed to facilitate the involvement of subject matter experts in the many areas covered by the SSP.”


Today’s response was essentially the same (Yes), but provides a little bit more information about the use of multiple Preparers and Reviewers.

FAST Act Rule Approved by OMB

On Friday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved the DOT’s Pipeline and Hazardous Material Safety Administration’s (PHMSA) direct final rule implementing the requirements of the Fixing America’s Surface Transportation (FAST) Act of 2015 (HR 22 – PL 114-94). OIRA acted fairly quickly on this rulemaking, given that it was submitted by PHMSA just back in June.

This rule implements Congressionally mandated changes to the hazardous material regulations related to railcars used to ship flammable materials. This includes changes to the DOT 111 phase-out schedule, and changes to the DOT 117 railcar standard. Since DOT was given no leeway on these changes by Congress, the rule did not require the normal publish and comment process; going instead directly to the issuing of the final rule.

This rule will almost certainly be published in the Federal Register this week.

New Wassenaar Rule Sent to OMB

On Friday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a final rule for review from the DOC’s Bureau of Industry and Security (BIS) concerning the latest updates to the 2015 Wassenaar Arrangement implementation. This rulemaking does not appear to address the ‘intrusion software’ issues associated with the 2013 Wassenaar Arrangement.

According to the abstract in the 2016 Spring Unified Agenda listing for this rulemaking this rulemaking will address:

“This rule harmonizes the CCL [the Commerce Control List] with the changes made to the WA List at the Plenary by revising Export Control Classification Numbers (ECCNs) controlled for national security reasons in each category of the CCL, as well as making other associated changes to the EAR. The WA agreements include raising of the Adjusted Peak Performance for high performance computers, therefore other parts of the EAR that have APP limitations are also amended by this rule, e.g., de minimis, License Exception APP, reporting requirements. This rule removes the Foreign National Review requirement associated with deemed exports under License Exceptions APP and CIV, because after years of reviewing these requests with no denials ever coming from this information BIS has determined it is not an efficient use of U.S. Government resources. Because this year's WA agreements include the total restructuring of Category 5 part 2, BIS is taking this opportunity to also streamline and update license requirements and policies associated with Category 5 part 2 [Information Security .PDF download] in this rule.”

The information security license and policy update portion of this rule should probably be watched fairly closely when it is published. Again, this is a direct final rule without the normal publish and comment process being required. This is the same process that was used (and later withdrawn) on the intrusion software rulemaking last year.

Saturday, July 30, 2016

PHMSA Looking at Rail Hazmat Insurance

Earlier this week DOT’s Pipeline and Hazardous Material Safety Administration (PHMSA) published a request for comments in the Federal Register (81 FR 48885-48886) to seek public comments on its on-going study addressing liability issues with rail transportation of hazardous materials. This study was required by §7310 of the Fixing America's Surface Transportation (FAST) Act of 2015 (PL 114-94).

Study Requirements


The FAST Act required PHMSA to prepare a report on the current state of “of insurance for railroad carriers transporting hazardous materials” {§7310(a)} as well as addressing what level and type of insurance would be necessary to both “allocate risk and financial responsibility
for claims” {§7310(b)(2)(A)} and “ensure that a railroad carrier transporting hazardous
materials can continue to operate despite the risk of an accident or incident” {§7310(b)(2)(B)}.

Public Input


In support of this study and report requirement PHMSA is soliciting public input on response to nine specific topics. They include:

• The current level, structure, and type of liability insurance coverage (including self-insurance and retentions) available for hazardous materials transportation by rail;
• The appropriateness of the current levels of liability insurance coverage for hazardous materials transportation by rail;
• The drivers of the current coverage limits for hazardous materials transportation liability insurance;
• The impact of foreign requirements related to insurance and liability coverage;
• Data relating to, any previous or current initiatives for sharing the cost of insurance and/or legal liability for hazardous material by rail incidents between shipper and carrier;
• Alternative approaches from other industries that may be applicable to liability and insurance related to hazardous materials transportation by rail;
Alternative programs that impose fees to fund secondary liability coverage and/or create liability caps;

Written comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # PHMSA-2016-0074). Comments should be submitted by September 9th, 2016.

Commentary


Railroads have long maintained that they bear the bulk of the potential liability for accidents involving the transportation of hazardous material by rail. While their safety record for hazmat transportation is pretty impressive the possible consequences of a major hazmat release in a rail accident can be quite large. This was more than adequately demonstrated a few years back during the derailment of a crude oil train in Quebec, Canada where large portions of the center of a town were incinerated.

There have been a number of attempts by the railroad to get the Surface Transportation Board to allow railroads to charge hazmat shippers a liability premium for shipments of hazardous material.

Hazmat shippers, on the other hand, note that the majority of railroad accidents are the result of deficiencies in railroad operations, either errors committed by railroad employees, or failure to adequately maintain railroad equipment (most often the actual rail lines). Shippers do not feel any obligation to assume any measure of liability for accidents caused by railroad errors.

Hopefully, the PHMSA report will include a look at the three different types of liabilities related to hazmat shipments; shipped-product safety liability, railcar maintenance liability and operational liability.

Shippers are responsible for the proper classification, packaging and marking of hazmat shipments. They generally argue that their liability should be limited to the results of errors associated with those responsibilities. Railroads argue that the inherent characteristics of hazardous materials increase the potential consequences and costs associated with railroad accidents. Since they are required by law to accept any properly classified, packaged and marked hazardous material shipment, railroads argue that the liability for the increased cost of the consequences of a hazmat release should be borne, at least in part, by the shipper.

The PHMSA report to Congress needs to clearly identify the issues of joint and severable liability for the consequences for hazardous material releases during railroad accidents. PHMSA is clearly not going to be able to resolve the issue; that is going to be an issue for either Congress or the Courts.


To ensure that PHMSA has all of the information necessary to adequately inform Congress about this hazmat shipping liability issue, the chemical industry will need to ensure that they are fully involved in the comment process. They need to fully document what they what they see as the limits of their liability in a hazmat release and what steps they take to protect themselves against the costs associated with that liability.

Friday, July 29, 2016

ICS-CERT Publishes Four Advisories

Earlier this week the DHS ICS-CERT published four advisories for industrial control system vulnerabilities in products from Rockwell and Siemens.

Rockwell Advisory


This advisory describes two authentication vulnerabilities in the Rockwell Automation FactoryTalk EnergyMetrix application. These vulnerabilities were self-reported. This advisory was originally released on the US CERT Secure Portal on June 21, 2016.

The two vulnerabilities are:

• Insufficient session expiration - CVE-2016-4531; and
• SQL injection - CVE-2016-4522

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to gain unauthenticated access to the affected system.

Siemens SINEMA Advisory


This advisory describes a cross-site scripting vulnerability in the Siemens SINEMA Remote Connect Server (VPN) application. The vulnerability was reported by Antonio Morales Maldonado of INNOTEC SYSTEM, and Alexander Van Maele and Tijl Deneut of Howest. Siemens has produced an update to mitigate the vulnerability but there is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to gain ongoing access to these devices, but a social engineering attack would be required.

Siemens SIMATIC Net PC Advisory


This advisory describes a denial-of-service vulnerability in the Siemens SIMATIC NET PC-Software. The vulnerability was reported by Vladimir Dashchenko and Sergey Temnikov from Kaspersky Labs. Siemens has produced a new version to mitigate the vulnerability but there is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to cause a denial-of-service of the OPC-Unified Architecture (UA) service. Siemens reports that the attacker would require network access to exploit this vulnerability.

Siemens SIMATIC WinCC Advisory


This advisory describes two separate input validation vulnerabilities in the Siemens SIMATIC WinCC, PCS 7, and WinCC Runtime Professional applications. The vulnerabilities were reported by Sergey Temnikov and Vladimir Dashchenko from Kaspersky Lab. Siemens has produced updates to mitigate these vulnerabilities, but there is no indication that the researchers have been provided an opportunity to verify the efficacy of the fixes.


ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to extract arbitrary files or remotely execute arbitrary code. Siemens reports that the attacker would require network access to exploit this vulnerability.

Thursday, July 21, 2016

S 3186 Introduced – Active Shooter Support

Last week Sen. Carper (D,DE) introduced S 3186, the Active Shooter Preparedness Enhancement Act of 2016. This is a companion bill to HR 5643, introduced earlier this month by Rep. Duckworth (D,IL).

Moving Forward


Carper is the ranking member of the Senate Homeland Security and Governmental Affairs Committee, the committee to which this bill was assigned for consideration. Thus, unlike HR 5643, this bill has the potential for being considered in Committee.

There is nothing in the bill that would draw any significant opposition, so there is a good chance that if the bill were considered in committee or on the Senate floor that it would pass with at least some bipartisan support. The problem is, this late into the final month of the 114th Congress few bills will make it to the floor for consideration.

Commentary



For anyone interested in this type of legislation, I would urge them to read my post on HR 5643. In short, any active shooter incident at an industrial facility needs to take into account the types, quantities and locations of any hazardous chemicals stored, produced or used at the site. I have seen little or no discussion of this inherent problem in any of the publications I have seen about active shooter events.
 
/* Use this with templates/template-twocol.html */