Tuesday, September 13, 2016

CSB to Hold Meeting on Freedom Spill Incident Report

Today the Chemical Safety and Hazard Investigation Board (CSB) published a meeting notice in the Federal Register (81 FR 62863) concerning a meeting to be held in Charleston, WV on September 28th, 2016. At this public meeting the staff will present findings and recommendations from the CSB investigation of the January 2014 leak from a storage tank at Freedom Industries that contaminated the local water supply.

With all due respect to the problems that the residents of Charleston and the communities downstream of the spill had to deal with because of municipal water system issues related to this spill, the chemical involved in the spill (Crude Cyclohexanedimenthanol – CHDM) is a relatively innocuous industrial chemical. This spill would not have received the national attention that it did without the resulting problems with the municipal water supply and relatively limited medical effects (but very important to the individuals concerned, I fully understand) resulting from contact with the contaminated drinking water.


While the storage and containment issues are certainly expected to be discussed at this meeting, it will be interesting to see what the report has to say about the detection and treatment issues that arose at the local water treatment facility just downstream from the leak. The spill was the result of criminal (adjudicated not opinion) negligence, but the real problems were the post spill drinking water problems.

Monday, September 12, 2016

ICS-CERT Publishes Two Alerts

Today the DHS ICS-CERT published two alerts for publicly disclosed vulnerabilities in control system products from Schneider and FENIKS Pro. It appears that these are based upon the disclosures from Karn Ganeshen that I described on Saturday. ICS-CERT did not identify the researcher doing the uncoordinated disclosure or the location of the public disclosure for either alert.

Schneider Alert


This alert describes  a cross site request forgery (CSRF) vulnerability with proof-of-concept (PoC) exploit code affecting Schneider Electric’s ION Power Meter products.

Karn’s disclosure on the Full Disclosure site lists additional vulnerabilities that I briefly described Saturday. It appears that ICS-CERT either did not consider them to be actual vulnerabilities (as opposed to ‘features’) or that Schneider has not acknowledged the existence of the vulnerabilities that did not make it into the ICS-CERT alert.

ICS-CERT notes that it had already been working with Schneider on their response to the CSRF vulnerability. They also report Schneider has provided interim security mitigation measures that device owners can use.

FENIKS Pro Alert


This alert describes authentication vulnerabilities with proof-of-concept (PoC) exploit code affecting FENIKS PRO Elnet LT Energy & Power analyzer.

The remaining vulnerabilities described in Karn’s second disclosure on the Full Disclosure site are almost certainly considered features (default passwords) by ICS-CERT. Additionally, the lack of a documented password discovery process is not really (?) a security issue; it is just an interesting way to allow the owner to brick their own devices.


ICS-CERT has provided its initial disclosure to FENIKS and is waiting for confirmation of the vulnerabilities and reports of mitigation measures.

Congressional Hearings – Week of 9-11-16

This week with both the House and Senate in town there will be two cybersecurity related hearings that may be of specific interest to readers of this blog. Those two hearings address information sharing and encryption.

Cybersecurity Markup


On Tuesday the House Homeland Security Committee will be holding a markup hearing that will cover a number of bills. Of specific interest will be HR 5459, Cyber Preparedness Act of 2016. Substitute language for that bill will be considered. That substitute does include the ‘missing’ definition of ‘cybersecurity risk’ taking it from 6 USC 148(a)(1). Unfortunately, that definition still uses the limited definition of ‘information system’ from 44 USC 3502(8). Thus there is still not authority provided for sharing information about control system security issues.

Encryption


The Senate Armed Services Committee will be holding a hearing on Tuesday looking at Encryption and Cyber Matters. There may be a closed session at the end of the public portion of the hearing. The witness list includes:

• Marcell J. Lettre II, Under Secretary Of Defense For Intelligence; and
• Michael S. Rogers, United States Cyber Command

On the Floor

There is one cyber related bill that will be taken up in the House today under their suspension of the rules process. House Resolution 847 addresses the perceived need for a national strategy for the Internet of Things to promote economic growth and consumer empowerment. This resolution was introduced last week, but I have not posted a review because it does not include a single mention of cybersecurity concerns. Since today’s consideration will not include an amendment process the resolution will be published without this critical area being considered. Fortunately, nothing more will come from this action, this only being a symbolic resolution.


There are news reports (for example) that we could see a continuing resolution coming out of the Senate this week. There will be lots of political gaming going on in the lead up to the Senate vote and the subsequent House vote (if it passes in the Senate).

NARA Sends Industrial Security Program NPRM to OMB

On Friday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking (NPRM) from the National Archives and Records Administration (NARA) for revisions of the National Industrial Security Program (NISP, 32 CFR 2004). NISP was established by Executive Order 12829.

According to the Spring 2016 Unified Agenda abstract:

“The Information Security Oversight Office (ISOO), a component of NARA, is proposing this rule pursuant to Executive Order 12829, relating to the National Industrial Security Program (NISP). The proposed changes are primarily administrative, bringing together the original 2006 regulation, the 2010 change, and some updated requirements. However, a small portion of the new provisions deal with requirements from Executive Order 13587 [link added] to implement the insider threat program, and could have a potentially significant effect on agencies implementing that program's requirements.”


NISP is a DOD defense industrial base information security program addressing classified information security and thus will have little direct effect on most manufacturing facilities. It could be instructive, however, for possible future regulations on other classified information sharing programs.

Saturday, September 10, 2016

NIST Guts Cybersecurity Framework Web Site

When I did my weekly check of the NIST Cybersecurity Framework web site today I was very disappointed to see that in making a wholesale change in the site format a large number of valuable information links were removed from the site. While the site history claims that the latest revision dates back to August 31st, I have a copy of the web page from last Saturday that includes the missing links.

The links from last Saturday’s version of the web site still work, though many of those pages today also show up in a revised format. The earlier (and now missing) information links include:

News;
Workshops;
RFIs

To make matters even worse the information provided on the newly formatted landing page is poorly written with a confusing mixture of verb tenses and a frequent lack of noun-verb agreement. I generally try not to complain about government-speak (glass houses and such), but this a truly egregious example that should not remain on the web.


Hopefully this is just a glitch in the format change process and the landing page will be done with all (or at least most) of the links being returned to the rightful place.

Public ICS Vulnerability Disclosures – 9-10-16

There were two interesting public (uncoordinated?) disclosures of control system vulnerabilities this week over at the Full Disclosure mailing list. Both were from Karn Ganeshen.

The first describes multiple vulnerabilities in the Powerlogic/Schneider Electric IONXXXX series Smart Meters. The reported vulnerabilities include:

• No access control
• Vulnerable to Cross-Site Request Forgery; and
• Weak Credential Management

The second describes multiple vulnerabilities in the ELNet Energy & Electrical Power Meter. He reported vulnerabilities include:

• Unauthenticated Web Management access;
• Weak Credential Management; and
• Password Recovery Functionality

Thanks to ‏@infracritical for tweeting about these vulnerabilities (here and here).


Both disclosures were late in the week. We may see (hopefully) ICS-CERT alerts on these next week.

ICS-CERT Publishes Jul-Aug 2016 Monitor

Yesterday the DHS ICS-CERT published the latest version of their ICS-CERT Monitor. Lots of DHS ‘corporate’ type news in this issue, but nothing about any industrial control system incidents.

The opening article, which usually describes a recent incident, provides an overview of what types of services ICS-CERT provides when responding to a control system security incident. I had really been hoping to see some more details about the Navis WebAccess problem that resulted in an alert, an incident response alert and an advisory back in August. This was apparently a very limited in application (very small number of systems) incident, but it was an SQL injection attack on a maritime control system in the wild.

Other corporate news included:

• Presidential Policy Directive on Cyber Incident Coordination;
• US-CERT Portal moving to HSIN, changing name in Fall 2016;
• CSET 8.0;
• ICSJWG Fall 2016 Meeting preview;
• NCCIC team wins 1st Place at FIRST Conference in Seoul; and
• ICS-CERT Training pursuing status as accredited provider of Continuing Education Units;


For those readers that really pay attention to ICS-CERT operations, this issue does provide some interesting information. But, if you were hoping to learn something about industrial control system security issues, this is probably a waste of time.
 
/* Use this with templates/template-twocol.html */