Tuesday, May 9, 2017

ICS-CERT Publishes 4 Advisories and Updates 2

Today the DHS ICS-CERT published four control system security advisories for three products from Siemens and one from Rockwell. The Rockwell advisory was originally posted to the NCCIC Portal on April 4, 2017. They also updated two previously issued advisories for products from Siemens.

Rockwell Advisory


This advisory describes multiple vulnerabilities in the Rockwell Automation Stratix 5900 services router. The vulnerabilities were reported by Cisco in Cisco software products used in the Rockwell Stratix 5900; some of these vulnerabilities have been previously reported. Rockwell has produced a new firmware version to mitigate these vulnerabilities.

The reported vulnerabilities include (take a deep breath):

• Improper input validation - CVE-2016-6380, CVE-2016-1409, CVE-2015-0642, CVE-2015-0643, CVE-2014-3361, CVE-2014-2113, and CVE-2014-2106;
• Resource management errors - CVE-2016-6393, CVE-2016-6384, CVE-2016-6381, CVE-2016-6382, CVE-2016-1350, CVE-2016-1344, CVE-2015-0646, CVE-2014-3359, CVE-2014-3355, CVE-2014-3356, CVE-2014-3354, CVE-2014-3299, CVE-2014-2108, and CVE-2014-2112;
• Information exposure - CVE-2016-6415;
• Multiple network time protocol daemon vulnerabilities (October 2015) - CVE-2015-7691, CVE-2015-7692, CVE-2015-7701, CVE-2015-7702, CVE-2015-7703, CVE-2015-7704, CVE-2015-7705, CVE-2015-7848, CVE-2015-7849, CVE-2015-7850, CVE-2015-7851, CVE-2015-7852, CVE-2015-7853, CVE-2015-7854, CVE-2015-7855, and CVE-2015-7871;
• Improper authentication - CVE-2015-1798, and CVE-2015-1799;
• Multiple OpenSSL vulnerabilities (March 2015) - CVE-2015-0207, CVE-2015-0209, CVE-2015-0285, CVE-2015-0287, CVE-2015-0288, CVE-2015-0289, CVE-2015-0290, CVE-2015-0291, CVE-2015-0292, CVE-2015-0293, and CVE-2015-1787;
• Cryptographic issues - CVE-2014-3566;
• Numeric issues - CVE-2014-3360;
• Multiple OpenSSL vulnerabilities - CVE-2010-5298, CVE-2014-0076, CVE-2014-0195, CVE-2014-0198, CVE-2014-0221, CVE-2014-0224, and CVE-2014-3470; and
• Network Address Translation Vulnerabilities - CVE-2014-2109 and CVE-2014-2111;

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to perform man-in-the-middle attacks, create denial of service conditions, or remotely execute arbitrary code. With some of these previously identified vulnerabilities up to 7 years old, I would bet that there are some publicly available exploits, but that was not mentioned in this advisory.

(SARCASM WARNING) I am glad that no other vendor uses any of these Cisco products.

Siemens SIMATIC Advisory


This advisory describes a denial of service vulnerability in the Siemens SIMATIC WinCC and SIMATIC WinCC Runtime Professional products. The vulnerability was reported by Sergey Temnikov and Vladimir Dashchenko of the Kaspersky Lab Critical Infrastructure Defense Team. Siemens has developed updates for the affected products to mitigate the vulnerability. There is no indication that the researchers have been afforded an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to cause the affected service to crash, resulting in a denial-of-service condition. The Siemens Security Advisory reports that the attacker must be member of the group administrators and have network access to an affected system.

Siemens PROFINET Advisory 1


This advisory describes two input validation vulnerabilities in Siemens devices using the PROFINET Discovery and Configuration Protocol (DCP). The vulnerability was reported by Duan JinTong, Ma ShaoShuai, and Cheng Lei from NSFOCUS Security Team. Siemens has produced firmware updates to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker with network access to the local Ethernet segment (Layer 2) could exploit the vulnerabilities to cause the targeted device to enter a denial-of-service condition, which may require human interaction to recover the system.

The Siemens Security Advisory reports that CNCERT/CC coordinated the disclosure of this vulnerability.

Siemens PROFINET Advisory 2


This advisory describes an improper input validation vulnerability in Siemens devices using using the PROFINET Discovery and Configuration Protocol (DCP). The vulnerability was reported by Duan JinTong, Ma ShaoShuai, and Cheng Lei from NSFOCUS Security Team. Siemens has produced updates that mitigate the vulnerability. There is no indication that the researchers have been afforded an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker with access to an adjacent network could exploit the vulnerability to cause a denial-of-service condition requiring a manual restart by exploiting this vulnerability.

The Siemens Security Advisory reports that:

“On a single host the affected component is shared among the affected products. Installing one fixed version will mitigate the vulnerability for all Siemens applications installed on the single host.”

Siemens Industrial Products Update


This update provides new information on an advisory that was originally issued on November 8, 2016 and then updated November 22nd, 2016; December 23rd, 2016; February 14th, 2017; and March 2nd, 2017. The new information includes:

• Updated version information for SIMATIC WinCC V7.4, SIMATIC WinCC Runtime Professional, SIMATIC WinCC (TIA Portal) Professional, and SIMATIC STEP 7 (TIA Portal) V13;
• Adds mitigation information for the above products; and
• Removes the above products from the ‘temporary fix’ list.

The Siemens Security Advisory was also updated.

Siemens S7-300/400 PLC Update


This update provides new information on an advisory that was originally issued on December 13, 2016. The new information includes:

• Adding Profibus as an access route for the inadequate encryption strength vulnerability; and
• Adds links for firmware updates for S7-300 CPUs;


The Siemens Security Advisory was also updated.

ISCD Resumes Publishing Monthly Updates

Yesterday the DHS Infrastructure Security Compliance Division (ISCD) resumed the publication of their monthly updates on the implementation of the Chemical Facility Anti-Terrorism Standards (CFATS) program. The previous series of updates stopped in October of last year when ISCD started the implementation of the new Chemical Security Assessment Tool (CSAT) 2.0.

New Format


As expected with the change in both the CSAT tools and the new risk assessment methodology, ISCD has changed both the formatting and information provided in the new Monthly Update. The table below shows the data being presented:


Total Facilities
Current Facilities
Covered Facilities

2,570
Authorization Inspections
2,914
2,386
Approved Security Plans
2,719
2,281
Compliance Inspections
2,053
1,921
Table 1: Reported Data

Commentary


A couple of notes here. First I changed the wording of the headings for the two data columns, the information is the same, but I think my wording is clearer. The Updates does note that some previously tiered facilities have been dropped from the CFATS program since they had their site security plan (SSP) authorized, approved, and/or inspected for a variety of reasons. An overview of the possible reasons is provided, but no details about the numbers for each category.

I added the ‘Covered Facilities’ line to the table above; it is not in the Update table. The number for the current facilities is provided in the text of the update. What would have been interesting to see here is listing of the total number of facilities that had, at one time or another, been a covered facility. The last number we had before CSAT 2.0 was 2,948, but the first Fact Sheet (April 2013) showed 4,382 facilities and the number has certainly been higher than that.

ISCD does report in the body of the new Update that they will probably see a continuing increase in the number of covered facilities, at least in the near term. This is due to their continuing to send out Top Screen notification letters to facilities that are currently not covered, as I explained late last month.

Given the 2015 GAO report on the CFATS program and its reporting of problems with compliance inspections it still disappoints me to see ISCD publish numbers of compliance inspections conducted without reporting on the pass/fail numbers on those inspections. I really do expect that ISCD can now report much better than the nearly 50% failure rate that GAO reported in 2015.


I am glad to see that ISCD has resumed publishing this update. The congressional pressure that was the impetus for providing this data back in 2013 is no longer present. That makes this that much more impressive that ISCD is sharing this information.

Friday, May 5, 2017

HR 2223 Introduced – Rail Spill Fund

Last month Rep. DeFazio (D,OR) introduced HR 2223, the Community Protection and Preparedness Act of 2017. The bill would establish a Rail Account within the Oil Spill Liability Trust Fund (OSLTF). The bill is similar to HR 5786 that was introduced in the 114th Congress, but significant changes were made to increase the chances of this bill being considered.

Changes


Section 3 of the earlier bill that added new requirements for rail track inspections has been removed from this version. In its place, DeFazio added §5 that would require DOT to report to Congress on rail track inspections. That report would include an assessment of current {§5(1)}:

• Railroad track inspections, including the frequency of inspections;
• Training provided to railroad track inspectors and related railroad personnel;
• Railroad compliance with Federal track safety regulations; and
• Federal oversight of railroads with respect to track safety

Another change is the addition of a new §3 that would require the DOT’s Pipeline and Hazardous Material Safety Administration (PHMSA) to complete their rulemaking on “Oil Spill Response Plans and Information Sharing for High-Hazard Flammable Trains”.

Moving Forward


DeFazio is the Ranking Member of the House Transportation and Infrastructure Committee and thus should be in position to move this bill forward to consideration by that Committee. The earlier bill drew too much opposition from railroads due to the costly track inspection requirements for the Committee to approve the bill. This was almost certainly the reason that the bill was not considered in the last session.

The removal of those track inspection requirements should remove the opposition of the railroads. In fact, there could be a quiet endorsement of this bill by the railroads as it would increase the costs to shippers of flammable liquids thus potentially reducing some of those shipments. This would help reduce railroad liability for accidents involving these hazardous materials. The presence of the Rail Fund in the OSLTF to help fund response training would also reduce calls for additional railroad funding of such training.

The main thing holding up consideration of this bill remains the opposition of the flammable liquid shippers to having to pay for the Rail Fund. That opposition is not as organized as the railroads were in their earlier opposition. That combined with the general Republican opposition to federal regulations may be enough to derail this bill. If the bill is considered by the Committee, the chances of it passing in the House would be much higher than I currently expect it to be.

Commentary


From a hazmat transportation safety perspective, the main problem with the OSLTF remains the limitation of consideration of spill response as a water contamination issue. Continuing to ignore the fire and explosion hazard related to these spills means that this fund will have little or no effect on the planning for, and spending on, responding to the biggest hazard for flammable liquid accidents in or near urban areas.

From a legal point of view, the easiest way to do this would be to either create a new hazardous chemical spill liability fund that would be completely separate from the current OSLTF. That way the new fund could be more appropriately targeted in the scope of emergency response planning and support. From a political point of view that is not going to happen absent a really huge hazmat transportation incident.

This bill tries to take the more politically expedient approach of adding a more generalized hazmat response under authority of 49 USC 5116 for a subset of the OSLTF established as the Rail Fund. The problem with this is that the folks currently administering the OSLTF are experienced and focused on the issues of protecting water from oil spills, not responding to fires and explosions. This involves two completely different sets of planning and response activities.


Having said that, I think that this is probably the most expedient method of dealing with an expensive and complex issue. It is not going to be really effective, but it will be more effective than what we currently have. We have to remember that politics is, at its heart, the art of the possible.

Thursday, May 4, 2017

ICS-CERT Publishes 4 Advisories

Today the DHS ICS-CERT published 4 control system security advisories for products from Rockwell, Advantech, Dahua Technology and Hikvision. The Rockwell advisory was previously published on the NCCIC Portal on April 4, 2017.

ICS-CERT also published the latest version of their ICS-CERT Monitor. Not worth reviewing, but it is out there.

Rockwell Advisory


This advisory describes a resource exhaustion vulnerability in Rockwell ControlLogic and CompactLogic controllers. This vulnerability was apparently self-reported. Rockwell has provided updated versions to mitigate the vulnerability.

ICS-CERT reports that an uncharacterized attacker could remotely exploit the vulnerability to cause the device that the attacker is accessing to become unavailable.

Advantech Advisory


This advisory describes an absolute path traversal vulnerability in the Advantech WebAccess. The vulnerability was reported by Zhou Yu via ZDI. Advantech has produced a new version to mitigate the vulnerability. ICS-CERT reports that Yu has verified the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to traverse the file system and gain access to files or directories, which could result in the device becoming unavailable.

Dahua Technology Advisory


This advisory describes two password vulnerabilities in the Dahua Digital Video Recorders and IP Cameras. Bashis disclosed these vulnerabilities without coordination with ICS-CERT (see Brian Krebs and ThreatPost articles for more information).

The two reported vulnerabilities are:

• Use of password hash instead of password for authentication - CVE-2017-7927; and
• Password in configuration file - CVE-2017-7925

ICS-CERT reports that a relatively low skilled attacker could use publicly available exploits to remotely exploit the vulnerabilities to allow the attacker to obtain user credentials, including password hashes, and use these credentials to bypass authentication.

Hikvision Advisory


This advisory describes two password vulnerabilities in the Hikvision cameras. The vulnerability was reported by IPcamtalk user “Montecrypto”. Hikvision has published a new version to mitigate one of the two vulnerabilities. There is no indication that Montecrypto was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper authentication - CVE-2017-7921; and
• Password in configuration file - CVE-2017-7923

In Passing



Please remember that when ICS-CERT publishes their 2017 stats that they will almost certainly include the Dahua and Hikvision vulnerabilities in their count of control system advisories for the year.

House Passes HR 244 – FY 2017 Spending

After a nearly party-line vote on the resolution adopting the rule for consideration of  HR 244, the House passed the Consolidated Appropriations Act, 2017 by a bipartisan vote of 309 to 118 (with 103 Republicans voting Nay). The Democratic opposition to the rule vote was an attempt to open consideration of HR 244 to the amendment process on the floor of the House.

Cybersecurity


The rule for consideration of HR 244 also added a new division to HR 244. The new Division N is the Intelligence Authorization Act for Fiscal Year 2017. As I have mentioned on a couple of occasions the House has passed various versions of this bill in both the 114th and 115th Congress, but the Senate has not taken up any version of this bill.

The version now included in HR 244 does not include any specific cybersecurity provisions beyond a reporting requirement; Sec. 614. Report on cybersecurity threats to seaports of the United States and maritime shipping. I have previously discussed this provision on a couple of occasions, the most recently here.

Moving Forward



The Senate is scheduled to debate HR 244 today and vote on cloture on Friday morning. The current plan for consideration in the Senate does not include a floor amendment process.

Tuesday, May 2, 2017

ICS-CERT Publishes 3 Advisories

Today the DHS ICS-CERT published three control system security advisories for products from Advantech, CyberVision and Schneider.

Advantech Advisory


This advisory describes a client-side authentication vulnerability in the Advantech B+B SmartWorx MESR901. The vulnerability was originally reported by Maxim Rupp. ICS-CERT reports that Advantech is unable to provide mitigations for this product and is working to replace the product with a new model.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to bypass authentication and access restricted pages.

CyberVision Advisory


This advisory describes a code injection vulnerability in the CyberVision Kaa IoT Platform. The vulnerability was reported Jacob Baines from Tenable Network Security. ICS-CERT reports that CyberVision has been unresponsive to multiple contact requests and has produced no mitigations for this vulnerability.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to allow for the creation of files with custom content, movement of files, and execution of arbitrary OS commands.

Schneider Advisory


This advisory describes an Improper XML Parser Configuration in the Schneider Wonderware Historian Client. The vulnerability was reported by Andrey Zhukov from USSC. Schneider has an update that mitigates the vulnerability. ICS-CERT reports that Zhukov has verified the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker (no discussion of access requirements) to cause denial of service of trend display or to disclose arbitrary files from the local file system to a malicious web site. The Wonderware Security Bulletin reports that a social engineering attack would be required to get an authorized user to load a malicious XML settings file.

Commentary


At this late date it is very disconcerting to see two ICS-CERT advisories reporting that vendors are not fixing reported vulnerabilities. I am disappointed in not seeing ICS-CERT report why Advantech is choosing to not fix their SmartWorx MESR901. I suspect that this is an end-of-life issue, but the product is still being actively advertised on the Advantech web site.


More disturbing is the failure of CyberVision to even respond to ICS-CERT about the reported vulnerability. The Kaa project is advertised as an open-source IOT platform. We have enough problems with IOT security issues without having people acknowledge and try to fix specifically identified security issues with their product.

ISCD Updates Another FAQ

Today the DHS Infrastructure Security Compliance Division (ISCD) updated the response to one of the frequently asked questions (FAQ) on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center. The FAQ in question was:


This is a complete re-write to the FAQ response, but very little information was actually changed. The two most important changes were the addition of links to three different sections of the CFATS regulations and a change to the name of the person to whom letters requesting determinations should be sent. The original FAQ response showed Amy Graydon as the acting Director of ISCD, that has long since changed to David Wulf as the Director.


This points out a common problem that is seen frequently in the FAQ responses. The addresses given in the various FAQs should only include position titles, not the name of the person currently holding that position. That way the FAQ’s do not need to be updated when personnel change.
 
/* Use this with templates/template-twocol.html */