Friday, January 12, 2018

Bills Introduced – 01-11-18

Yesterday, with both the House and Senate in session, there were 43 bills introduced. Of these, two may be of specific interest to readers of this blog:

HR 4766 To amend title 49, United States Code, to prohibit further extension of requirement to implement positive train control beyond December 31, 2018, and for other purposes. Rep. DeFazio, Peter A. [D-OR-4]

HR 4773 To require the Administrator for General Services to obtain an antivirus product to make available to Federal agencies in order to provide the product to individuals whose personally identifiable information may have been compromised. Rep. Cartwright, Matt [D-PA-17]

It looks like HR 4766 would attempt to remove the current discretionary authority of the Department of Transportation to extend the PTC deadline.


I’m not sure that HR 4773 will get any further mention here, but I have to watch for the language of this bill to see if it really is as non-sensical as the current description would lead us to believe.

ICS-CERT Publishes Alert, 3 Advisories and 1 Update

Yesterday ICS-CERT published an alert for the Intel Meltdown and Spectre vulnerabilities. They published three control system security advisories for products from Phoenix Contact, Moxa, and WECON. They also updated a previously published advisory for products from Advantech.

Meltdown Alert


This alert describes the CPU hardware vulnerable to side-channel attacks vulnerabilities known as  Meltdown and Spectre. The alert provides links to the following vendor notifications about these vulnerabilities:

ABB;
Rockwell Automation (account required for login); and
Siemens

The alert also provides a generic link to the ICS-CERT recommended practices page. It is disappointing that, in light of the problems seen with the Windows Update for Meltdown seen on some systems (here and here for example), ICS-CERT has not specifically mentioned the need for checking any updates on a test platform before uploading to a live control system.

Phoenix Contact Advisory


This advisory describes two vulnerabilities in the Phoenix Contact FL Switch product line. The vulnerabilities were reported by Ilya Karpov and Evgeniy Druzhinin of Positive Technologies. Newer versions of the firmware mitigate these vulnerabilities. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper authorization - CVE-2017-16743; and
• Information exposure - CVE-2017-16741

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to gain administrative privileges and expose information to unauthenticated users.

Moxa Advisory


This advisory describes an unquoted search path vulnerability in the Moxa MXview network management software. The vulnerability was reported by Karn Ganeshen. Moxa has produced a firmware update that mitigates the vulnerability. There is no indication that Ganeshen was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker with locally authorized access could exploit the vulnerability to escalate privileges by inserting arbitrary code into the unquoted service path.

WECON Advisory


This advisory describes two vulnerabilities in the WECON LeviStudio HMI Editor. The vulnerabilities were reported by Sergey Zelenyuk of RVRT, HanM0u of CloverSec Labs, and Brian Gorenc via the Zero Day Initiative. The latest version of the software mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2017-16739; and
• Heap-based buffer overflow - CVE-2017-16737

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to effect arbitrary code execution.

Advantech Update


This update updates information on an advisory that was originally published on January 4th, 2018. This update adds two vulnerabilities to those previously reported:

• Unrestricted upload of file with dangerous type - CVE-2017-16736 and

• Use after free - CVE-2017-16732

Thursday, January 11, 2018

HR 4650 Introduced – Active Shooter Guidance

Last month Rep. Aguilar (D,CA) introduced HR 4650, the Providing Rational Options Toward the Elimination of Catastrophic Terrorism (PROTECT) Act of 2017. The bill would require DHS to provide guidance on planning for and responding to active shooter incidents. It would also add active shooter incidents to the list of priorities for State and Urban Area Initiative grant programs under 6 USC 608.

The bill would add a new section (§890B) to the Homeland Security Act of 2002 that would require DHS to develop and make available guidance “to assist in the development of emergency action and response plans for active shooter and mass casualty incidents in public and private locations” {new §890B(a)}.

Moving Forward


Aguilar is not a member of the House Homeland Security Committee to which this bill was assigned for consideration, but one of his co-sponsors, Rep. Watson-Coleman (D,NJ) is. This means that it is possible that Watson-Coleman has enough influence to have this bill considered in Committee.

There is nothing in this bill that would engender any significant opposition. The bill would probably draw bipartisan support if it were considered. If it makes it to the floor of the House, I suspect that it would be considered under the suspension of the rules process.

Commentary


This bill is very generic in its guidance requirements. The most important piece of the bill is the amendment of §608 that adds ‘active shooters’ to the list of threats that DHS will consider when awarding homeland security grants under the Urban Area Security Initiative (§604) and the State Homeland Security Grant Program (§605).

I am disappointed (though hardly surprised) that the bill does not require DHS to prepare specific guidance for responding to active shooter incidents at facilities that store hazardous materials; particularly flammable liquids and gasses or toxic liquids and gasses. Over the years I have talked to police officers in a number of jurisdictions (including one with specific response responsibilities at an oil refinery) and none of them have been aware of the specific hazards associated with the discharge of firearms in facilities with potentially flammable atmospheres. Nor have they been aware of how easy it is for bullets to penetrate the walls of many storage tanks used to store toxic and flammable liquids.


If this bill makes it out of committee without language being added to require this sort of specific guidance being added, it is unlikely that it would be subsequently added in the legislative process. Any floor action in the House or Senate would almost certainly be made under abbreviated consideration rules which do not typically provide for amendments being offered.

Tuesday, January 9, 2018

House Passes HR 3202 – DHS Vulnerability Reporting

This afternoon the House passed HR 3202, the Cyber Vulnerability Disclosure Reporting Act, by a voice vote. There were only 12 minutes of debate and no amendments were authorized from the floor. The bill would require an unclassified report to Congress on procedures that DHS has developed with regards to vulnerability disclosures.

While it is currently unclear whether or not the Senate will take up the bill, it would most likely be considered under the Senate’s unanimous consent process which would involve even less debate and no provision for amendments.


NOTE: This bill gives lie to the current picture of the House as a strictly partisan body. The bill was introduced by Rep. Jackson-Lee (D,TX) with no Republican co-sponsors. The bill moved relatively quickly through the Homeland Security Committee and then to the floor of the House. This could only happen if the Democrat, Ms Jackson-Lee, had the explicit support of her Republican Committee Chair.

ICS-CERT Publishes 2 Advisories

Today the DHS ICS-CERT published two control system security advisories for products from General Motors and Rockwell Automation. The GM advisory was originally issued on the National Cybersecurity and Communications Integration Center (NCCIC) secure portal on August 22nd, 2017.

GM Advisory


This advisory describes multiple vulnerabilities in the General Motors Shanghai OnStar (SOS) iOS Client. The vulnerability was reported by Charles Gans. GM has produced a new version of the SOS iOS Client and is scheduled to release a new version of the North American OnStar iOS Client. There is no indication that Gans has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Clear-text storage of sensitive information - CVE-2017-9663;
• Channel accessible by non-endpoint - CVE-2017-12697; and
• Improper authentication - CVE-2017-12695

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to remotely gain full access to the Shanghai OnStar iOS client, allowing for the control of remote vehicle commands and the ability to view and edit account data.

NOTE: There is nothing on the Automotive ISAC web site about this set of vulnerabilities (or any other public vulnerability reports for that matter) even though one of the mitigation measures suggested by GM directly applies to the using public. Nor have I seen any news reports of GM sharing this information directly with the public.

Rockwell Advisory


This advisory describes a buffer overflow vulnerability in the Rockwell Allen-Bradley MicroLogix 1400 Controllers. The vulnerability was reported by Thiago Alves of the University of Alabama. The latest firmware version mitigates the vulnerability. There is no indication that Alves was provided an opportunity to verify the efficacy of the fix.


ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause the device that the attacker is accessing to become unresponsive to Modbus TCP communications and affect the availability of the device.

ICS-CERT Publishes AV Update Guidance

Yesterday the DHS ICS-CERT published a link to a National Cybersecurity and Communications Integration Center (NCCIC) recommended practices document; “Updating Antivirus in an Industrial Control System”. This is essentially the same guidance (complete with the same ICS network architecture diagram) that ICS-CERT published last fall in their Sep-Oct 2017 Monitor.

The timing for this publication is interesting with all of the current brouhaha about Microsoft not allowing automatic updates being sent to systems that do not have an updated AV registry key.

As I said last fall, nothing new here. The addition of this new recommended practice document just means that ICS-CERT has another document to link to for the mitigation measures portion of their advisories and alerts.


Monday, January 8, 2018

ISCD Publishes CFATS Update – December 2017

Today the DHS Infrastructure Security Compliance Division (ISCD) updated the data on the Chemical Facility Anti-Terrorism Standards (CFATS) Monthly Update page. The new data for December 2017 shows the continued progress being  made implementing the CFATS program.

Facility Status


The table below shows the change in the current covered facility status for those facilities covered by the CFATS chemical security program over the last two months. A decline in the number of ‘Tiered Facilities’ is expected as recently tiered facilities complete their site security plans and have those plans authorized and ultimately approved.

CFATS Facility Status
Nov-17
Dec-17
Tiered
843
723
Authorized
429
493
Approved
2276
2340
Total
3548
3556

It looks like ISCD has completed the notification process for facilities to resubmit Top Screens in support of the implementation of CSAT 2.0. The increase in the number of covered facilities appears to be leveling off. Based upon program history, I would not be surprised to see the number of covered facilities start to actually decline.

ISCD Activities


The next table shows the activities that ISCD had taken during the month of December to support the CFATS program. The ‘to Date’ data reflects the total number of inspections/visits that have been completed since the CFATS program began.

CFATS Activities
Nov-17
Dec-17
Authorization Inspections to Date
3102
3132
Authorization Inspections Month
70
49
Compliances Inspections to Date
3065
3112
Compliances Inspections Month
87
77
Compliance Assistance Visits to Date
3723
3799
Compliance Assistance Visits Month
92
100

ISCD continues to have problems with reconciling the reported number of monthly inspections/visits and the number of those visits to date. Looking at the ‘Authorization Inspection’ data we see an increase of just 30 inspections done since the last report while reporting that there were 49 inspections completed in December. We see a similar difference in the compliance inspection and compliance assistance visit data.


In the past the discrepancy has been the other way; with a larger increase in the cumulative inspections than was reported as having been conducted. I had suggested in earlier blogs that these earlier data oddities could be explained by a number of facilities leaving the program or failing inspections. Neither of those explanations would explain the differences seen this month.
 
/* Use this with templates/template-twocol.html */