Saturday, November 3, 2018

Public ICS Disclosure – Week of 10-27-18


This week we have two vendor disclosures from ABB and two exploits for products from Modbus Tools.

CMS-770 Advisory


ABB published an advisory for a configuration file vulnerability in the CMS-770 control unit. The vulnerability was reported by Maxim Rupp. ABB has updated the manual for this product to outline additional security measures that mitigate the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

ABB reports that successful exploitation of this vulnerability could cause the product to reveal the credentials allowing to take over the entire control of the product.

M2M Ethernet Network Analyzer Advisory


ABB published an advisory for a language file vulnerability in the M2M Ethernet Network Analyzer. The vulnerability was reported by Maxim Rupp. ABB has updated the manual for this product to outline additional security measures that mitigate the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

ABB reports that successful exploitation of this vulnerability could allow an attacker to upload a language file to the product without being requested to authenticate himself.

Modbus Tools Exploits


Kağan Çapar published an exploit for a buffer overflow vulnerability in the Modbus Tools Modbus Slave programming tool. No CVE number is provided so this may be a 0-day vulnerability.

Ihsan Sencan published an exploit for a denial of service vulnerability in the Modbus Tools Modbus Slave programming tool. A new (no details available) CVE number was provided so there is a possibility that the vendor has been contacted about this vulnerability.

Friday, November 2, 2018

Four Advisories and One Update Published


Yesterday the DHS NCCIC-ICS published four new control system security advisories for products from Fr. Sauter, Circontrol, Schneider Electric, AVEVA. They also updated a previously published advisory for products from Rockwell.

Sauter Advisory


This advisory describes an improper restriction of XML external entity reference in the Sauter CASE Suite application. The vulnerability was reported by Gjoko Krstic of Applied Risk. Sauter has an update that mitigates the vulnerability. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low skilled attacker could remotely exploit the vulnerability to allow an attacker to remotely retrieve unauthorized files from the system.

Circontrol Advisory


This advisory describes two vulnerabilities in the Circontrol CirCarLife electric vehicle charging station. The vulnerabilities were reported by Ankit Anubhav of NewSky Security, M. Can Kurnaz Senior Consultant at KPMG Netherlands, Alim Solmaz Security Consultant at Atos, Michael John Chief Information Security Officer at WePower Network, and Gyorgy Miru Security Researcher at Verint. Circontrol has a new version that mitigates the vulnerability. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Authentication bypass using an alternate path or channel - CVE-2018-17918; and
Insufficiently protected credentials - CVE-2018-17922

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow a remote attacker to retrieve credentials stored in clear text to bypass authentication, and see and access critical information.

Schneider Advisory


This advisory describes a DLL hijacking vulnerability in the Schneider Software Update (SESU) installed with a wide variety of Schneider products. The vulnerability was reported by Haojun Hou of ADLab of Venustech. Schneider has an update that mitigates the vulnerability. There is no indication hat Haojun has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to execute arbitrary code on the target system.

NOTE: I had previously discussed this vulnerability last weekend.

AVEVA Advisory


This advisory describes two vulnerabilities in the AVEVA InduSoft Web Studio and InTouch Edge HMI. These vulnerabilities were reported by Tenable. AVEVA has new versions that mitigate the vulnerabilities. There is no indication that Tenable was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-17916; and
• Empty password in configuration file - CVE-2018-17914

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an unauthenticated user to remotely execute code.

Rockwell Update


This update provides additional information on an advisory that was originally published on October 26th, 2017. The update provides new mitigation information based upon new limitations on the impact of the vulnerability.

NOTE: This is the KRACK vulnerability advisory for the Rockwell Stratix 5100 Wireless Access Point/Workgroup Bridge.


Thursday, November 1, 2018

ISCD Published CFATS Update – 11-01-18


Today the DHS Infrastructure Security Compliance Division (ISCD) revised the CFATS Statistics web page to reflect data from October 2018. The numbers show a continued increase in the number of facilities with approved site security plans (80.2%) and a resumption of the slow decline in the number of covered facilities after slight increases in the two previous months.

The first table below outlines the activities completed by the ISCD chemical facility inspectors over the last three months. The total number of reported activities continues to show a general decline since February, but it is hard to do a reasonable statistical analysis of the trend because of a clear definition of the time frame for which the data is reported. Further, trying to assess the rate of CSI utilization from this data is complicated by the fact that the number of CSI involved in any activity varies with the complexity and size of the facility involved.

CFATS Activities
Aug-18
Sep- 18
Oct-18
Authorization Inspections to Date
3822
3854
3875
Authorization Inspections Month
68
35
25
Compliance Inspections to Date
3819
3891
3995
Compliance Inspections Month
78
71
106
Compliance Assistance Visits to Date
4749
4897
5008
Compliance Assistance Visits Month
158
126
121

The second table below shows the status of facilities currently covered by the CFATS program. The recent two-month uptick in the number of covered facilities (the ‘Total’ line in the table) has been an anomalous in the history of the program; generally speaking (with notable exceptions) facilities have a number of economic incentives to minimize their chemical security risk through reducing the number of DHS chemicals of interest (COI) on the facility or reducing the maximum inventory quantity of those COI remaining.

CFATS Facility Status
Aug-18
Sep-18
Oct-18
Tiered
218
211
205
Authorized
562
493
456
Approved
2586
2665
2701
Total
3366
3369
3362

Still missing from the monthly reporting (and at this point this is practically a pro forma comment) is any information on the compliance rate for facility inspections.

Wednesday, October 31, 2018

One Advisory and Two Updates Published


Yesterday the DHS NCCIC-ICS published one new control system security advisory and updates for two previously published advisories.

PEPPERL+FUCHS Advisory


This advisory describes and improper privilege management vulnerability in the PEPPERL+FUCHS CT50-Ex. This vulnerability is being self-reported. PEPPERL+FUCHS has an update available that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow a malicious third-party application to gain elevated privileges and obtain access to sensitive information.

NOTE: I discussed this vulnerability (and the associated Honeywell advisory) two weeks ago.

Rockwell Update


This update provides new information on an advisory that was originally reported on March 1st, 2016. The new information includes:

• Report of a publicly available exploit;
• Added affected products and associated mitigation measures;
• Added a second reporting researcher {Venkatesh Sivakumar (@PranavVenkatS)}; and
Added additional mitigation measures.

NOTE: Rockwell has not updated their security advisory to reflect these changes.

Vecna Update


This update provides new information on an advisory that was originally published on April 24th, 2018. The new information includes:

• Report of remote exploitability;
• Added two new vulnerabilities;
• Expanded exploit risk;
• Clarified affected versions; and
• Added three new vulnerabilities

ISCD Updates CFATS Web Site – 10-30-18


Yesterday the DHS Infrastructure Security Compliance Division (ISCD) updated their Chemical Facility Anti-Terrorism Standards (CFATS) program web site. Significant changes were made to the CFATS landing page and the CFATS Resources page. Actually, the changes to the landing page were mainly the removal of the ‘CFATS Announcement’ section that dated back to August.

CFATS Resources


The CFATS Resources page is basically a listing of links to publications about the CFATS program. A new category of documents (Industry-related Chemicals Fact Sheets) was added to the page and a new fact sheet (CFATS Resubmitting a Top-Screen Fact Sheet) was added to the existing Fact Sheets section of the page.

The new industry fact sheets section provides links to a number of industry specific fact sheets about the CFATS program. These fact sheets are part of the ongoing outreach effort that CFATS is undertaking to ensure that all facilities with holdings of DHS chemicals of interest (COI) know about their CFATS Top Screen reporting requirements. I have written about a number of these fact sheets as they have been published, but this new section provides links to fact sheets that I had not seen before. Nothing really new in the fact sheets, they are just targeting industries that had not yet been singled out for attention. The new industries include:


There is one minor problem with this new ‘fact sheet’ section on the page; all of the links take you to the same separate ‘Industry-related Chemicals Fact Sheets’ page where an identical list of industries provides links to the actual fact sheets. It would be less disruptive if that intermediate page were removed.

NOTE: These new fact sheets were also reported on the CFATS Knowledge Center.

Resubmitting a Top Screen


This new fact sheet (actually dated ‘November 2018’) addresses the issue of when facilities are required to resubmit Top Screens. In addition to the Tier-specific periodic resubmission specified in the CFATS regulations it mentions the ‘material modification’ requirements. ISCD has had a continuing problem with providing industry with a concrete definition of this slippery term. The major reason for this is that ISCD has not been willing to share the details of their risk assessment model so that industry could see exactly what type and scope of changes could result in a change of their facility tiering.

This new fact sheet does provide some new information. Along with the addition or deletion of a COI from the facility inventory, ISCD now lists “Changes to quantity, location, or packaging of a COI as previously reported on a Top-Screen” as a category of activities that could trigger a requirement to resubmit a Top Screen.

To limit the number of Top Screen submissions that a facility might have to submit, ISCD does offer this bit of advice:

“As a best practice, DHS recommends that a facility predict the highest expected quantity and concentration of COI it anticipates possessing at a given time over the lifecycle of the facility’s operations to ensure more efficient reporting.”

Unfortunately, following this advice will could also result in the requirement to maintain a security system for a Tier ranking higher than the facility deserves on a routine basis. It would be more helpful to facilities if ISCD were able to tell facilities what level of inventory for currently listed COI would trigger an increase in Tier ranking. That way facilities could put administrative controls into place to ensure that that inventory level was not reached without a specific consideration of the costs of added security measures.

Monday, October 29, 2018

CEII Admin Procedures NPRM Published


The Department of Energy published a notice of proposed rulemaking (NPRM) today in the Federal Register (83 FR 54268-54278) describing the DOE’s proposed procedures for the designation and control of Critical Electric Infrastructure Information (CEII) that would parallel the Federal Energy Regulatory Commission’s rules on CEII (18 CFR 388.113). This rule implements the CEII requirements set forth in §61003(d) of the 2015 FAST Act {PL 114-94, 129 STAT. 1773; codified at 16 USC 824o-1(d)}.

The NPRM would add 10 CFR 1004.13, Critical Electric Infrastructure Information. This would include sub-paragraphs for:

Protection of CEII (Note: This is apparently mismarked at ‘(6)’ not ‘(g)’ in the NPRM);

Readers are reminded that CEII is a listed type of controlled unclassified information (CUI) under the Information Security Oversight Office (ISOO) regulations (32 CFR 2002). Where the requirements of this new DOE rule do not exceed the requirements of the ISOO regulation, the ISOO regulation supersedes these requirements.

DOE is soliciting comments on this NPRM. Comments must be received by December 28th, 2018. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; RIN 1901-AB44).

Saturday, October 27, 2018

Public ICS Disclosures – Week of 10-20-18


This week we have two vendor notifications for products from Schneider Electric and Eaton.

Schneider Advisory


This advisory describes a DLL hijacking vulnerability in the Schneider Electric Software Update (SESU) which is installed with a wide variety of Schneider products. The vulnerability was reported by Haojun Hou (ADLab of Venustech). Schneider has an update available to mitigate the vulnerability. There is no indication that Haojun has been provided an opportunity to verify the efficacy of the fix.

Eaton Advisory


This advisory mentions an un-explicated vulnerability in the Eaton Network Card-MS for UPS. This vulnerability is apparently being self-reported. Eaton has a newer version of the firmware that mitigates the vulnerability.

NOTE: This is about the most worthless security notification that I have ever seen. Not only does it not describe the vulnerability (or provide a CVE number, or describe the associated risk), but the “link” to cybersecurity whitepaper which presumably provides potentially useful generic workaround information for power distribution systems is not actually a link; it is just the blue-underlined word “here”. Oh, and by the way, how many people know the firmware version number of the network communication card is in their UPS?

 
/* Use this with templates/template-twocol.html */