Wednesday, February 13, 2019

6 Advisories and 7 Updates Published – 02-12-19


Yesterday the DHS NCCIC-ICS published six control system security advisories for products from Siemens (5) and OSIsoft. They also updated seven previously published advisories for products from Siemens.

CP1604 Advisory


This advisory describes three vulnerabilities in the Siemens CP1604 and CP1616 products. These vulnerabilities were self-reported. Siemens has a new version that mitigates the vulnerabilities.

The three reported vulnerabilities are:

• Clear-text transmission of sensitive information - CVE-2018-13808;
• Cross-site scripting - CVE-2018-13809; and
Cross-site request forgery - CVE-2018-13810

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow a denial-of-service condition and information exposure. An attacker could inject arbitrary JavaScript in a specially crafted URL request to execute on unsuspecting user’s systems, allowing an attacker to trigger actions via the web interface that a legitimate user is allowed to perform.

NOTE: I briefly discussed this advisory on January 12th.

Intel Active Management Advisory


This advisory describes three vulnerabilities in the Intel Active Management Technology (AMT) of Siemens SIMATIC IPCs. The vulnerabilities are self-reported. These vulnerabilities exist in third-party (Intel) firmware on the affected PCs. Siemens has firmware updates that mitigate the vulnerabilities.

The three reported vulnerabilities are:

• Cryptographic issues - CVE-2018-3616;
• Improper restrictions of operations within the bounds of a memory buffer - CVE-2018-3657; and
• Resource management errors - CVE-2018-3658

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow arbitrary code execution, a partial denial-of-service condition, or information disclosure. The Siemens advisory reports that:

“The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction.”

NOTE: These vulnerabilities could be found on a large number of industrial PC’s not related to the Siemens products in this advisory.

SIMATIC Advisory


This advisory describes an improper input validation vulnerability in the Siemens SIMATIC S7-300 CPU. The vulnerability was reported by the China Industrial Control Systems Cyber Emergency Response Team (CIC). Siemens has a firmware update that mitigates the vulnerability. There is no indication that CIC has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to all the attacker to  crash the device being accessed, resulting in a denial-of-service condition.

NOTE: I briefly discussed this advisory on January 12th.

Licensing Software Advisory


This advisory describes three vulnerabilities in the Siemens WibuKey Digital Rights Management (DRM) used with SICAM 230. These vulnerabilities are self-reported. Siemens has provided links to a third-party update to mitigate the vulnerabilities. These vulnerabilities were originally reported in the WibuKey product in December by Talos; see the links on the CVE numbers for the Talos reports.

The three reported vulnerabilities are:

• Input validation (3) - CVE-2018-3989, CVE-2018-3990, and CVE-2018-3991.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow information disclosure, privilege escalation, or remote code execution. NOTE: The Talos reports provide proof of concept exploit code.

Again, as with any third-party vulnerability, these problems could be seen in systems from other vendors that also use the WibuKey DRM.

EN100 Ethernet Communications Module Advisory


This advisory describes an improper input validation vulnerability in the Siemens EN100 Ethernet Communication Module and SIPROTEC 5 Relays. The vulnerability was reported by Lars Lengersdorf from Amprion GmbH. Siemens has updates for some of the affected products. There is no indication that Lengersdorf has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to conduct a denial-of-service attack over the network.

OSIsoft Advisory


This advisory describes a cross-site scripting vulnerability in the OSIsoft PI Vision application. The vulnerability is self-reported. OSIsoft has a new version that mitigates this vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow an attacker to read and modify the contents of the PI Vision web page and data related to the PI Vision application in the victim’s browser.

NOTE: I briefly discussed this vulnerability on December 18th, 2018.

Meltdown Spectre Update


This update provides additional information on an advisory that was originally published on January 11th, 2018 and updated on January 16th, 2018, January 17th, 2018, January 30th, 2018, February 20th, 2018, February 22nd, 2018, March 1st, 2018, July 10th, 2018, and most recently on September 11th, 2018.. The new information includes a link to a new Meltdown/Spectre advisory from Siemens for their SIMATIC Industrial Thin Clients.

EN100 Ethernet Communications Module Update


This update provides additional information on an advisory that was originally published on December 13th, 2018. The new information includes updated version data and mitigation links for or firmware variant IEC104 for EN100 Ethernet modules.

SIMATIC S7-1500 Update


This update provides additional information on an advisory that was originally published on October 9th, 2018. The new information includes updated version data and mitigation links for:

• SIMATIC ET 200 SP Open Controller; and
• SIMATIC S7-1500 Software Controller

Open SSL Update


This update provides additional information on an advisory that was originally published on August 14th, 2018 and updated on September 11th, 2018, October 9th, 2018, and again on November 13th, 2018. The update provides new affected version and mitigation information for:

• SIMATIC S7-1500 Software Controller; and
• SIMATIC ET 200SP Open Controller CPU 1515SP PC

SIPROTEC 4 Update


This update provides additional information on an advisory that was originally published on March 8th, 2018 and updated on April 18th, 2018. The update provides new affected version and mitigation information for IEC 104 variant of EN100 module.

Industrial Products Update #1

This update provides additional information on an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th, November 28th, February 27th, 2018, May 3rd, 2018 May 15th, 2018, September 11th, 2018, October 9th, 2018, November 13th, 2018, December 11th, 2018, and most recently on February 5th, 2019. The update provides new affected version and mitigation information for SIMATIC ET 200SP IM155-6 PN HA.

Industrial Products Update #2


This update provides additional information on an advisory that was originally published on January 12th, 2018. The update provides new affected version and mitigation information for SIMATIC CP 1626.

Siemens Advisory Update


Yesterday’s publications by ICS-CERT is really rather remarkable since most of the Siemens advisories covered were published yesterday. NCCIC-ICS has now reported on all of the original advisories from Siemens from January and all but one of the updates (the GNU/Linux vulnerabilities that have not been reported by NCCIC-ICS).

Of the four advisories and 12 updates published yesterday by Siemens only 8 updates have not been directly covered by NCCIC-ICS in yesterday’s reporting. Unless those are reported by NCCIC-ICS on Thursday, I will have more details this weekend.

Monday, February 11, 2019

ISCD Publishes CFATS Update for December and January


Today the DHS Infrastructure Security Compliance Division (ISCD) published their Chemical Facility Anti-Terrorist Standards (CFATS) update for December 2018 and January 2019. Needless to say the Federal Funding Fiasco has had a major impact on the numbers being reported since the Chemical Security Inspectors were furloughed for 35-days straddling those two months. Sorry to say, this is going to play hell with statistical analysis.

The first table below shows the reported CSI activity data for December and January from today’s report (the November numbers come from the ISCD report in early December). The Authorization and Compliance inspection goose eggs are due to the fact that these inspections require more prior coordination than does a compliance inspection. The ‘NR’ notation means ‘not reported’.

CFATS Activities
Nov-18
Dec-18
Jan-19
Authorization Inspections to Date
3886
NR
3913
Authorization Inspections Month
14
18
0
Compliance Inspections to Date
4135
NR
4269
Compliance Inspections Month
143
97
3
Compliance Assistance Visits to Date
5065
NR
5131
Compliance Assistance Visits Month
53
36
0

The second table shows the status of covered facilities. ISCD did not report interim numbers for December.

CFATS Facility Status
Nov-18
Dec-18
Jan-19
Tiered
178

137
Authorized
454

426
Approved
2723

2766
Total
3355

3329

The sharp drop in the number of covered facilities (-26) since November is large, but not the largest two-month drop. That was -27 in June-July of 2018. Still it is rather impressive given that ISCD was not processing Top Screens for 35-days during the period and every one was kind of holding their breath until January 18th, when the President signed the 15-month extension of the CFATS program authorization.

BTW: The CFATS landing page was updated to ‘report’ the signing of the extension.

Committee Hearings – Week of 02-10-19


Apparently due to the Federal Funding Fiasco, Congress has been slow to start its committee processes. Last week we saw a bunch of organizational meetings finally being held. This week we start to see a more ‘normal’ hearing schedule. There are two potential hearings of interest here dealing with cybersecurity issues.

Cybersecurity Markup Hearing?


On Wednesday the Senate Homeland Security and Governmental Affairs Committee will hold a business meeting. The agenda on the Committee web site does not list any cybersecurity bills, but the Senate hearing web site lists the following cybersecurity bills as bills that would be considered:

• S.315, to authorize cyber hunt and incident response teams at the Department of Homeland Security,
• S.333, to authorize the Secretary of Homeland Security to work with cybersecurity consortia for training, and
An original bill entitled, "Federal Rotational Cyber Workforce Program Act of 2019

This may be an old and out-of-date listing. The final bill listed above was introduced last week as S 406. None of these bills have been published yet, so I have not had a chance to review them.

Energy Cybersecurity


On Thursday the Senate Energy and Natural Resources Committee will hold a hearing on “To Consider the Status and Outlook for Cybersecurity Efforts in the Energy Industry”. The witness list includes:

• Neil Chatterjee, FERC;
• Karen Evans, CSER;
• William J. Keber, West Virginia National Guard Critical Infrastructure Protection Battalion
• James B. Robb, North American Electric Reliability Corporation; and
David Edward Whitehead, Schweitzer Engineering Laboratories, Inc.

Saturday, February 9, 2019

CG Withdraws Two Hazardous Substance Response Plan Rulemakings


Yesterday the Coast Guard published two notices in the Federal Register (84 FR 2799-2800 and 84 FR 2800-2801) announcing the withdrawal of two long-dormant rulemakings concerning hazardous-substance spill response plans for marine transportation related facilities and tank vessels. These rulemakings, dating back to 2000 and 1999 respectively, were intended to expand the existing oil spill response plan requirements to hazardous substances. In both instances the CG justified the withdrawal of the rulemakings by noting that: “the proposed rules are no longer appropriate to the current state of spill response in the chemical industry”.

Neither of these rulemakings had been on the Active Unified Agenda since I have been watching that for this blog until the Trump Administration added them back to the Active Agenda for the Fall 2017 Unified Agenda. It is now apparent that it was added simply because the Coast Guard was reviewing the rulemakings to be determined if they should be withdrawn.

Both announcements carefully note that:

The withdrawal of the NPRM qualifies as a deregulatory action under Executive Order 13771 (Reducing Regulation and Controlling Regulatory Costs), which directs agencies to reduce regulation and control regulatory costs and provides that “for every one new regulation issued, at least two prior regulations be identified for elimination, and that the cost of planned regulations be prudently managed and controlled through a budgeting process.”

Friday, February 8, 2019

DHS Publishes 60 ICR Revision Notice for CSAT – 02-07-19


Yesterday the DHS Cybersecurity and Infrastructure Security Agency (CISA) published a 60-day information collection request notice (ICR) in the Federal Register (84 FR 2558-2564) for the Chemical Facility Anti-Terrorism Standards (CFATS) program Chemical Security Assessment Tool (CSAT). The CSAT is an online tool that the Agency (via the Infrastructure Security Compliance Division) uses to collect information from chemical facilities to oversee the CFATS program.

ICR Data


The previous ICR for this program was initiated to allow the ISCD to implement CSAT 2.0, the revised information collection and assessment tool that was introduced in 2016. Yesterday’s ICR notice is intended to revise collection and burden estimate to reflect on-going collection requirements now that the CSAT 2.0 implementation is complete. Table 1 below provides a comparison between the currently approved ICR and the new estimate from CISA.


Current
Proposed
Total Responses
18,450
22,543
Total Burden Hours
22,239
14,359
Total Burden $
$15.3 M
$1.1 M
Table 1: Burden Comparison

The data in Table 1 is not directly provided in the ICR notice; it is compiled from the information provided for in the notice for each of the six data collection tools included in CSAT. Table 2 provides a summary of the data provided. The links in the table are to the detailed discussion in the ICR notice explaining how CISA arrived at the figures.

Responses
Hours
Dollars
       2,332
  2,553
   $203,450
       1,683
  2,083
   $166,028
       1,683
  4,582
   $365,141
     15,000
  2,500
   $199,233
       1,000
  2,500
   $199,233
          845
     141
     $11,223
Total
22,543
14,359
$1,144,308
Table 2: ICR Burden Details

Risk Identification


The one tool that may not be immediately familiar to folks in the CFATS community is the risk identification tool. Actually, the ICR notice provides a more complete title; Identification of Additional Facilities and Assets at Risk. In the currently approved ICR the document [.DOCX download] describing this data collection shows two different types of information being collected as a result of compliance inspections.

The first addresses identification of facilities at risk. At facilities that receive, or ship DHS chemicals of interest are requested to voluntarily provide data on:

• Shipping and/or receiving procedures
• Invoices and receipts
Company names and locations that COI is shipped to and/or received from

The discussion in the ICR notice would seem to indicate that CISA will only be collecting the above information from facilities that ship COI.

The second addresses assets at risk. Facilities that are identified as having “SCADA, DCS, PCS, or ICS” are requested to voluntarily provide information on:

• Details on the system(s) that controls, monitors, and/or manages small to large production systems as well as how the system(s) operates.
• If it is standalone or connected to other systems or networks and document the specific brand and name of the system(s)

This ICR notice only mentions the description of the facilities at risk data collection. Neither the 60-day ICR notice for the existing ICR nor does the supporting document [.DOCX download] provided to OMB describes either risk data collection. They only mention that the data collection is voluntary and expect that each facility providing a site security plan (SSP) will provide data under this collection.


Commentary


This ICR notice provides a look at the interesting problem agencies have in preparing their burden estimates for data collections that are not strictly periodic. When programs start up (or significant changes are made) the collection requirements are generally going to be higher as the affected entities have to put reporting (and the internal data collection) processes into place. Presumably, after that initial effort is complete, presumably the burden will decrease for subsequent data submissions.

In the detailed discussions in this notice CISA continues the established process that has been used throughout the history of the CFATS program in providing detailed information in its ICR notices. With the level of information provided, interested parties have enough information to determine if they have specific questions about the burden estimates or have suggestions on how the agency can improve those estimates. That, after all, is the whole purpose of publishing these ICR notices.

I find it interesting to see that the CFATS program attempted to gain additional information on industrial control systems used at covered facilities. This bears further investigation.

Bills Introduced – 02-07-19


Yesterday with both the House and Senate in session there were 151 bills introduced. Only three of these may see future coverage in this blog:

HR 1062 To authorize the Secretary of Homeland Security to work with cybersecurity consortia for training, and for other purposes. Rep. Castro, Joaquin [D-TX-20]

S 406 A bill to establish a Federal rotational cyber workforce program for the Federal cyber workforce. Sen. Peters, Gary C. [D-MI] 

S 429 A bill to require the establishment of exchange programs relating to cybersecurity positions between the private sector and certain Federal agencies, and for other purposes. Sen. Klobuchar, Amy [D-MN]

These all sound like they may be re-introductions of bills from the 115th Congress. I will be watching these for control system security language (but probably will not find it).

Thursday, February 7, 2019

2 Advisories and 3 Updates Published – 02-07-19


Today the DHS NCCIC-ICS published two control system advisories for products from Siemens and three updates for products from Kunbus, Omron and Fuji electric.

EN100 Advisory


This advisory describes two improper input validation vulnerabilities in the Siemens EN100 Ethernet module. These vulnerabilities were reported by Victor Nikitin, Vladislav Suchkov, and Ilya Karpov from ScadaX. Siemens has provided updates for some of the affected products. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to conduct a denial-of-service attack over the network.

NOTE: I briefly discussed this update on January 12th.

SICAM Advisory


This advisory describes an uncaught exception vulnerability in the Siemens SICAM A8000 RTU. The vulnerability was reported by Emanuel Duss and Nicolas Heiniger from Compass Security. Siemens has updates that mitigate the vulnerability. There is no indication that the researchers have been offered an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow unauthenticated remote users to cause a denial-of-service condition on the web server of affected products.

NOTE: I briefly discussed this update on January 12th.

Siemens Update – There are two advisories from the January 8th tranche of vulnerability disclosures from Siemens. It will be interesting to see if they are processed by NCCIC-ICS before the next scheduled Siemens advisory disclosures on February 12th.

Kunbus Update


This update provides additional information on an advisory that was originally published on February 5th, 2019. The update includes:

• Adding two additional vulnerabilities (Information exposure through query strings in get request and clear-text storage of sensitive information); and
Report that the two added vulnerabilities will be mitigated in the next version (end of the month).

Omron Update


This update provides additional information on an advisory that was originally published on January 17th, 2019. The update includes:

• Adding two additional vulnerabilities (access of uninitialized pointer and out-of-bounds read); and
• Added Michael DePlante as a vulnerability reporter;

Fuji Update


This update provides additional information on an advisory that was originally published on September 27th, 2018. The updates reports that a new version is available that mitigates the vulnerability.

 
/* Use this with templates/template-twocol.html */