Wednesday, August 7, 2019

2019 CSSS Presentations Available


Yesterday the DHS Cybersecurity and Infrastructure Security Agency (CISA) updated both the Chemical Facility Anti-Terrorism Standards (CFATS) landing page and the Chemical Sector Security Summit (CSSS) web site to provide a link to the presentations page for the 2019 CSSS. As is usual for the CSSS, even given the advent of live web casts of many of the presentations, the presentations page just provides copies of the slides used during the CSSS, not the voice or text of the actual presentation, so many of the details have been lost to posterity.

The list of presentations, however, is impressive (see the presentation page for links to the documents):

• Air Domain Awareness           522.67 KB
• Assessing the Risk from Stolen or Diverted Toxic Industrial Chemicals 2.61 MB
• Building an International Network of Chemical Security Practitioners   994.41 KB
• CFATS and the Personnel Surety Program (PSP) Overview      1.74 MB
• CFATS Deep Dive     2.3 MB
• CFATS Personnel Surety Program      781.18 KB
• Chemical Sector 101  2.81 MB
• Chemical Security Analysis Center (CSAC) Overview 3.55 MB
• CISA Regional Service Delivery Model           2.02 MB
• Compliance Requirements for Release Chemicals        2.13 MB
• Dow Incident and Crisis Management 420.26 KB
• Extreme Weather Impacts       3.29 MB
• Federal Emergency Management Agency's Chemical, Biological, Radiological, and Nuclear (CBRN) Office: Chemical Portfolio Overview    1.44 MB
• Industrial Control Systems Vulnerabilities and Resources         1.63 MB
• International Chemical Security Framework     831.89 KB
• International Supply Chain Protection Challenges and Solutions           1.85 MB
• Introduction to the Maritime Transportation Security Act (MTSA)        2.12 MB
• Jack Rabbit II Update and Impacts      2.65 MB
• Little Arc-Flash: How Digital Attacks Can Cause Physical Ramifications          1.45 MB
• Multidisciplinary Partnerships in Chemical Security and Preparedness  1.68 MB
• Office for Bombing Prevention (OBP) Overview         417.7 KB
• Reducing the Threat of Improvised Explosive Device Attacks by Restricting Access to Explosive Precursor Chemicals        737.28 KB
• Supply Chain Risk Management         1.63 MB
• U.S. Coast Guard Cyber Risk Management      1.17 MB
• Waterside Security of Especially Hazardous Cargoes (EHC)     1.83 MB
• Weather Hazard Preparedness 5.12 MB
• What to Expect During a CFATS Inspection    1.01 MB

I have not had a chance to do a detailed review, or even look at all of the presentations, but a quick review of the CFATS Deep Dive presentation shows that the slides may contain a great deal of useful information for CFATS facilities and chemical facilities that are not currently involved in the CFATS program but are concerned about their facility security. Interesting bits of information from this presentation include:

Shipping/Receiving COI slide contains note about “In-Transit Security and Tracking”;
Response slide contains note that: “Local Emergency Planning Committees (LEPC) may be contacted by local Chemical Security Inspectors to verify that facilities have developed plans for emergency notification, response, evacuation, etc.”;
Good detail in Crisis Management slide;
Outreach with Local Responders slide includes note to: “Invite Local Law Enforcement and Responders to DHS Inspections”;
Cybersecurity slide provides brief discussion of what computer systems might be covered under CFATS program;
Personnel Surety slide contains a good ‘Hiring Checklist’, but missed the opportunity to provide a similar ‘departure checklist’ (maybe it was discussed in the actual presentation?);
Annual Audit Example slide contains a detailed example of how to record (and by inference conduct) an annual audit of the facility’s CFATS program;

I really like the idea of inviting off-site response personnel to CFATS inspections. It helps keep them involved in the process, aware of what is going on, and should provide some chemical security training that is missing from most professional training programs for these personnel. A copy of invite letters should be kept in the facility’s CFATS records to demonstrate positive outreach to these folks, even if they do not participate.

I hope to get to do more detailed reviews of some of the presentations here over the next couple of weeks.

Saturday, August 3, 2019

Public ICS Disclosures – Week of 07-27-19


It has been a very busy week in the ICS disclosure arena. We have vendor disclosures about the VxWorks vulnerabilities announced earlier this week; disclosures from Siemens, ABB, Schneider and Belden. We also have vendor disclosures from 3S and an update from Rockwell. Finally, we have new Metasploit module for a previously disclosed vulnerability from Schneider.

VxWorks Vulnerability


The Wind River OS vulnerabilities were just reported this week and we already have three (major) ICS vendors adding their advisories to the list of vulnerable products:

Siemens (in an out-of-cycle report);
Schneider; and
ABB, in:
AC 800PEC;
Belden

It will be interesting to see if NCCIC-ICS updates their advisory for each new vendor that adds to the list of covered products. Unfortunately, I do not expect NCCIC-ICS to provide any information about future updates (and there will be many as fixes are further applied) to the advisories published.

3S Advisories


This week, as earlier noted, 3S published 8 advisories for their CODESYS operating system, two of which NCCIC-ICS has reported. The remaining six advisories are covered below:

OPC UA Server Advisory

3S published an advisory describing a null pointer dereference vulnerability in the CODESYS Control V3 OPC UA Server. The vulnerability is self-reported. 3S has an update available to mitigate the vulnerability.

Communications Server Advisory

3S published an advisory describing a detection of error condition without action vulnerability in CODESYS V3 products containing a CODESYS communication server. The vulnerability was reported by Martin Hartmann from cirosec GmbH. 3S has a new version that mitigates the vulnerability. There is no indication that Hartmann has been provided an opportunity to verify the efficacy of the fix.

Library Manager Advisory

3S published an advisory describing a cross-site scripting vulnerability in the CODESYS V3 Library Manager. The vulnerability was reported by Heinz Füglister of WRH Walter Reist Holding AG. 3S has an update that mitigates the vulnerability. There is no indication that Füglister has been provided an opportunity to verify the efficacy of the fix.

On-Line User Management Advisory

3S published an advisory describing an incorrected inherited permissions vulnerability in the CODESYS Control V3 online user management. The vulnerability was reported by Martin Hartmann from cirosec GmbH. 3S has updates available that mitigate the vulnerability. There is no indication that Martin has been provided an opportunity to verify the efficacy of the fix.

Channel Management Advisory

3S published an advisory describing an uncontrolled memory allocation vulnerability in CODESYS Gateway V3 memory management. The vulnerability was reported by Martin Hartmann from cirosec GmbH. 3S has an update available that mitigates the vulnerability. There is no indication that Martin has been provided an opportunity to verify the efficacy of the fix.

Web Server Advisory

3S published an advisory describing a directory traversal vulnerability in the CODESYS V3 web server. The vulnerability was reported by Ivan Cheyrezy of Schneider Electric. 3S has an update that mitigates the vulnerability. There is no indication that Cheyrezy has been provided an opportunity to verify the efficacy of the fix.

Rockwell Update


Rockwell published an update to their advisory on PanelView 5510 Graphic Terminals that was originally published on July 9th, 2019. The update includes:

Modified description of the vulnerability;
Revision of the recommended work arounds; and
Provided a link for CVE-2019-10970

Schneider Metasploit


Lucas Dinucci published a Metasploit module for a previously disclosed vulnerability in the Schneider Electric Pelco Endura NET55XX webUI.

Friday, August 2, 2019

6 Advisories Published – 08-01-19


Yesterday the DHS NCCIC-ICS published six control system advisories for products from Leão Consultoria e Desenvolvimento de Sistemas (LCDS), Rockwell, 3S (2), Fuji Electric and Advantech.

LCDS Advisory


This advisory describes two vulnerabilities in the LCDS LAquis SCADA software. The vulnerabilities were reported by Francis Provencher (PRL) via the Zero Day Initiative. LCDS has an update available that mitigates the vulnerability. There is no indication that Provencher has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Out-of-bounds read - CVE-2019-10994; and
Type confusion - CVE-2019-10980


NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to obtain confidential information or execute remote code.

Rockwell Advisory


This advisory describes two vulnerabilities in the Rockwell Arena Simulation Software. The vulnerabilities were reported by kimiya of 9SG Security Team via ZDI. Rockwell has a new version that mitigates the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

Use after free - CVE-2019-13510; and
Information exposure - CVE-2019-13511

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to cause a current Arena session to fault or enter a denial-of-service (DoS) state, allowing the attacker to run arbitrary code.

First CODESYS Advisory


This advisory describes an insufficiently protected credentials vulnerability in the CmpUserMgr component of 3S CODESYS products. The vulnerability was reported by JunYoung Park. 3S will correct this vulnerability in a new version to be released in February. The 3S advisory strongly recommends activating and using encryption of online communication whenever possible.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow for an attacker with access to PLC traffic to obtain user credentials.

NOTE: Is it just me or is this advisory just a seven-month zero-day announcement?

Second CODESYS Advisory


This advisory describes two vulnerabilities in the CmpGateway component of the 3S CODESYS products. These vulnerabilities are self-reported. 3S has a new version that mitigates the vulenrabilities.

The two reported vulnerabilities are:

Unverified ownership - CVE-2019-9010; and
Uncontrolled memory allocation - CVE-2019-9012 

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow a remote attacker to close existing communication channels or to take over an already established user session to send crafted packets to a PLC.

NOTE 1: There were six other advisories published by 3S at the same time as the two referenced in these two NCCIC-ICS advisories. I will address them this weekend.

NOTE 2: A reminder that the CODESYS operating system is used in a wide variety of devices and systems. These vulnerabilities will have widespread application. Few vendors are expected to publish updates referencing these vulnerabilities.

Fuji Advisory


This advisory describes and out-of-bounds read vulnerability in the Fuji  FRENIC Loader. The vulnerability was reported by kimiya of 9SG Security Team via ZDI. Fuji has a new version that mitigates the vulnerability. There is no indication that the kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow information disclosure.

Advantech Advisory


This advisory describes an out-of-bounds write vulnerability in the Advantech WebAccess HMI Designer. The vulnerability was reported by Mat Powell via ZDI. Advantech has a new version that mitigates the vulnerability. There is no indication that Powell has been provided an opportunity to verify the efficacy of the fix.

Thursday, August 1, 2019

Bills Introduced – 07-31-19


Yesterday with just the Senate in session, there were 77 bills introduced. One of those bills will see future coverage in this blog:

S 2402 A bill to enhance the safety of Class 3 flammable liquid transportation by rail, and for other purposes. Sen. Wyden, Ron [D-OR]

Bills Introduced – 07-30-19


On Tuesday with the Senate in Washington and the House meeting in proforma session, there were 94 bills introduced. Three of those bills may receive additional coverage here in this blog:

HR 4091 To amend the America COMPETES Act to reauthorize the ARPA-E program, and for other purposes. Rep. Johnson, Eddie Bernice [D-TX-30]

S 2318 A bill to amend the Homeland Security Act of 2002 to authorize the Secretary of Homeland Security to establish a continuous diagnostics and mitigation program in the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, and for other purposes. Sen. Cornyn, John [R-TX]

S 2333 A bill to provide for enhanced energy grid security. Sen. Cantwell, Maria [D-WA] 

I will be watching HR 4091 to see if it includes language specifically authorizing grid cybersecurity research programs.

I will be watching S 2318 to see if it includes authorization to provide CDM coverage to private sector critical infrastructure facilities.

Tuesday, July 30, 2019

2 Advisories and 1 Alert Published – 07-30-19


Today the DHS NCCIC-ICS published a control system security alert for CAN bus network implementation in avionics and two control system security advisories for products from Prima Systems ad Wind River.

CAN Bus Alert


This alert briefly describes a public report about insecure implementation of CAN bus networks affecting aircraft. The report was published by Patrick Kiley of Rapid7.

Prima Systems Advisory


This advisory describes nine vulnerabilities in the Prima Systems FlexAir access control platform. The vulnerabilities were reported by Gjoko Krstic of Applied Risk. Prima Systems has a new version that mitigates the vulnerabilities. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

The nine reported vulnerabilities are:

OS command injection - CVE-2019-7670;
Unrestricted upload of file with dangerous type (2) - CVE-2019-7669 and CVE-2019-9189;
Cross-site request forgery - CVE-2019-7281;
Small space of random values - CVE-2019-7280;
Cross-site scripting - CVE-2019-7671;
Exposure of a backup file to an unauthorized control sphere - CVE-2019-7667;
Improper authentication - CVE-2019-7666; and
Use of hard-coded credentials - CVE-2019-7672

NOTE 1: NCCIC-ICS does not include a default credentials vulnerability, CVE-2019-7668, reported by Krstic.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to execute commands directly on the operating system, upload malicious files, perform actions with administrative privileges, execute arbitrary code in a user’s browser, discover login credentials, bypass normal authentication, and have full system access.

NOTE 2: I briefly described the Rapid7 report back in May.

Wind River Advisory


This advisory describes eleven vulnerabilities in the Wind River VxWorks operating system. The vulnerabilities were reported by Armis researchers Gregory Vishnepolsky, Dor Zusman, and Ben Seri. Wind River has patches to mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The eleven reported vulnerabilities are:

Stack-based buffer overflow - CVE-2019-12256;
Heap-based buffer overflow - CVE-2019-12257;
Integer underflow - CVE-2019-12255;
Improper restrictions of operations within the bounds of a memory buffer (2) - CVE-2019-12260 and CVE-2019-12261;
Race condition - CVE-2019-12263;
Argument injection or modification (4) - CVE-2019-12258, CVE-2019-12262, CVE-2019-12264 and CVE-2019-12265; and
Null pointer dereference - CVE-2019-12259;

Since the affected operating systems are used in a large number of IoT and ICS systems we can expect advisories from affected vendors implementing the Wind River mitigations measures. The NCCIC-ICS advisory already lists 2 vendor advisories and the Armis report adds a third. The three vendor advisories available to date include:

Rockwell,
Xerox, and

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow remote code execution.

Committee Hearings – Week of 07-28-19


With just the Senate in session (the House already having started their summer recess) the committee hearing list is pretty short this week. We do have two hearings of interest to look at. The first is a markup hearing looking at two authorization bills that were introduced last week and the second is re-look at positive train control implementation.

Authorization Markups


On Wednesday the Senate Commerce, Science, and Transportation Committee will markup two bills:

S 2297, Coast Guard Reauthorization Act of 2019; and
S 2299, Protecting Our Infrastructure of Pipelines Enhancing Safety (PIPES) Act of 2019

Neither bill has yet been officially published; the links above are to committee prints. A quick review of S 2297 shows that it includes a similar change to the MTSA rules found in the House version of the bill (HR 3409) requiring DHS to approve updates to security plans. HR 3409 was passed in the House last week.

PTC Hearing


On Wednesday the Senate Commerce, Science, and Transportation Committee will hold a hearing on “Next Steps for Positive Train Control Implementation”. The witness list includes:

Ronald Batory, Federal Railroad Administration;
Robert Bourg, Wabtec Corporation;
Jim Derwinski, Metra;
Susan Fleming, Government Accountability Office; and
Chris Matthews, BNSF Railway

 
/* Use this with templates/template-twocol.html */