Saturday, September 14, 2019

FAA Sends UAS Identification Rule to OMB


On Thursday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking from the DOT’s Federal Aviation Administration (FAA) for “Remote Identification of Unmanned Aircraft Systems” (UAS).

The abstract for this rulemaking in the Spring 2019 Unified Agenda notes:

“This action would implement system(s) for the remote identification of certain unmanned aircraft systems. The remote identification of unmanned aircraft systems in the national airspace system would further address security and law enforcement concerns regarding the further integration of these aircraft into the national airspace while also enabling greater operational capabilities by these same aircraft.”

I suspect that this rulemaking will be limited to larger, commercial UAS not the smaller hobbies drones.

Public ICS Disclosures – Week of 09-07-19


This week we have 11 vendor disclosures for products from Siemens (3), Schneider (3), Bosch (2), 3S, Eaton, and Draeger. We also have 3 vendor updates from Schneider (2) and Siemens.

Siemens Advisories


DejaBlue Advisory

Siemens published an advisory describing the Microsoft Windows® DejaBlue vulnerabilities in the Siemens Healthineers Products. In most of the affected products Siemens is recommending applying the appropriate MS patches.

Siemens repeatedly makes the following observation: “The compatibility of Microsoft security patches with products from Siemens Healthineers that are beyond their End of Support date cannot be guaranteed.”

RUGGEDCOM URGENT/11 Advisory

Siemens published an advisory describing the Wind River URGENT/11 vulnerabilities in the Siemens RUGGEDCOM Win base stations. Siemens provides generic workarounds for the vulnerabilities.

SINEMA Advisory

Siemens published an advisory describing four vulnerabilities in the Siemens r SINEMA Remote Connect Server. The vulnerabilities were reported by Hendrik Derre and Tijl Deneut from HOWEST. Siemens has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

Password guessing - CVE-2019-13918;
Privilege escalation - CVE-2019-13919;
Cross-site request forgery - CVE-2019-13920; and
Password hash - CVE-2019-13922

Siemens Update


Siemens published an update for an advisory that was originally published on June 9th, 2019. This update provides corrected version information and mitigation information for:

FieldPG M4;
FieldPG M5; and
ITP1000

Schneider Advisories


U.Motion Server Advisory

Schneider published an advisory describing six vulnerabilities in the Schneider U.motion din rail and touch panel servers. The vulnerabilities were reported by Zhu Jiaqi and Constantin-Cosmin Craciun. Schneider has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

Cross-site scripting - CVE-2019-6835;
Improper access control (3) - CVE-2019-6836, CVE-2019-6838 and CVE-2019-6839;
Server-side request forgery - CVE-2019-6837; and
Format string - CVE-2019-6840

Modicon Quantum Advisory

Schneider published an advisory describing an improper check for unusual or exceptional conditions vulnerability for the Schneider Modicon Quantum 140 NOE771x1 controllers. The vulnerability is self-reported. Schneider has a new version that mitigates the vulnerability.

TwidoSuite Advisory

Schneider published an advisory describing two vulnerabilities in the Schneider TwidoSuite product. The vulnerability is self-reported. This product is no longer supported.

The two reported vulnerabilities are:

Untrusted search path;
Input validation

Schneider Updates


BlueKeep Update

Schneider published an update for an advisory that was originally published on July 12, 2019. The update includes:

Exploit information; and
Updated affected product versions

 Floating License Manager Update

Schneider published an update for an advisory that was originally published on May 14th, 2019. The update provides updated affected product information.

Bosch Advisories


Bosch published two advisories (here and here) describing vulnerabilities in the Access Professional access control system. The vulnerabilities were reported by Oleksii Orekhov. Bosch has a new version that mitigates the vulnerabilities. There is no indication that Orekhov has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Hard-coded credentials - CVE-2019-11898; and
Improper access control - CVE-2019-11899

3S Advisory


3s published an advisory describing a stack-based buffer overflow vulnerability in the CODESYS V2.3 ENI servers. This vulnerability was reported by Chen Jie from NSFOCUS. 3S has an update that mitigates the vulnerability. There is no indication that Chen has been provided an opportunity to verify the efficacy of the fix.

Eaton Advisory


Eaton published an advisory describing multiple undisclosed vulnerabilities in the Eaton Intelligent Power Protector. The vulnerabilities are apparently self-reported. Eaton has a new version that mitigates the vulnerabilities.

NOTE: Eaton continues to publish unusable security advisories.

Drager Advisory


Drager published an advisory describing the Microsoft Windows® DejaBlue vulnerabilities in Drager products.

Friday, September 13, 2019

Bills Introduced – 09-12-19


Yesterday with both the House and Senate in session, there were 52 bills introduced. Of those, four will likely receive additional attention in this blog:

HR 4306 To require the Administrator of the Federal Railroad Administration to conduct an evaluation of the safety, security, and environmental risks of transporting liquefied natural gas by rail, and for other purposes. Rep. DeFazio, Peter A. [D-OR-4]

S 2469 A bill to amend title 49, United States Code, to require the use of advanced leak detection technology for pipelines, and for other purposes. Sen. Udall, Tom [D-NM]

S 2470 An original bill making appropriations for energy and water development and related agencies for the fiscal year ending September 30, 2020, and for other purposes. Sen. Alexander, Lamar [R-TN]

S 2474 An original bill making appropriations for the Department of Defense for the fiscal year ending September 30, 2020, and for other purposes. Sen. Shelby, Richard C. [R-AL]

DeFazio has been fighting a PHMSA special permit for shipping LNG by rail for a couple of months now. This appears to be the latest salvo.

Two of the three spending bills that were scheduled for this week were adopted in the Senate Appropriations Committee. The failure of the Committee to vote on the Labor, Health and Human Services, Education, and Related Agencies bill reflects the continuing problem the Congress is having with spending bills.

This is going to have an impact on how the Senate deals with the first House spending minibus (HR 2740) that passed in the House in June. Since that minibus included all three of the spending bills mentioned above, the Senate will not be able to take up HR 2740 and substitute language from their three bills (only two have been published). They can either substitute language from the two bills that were adopted by Committee and try to just amend the House language on the LHHE portion of the bill, or just wait until the Committee can reach an internal compromise that would allow the introduction of the Senate LHHE bill. I suspect the later will be the case. If this cannot be accomplished in the next week or so, we have no real chance of seeing spending bills sent to the President and will have to wait for a continuing resolution and an omnibus bill later in the year. Not looking forward to this, haven’t been all year.

6 Advisories Published – 09-12-19


Yesterday the DHS NCCIC-ICS published five control system security advisories for products from 3S and a medical device security advisory for products from Philips.

Communication Server Advisory


This advisory describes a detection of error condition without action vulnerability in the CODESYS V3 products containing a CODESYS communication server. The vulnerability was reported by Martin Hartmann from cirosec GmbH. 3S has a new version that mitigates the vulnerability. There is no indication that Hartmann has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to cause a denial-of-service condition.

OPC UA Server Advisory


This advisory describes a null pointer dereference vulnerability in the CODESYS Control V3 OPC UA Server. The vulnerability is self-reported. 3S has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial-of-service condition.

Online User Management Advisory


This advisory describes an incorrect permission assignment for critical resource vulnerability in the CODESYS Control V3 online user management. The vulnerability is apparently self-reported. 3S has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow unauthorized actors access to unintended functionality and/or information.

Library Manager Advisory


This advisory describes a cross-site scripting vulnerability in the CODESYS V3 Library Manager. The vulnerability was reported by Heinz Füglister of WRH Walter Reist Holding AG. 3S has a new version that mitigates the vulnerability. There is no indication that Füglister has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow malicious content from manipulated libraries to be displayed or executed.

Web Server Advisory


This advisory describes two vulnerabilities in the CODESYS V3 web server. The vulnerability was reported by Ivan Cheyrezy of Schneider Electric. 3S has new versions that mitigate the vulnerability. There is no indication that Cheyrezy has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Path traversal - CVE-2019-13532; and
Stack-based buffer overflow - CVE-2019-13548

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to create a denial-of-service condition, to perform remote code execution, or to access restricted files.

NOTE 1: It is good to see cooperative sharing of vulnerability information between vendors, but I suspect that Schneider reported these vulnerabilities because they found them in their own product that used the CODESYS web server as a third-party component of one or more of their products. It will be interesting to see how long it takes Schneider to report these vulnerabilities.

NOTE 2: 3S has not yet reported any of the vulnerabilities in the above advisories on their web site. They did, however, publish an advisory on another product earlier this week that I will discuss tomorrow.

Philips Advisory


This advisory describes two vulnerabilities in the Philips IntelliVue WLAN, portable patient monitors. The vulnerabilities were reported by Shawn Loveric of Finite State, Inc. One of the affected WLAN versions is out-of-support and will not receive mitigation actions. Philips intends to have a patch available by the end of the year.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerabilities to cause corruption of the IntelliVue WLAN firmware and impact to the data flow over the WLAN Version A and WLAN Version B wireless modules. This would lead to an inoperative condition alert at the device and Central Station. The Phillips Advisory reports that it would take “an unauthorized user with a high skill level and access to the device’s local area network” to exploit the vulnerabilities.

Thursday, September 12, 2019

HR 4091 Introduced – ARPA-E Reauthorization


Last month Rep. Johnson (D,TX) introduced HR 4091, the ARPA–E Reauthorization Act of 2019. In addition to reauthorizing the DOE Advanced Research Projects Agency—Energy, it expands the goals of ARPA-E to include security.

Security Goal


The bill would amend 42 USC 16538(c)(1)(A) by adding a new subparagraph (v):

(v) improve the resilience, reliability, and security of infrastructure to produce, deliver, and store energy; and

There is no other discussion of ‘security’ within the bill and no definitions are provided.

Moving Forward


Johnson is the Chair of the House Science, Space, and Technology Committee to which this bill was assigned for consideration. There are 29 cosponsors to the bill; only two of those are Republicans and neither are on the Committee.

The bill was considered by the Energy Subcommittee yesterday and ordered reported favorably to the full Committee by a voice vote. One amendment was considered; a Republican amendment to reduce the amounts of monies authorized for Energy Transformation Acceleration Fund. The amendment failed on a voice vote.

Commentary


It would make some sense to me that when adding a goal to an agency mission one should ensure that the purpose of that goal is clearly defined. With that in mind, I would like to propose the addition of the following definition to §16538:

Section 16538(a) is amended by adding subparagraph (4):
“(4) Security – The term ‘security’ means measures undertaken to prevent, identify or respond to:
(i) unauthorized physical access to facilities;
(ii) the unauthorized application of force against, or direction of energy at, a facility with the intent to disrupt operations of the facility; or
(iii) to protect against cybersecurity threats as that term is defined in 6 USC 1501.

This definition would make it clear that AREPA-E funded investigations could address the full range of security measure to protect energy product, storage or transmission facilities, including measures to prevent/mitigate cyberattacks and electromagnetic pulse attacks.

Bills Introduced – 09-11-19


Yesterday with both the House and Senate in session, there were 29 bills introduced. One of these bills may receive additional attention in this blog:

S 2466 A bill to provide supplemental appropriations for safe and secure water, and for other purposes. Sen. Harris, Kamala D. [D-CA] 

While I suspect that the ‘secure water’ mentioned in the description of this bill refers to water supply security not cybersecurity or chemical security at water treatment facilities, I could be wrong.

OMB Approves PHMSA Pipeline Safety Rule – 09-11-19


Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a final rule from the DOT’s Pipeline and Hazardous Material Safety Administration (PHMSA) that would expand certain pipeline safety requirements for gas transmission pipelines. The notice of proposed rulemaking (NPRM) for this rule was published in April 2016.

According to the abstract for this rulemaking published in the Spring 2019 Unified Agenda:

“This rulemaking amends the pipeline safety regulations to address the testing and pressure reconfirmation of certain previously untested gas transmission pipelines and certain gas transmission pipelines with inadequate records, require operators incorporate seismicity into their risk analysis and data integration, require the reporting of maximum allowable operating pressure exceedances, allow a 6-month extension of integrity management reassessment intervals with notice, and expand integrity assessments outside of high consequence areas to other populated areas.”

There is no telling how long it will take PHMSA to publish this final rule in the Federal Register. Agencies in the Trump Administration have been taking longer than the historical norm to publish regulations.

 
/* Use this with templates/template-twocol.html */