Tuesday, April 7, 2020

S 3506 Introduced – CFATS Extension


Last month Sen Lankford (R,OK) introduced S 3506, the Chemical Facility Anti-Terrorism Standards Program Extension Act of 2020. This bill was intended to provide a short-term extension of the CFATS program through July 18th, 2020.

Moving Forward


While Lankford is a sub-committee chair in the Senate Homeland Security and Governmental Affairs Committee, the committee to which this bill was assigned for consideration, future consideration of this bill has been made problematic since another short-term extension was provided for the program in HR 748 (PL 116-136). That bill extended the program authorization through July 23rd, 2020.

Commentary


This bill was introduced three days after the House passed HR 6160, a longer-term extension of the CFATS program. That bill would extend the authorization for the program through April 18th, 2020. The shorter extension in S 3506 would have given the Republican leadership another chance to get S 3416 through Committee and onto the floor of the Senate. Unfortunately, I think the COVID-19 problems are going to effectively block any controversial bills from consideration in the Senate for the remainder of the session.

The only CFATS bill that appears to have any chance of making it to the President is HR 6160. This kicks the can to the 117th Congress. That Congress (which could be dominated by the Democrats in both the House and Senate) will be focused on re-building the economy after the pandemic has run its course. I expect that the CFATS program is going to run on short term extensions for a while.

There is still a possible monkey wrench that could disable the program. While CFATS generally has wide spread support in Congress, the President’s 2021 budget request proposed shutting down the program and moving the chemical security inspectors into protective security advisor slots. If Trump is serious about closing the CFATS program, then a veto of HR 6160 would certainly be an easy way to do that. I suspect that partisanship in the Senate would overcome CFATS support in preventing an override of that veto.

Rep Thompson (D,MS), Chair of the House Homeland Security Committee, is well aware of the President’s stated opposition to the CFATS program (any regulatory program for that matter) so we may see another short-term reauthorization in the inevitable next COVID-19 relief bill. That extension would probably carry through October 1st so that repeated CFATS extensions could go back into the DHS spending bill or continuing resolutions where they resided for so many years.

Monday, April 6, 2020

CFATS PSP Instructions Not Available 4-6-20


Today the Chemical Facility Anti-Terrorism Standards (CFATS) program landing page was updated with a reference to the signing into law of the  Coronavirus Aid, Relief, and Economic Security (CARES) Act. That act extended the CFATS program authorization until July 23rd, 2020. As is usual when this page is updated, I went back and reviewed some of the sub-pages to the web site, looking for changes. Instead of finding any significant changes I found that there was no longer any actual link to the Personnel Surety Program (PSP) instruction book. This would be the Chemical Security Assessment Tool (CSAT) manual for completing the PSP program submissions.

There are two different paths that people should be able to use to get to the PSP manual. Both start on the landing page. The first (and shorter path) goes:

3. Guidance Document  back to #2.

The second path goes:

5. Guidance Document back to #4

The unintended loop set up by the ‘Guidance Document’ (different links for the two apparently identical versions) in the two paths is what prevents folks from getting to the actual document. None of the other CSAT instruction manuals have a ‘Guidance Document’ link. That makes a certain amount of sense since these are not (for the most part) guidance documents, but instructions for using the on-line tools. Why the PSP instructions need the guidance document disclaimer is not clear.

I cannot tell when this manual became unavailable. For the most part DHS stopped dating their web site pages some time ago. Because of the involvement of the ‘Guidance Document’ linkage in the problem, I suspect that this dates back to the DHS implementation of Executive Order 13,891, Promoting the Rule of Law Through Improved Agency Guidance Documents, in February of this year.

By the way, I went back to the latest link that I have for the document and that returns a ‘Page Not Found’ page. This is unusual, these older links typically remain active for quite some time.

HR 6395 Introduced – FY 2021 NDAA


Last month before the House left for their extended COVID-19 recess, Rep Smith introduced HR 6395, the National Defense Authorization Act for Fiscal Year 2021. This bill is one of the ‘must pass’ bills that Congress will have to deal with this year.

The version of the bill introduced is not complete. For the purpose of this blog an important missing piece is Title XVI of Division A, Strategic Programs, Cyber, and Intelligence Matters. It is expected that subsequent markups of the bill by both subcommittees of, and the full, House Armed Services Committee will fill in the missing pieces.

As introduced, there are no cyber provisions within HR 6395.

Saturday, April 4, 2020

Public ICS Disclosures – Week of 3-28-20


This week we have eight vendor disclosures for products from PEPPERL+FUCHS, ABB (4), B&R Automation, GE Digital and BD and updates for two previous vendor disclosures from 3S.

PEPPERL+FUCHS Advisory


VDE CERT published an advisory describing a time-of-check time-of-use race condition vulnerability in the PEPPERL+FUCHS Tab-Ex 02 mobile device. This is the third party 'Kr00k' vulnerability affecting encrypted WiFi traffic and PEPPERL+FUCHS reports that this is the only device of theirs that is vulnerable. PEPPERL+FUCHS plans on releasing an update to mitigate this vulnerability in May 2020.

NOTE: This vulnerability affects a variety of Broadcom and Cypress chipsets.

ABB Advisories


ABB published an advisory describing two weak file permission vulnerabilities in their System 800xA. The vulnerabilities were reported by William Knowles at Applied Risk. ABB has new versions that mitigate the vulnerability. There is no indication that Knowles has been provided an opportunity to verify the efficacy of the fix.


ABB published an advisory describing four vulnerabilities in their Telephone Gateway. The vulnerabilities were reported by Maxim Rupp. The product was phased out in 2015 and there are no plans to mitigate the vulnerability.

The four reported vulnerabilities are:

• Improper authentication and access control - CVE-2019-19104;
• Unprotected storage of credentials - CVE-2019-19105;
• Permissions, privileges and access control - CVE-2019-19106; and
• Information exposure - CVE-2019-19107


ABB published an advisory describing a remote code execution vulnerability in their System 800xA information manager. The vulnerability was reported by William Knowles at Applied Risk. An update to mitigate this vulnerability will be included in the next product release.


ABB published an advisory describing a weak registries permission vulnerability in their System 800xA. The vulnerability was reported by William Knowles at Applied Risk. ABB has a new version that mitigates the vulnerability. There is no indication that Knowles has been provided an opportunity to verify the efficacy of the fix.

B&R Advisory


B&R published an advisory describing a race condition vulnerability in a variety of their products. This is the third-party vulnerability, the Intel TPM Fail. B&R has bios patches available to mitigate the vulnerability.

GE Advisory


GE published an advisory describing a privilege escalation vulnerability in their CIMPLICITY HMI/SCADA product. The vulnerability was reported by Claroty. GE has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

BD Advisory


BD published an advisory describing three remote code execution vulnerabilities on a variety of BD products. These are third-party Microsoft vulnerabilities in the Remote Desktop services. BD reports that it is currently working to test and validate the Microsoft patch for their products.

The three reported vulnerabilities (links are to MS reports on the vulnerability) are:

CVE-2020-0610; and

3S Updates


3S published an update [.PDF download link] for an advisory that was originally published on March 25th, 2020. The new information includes reporting the availability of publicly available proof-of-concept exploit code that I reported last week.


3S published an update [.PDF download link] for an advisory that was originally published on March 25th, 2020. The new information includes reporting the availability of publicly available proof-of-concept exploit code that I reported last week.

Commentary


There are a lot of ‘third-party’ vulnerabilities being reported this week; all in systems that are likely to be found in products from other vendors. This is especially true when the ‘third-party’ is a major player like Intel or Microsoft.

Thursday, April 2, 2020

1 Advisory Published – 4-2-20


Today the CISA NCCIC-ICS published a control system security advisory for products from B&R Automation.

B&R Advisory


This advisory describes three vulnerabilities in the B&R Automation Studio. The vulnerabilities were reported by Nadav Erez of Claroty. B&R has new versions that mitigate the vulnerabilities. There is no indication that Erez has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Improper privilege management - CVE-2019-19100;
• Missing required cryptographic step - CVE-2019-19101; and
• Path traversal - CVE-2019-19102

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to  allow an attacker to delete arbitrary files from this system, fetch arbitrary files, or perform arbitrary write operations.

Wednesday, April 1, 2020

TSA Publishes Surface Transport Security Training Rule


Last week the Transportation Security Agency published a final rule in the Federal Register (85 FR 16456-16517) on “Security Training for Surface Transportation Employees”. The NPRM for this rule was published in January 2017. The rule requires owner/operators of higher-risk freight railroad carriers, public transportation agencies, passenger railroad carriers, and over-the-road bus companies, to provide TSA-approved security training to employees performing security-sensitive functions.

The Rule


The rule would:

• Require security training for employees of higher-risk freight railroad carriers, public transportation agencies (including rail mass transit and bus systems), passenger railroad carriers, and over-the-road bus (OTRB) companies;
• Owner/operators of these higher-risk railroads, systems, and companies would be required to train employees performing security-sensitive functions, using a curriculum addressing preparedness and how to observe, assess, and respond to terrorist-related threats and/or incidents;
• Require affected owner/operators to submit their training programs to TSA for approval;
• Expand current requirements for rail security coordinators and reporting of significant security concerns (currently limited to freight railroads, passenger railroads, and the rail operations of public transportation systems) to include the bus components of higher-risk public transportation systems and higher-risk OTRB companies;
• Make the maritime and land transportation provisions of TSA's regulations consistent with other TSA regulations by codifying general responsibility to comply with security requirements; compliance, inspection, and enforcement; and procedures to request alternate measures for compliance;
• Add a definition for Transportation Security-Sensitive Materials (TSSM); and
• Other provisions are being amended or added, as necessary, to implement these additional requirements.

Changes made from the proposed language in the NPRM include:

• TSA is modifying the recurrent security training schedule to a three-year cycle rather than annual.
• Changes to security programs and plans may require training certain employees within 90 days of the changes.
• The final rule includes a specific list of the types of changes that would trigger the need to update the security training program.
• The final rule requires an amendment to the approved security training program to be requested no later than 65 days after the change to the security program/measures/plans takes effect.
• Final rule limits the scope of the security coordinator requirement to rail operations of public transportation agencies and the bus-only operations of those determined by TSA to be higher-risk.
• Final rule limits the scope of the reporting security issues requirement to rail operations of public transportation agencies and the bus-only operations of those determined by TSA to be higher-risk.

Effective Date


The effective date for this rulemaking is June 22nd, 2020. Effective dates for specific provisions include:

• Deadline for notifying TSA of applicability determination (1570.105) – July 22nd, 2020;
• Deadline for providing security coordinator information to TSA (1570.201) – July 29th, 2020;
• Deadline for submission of security training program to TSA for approval (1570.109(b)) – October 28th, 2020;
• TSA approval or notification of required modification (1570.109(c)) – 60-days from receipt;
• Initial training of security-sensitive employees (1570.111(a)) – 1-year from TSA approval;
• Recurrent training of security-sensitive employees (1570.111(b)) – 3-years from initial training.

Cybersecurity


There is an interesting mention of cybersecurity in the preamble to the bill. In response to a commenters question about whether a ‘cyber-expert’ would be considered an ‘employee in a security-sensitive position’, the TSA responded:

“A cyber-expert may be considered a security-sensitive employee based upon specific job functions, such as functions involving control or movement of trains, or because of other cyber-security responsibilities related to the owner/operators security measures in its security plan to protect the integrity of its information systems.”

Commentary


It is interesting that the TSA used the congressional mandate for this rulemaking as a response/justification to several commenters’ questions and objections in the formulation of this final rule. The fact that TSA’s hands were tied in a lot instances by the congressional mandate was grandly ignored in one specific instance. In 6 USC 1137(c)(6) (and similarly in §1167 and §1184) Congress required as one of the elements of the mandated training:

“Training related to behavioral and psychological understanding of, and responses to, terrorist incidents, including the ability to cope with hijacker behavior, and passenger responses.”

That training requirement is conspicuously absent from the requirements in this rulemaking. To be sure, this requirement would have been difficult and time consuming to have been adequately, much less effectively, addressed in a training program, but it was a ‘congressional mandate’; no matter how inappropriate. If that one could be ignored, so could have all of the others.

Tuesday, March 31, 2020

3 Advisories and 1 Update Published – 3-31-20


Today the CISA NCCIC-ICS published two control system security advisories for products from Mitsubishi Electric and Hirschmann Automation and a medical device security advisory for products from BD. They also updates an advisory for products from Schneider Electric.

Mitsubishi Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the Mitsubishi MELSEC programmable controllers with MELSOFT transmission port (UDP/IP). The vulnerability was reported by Rongkuan Ma, Jie Meng, and Peng Cheng. Mitsubishi provided generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to render the device unresponsive.

Hirschmann Advisory


This advisory describes a classic buffer-overflow vulnerability in the Hirschmann HiOS, HiSecOS. The vulnerability was reported by Sebastian Krause and Toralf Gimpel of GAI NetConsult. Hirschmann has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an unauthenticated, remote attacker to overflow a buffer and fully compromise the device.

NOTE: The NCCIC-ICS advisory is actually based on a second revision of the Belden advisory that was originally reported originally published on February 14th, 2020 and most recently updated on February 26th, 2020. The most recently added information from Belden is the CVE number and link.

BD Advisory


This advisory describes a protection mechanism failure vulnerability in the BD Pyxis MedStation and Pyxis Anesthesia (PAS) ES System. The vulnerability is self-reported. BD provides generic workarounds to mitigate the vulnerability. The BD advisory states that they are in the process of deploying a security update that strengthens kiosk mode to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with physical access could exploit the vulnerability to allow an attacker to bypass kiosk mode and view and/or modify sensitive data.

Schneider Update


This update provides additional information on an advisory that was originally published on January 16th, 2020. The new information includes an updated CVSS score for CVE-2018-7794.

 
/* Use this with templates/template-twocol.html */