Thursday, May 7, 2020

1 Advisory Published – 5-7-20


Today the CISA NCCIC-ICS published a control system security advisory for products from Advantech.

Advantech Advisory

This advisory describes eight vulnerabilities in the Advantech WebAccess Node. The vulnerabilities were reported by Natnael Samson and Z0mb1E via the Zero Day Initiative. Advantech has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The eight reported vulnerabilities:

• Improper validation of array index - CVE-2020-12022,
• Relative path traversal - CVE-2020-12010, CVE-2020-12006,
• SQL injection - CVE-2020-12014,
• Stack-based buffer overflow - CVE-2020-12002,
• Heap-based buffer overflow - CVE-2020-10638, and
• Out-of-bounds read - CVE-2020-12018

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow information disclosure, remote code execution, and compromise system availability.

Tuesday, May 5, 2020

2 Advisories Published – 5-5-20


Today the CISA NCCIC-ICS published two control system security advisories for products from SAE IT-systems and Fazecast.

SAE Advisory 


This advisory describes two vulnerabilities in the SAE FW-50 RTU modular telecontrol system. The vulnerabilities were reported by Murat Aydemir of Biznet Bilisim. SAE has a new CPU card that mitigates the vulnerability.

The two reported vulnerabilities are:

• Cross-site scripting - CVE-2020-10630; and
• Path traversal - CVE-2020-10634

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to execute remote code, disclose sensitive information, or cause a denial-of-service condition.

NOTE: Is it just me, or does replacing a CPU to fix a programming problem seem to be just a tiny bit of overkill?

Fazecast Advisory  


This advisory describes an uncontrolled search path element vulnerability in the Fazecast jSerialComm, a platform-independent serial port access library for Java. The advisory reports that this vulnerability (presumably as a third-party vuln) also affects the Schneider EcoStruxure IT Gateway (no Schneider advisory has been published yet). The vulnerability was reported by Ryan Wincey of Securifera via the Zero Day Initiative. Fazecast (and Schneider) has a new version that mitigates the vulnerability. There is no indication that Wincey has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an unauthenticated attacker to execute arbitrary code on a targeted system.

NOTE: It seems strange to see a library vulnerability advisory including the mention of an affected vendor on the day of the initial release. I suppose that Fazecast told either ZDI or NCCIC-ICS who their customers were so that NCCIC-ICS could contact them about the vulnerability. It will be interesting to see what (if) other vendors are using this Java library.

ISCD Publishes New CFATS FAQ – 05-05-20


Today the CISA Infrastructure Security Compliance Division (ISCD) published a new frequently asked question (and response) on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center. FAQ #1795 addresses the requirement for facilities to conduct annual audits of their site security plan (or alternate security plan as appropriate).

The new FAQ


FAQ #1795 - When is a covered facility required to conduct a Site Security Plan/Alternative Security Program (SSP/ASP) Audit?

Answer - A covered facility must conduct an audit of its compliance with its SSP/ASP no later than one year after the date of the SSP/ASP approval. Thereafter, it must conduct its annual audit no later than one year after the date of its previous audit.

Commentary


It is just a little bit odd that the response does not include a reference. There is no law requiring a FAQ response to quote the appropriate place in the regulation or statute that provides the quoted mandate, but ISCD has been very good (almost compulsive) about including such references. For the record 6 CFR 27.225(e) contains the requirement for a facility to “conduct an annual audit of its compliance with its Site Security Plan.” All FAQ #1795 does is inserts a common regulatory definition of the term ‘annual’ in that requirement.

There is no listing in the ‘Latest News’ section of the Knowledge Center announcing the new FAQ. We will probably see on later this week.

NOTE: A couple of weeks back CISA started to add revision dates back to the web pages on the CFATS web site. Instead of putting a ‘last changed’ date on the bottom of the page as the standard used-to-be, CISA is adding an ‘Original Release Date: Last Revised:’ line just below the page title. I am glad to see them doing this. It makes it easier for gadflies like me to keep up with the changes.

BTW: The CFATS Knowledge Center page does not have the dateline added yet.

Sunday, May 3, 2020

EO 13920 Published – Protecting the Grid


The White House published EO 13920 in Monday’s (available online Saturday) Federal Register (85 FR 26595-26599) addressing “Securing the United States Bulk-Power System”. The EO provides the Secretary of Energy the authority to prohibit the use of foreign made electric equipment in the US bulk-power system.

To justify the authority, the EO explains that:

• The bulk-power system is a target of those seeking to commit malicious acts against the United States and its people; and
• The unrestricted acquisition or use in the United States of bulk-power system electric equipment designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of foreign adversaries augments the ability of foreign adversaries to create and exploit vulnerabilities in bulk-power system electric equipment.

The President then states:

“I therefore determine that the unrestricted foreign supply of bulk-power system electric equipment constitutes an unusual and extraordinary threat to the national security, foreign policy, and economy of the United States, which has its source in whole or in substantial part outside the United States. This threat exists both in the case of individual acquisitions and when acquisitions are considered as a class. Although maintaining an open investment climate in bulk-power system electric equipment, and in the United States economy more generally, is important for the overall growth and prosperity of the United States, such openness must be balanced with the need to protect our Nation against a critical national security threat. To address this threat, additional steps are required to protect the security, integrity, and reliability of bulk-power system electric equipment used in the United States. In light of these findings, I hereby declare a national emergency with respect to the threat to the United States bulk-power system.”

Prohibitions


Section 1(a) of the EO prohibits “any acquisition, importation, transfer, or installation of any bulk-power system electric equipment” where the Secretary of Energy (in consultation with the Director of OMB) finds that “the transaction involves bulk-power system electric equipment designed, developed, manufactured, or supplied, by persons owned by, controlled by, or subject to the jurisdiction or direction of a foreign adversary” and the transaction:

• Poses an undue risk of sabotage to or subversion of the design, integrity, manufacturing, production, distribution, installation, operation, or maintenance of the bulk-power system in the United States;
• Poses an undue risk of catastrophic effects on the security or resiliency of United States critical infrastructure or the economy of the United States; or
• Otherwise poses an unacceptable risk to the national security of the United States or the security and safety of United States persons.

Designated Actions


Section 1(b) allows the Secretary to “design or negotiate measures to mitigate concerns identified under section 1(a)” and use such measures as a precondition to approvals of transactions that would otherwise be prohibited.

Section 2(a) authorizes the Secretary to:

• Direct the timing and manner of the cessation of pending and future transactions prohibited pursuant to section 1 of this order,
• Adopt appropriate rules and regulations, and
• Employing all other powers granted to the President by the International Emergency Economic Powers Act (50 USC 1701 et seq.; IEEPA) as may be necessary to implement this order.

Section 2(b) directs the Secretary to issue rules and regulations implementing this EO. Those would include rules or regulation that would:

• Determine that particular countries or persons are foreign adversaries exclusively for the purposes of this order;
• Identify persons owned by, controlled by, or subject to the jurisdiction or direction of foreign adversaries exclusively for the purposes of this order;
• Identify particular equipment or countries with respect to which transactions involving bulk-power system electric equipment warrant particular scrutiny under the provisions of this order;
• Establish procedures to license transactions otherwise prohibited pursuant to this order; and
• Identify a mechanism and relevant factors for the negotiation of agreements to mitigate concerns raised in connection with subsection 1(a) of this order.

Section 2(d)(i) directs the Secretary to “identify bulk-power system electric equipment designed, developed, manufactured, or supplied, by persons owned by, controlled by, or subject to the jurisdiction or direction of a foreign adversary that poses an undue risk of sabotage to or subversion of the design, integrity, manufacturing, production, distribution, installation, operation, or maintenance of the bulk-power system in the United States” that:

• Poses an undue risk of catastrophic effects on the security or resiliency of United States critical infrastructure or the economy of the United States, or
• Otherwise poses an unacceptable risk to the national security of the United States or the security and safety of United States persons.

Task Force Established


Section 3 establishes the Task Force on Federal Energy Infrastructure Procurement Policies Related to National Security. The Task Force will be chaired by the Secretary and include representatives from at least six listed federal agencies. The Task Force will:

• Develop a recommended consistent set of energy infrastructure procurement policies and procedures for agencies, to the extent consistent with law, to ensure that national security considerations are fully integrated across the Federal Government, and submit such recommendations to the Federal Acquisition Regulatory Council (FAR Council);
• Evaluate the methods and criteria used to incorporate national security considerations into energy security and cybersecurity policymaking;
• Consult with the Electricity Subsector Coordinating Council and the Oil and Natural Gas Subsector Coordinating Council in developing the recommendations and evaluation described in subsections (c)(i) through (ii) of this section; and
• Conduct any other studies, develop any other recommendations, and submit any such studies and recommendations to the President, as appropriate and as directed by the Secretary.

Definitions


Section 4 provides definitions for key terms used in this EO. The terms defined include:

• Bulk-power system,
• Bulk-power system electric equipment,
• Entity,
• Foreign adversary,
• Person,
• Procurement, and
• United States person

Most of these definitions are generic descriptions of standard regulatory terms. The interesting exception is the term ‘Bulk-power system electric equipment’. This definition starts off with a lengthy list of industrial power equipment that includes:

• Reactors,
• Capacitors,
• Substation transformers,
• Current coupling capacitors,
• Large generators,
• Backup generators,
• Substation voltage regulators,
• Shunt capacitor equipment,
• Automatic circuit reclosers,
• Instrument transformers,
• Coupling capacity voltage transformers,
• Protective relaying,
• Metering equipment,
• High voltage circuit breakers,
• Generation turbines,
• Industrial control systems,
• Distributed control systems, and
• Safety instrumented systems.

The definition then concludes by stating that: “Items not included in the preceding list and that have broader application of use beyond the bulk-power system are outside the scope of this order.” Thus, communications equipment, security software and access control systems, for example, could not be addressed under this Executive Order.

Commentary


It seems clear to me that this EO is primarily directed at limiting the spread of Chinese equipment in the bulk-power system; certainly the President is not concerned with US companies using equipment made in North Korea or Iran, or designed by Hezbollah. Unfortunately, failing to actually name the Chinese government as the intended foreign adversary paves the way for this EO to be used in a wide variety of trade disputes around the world.

It is particularly odd that the President is providing the Secretary of Energy with broad powers (employing all other powers granted to the President) under IEEPA. Those authorities include levying economic sanctions and taking control of foreign owned property and assets within the United States. Those authorities are typically limited to the State Department or Treasury Department. Providing blanket authority to the Secretary of Energy in this way greatly expands the reach of the Energy Department well beyond that defined by Congress.

One final oddity here, the distressing lack of discussion of cybersecurity issues. There is only a single mention of cybersecurity in the EO and that is in describing the duties of the Task Force; “evaluate the methods and criteria used to incorporate national security considerations into energy security and cybersecurity policymaking”. Certainly, a major portion of the perceived threat is via cyber attacks on components of the bulk-power systems. Failure to specifically require the Secretary to address those concerns in consultation with the Cybersecurity and Infrastructure Security Agency is a major oversight in this EO.

Saturday, May 2, 2020

Public ICS Disclosures – Week of April 25th, 2020


This week we have two vendor disclosures for products from Moxa and BD. We also have one researcher disclosure for products from Flexera.

Moxa Advisory


Moxa published an advisory describing an unauthenticated information disclosure vulnerability in their NPort 5100A Series Serial Device Servers. The vulnerability was reported by Maayan Fishelov from SCADAfence. Moxa has a new firmware version that mitigates the vulnerability. There is no indication that Fishelov has been provided an opportunity to verify the efficacy of the fix.

BD Advisory


BD published an advisory describing a third-party scripting engine memory corruption vulnerability affecting their product line. The Internet Explorer® vulnerability was reported and fixed by Microsoft in February 2020. BD is currently working to test and validate the Microsoft patch for BD products.

Flexera Advisory


Tenable published a report describing an  improper validation of user-supplied data vulnerability in the Flexera FlexNet Publisher. This was a coordinated disclosure. Flexera has a new version that mitigates the vulnerability. The Tenable report includes proof-of-concept exploit code.

NOTE: This license management tool is used as a third-party component of many products, including some ICS products from vendors like Johnson Controls, Schneider Electric and Rockwell to name a few that have shown up invulnerability reports in the past. It will be interesting to see how fast we see the subsidiary reporting from those affected vendors.

Friday, May 1, 2020

TSA Extends Security Training Rule Deadlines


Today the Transportation Security Administration (TSA) published a final rule in the Federal Register (85 FR 25315-25317) delaying the effective date of the final rule entitled, “Security Training for Surface Transportation Employees” that was published on April 1st, 2020. TSA is taking this action because it has determined that covered entities may have difficulties complying with the published deadlines because of actions taken in response to the COVID-19 pandemic.

The effective date of the earlier rule is changed from June 22nd, 2020 to September 21st, 2020. As a result of this change the following deadlines within the earlier rule are also being changed. They include:

• Deadline for notifying TSA of applicability determination (1570.105) – from July 22nd, 2020 to October 21st, 2020;
• Deadline for providing security coordinator information (49 CFR 1570.201) – from July 29th, 2020 to October 28th, 2020; and
• Deadline for submission of security training program to TSA for approval (1570.109(b)) – September 20th, 2020 to December 21st, 2020.

Because of the nature of the changes made by this new final rule and the imminent nature of the impending deadlines, TSA determined that the normal rule making processes, including OMB review and the publish/public comment process, were not required.

HR 6527 Introduced – EPCRA Release Meetings


Earlier this month Rep Blunt-Rochester (D,DE) introduced HR 6527, the Alerting Localities of Environmental Risks and Threats Act of 2020. The bill would amend the Emergency Planning and Community Right-To-Know Act (EPCRA) of 1986 to require companies to hold public meetings after reportable releases and annual meetings about inventories of reportable substances.

Post Incident Meetings


Section 2(a) would amend 42 USC 11004(b) to add provisions requiring the holding of a public meeting for chemical releases that require reporting under §11004(a). A public notice for the meeting would be required to be published within 72 hours of the covered release providing 24-hour notice of the meeting. At the meeting the owner/operator would be required to discuss the information reportable under §11004(b)(2) subject to the trade secrets limitations set forth in §11042.

Annual Meetings


Section 2(b) would amend EPCRA by adding a new § 306, Annual Public Meeting. The new section would require each EPCRA covered facility to conduct an annual public meeting. The meeting would be required to provide information on {new §306(2)}:

• The chemical name of each substance on the list published under section 302(a) [42 USC 11002(a)] that was present at such facility, in an amount in excess of the threshold planning quantity established for such substance under such section, at any time in the preceding calendar year [see 40 CFR 355 Appendix A];
• An estimate of the maximum amount of each such substance present at such facility during the preceding calendar year; and
• The details of the methods and procedures to be followed to respond to a release of such a substance pursuant to the applicable emergency plan prepared under section 303(c) [42 USC 11003(c)].’’

The requirement to hold these annual meetings would be enforceable under 42 USC 110045(c)(1).

Moving Forward


Blunt-Rochester is a member of the House Energy and Commerce Committee to which this bill was assigned for consideration. This means that this bill could be considered in Committee. While there would be no Republican support for this bill, if it were considered, it would be approved. Since the bill would not receive bipartisan support as offered, the House would not take up the bill under the suspension of the rules process. It is unlikely that the full House would take up this bill under regular order.

Commentary


I think that this bill might receive some Republican support if the provisions for the annual meetings were removed. It would probably not be enough for the bill to be considered under the suspension of the rules process so this would not be enough to see the bill move forward.

I understand the reason for the annual meeting requirement in the bill and I think that some form of such a meeting would be an excellent idea. There is an interesting problem with the way this requirement is crafted, the emergency plan discussion required in the bill is not the responsibility of the covered facility. That emergency plan is required to be prepared by the local emergency planning committee. The way the bill is crafted the facility could be fined if it did not discuss a plan that had not been completed by the LEPC. To correct this potential problem, I would reword the new §306(2)(C) to read:

‘‘(C) The local emergency planning commission would be invited to explain the details of the methods and procedures to be followed to respond to a release of such a substance pursuant to the applicable emergency plan prepared under section 303(c).’’

 
/* Use this with templates/template-twocol.html */