Saturday, June 20, 2020

OMB Approves LNG by Rail Final Rule


Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a final rule from the DOT’s Pipeline and Hazardous Material Safety Administration (PHMSA) on “Hazardous Materials: Liquefied Natural Gas by Rail”. The rule was sent to OIRA for approval on May 1st. The notice of proposed rulemaking (NPRM) for this action was published in October 2019.

With the possibility becoming more pronounced that Trump may be a single-term President, we are starting to approach the time when an outgoing administration begins to worry about its legacy. Trump came into office as an anti-regulatory campaigner. While that has not generally changed, the Administration is becoming more prolific in writing permissive regulations that allow industry to take actions that were not previously allowed.

This rulemaking certainly fits that description and that is almost certainly the reason that we have seen such a quick turnaround of the final bill (less than six months since the end of the comment period) even with the large number of comments that were submitted in opposition to the proposed rule. The downside of this is that if Trump is not re-elected and the Republicans to not retain control of the Senate, this rulemaking would be a prime target for reversal under the Congressional Review Act of 1996.

Public ICS Disclosures – Week of 6-13-20


This week we have eight vendor disclosures (3 for the Ripple20 vulnerabilities) for products from Beckhoff, Moxa, Medtronic, GE Health, Draeger (2), Rockwell, and BD. There is also a researcher report of a zero-day for products from Inductive Automation.

Ripple20 Advisories


Medtronic published a Ripple20 advisory reporting no impact.

GE Healthcare published a Ripple20 advisory reporting no impact but advising that there may be possible impact to third party components used in combination with GE Healthcare products.

Draeger published a Ripple 20 advisory reporting no impact.

NOTE: “No impact” reports are valuable information. I think the GE nuanced ‘no impact’ report is important where the vendor software may be running on a machine that includes other non-vendor produced software (perhaps including OS?).

Beckhoff Advisory


CERT-VDE published an advisory describing an information leak vulnerability in the Beckhoff TwinCAT RT network driver. The vulnerability is self-reported. Beckhoff has patches that mitigate the vulnerability.

Moxa Advisory


Moxa published an advisory describing a stack-based buffer overflow vulnerability in their EDR-G902 Series and EDR-G903 Series Secure Routers. The vulnerability was reported by Tal Keren from Claroty. Moxa has new firmware to mitigate the vulnerability. There is no indication that Keren has been provided an opportunity to verify the efficacy of the fix.

Draeger Advisory


Draeger published an advisory describing an improper input validation vulnerability in their Perseus A500 product. The vulnerability is self-reported. Draeger has new software that mitigates the vulnerability.

Rockwell Vulnerability


Rockwell published an advisory describing a path traversal advisory in their FactoryTalk Linx software. This vulnerability was discovered in the ZDI Pwn2Own competition in this year’s S4 Security conference. Rockwell has a patch that mitigates the vulnerability.

NOTE: Rockwell reports that they had previously disclosed this vulnerability in an advisory that was published on June 11th, 2020. I suppose that the Pwn2Own announcement could have been included as an update to that advisory. This may be why NCCIC-ICS has not picked up this advisory.

BD Advisory


BD published an advisory describing a remote code execution vulnerability in a number of BD products that use the Microsoft Windows 10®. This is a third-party (MS) SMBv3 server vulnerability. BD is currently working to test and validate the Microsoft patch on the affected products.

Inductive Automation Advisory


The Zero Day Initiative published an advisory describing a deserialization of untrusted data information disclosure vulnerability in the Inductive Automation Ignition product. The vulnerability was reported by Chris Anastasio (muffin) and Steven Seeley (mr_me) of Incite Team. This vulnerability was discovered in the ZDI Pwn2Own competition in this year’s S4 Security conference and reported to the vendor. The vendor has not been able to provide an estimated fix date to either ZDI or NCCIC-ICS. This is effectively a zero-day vulnerability.

Friday, June 19, 2020

Bills Introduced – 6-18-20


Yesterday with the Senate in Washington and the House still meeting in pro forma session, there were 86 bills introduced. Of those there are three that may receive future coverage in this blog:

HR 7248 To authorize funds for Federal-aid highways, highway safety programs, and transit programs, and for other purposes. Rep. Graves, Sam [R-MO-6] 

HR 7264 To make supplemental appropriations for the Departments of Agriculture, the Interior, Homeland Security, Labor, and Commerce for the fiscal year ending September 30, 2020, and for other purposes. Rep. Neguse, Joe [D-CO-2]

HR 7265 To improve assistance provided by the Hollings Manufacturing Extension Partnership to small manufacturers in the defense industrial supply chain on matters relating to cybersecurity, and for other purposes. Rep. Panetta, Jimmy [D-CA-20] 

HR 7248 appears to be a Republican alternative DOT authorization bill. This bodes ill for the ‘INVEST in America Act” that the House Transportation and Infrastructure Committee completed marking up yesterday; Graves is the Ranking Member of that Committee. The House will have no problem passing the yet to be introduced Committee bill, but this Republican alternative would seem to indicate that the Committee language will have a hard time passing in the Senate.

I will be watching this bill (and the Committee version) for cybersecurity language for autonomous vehicles, chemical transportation safety issues, and LPG by rail languate.

HR 7264 would appear to be a bill providing additional COVID-19 related funding for the current fiscal year. I will be watching this bill in particular to see if it includes CFATS extension language (current authorization expires on July 23). I will also be watching for cybersecurity language.

11 Advisories and 1 Update Published – 6-18-20


Today the CISA NCCIC-ICS published five control system security advisories for products from Rockwell Automation (2), ICONICS, Mitsubishi Electric, and Johnson Controls; and six medical device security advisories for products from BD, BIOTRONIC and Baxter (6). They also updated the Treck TCP/IP advisory that was published earlier this week.

FactoryTalk View SE Advisory


This advisory describes four vulnerabilities in the Rockwell FactoryTalk View SE. The vulnerabilities were reported by the Zero Day Initiative. Rockwell has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Improper input validation - CVE-2020-12029,
• Improper restriction of operations within a memory buffer - CVE-2020-12031,
• Permissions, privileges, and access control - CVE-2020-12028, and
• Exposure of sensitive information to an unauthorized actor - CVE-2020-12027

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow a remote authenticated attacker to manipulate data of affected devices.

NOTE: These vulnerabilities were discovered in the Pwn-2-Own competition at this year’s S4 Security conference in Miami, Florida.

FactoryTalk Services Platform Advisory


This advisory describes an improper input validation vulnerability in the Rockwell FactoryTalk Services Platform. No vulnerability disclosure information is provided in the advisory. Rockwell provides generic mitigation measures.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an unauthenticated attacker to execute remote COM objects with elevated privileges.

NOTE: These vulnerabilities were discovered in the Pwn-2-Own competition at this year’s S4 Security conference in Miami, Florida.

ICONICS Advisory


This advisory describes five vulnerabilities in the ICONICS GENESIS64 and GENESIS32 products. The vulnerabilities were reported by Tobias Scharnowski, Niklas Breitfeld, Ali Abbasi, Yehuda Anikster of Claroty; Pedro Ribeiro and Radek Domanski of Flashback; Ben McBride of Oak Ridge National Laboratory; and Steven Seeley and Chris Anastasio of Incite. ICONICS has patches that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Out-of-bounds write - CVE-2020-12011,
• Deserialization of untrusted data (3) - CVE-2020-12015, CVE-2020-12009, and CVE-2020-12007, and
• Code injection - CVE-2020-12013

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow remote code execution or denial of service.

NOTE: ICONICS takes an unusual approach to the publication of security advisories. The two separate product advisories for this NCCIC-ICS report (GENESIS64 and GENESIS32) contains summaries of all the vulnerabilities reported to/by NCCIC-ICS (and its predecessor, ICS-CERT) since 2011. If/when new vulnerabilities are reported, they are added to the respective product vulnerability report.

Mitsubishi Advisory


This advisory describes five vulnerabilities in the Mitsubishi MC Works64 MC Works32 products. The vulnerabilities were reported by Tobias Scharnowski, Niklas Breitfeld, Ali Abbasi, Yehuda Anikster of Claroty; Pedro Ribeiro and Radek Domanski of Flashback; Ben McBride of Oak Ridge National Laboratory; and Steven Seeley and Chris Anastasio of Incite. Mitsubishi has patches that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Out-of-bounds write - CVE-2020-12011,
• Deserialization of untrusted data (3) - CVE-2020-12015, CVE-2020-12009, and CVE-2020-12007, and
• Code injection - CVE-2020-12013

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit these vulnerabilities to allow remote code execution, a denial-of-service condition, information disclosure, or information tampering.

NOTE 1: The reporting information and CVE numbers indicate that these are the same vulnerabilities reported in the ICONICS advisory above. It is interesting to note the differing exploit information in the two advisories.

NOTE 2: Mitsubishi now has a publicly available PSIRT page.

Johnson Controls Advisory


This advisory describes an improper verification of cryptographic signature vulnerability in the Johnson Controls exacqVision product. The vulnerability was reported by Michael Norris. Johnson Controls has newer versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow the execution of operating system commands on the system. It would seem that [IMO] a social engineering attack would be required to cause a person with administrative privileges to potentially download and run a malicious executable.

BD Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the BD Alaris PCU. The vulnerability is self-reported. BD provides generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial of service (DoS) on the target system and could cause the BD Alaris PCU to disconnect from the facility’s wireless network.

NOTE: This vulnerability is one of three SACK vulnerabilities reported in the FreeBSD and Linux kernels. It would seem to me that the other two vulnerabilities might also be found in this product.

BIOTRONIK Advisory


This advisory describes five vulnerabilities in the BIOTRONIK CardioMessenger II-S T-Line and CardioMessenger II-S GSM products. The vulnerabilities were reported by Guillaume Bour, Anniken Wium Lie, and Marie Moe. BIOTRONIK has provided generic workarounds to mitigate the vulnerability.

The five reported vulnerabilities are:

• Improper authentication (2) - CVE-2019-18246 and CVE-2019-18252,
• Cleartext transmission of sensitive information - CVE-2019-18248,
• Missing encryption of sensitive data - CVE-2019-18254, and
• Storing passwords in an accessible format - CVE-2019-18256

NCCIC-ICS reports that a relatively low-skilled attacker with physical access to the device could exploit the vulnerabilities to obtain sensitive data, obtain transmitted medical data from implanted cardiac devices with the implant’s serial number or impact Cardio Messenger II product functionality. The same attacker with adjacent access could exploit the vulnerabilities to allow an attacker with adjacent access to influence communications between the Home Monitoring Unit (HMU) and the Access Point Name (APN) gateway network.

NOTE: See this TWITTER thread by Marie Moe about this advisory.

Sigma Spectrum Infusion Pump Advisory


This advisory describes six vulnerabilities in the Baxter Sigma Spectrum Infusion systems. The vulnerabilities are self-reported. Baxter provided generic workarounds to mitigate the vulnerabilities.

The six reported vulnerabilities are:

• Use of hard-coded passwords (3) - CVE-2020-12039, CVE-2020-12045 and CVE-2020-12047,
• Cleartext transmission of sensitive data - CVE-2020-12040,
• Incorrect permission assignment for critical resource - CVE-2020-12041, and
• Operation on a resource after expiration or release - CVE-2020-12043

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow access to sensitive data, alteration of system configuration, and impact to system availability.

NOTE: NCCIC-ICS did not provide a link to the related Baxter advisory.

Phoenix Hemodialysis Advisory


This advisory describes a cleartext transmission of sensitive information vulnerability in the Baxter Phoenix Hemodialysis Delivery System. This vulnerability is self-reported. Baxter provides generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to view sensitive data.

NOTE: NCCIC-ICS did not provide a link to the related Baxter advisory.

PrismaFlex Advisory


This advisory describes three vulnerabilities in the Baxter PrismaFlex and PrisMax medical systems. The vulnerabilities are self-reported. Baxter has new versions that mitigate the vulnerabilities.

The three reported vulnerabilities are:

• Cleartext transmission of sensitive information - CVE-2020-12036;
• Improper authentication - CVE-2020-12035, and
• Use of hard-coded passwords - CVE-2020-12037

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to view and alter sensitive data.

NOTE: NCCIC-ICS did not provide a link to the related Baxter advisory.

ExactaMix Advisory


This advisory describes seven vulnerabilities in the Baxter Baxter ExactaMix systems. The vulnerabilities are self-reported. Baxter has new versions that mitigate the vulnerabilities.

The seven reported vulnerabilities are:

• Use of hard-coded password (2) - CVE-2020-12016 and CVE-2020-12012,
• Cleartext transmission of sensitive information - CVE-2020-12008,
• Missing encryption of sensitive data - CVE-2020-12032,
• Improper access control - CVE-2020-12024,
• Exposure of resource to wrong sphere - CVE-2020-12020, and
• Improper input validation - CVE-2017-0143

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow unauthorized access to sensitive data, alteration of system configuration, alteration of system resources, and impact to system availability.

NOTE: NCCIC-ICS did not provide a link to the related Baxter advisory.

Treck Update


This update provides additional information on an advisory that was originally published on June 16th, 2020. The new information is a link to the Baxter advisory on the issue.

Thursday, June 18, 2020

NTIA Software Component Transparency Meeting – 7-9-10


The DOC National Telecommunications and Information Administration (NTIA) published a meeting notice in the Federal Register (85 FR 36837-36838) for the next meeting of the “Multistakeholder Process on Promoting Software Component Transparency”. The virtual meeting will be held on July 9th, 2020 and will be open to the public.

The purpose of the July meeting is to share progress from the working groups; to give feedback on the ongoing work around technical challenges, tooling, demonstrations, and awareness and adoption; and to continue discussions around potential guidance or playbook documents. The Working Groups include:

Framing,

Information on online slide share and dial-in details will be available on the Software Transparency web site.

Wednesday, June 17, 2020

S 3688 – Energy Infrastructure Security – Miscellaneous Provisions


This is the fifth in a series of posts about the introduction of S 3688, the Energy Infrastructure Protection Act of 2020. The earlier posts in the series were:

S 3688 Introduced – Energy Infrastructure Security
            S 3688 – Energy Infrastructure Security – Security Assistance to Energy Infrastructure
S 3688 – Energy Infrastructure Security – CEII disclosure authorization
In this blog post I will look at the last three sections that bill would add to the Federal Power Act:

§235. Designating information held by other governmental authorities,
§236. Wartime clearance,
§237. Enforcement and sanctions

Government Requests for CEII Designation


Section 235 establishes the procedures that will be used by eligible government entities to request the designation of information as Critical Electrical Infrastructure Information (CEII). In this section the term ‘eligible entities’ is defined as {§235(a)(1)}:

• A Federal, State, political subdivision, or Tribal authority [excluding DOE and FERC], and
• A utility owned or operated by 1 or more of the authorities above, including a joint action agency or similar entity.

While those agencies fall within the ‘any individual or entity’ terminology used in §231(c)(3)(B) authority to request CEII designation, requests under §235 require DOE or FERC, if they approve CEII designation, to apply that designation for 10 years, not the general period “the information is related to energy infrastructure in service” standard established under §231(c)(9)(A).

Paragraph (d) makes the requesting government entity responsible for the defense “against any claim for disclosure of the designated information” {§235(d)(2)}, not DOE or FERC.

Wartime Clearance


Section 236 allows DOE and FERC to loosen CEII disclosure rules “during the state of war or period of national disaster due to enemy attack” {§236(a)}. That loosening of disclosure rules is limited to the authority “to confer with individuals and grant individuals access to critical electric infrastructure information pending further investigation of those individuals”.

Enforcement


Section 237(a) provides that any entity that does not return an item of CEII within 90 days of a request by DOE or FERC will be subject to enforcement under 16 USC 825m, §825o, and §825o-1.

Section 237(b) requires DOE and FERC to establish appropriate sanctions for knowingly and willfully disclosing critical electric infrastructure information in a manner that is not authorized under this new subpart of the Federal Power Act. It specifically provides that the minimum sanctions for FERC Commissioner or former Commissioner who knowingly and willfully discloses CEII in an unauthorized manner will be {§237(b)(1)(A)}:

• The potential loss of access to critical electric infrastructure information; and
• The potential public issuance of letters of reprimand.

Tuesday, June 16, 2020

1 Advisory and 1 Update Published – 6-16-20


Today the NCCIC-ICS published a control system security advisory for products from Treck. They also updated an earlier advisory for products from Mitsubishi.

Treck Advisory


This advisory describes 19 vulnerabilities in the Treck TCP/IP stack. The vulnerabilities were reported (Ripple20) by Shlomi Oberman and Moshe Kol from JSOF. Treck has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The 19 reported vulnerabilities are:

• Improper handling of length parameter inconsistency (4) - CVE-2020-11896, CVE-2020-11897, CVE-2020-11898, CVE-2020-11907,
• Improper input validation (9) - CVE-2020-11899, CVE-2020-11901, CVE-2020-11902, CVE-2020-11906, CVE-2020-11909, CVE-2020-11910, CVE-2020-11912, CVE-2020-11913, CVE-2020-11914
• Double free - CVE-2020-11900,
• Out-of-bounds read (2) - CVE-2020-11903, CVE-2020-11905,
• Integer overflow or wraparound - CVE-2020-11904,
• Improper null termination - CVE-2020-11908,
• Improper access control - CVE-2020-11911,

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerabilities to allow remote code execution or exposure of sensitive information. NOTE: There is publicly available (registration required) exploit code for two of the vulnerabilities; CVE-2020-11896 RCE, and CVE-2020-11898 Info Leak.

NOTE: The Treck TCP/IP stack is used by a number of vendors. NCCIC reports that the following vendors have prepared advisories for their affected products (no real mitigations available yet):

B.Braun



Mitsubishi Update


This update provides additional information on an advisory that was originally published on June 9th, 2020. The new information includes revised mitigation instructions.

 
/* Use this with templates/template-twocol.html */