Saturday, July 18, 2020

Public ICS Disclosures – Week of 7-11-20


This week we have four Ripple20 vendor disclosures from Siemens, ABB, Rockwell, Carestream and Schneider Electric; two SigRed vendor disclosures from Philips and GE Healthcare; and three other vendor disclosures from HMS and Schneider (2). Four vendor updates from Schneider (2) and Siemens (2) and  two researcher disclosures for products from Siemens and Advantech round out the weeks’ offerings.

Ripple20 Disclosures and Updates


Siemens published a Ripple20 advisory for their SPPA-T3000 Solutions distributed control system. Siemens provides generic mitigation measures for these vulnerabilities.

NOTE: Siemens published a note at the top of their Security Publications page noting that:

“No Siemens product is known to use Treck Inc.'s TCP/IP stack, or otherwise be affected by the reported vulnerabilities.
“Note that Siemens products and systems might interact with products from other manufacturers which are affected by the reported vulnerabilities. In such cases Siemens recommends that owners of operational infrastructures verify if these products are affected and evaluate the potential impact of the Ripple20 vulnerabilities.”

Since the SPPA-T3000 advisory also contains two Intel Server Platform Services vulnerabilities, I suspect that the Ripple20 vulnerabilities come with the Intel server upon which the T-3000 is built.

ABB published a Ripple20 advisory. The advisory contains a list of affected products and generic mitigation measures pending further work to address the vulnerabilities.

Rockwell updated their Ripple20 advisory. The new information includes an updated table of affected products.

Carestream updated their Ripple20 advisory (.PDF download link). The new information includes adding 20 products that were on the ‘still evaluating list’ to the not affected list. The list of affected products has not changed.

Schneider updated their Ripple20 advisory. The new information includes removing the “Smartlink ELEC” from the list of affected products.

SigRed Disclosures


SigRed is the ‘cute’ name given to the Microsoft ‘wormable’ remote code execution DNS vulnerability (CVE-2020-1350).

Phillips published a SigRed advisory noting that: “Philips is currently in the process of evaluating the Microsoft patch and vendor recommended mitigation options.”


GE Healthcare published a SigRed advisory noting that: “GE Healthcare is actively assessing products that utilize impacted Microsoft Operating Systems.”

Neither of these advisories provide much in the way of information beyond noting that a vague ‘some’ of their products may be affected.

Vendor Disclosures


HMS published an advisory describing a remote code execution vulnerability in their eCatcher product. The vulnerability was reported by Claroty. HMS has an update that mitigates the vulnerability. There is no indication that Claroty was provided an opportunity to verify the efficacy of the fix.

Schneider published an advisory describing an open redirect vulnerability in their Schneider Electric Software Update (SESU). The vulnerability was reported by Amir Preminger of Claroty. Schneider has a new version that mitigates the vulnerability. There is no indication that Preminger has been provided an opportunity to verify the efficacy of the fix.

Schneider published an advisory describing two denial of service vulnerabilities in their Floating License
Manager. These are third-party vulnerabilities in the Flexera FlexNet Publisher (reported here and here). Schneider has a new version that mitigates these vulnerabilities.

NOTE: Flexera is also reporting three other vulnerabilities (CVE-2019-8963, CVE-2020-12080, and CVE-2020-12081) that could potentially affect the Schneider Floating License Manager and a variety of other vendor ‘license manager’ products based upon the Flexera product.

Vendor Updates


Schneider updated their ZombieLoad advisory. The new information includes updated mitigation measures for the HMI products.

Schneider updated their BlueKeep advisory. The new information includes updated mitigation measures for the HMI products.

Siemens updated their Vulnerabilities in Intel CPUs advisory. The new information includes:

• Updated mitigation and affected version information for SIMATIC ITP1000, and
• Removed SIMATIC IPC827E from list of affected devices

Siemens updated heir GNU/Linux advisory. The new information includes adding:

CVE-2020-12114,
• CVE-2020-12659,
• CVE-2020-13630,
• CVE-2020-13631, and
• CVE-2020-13632

Researcher Disclosures


Talos published a report on the Siemens LOGO web server vulnerability that was reported earlier this week. The Talos report includes proof-of-concept code for the vulnerability.

The Zero Day Initiative published 43 reports, all based upon research by rgod, about the Advantech iView vulnerabilities that were reported earlier this week. Most of the reports provided more details on the three CVE’s listed in the NCCIC-ICS advisory. One of the reports, however, described an input validation vulnerability that was not reported by NCCIC-ICS.

Friday, July 17, 2020

Bills Introduced – 7-16-20


Yesterday with both the House and Senate meeting in pro forma session there were 60 bills introduced. Of those three may receive additional coverage in this blog:

HR 7616 Making appropriations for the Departments of Transportation, and Housing and Urban Development, and related agencies for the fiscal year ending September 30, 2021, and for other purposes. Rep. Price, David E. [D-NC-4]

HR 7617 Making appropriations for the Department of Defense for the fiscal year ending September 30, 2021, and for other purposes. Rep. Visclosky, Peter J. [D-IN-1]

HR 7667 Making appropriations for the Departments of Commerce and Justice, Science, and Related Agencies for the fiscal year ending September 30, 2021, and for other purposes. Rep. Serrano, Jose E. [D-NY-15]

Thursday, July 16, 2020

ISCD Updates 6 FAQ Responses – 7-16-20


Today the CISA Infrastructure Security Compliance Division (ISCD) updated the responses to six frequently asked questions on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center. This is part of an on-going effort at ISCD to make FAQ editorial changes designed to: reflect changes in program management (CISA branding), to change URL’s to page links (see the similar 6-22-20 blog post) and to make the responses more helpful; rather than reflecting changes in ISCD policy.


S 4096 Introduced – CFATS Extension


Last month Sen Johnson (R,WI) introduced S 4096, a bill that would extend the Chemical Facility Anti-Terrorism Standards (CFATS) program through July 27th, 2023.

Two days after this bill was introduced Johnson introduce a second CFATS extension bill, S 4148. That bill would also extend the CFATS program through July 27th, 2023. S 4148 was passed by the Senate the same day it was introduced.

The bill the Senate passed was the same as S 4096 except that it added a second paragraph:

“(b) EFFECTIVE DATE.—The amendment made by subsection (a) shall take effect on the date that is 1 day after the date of enactment of this Act.”

The House passed their own clean extension of the CFATS program (HR 6160) back in March. It would extend the CFATS program authorization through October 18th, 2021. Technically, the wording of HR 6160 was made obsolete by the passage of HR 748 as that bill replaced the old “5 years and 3 months” language with an actual date; “July 23, 2020”.

Both the House and the Senate will be back in Washington next week in time to address the pending expiration of the CFATS program authorization on July 23rd. While the Democrats in the House really want a chance to make some changes to the CFATS program, I suspect that they will go along with the three year extension as they hope to be in a stronger position to send legislation to the President in the 117th Congress.

Interestingly, after this bill was introduced, Johnson introduced a third CFATS extension bill, S 4197. The language of that bill has not yet been printed, but it did not have any Democratic Senators as cosponsors.

Wednesday, July 15, 2020

HR 7214 Introduced – Transportation R&D Authorization


Last month Rep Johnson (D,TX) introduced HR 7214, the Surface Transportation Research and Development Act of 2020. The bill would authorize FY 2021 appropriations to the DOT for surface transportation research, development, and deployment. There are two cybersecurity related provisions in the bill.

Highway Safety Improvement Project


Section 102 of the bill would amend 23 USC 148(a)(4)(B) by adding four new categories of to the list of projects that would qualify as Highway Safety Improvement Projects. The last of these new categories is the undefined ‘cybersecurity’.

Autonomous Trucking


Section 207 of the bill would add a new §5507 to 49 USC Chapter 55. It would require DOT to establish the Heavy Freight Autonomous Trucking Research Initiative. In addition to establishing an R&D agenda that would include “analyzing, modeling, and piloting the feasibility and benefits of dedicated autonomous trucking corridors” {new §5507(c)(1)} the initiative would provide deployment guidance. Of the three specific topics to be addressed in the guidance, one would be “cyber-physical security” {new §5507(c)(2)}.

The bill would authorize $6 million per year through 2025 for the initiative.

Moving Forward


Johnson is the Chair of the House Science, Space, and Technology Committee, one of the two committees to which this bill was assigned for consideration. She is also a member of the House Transportation and Infrastructure Committee the other committee. This means that it is highly likely that the SS&T Committee will take up the bill and probable that the T&I Committee will as well.

This is not a must pass authorization bill, but one that will likely make its way to the full House. I suspect that the bill will pass with some bipartisan support. I am not sure that the bill has enough weight to make it to the President’s desk in this COVID-19 impacted election year.

Note: Corrected bill number prefix in the title to HR 7214, it was correct in text 8:20 EDT 7-16-20

12 Updates Published – 7-14-20


Yesterday CISA NCCIC-ICS published 11 control system security updates for products from Siemens (10) and Treck. They also published a medical device security update for products from Baxter.

PROFINET Update #1


This update provides additional information on an advisory that was originally published on May 9th, 2017 and most recently updated on October 8th, 2019. The new information includes adding SIMATIC TDC CP51M1 and CPU555 to the list of affected products.

Industrial Products Update #1


This update provides additional information on an advisory that was originally published on December 5th, 2017 and most recently updated on October 8th, 2019. The new information includes adding SIMATIC TDC CP51M1 and CPU555 to the list of affected products.

SCALANCE Update


This update provides additional information on an advisory that was originally published on August 15th, 2019. The new information includes adding mitigation links and updating affected version data for  SCALANCE XB-200, XC-200, XP-200,XF-200BA and XR-300WG.

PROFINET Update #2


This update provides additional information on an advisory that was originally published on October 10th, 2019 and most recently updated on March 14th, 2020. The new information includes adding  SIMATIC TDC CP51M1 and CPU555 to the list of affected products.

S7-1200 Update


This update provides additional information on an advisory that was originally published on November 14th 2019 and most recently updated on December 10th, 2019. The new information includes mitigation links and updated version information for SIMATIC S7-1200 and SIMATIC S7-200 SMART.

SIMATIC Update #1


This update provides additional information on an advisory that was originally published on February 11th, 2020 and most recently updated on May 12th, 2020. The new information includes mitigation links and updated version information for SIMATIC PCS 7 V9.0.

Industrial Products Update #2


This update provides additional information on an advisory that was originally published on February 11th, 2020. The new information includes mitigation links and updated version information for IE/PB LINK PN IO.

SIMATIC Update #2


This update provides additional information on an advisory that was originally published on March 10th, 2020. The new information includes:

• Adding SIMATIC TDC CP51M1 and SIMATIC TDC CPU555 to the list of affected products, and
• Adding mitigation links and updated affected version information for SINUMERIK 840D sl.

SIMATIC Update #3


This update provides additional information on an advisory that was originally published on July 9th, 2020. The new information includes mitigation links and updated version information for SIMATIC PCS 7 V9.0.

SIMATIC Update #4


This update provides additional information on an advisory that was originally published on July 9th, 2020. The new information includes mitigation links and updated version information for:

• SIMATIC STEP 7 V13,
• SIMATIC STEP 7 V16,
• SIMATIC WinCC Runtime Professional V13,
• SIMATIC WinCC Runtime Professional V16, and
• SIMATIC WinCC Runtime Advanced

Treck Update


This update provides additional information on an advisory that was was originally published on June 16th, 2020 and most recently updated on July 7th, 2020. The new information includes links to vendor advisories from DIGI International and Meile.

NOTE 1: I briefly mentioned the Meile advisory last Saturday.

NOTE 2: NCCIC-ICS missed the Siemens' Treck related advisory, more on that this weekend.

Baxter Update


This update provides additional information on an advisory that was was originally reported on June 18th, 2020 and most recently updated on June 23rd, 2020. The new information includes additional mitigation information for one version of Prismaflex.

Other Siemens Updates


There were two additional updated advisories published yesterday by Siemens that were not addressed by NCCIC-ICS. I will look at those on Saturday.

Tuesday, July 14, 2020

9 Advisories Published – 7-14-20


Today the CISA NCCIC-ICS published eight control system security advisories for products from Siemens (6), Moxa and Advantech. They also published one medical device security advisory for products from Capsule Technologies.

NOTE: NCCIC-ICS also published 12 updates, but I will not try to get a report done on those this evening. Look for it tomorrow morning

Logo Advisory


This advisory describes a classic buffer overflow vulnerability in the Siemens LOGO! Web Server. The vulnerability was reported by Alexander Perez-Palma and Dave McDaniel from Cisco Talos and Emanuel Almeida from Cisco Systems. Siemens has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to  allow remote code execution..

Opcenter Advisory


This advisory describes three vulnerabilities in the Seiemens  Opcenter Execution Core. The vulnerabilities are self-reported. Siemens has a new version that mitigates the vulnerabilities.

The three reported vulnerabilities are:

• Cross-site scripting - CVE-2020-7576,
• SQL injection - CVE-2020-7577, and
• Improper access control - CVE-2020-7578
NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to obtain session cookies, read and modify application data, read internal information, and perform unauthorized changes. Should the attacker gain access to the session cookies, they could then hijack the session and perform arbitrary actions in the name of the victim.

SIMATIC S7 Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the Siemens SIMATIC S7-200 SMART CPU family. The vulnerability was reported by Ezequiel Fernandez. Siemens has a new version that mitigates the vulnerability. There is no indication that Fernandez has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to cause a denial-of-service condition.

UMC Stack Advisory


This advisory describes three vulnerabilities in the Siemens UMC Stack. The vulnerabilities were reported by Victor Fidalgo of INCIBE and Reid Wightman of Dragos. Siemens has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Unquoted search path or element - CVE-2020-7581,
• Uncontrolled resource consumption - CVE-2020-7587, and
• Improper input validation - CVE-2020-7588

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to cause a partial denial-of-service condition on the UMC component of the affected devices under certain circumstances. This could also allow an attacker to locally escalate privileges from a user with administrative privileges to execute code with SYSTEM level privileges.

SIMATIC HMI Advisory


This advisory describes a cleartext transmission of sensitive information in the Siemens SIMATIC HMI Panels. The vulnerability was reported by Richard Thomas and Tom Chothia of the University of Birmingham.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to access sensitive information under certain circumstances.

SICAM Advisory


This advisory describes nine vulnerabilities in the Seimens SICAM MMU, SICAM T and SICAM SGU products. The vulnerabilities were reported by Luca Simbürger, Luca Hofschuster, Lukas Kahnert, Jakob Lachermeier, Christian Costa, Simon Huber, Lukas Sas Brunschier, Florian Freiberger, Florian Burger, Marie-Louise Oostveen, Magdalena Thomeczek, and Johann Uhrmann from Landshut University of Applied Sciences and Max Hirschberger, Simon Hofmann, and Peter Knauer from Augsburg University of Applied Sciences. Siemens has updates that mitigate the vulenrabilites. There is no indication that researchers have been provided an opportunity to verify the efficacy of the fix.

The nine reported vulnerabilities are:

• Out-of-bounds read - CVE-2020-10037,
• Missing authentication for critical function - CVE-2020-10038,
• Missing encryption of sensitive data - CVE-2020-10039,
• Use of password has with insufficient computational effort - CVE-2020-10040,
• Cross-site scripting - CVE-2020-10041,
• Classic buffer overflow - CVE-2020-10042,
• Basic XSS - CVE-2020-10043, and
• Authentication bypass by capture replay - CVE-2020-10045

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to affect the availability, read sensitive data, and gain remote code execution on the affected devices.

Moxa Advisory


This advisory describes a stack-based buffer overflow in the Moxa EDR-G902 and EDR-G903 Series Routers. The vulnerability was reported by Tal Keren of Claroty. Moxa has a firmware patch that mitigates the vulnerability. There is no indication that Keren has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to  crash the device being accessed; a buffer overflow condition may allow remote code execution.

NOTE 1: NCCIC-ICS did not publish a link to the Moxa advisory.

NOTE 2: I briefly discussed this vulnerability last month.

Advantech Advisory


This advisory describes six vulnerabilities in the Advantech iView device management application. The vulnerabilities were reported by rgod via the Zero Day Initiative. Advantech has a new version that mitigates the vulnerability. There is no indication that rgod has been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• SQL injection - CVE-2020-14497,
• Path traversal - CVE-2020-14507,
• Command injection - CVE-2020-14505,
• Improper input validation - CVE-2020-14503,
• Missing authentication for critical function - CVE-2020-14501, and
• Improper access control -CVE-2020-14499

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to read/modify information, execute arbitrary code, limit system availability, and/or crash the application.

Capsule Technologies Advisory


This advisory describes protection mechanism failure in the Capsule Technologies SmartLinx Neuron 2 medical device platform. The vulnerability was reported by Patrick DeSantis of Cisco Talos (NOTE: Talos report includes exploit code). Capsule Technologies has a new version that mitigates the vulnerability. There is no indication that DeSantis has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could use publicly available code to exploit the vulnerability to provide an attacker with full control of a trusted device on a hospital’s internal network.

 
/* Use this with templates/template-twocol.html */