Thursday, September 10, 2020

4 Advisories Published – 9-10-20


Today the CISA NCCIC-ICS published three control system and one medical device security advisories for products from HMS Network, FATEK Automation, AVEVA, and Philips.

HMS Advisory


This advisory describes a permissive cross-domain policy with untrusted domains vulnerability in the HMS Ewon Flexy and Cosy products. The vulnerability was reported by Parth Srivastava of Protiviti India Member Private Limited. HMS has updated firmware that mitigates the vulnerability. There is no indication that Srivastava has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow attackers to retrieve limited confidential information.

FATEK Advisory


This advisory describes a stack-based buffer overflow vulnerability in the FATEK PLC WinProladder. The vulnerability was reported by Natnael Samson via the Zero Day Initiative. FATEK has not responded to NCCIC-ICS about this vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to crash the device being accessed; a buffer overflow condition may cause a denial-of-service event and remote code execution.

AVEVA Advisory


This advisory describes an SQL injection vulnerability in the AVEVA Enterprise Data Management Web. The vulnerability was reported by Yuri Kramarz of Cisco Talos. AVEVA has an upgrade that mitigates the vulnerability. The AVEVA advisory notes that Kramzrz has verified the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow a remote attacker to execute arbitrary SQL commands on the affected device.

Philips Advisory


This advisory describes eight vulnerabilities in the Philips  Patient Information Center iX (PICiX); PerformanceBridge Focal Point; IntelliVue Patient Monitor products. The vulnerabilities were reported by Julian Suleder, Nils Emmerich, Birk Kauer of ERNW Research GmbH, Dr. Oliver Matula of ERNW Enno, and Rey Netzwerke GmbH via BSI. Philips plans on releasing updates over the next year.

The eight reported vulnerabilities are:

• Improper neutralization of formula elements in a CSV file - CVE-2020-16214,
• Cross-site scripting - CVE-2020-16218,
• Improper authentication - CVE-2020-16222,
• Improper check for certificate revocation - CVE-2020-16228,
• Improper handling of length parameter inconsistency - CVE-2020-16224,
• Improper validation of syntactic correctness of input - CVE-2020-16220,
• Improper input validation - CVE-2020-16216, and
• Exposure of resource to wrong sphere - CVE-2020-16212

NCCIC-ICS reports that a relatively low-skilled attacker with either physical access to surveillance stations and patient monitors or access to the medical device network could exploit the vulnerabilities to allow unauthorized access, interrupted monitoring, and collection of access information and/or patient data.

Wednesday, September 9, 2020

ISCD Updates 2 FAQ Responses – 9-9-20


Today the CISA Infrastructure Security Compliance Division (ISCD) updated the responses to two frequently asked questions (FAQs) on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center. Most of the changes are non-substantive editorial changes, but there is a new link to a relatively new CSAT web page.

Updated FAQ


The following FAQ responses were revised today:


NOTE: The links provided for the FAQs in this post were copied from the CFATS Knowledge Center but may not work when followed from your machine. This is an artifact of that web site. If the links do not take you to the referenced FAQ you will have to use the ‘Advanced Search’ function on the page to link to the FAQ or download the ‘All FAQs’ document at the bottom of the ‘Advanced Search’ page.

The following changes were made in the referenced FAQs:

#387 Adds link to new CSAT Top Screen Submissions Tips page,
#1143 Changed URLS to document links

Top Screen Submission Tips Page


According to the date on the web page it was originally published this last May, but this is the first time I have seen the page. The CFATS web site is huge and ISCD does not do a good job of communicating changes to the site.

This page begins with a brief overview of the purpose of the Top Screen. It then goes on to look at five major topics:

• Resubmissions for material modifications,
• Business operations: predictive top-screen filing,
• Business planning: hypothetical top-screen filing,
• Regular resubmissions, and
• Facility closures

I followed all of the links on the page and found that the following two pages had been updated since this new page was published:


I do not see any major changes to those pages.

7 Updates Published – 9-8-20


Yesterday the CISA NCCIC-ICS published updates for seven control system security advisories for products from Siemens.

Industrial Products Update


This update provides additional information on an advisory that was originally published on September 10th, 2019 and most recently updated on August 11th, 2020. The new information includes the addition of mitigation measures for SIMATIC RF18xC/CI.


PROFINET Update


This update provides additional information on an advisory that was originally published on October 10th, 2019 and most recently updated on August 11th, 2020. The new information includes the addition of mitigation measures for:

• EK-ERTEC 200P, and
• S7-410 V8

SIMATIC Update #1


This update provides additional information on an advisory that was originally published on February 11th, 2020 and most recently updated on July 14th, 2020. The new information includes the addition of mitigation measures for SIMATIC WinCC (TIA Portal) V15.1.

SCALANCE Update


This update provides additional information on an advisory that was originally published on April 14th, 2020 and most recently updated on August 11th, 2020. The new information includes data about successor products for SIMATIC RF180C and RF182C.

RUGGEDCOM Update


This update provides additional information on an advisory that was originally published on April 14th, 2020 and most recently updated on May 12th, 2020. The new information includes the addition of mitigation measures for  SIMATIC RF18xC/CI.

SIMATIC Update #2


This update provides additional information on an advisory that was originally published on July 9th, 2020 and most recently updated on August 11th, 2020. The new information includes the addition of mitigation information for:

• SINAMICS Startdrive,
• SIMATIC STEP 7 (TIA Portal) V15, and
• SIMATIC WinCC Runtime Professional V15

UMC Stack Update


This update provides additional information on an advisory that was originally published on July 14th, 2020 and most recently updated on August 11th, 2020. The new information includes mitigation measures for SIMATIC STEP 7 (TIA Portal) V15.

Other Siemens Updates


Yesterday Siemens published three other updates that were not covered by NCCIC-ICS. If they are not addressed by CISA on Thursday, I will discuss them this weekend.

Tuesday, September 8, 2020

9 Advisories Published – 9-8-20


Today the CISA NCIC-ICS published nine control system security advisories for products from Wibu-Systems and Siemens (8). The Wibu advisory was originally published with restricted access on the HSIN ICS library on July 21st, 2020. It has been a little over 22 months since NCCIC-ICS last published an advisory on HSIN before releasing it to the general public.

NOTE: NCCIC-ICS also updated seven advisories from Siemens. I will address those in a separate blog post, probably tomorrow.

Wibu-Systems Advisory


This advisory describes six vulnerabilities in the Wibu-Systems CodeMeter. These vulnerabilities were reported by Sharon Brizinov and Tal Keren of Claroty. Wibu has a new version that, along with other specific measures mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Buffer access with incorrect length value - CVE-2020-14509,
• Inadequate encryption strength - CVE-2020-14517,
• Origin validation error - CVE-2020-14519,
• Improper input validation - CVE-2020-14513,
• Improper verification of cryptographic signature - CVE-2020-14515, and
• Improper resource shutdown or release - CVE-2020-16233

NOTE: The CVE links are to the respective Wibu advisory. They apparently publish a separate advisory for each vulnerability. These advisories provide a bit more detail than does the NCCIC-ICS advisory.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to alter and forge a license file, cause a denial-of-service condition, potentially attain remote code execution, read heap data, and prevent normal operation of third-party software dependent on the CodeMeter.

NOTE: NCCIC-ICS provided links to two vendor advisories for products affected by this vulnerability:

Siemens, and


Polarian Advisory


This advisory describes two vulnerabilities in the Siemens Polarion Subversion Webclient. The vulnerabilities were reported by Li Yifan. Siemens considers the product shareware, distributed “as is,” and will be no fix as it is no longer supported.

The two reported vulnerabilities are:

• Basic XSS - CVE-2020-15788, and
• Cross-site request forgery - CVE-2020-15789

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to to induce the victim to issue an HTTP request could lead to a state-changing operation.

Industrial Products Advisory


This advisory describes an exposure of sensitive information to an unauthorized actor vulnerabilities in the Siemens Industrial Products. The Siemens advisory notes that this is the third-party (Intel) Crosstalk vulnerability. The vulnerability was reported by Alyssa Milburn, Hany Ragab, Kaveh Razavi, Herbert Bos, and Cristiano Giuffrida from the VUSec group. Siemens is working on an update and currently only provides generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with local access could exploit this vulnerability to allow an authenticated user to enable information disclosure via local access.

SIMATIC Advisory #1


This advisory describes two vulnerabilities in the Siemens SIMATIC HMI Products. The vulnerabilities were reported by Joseph Gardiner from Bristol Cyber Security Group. Siemens is working on an update and currently only provides generic workarounds to mitigate the vulnerability.

The two reported vulnerabilities are:

• Improper restriction of excessive authentication attempts - CVE-2020-15786, and
• Authentication bypass by primary weakness - CVE-2020-15787.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow a remote attacker to discover user passwords and obtain access to the Sm@rt Server via a brute-force attack.

Siveillance Advisory


This advisory describes a cleartext transmission of sensitive information vulnerability in the Siemens Siveillance Video Client IP video management software. The vulnerability is self-reported. Siemens has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to obtain valid administrator login names and use this information to launch further attacks.

Spectrum Advisory


This advisory describes two vulnerabilities in the Siemens Spectrum Power products. The vulnerabilities were reported by Can Demirel of Cyberwise. Siemens has updates that mitigate the vulnerabilities. There is no indication that Demirel has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Cleartext storage of sensitive information - CVE-2020-15784, and
• Exposure of information through directory listing - CVE-2020-15790

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerabilities to allow an unauthorized attacker to retrieve a list of software users, or in certain cases to list the contents of a directory.

License Management Advisory


This advisory describes an execution with unnecessary privileges vulnerability in the Siemens License Management Utility (LMU). The vulnerability was reported by Bundesamt für Sicherheit in der Informationstechnik (BSI). Siemens has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow local users to escalate privileges.

SIMATIC Advisory #2


This advisory describes an insufficiently protected credentials vulnerability in the Siemens SIMATIC S7-300 and S7-400 CPUs. The vulnerability was reported by Hyunguk Yoo from University of New Orleans and Irfan Ahmed and Adeen Ayub from Virginia Commonwealth University. Siemens has provided generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow credential disclosure.

SIMATIC Advisory #3


This advisory describes three vulnerabilities in the Siemens SIMATIC RTLS Locating Manager. The vulnerabilities were self-reported. Siemens has an update that mitigates the vulnerabilities.

The three reported vulnerabilities are:

• Incorrect default permissions - CVE-2020-10049 and CVE-2020-10050, and
• Unquoted search path or element -CVE-2020-10051

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow a privileged local user to escalate privileges.

Sunday, September 6, 2020

ISCD Updates 2 FAQS – 9-4-20


On Friday CISA’s Infrastructure Security Compliance Division (ISCD) corrected the responses to two frequently asked questions (FAQs) on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center. The changes were non-substantive editorial changes.

The following FAQ responses were revised Friday:


NOTE: The links provided for all FAQs in this post were copied from the CFATS Knowledge Center but may not work when followed from your machine. This is an artifact of that web site. If the links do not take you to the referenced FAQ you will have to use the ‘Advanced Search’ function on the page to link to the FAQ or download the ‘All FAQs’ document at the bottom of the ‘Advanced Search’ page.

The following changes were made in the referenced FAQs:

#1666 Correct minor typo (caps), and
#1724 Correct minor typo (caps)

Saturday, September 5, 2020

Public ICS Disclosures – Week of 8-29-20


This week we have two new vendor disclosures for products from SICK and BD. There were also three Ripple20 [Corrected link, 10-18-20, 0857] updates published for products from HMS, Braun and Schneider. We also have a vendor update from Yokogawa. There is also one researcher report with exploits for vulnerabilities for products from Red Lion.

SICK Advisory


SICK published an advisory describing an improper handling of exceptional conditions vulnerability in their SOPAS Engineering Tool. The vulnerability was reported by Ruben Santamarta of IOActive. SICK has released new firmware versions that mitigate the vulnerability. There is no indication that Santamarta has been provided an opportunity to verify the efficacy of the fix.

BD Advisory


BD published an advisory describing three third-party (VMware) vulnerabilities in selected BD products. BD is currently testing the VMware update.

The three reported vulnerabilities are:

• Local privilege escalation - CVE-2020-3957,
• Denial of service - CVE-2020-3958, and
• Memory leak - CVE-2020-3959

Ripple20 Updates


HMS published an update of their Ripple20 advisory that was originally published on June 23, 2020. The new information includes adding the following products to the not affected list:

• Anybus M-Bus to Modbus TCP gateway,
• Anybus WLAN Access Points (AWB4xxx), and
• Ewon Netbiter 100, 200 and 300-series

Braun published an update of their Ripple20 advisory that was originally published on June 30th, 2020. The updated information includes more details on the Ripple20 effect on the Outlook 400ES infusion pump.

Schneider published an update of their Ripple20 advisory that was originally published on June 23, 2020 and most recently updated on August 6th, 2020. The new information includes:

• Adding mitigation measures for Cooling Products using NMC2, and
• Adding partial remediations for TM3BC bus coupler module – EIP, TM3BC bus coupler module – SL, and TM3BC bus coupler module – CANOpen

Yokogawa Update


Yokogawa published an update for their CAMS for HIS advisory that was originally published on July 31st, 2020. The new information includes updated affected product data.

Red Lion Report


SEC Consult published a report on multiple vulnerabilities in the Red Lion N-Tron products that were reported last week by CISA NCCIC-ICS. The SEC Consult report includes proof-of-concept exploit code and a list of outdated third-party components.

Wednesday, September 2, 2020

ISCD Publishes 1 New FAQ and Updates 6 FAQ Responses – 9-2-20


Today CISA’s Infrastructure Security Compliance Division (ISCD) published one new frequently asked question (FAQ) and updated responses to six existing FAQ’s on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center. The updates are generally not substantive changes in policy or guidance, but rather issued to increase their ease of use.

New FAQ


The newly published FAQ is:


NOTE: The links provided for all FAQs in this post were copied from the CFATS Knowledge Center but may not work when followed from your machine. This is an artifact of that web site. If the links do not take you to the referenced FAQ you will have to use the ‘Advanced Search’ function on the page to link to the FAQ or download the ‘All FAQs’ document at the bottom of the ‘Advanced Search’ page.

The short answer is found in the first paragraph of the response:

“A covered chemical facility that has closed must report the closure to CISA so that the facility record may be archived. Notification is accomplished by submitting a revised Top-Screen and sending a signed letter to CISA notifying CISA of the facility’s closure.”

This ‘must report’ answer is based upon the requirement in 6 CFR 27.210(d) to report ‘material modifications’ to a facility’s operations or site within 60 days.

Not mentioned in the FAQ response is the necessity of informing ISCD (if you do not do it in your letter submission, they will certainly ask) about the disposition of the remaining DHS chemicals of interest at the site. It is unlikely that ISCD will relieve a facility owner of the responsibility of maintaining the site security plan operations while COI remains on site.

Updated FAQ


The following FAQ responses were revised today:


The following changes were made in the referenced FAQs:

• #1724 – Corrected grammatical error is question,
• #1738 – Added reference to “Chemical Facility Anti-Terrorism Standards Act of 2014 (CFATS Act)”,
• #1739 – Added links to referenced documents,
• #1758 – Added linked reference to Federal Register Notice,
• #1759 – Added linked reference to Federal Register Notice, and
• #1769 – Changed URL to link to CFR reference.

 
/* Use this with templates/template-twocol.html */