Saturday, October 10, 2020

ISCD Updates 1 FAQ Response – 10-9-20

Yesterday the CISA Infrastructure Security Compliance Division (ISCD) updated the responses to one frequently asked question (FAQ) on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center web page. None of the changes were substantive nor did they reflect policy changes.

The following FAQ response was revised:

FAQ #1785 How does the Cybersecurity and Infrastructure Security Agency (CISA) notify a facility of its tiering?

NOTE: The links provided for the FAQs in this post were copied from the CFATS Knowledge Center but may not work when followed from your machine. This is an artifact of that web site. If the links do not take you to the referenced FAQ you will have to use the ‘Advanced Search’ function on the page to link to the FAQ or download the ‘All FAQs’ document at the bottom of the ‘Advanced Search’ page.

The following changes were made in the referenced response:

#1785 Replace ‘DHS’ with ‘CISA’, added regulatory links and replaced URLs with links.

Public ICS Disclosures – Week of 10-03-20

This week we have one vendor disclosure from PEPPERL+FUCHS and one vendor update for products from 3S.

PEPPERL+FUCHS Advisory

CERT-VDE published an advisory describing five vulnerabilities in the PEPPERL+FUCHS Comtrol RocketLinx ethernet switches. The vulnerabilities were reported by T. Weber of SEC Consult Vulnerability Lab. PEPPERL+FUCHS has new firmware versions available that mitigate the vulnerabilities. There is no indication that Weber has been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Unauthenticated device administration (2) - CVE-2020-12500 and CVE-2020-12502,

• Undocumented accounts - CVE-2020-12501,

• Multiple authenticated command injections - CVE-2020-12500, and

• Active TFTP-service - CVE-2020-12504

NOTE 1: The current version of this advisory on the CERT-VDE web page is marked as ‘Update A’, the original version was apparently published earlier in the week.

NOTE 2: SEC Consult reports that this is an OEM vulnerability which they do not name pending response to the vulnerability notification.

3S Update

3S published an update [.PDF download link] for their CodeMeter advisory that was originally published on September 16th, 2020 and most recently updated on September 24th, 2020. The new information includes more details about the coverage of the update for CODESYS v3.5.16.20.

Thursday, October 8, 2020

2 Advisories Published – 10-8-20

Today the CISA NCCIC-ICS published two control system security advisories for products from Mitsubishi and Johnson Controls.

Mitsubishi Advisory

This advisory describes an uncontrolled resource consumption vulnerability in the Mitsubishi MELSEC iQ-R Series modules. The vulnerability was reported by Yossi Reuven of SCADAfence. Mitsubishi plans to release a patch to mitigate the vulnerability. In the meantime, they have provided generic workarounds.

According to NCCIC-ICS a relatively low-skilled attacker could remotely exploit this vulnerability to result in a denial-of-service condition due to uncontrolled resource consumption.

NOTE: NCCIC-ICS did not provide a link to the Mitsubishi advisory.

Johnson Controls Advisory

This advisory describes an improper authorization vulnerability in the Johnson Controls American Dynamics victor Web Client. The vulnerability was reported by Joachim Kerschbaumer. Johnson Controls has a new version that mitigates the vulnerability. There is no indication that Kerschbaumer has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with access to an adjacent network could exploit the vulnerability to allow a remote unauthenticated attacker to delete arbitrary files on the system or render the system unusable through a denial-of-service attack.

Tuesday, October 6, 2020

FAA Sends Two Drone Final Rules to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received two final rules from the DOT’s Federal Aviation Administration (FAA) for review. Both rulemakings address unmanned aircraft operations. The rulemakings address remote identification of drones and operations over people.

Remote Identification

The first rulemaking concerns “Remote Identification of Unmanned Aircraft Systems”. The notice of proposed rulemaking (NPRM) for this rule was published in December of last year. According to the Spring 2020 Unified Agenda listing for this action:

“This action would require the remote identification of unmanned aircraft systems. The remote identification of unmanned aircraft systems in the airspace of the United States would address safety, national security, and law enforcement concerns regarding the further integration of these aircraft into the airspace of the United States while also enabling greater operational capabilities.”

Operating Over People

The second rulemaking concerns “Operations of Small Unmanned Aircraft Over People”. The NPRM for this rule was published in February of 2019. . According to the Spring 2020 Unified Agenda listing for this action:

“This rulemaking would address the performance-based standards and means-of-compliance for operation of small unmanned aircraft systems (UAS) over people not directly participating in the operation or not under a covered structure or inside a stationary vehicle that can provide reasonable protection from a falling small unmanned aircraft. This rule would provide relief from certain operational restrictions implemented in the Operation and Certification of Small Unmanned Aircraft Systems final rule (RIN 2120-AJ60).”

Saturday, October 3, 2020

Update on CISA Chemical Security Seminars – 10-3-20

This week the Cybersecurity and Infrastructure Security Agency updated their Chemical Security Summit web page, providing additional information on the chemical security seminars that will be taking the place of this year’s COVID-19 canceled Chemical Security Summit. Seminars will be held on December 2nd, 9th, and 16th. A brief agenda outline has been included.

The topics that will be addressed include:

• The state of chemical security—Updates for the Chemical Facility Anti-Terrorism Standards (CFATS) program and ongoing nonregulatory chemical security efforts

• A demo of the CFATS Personnel Surety Program application

• A deep dive into the 18 CFATS Risk-Based Performance Standards (RBPS) and best practices

• A chemical threat briefing

• Managing chemical security during natural disasters: hurricanes, wildfires, floods, and pandemics

• Challenges encountered with chemical security during the COVID-19 pandemic

• Growing a global culture of chemical security

• The convergence of cyber and physical security

Public ICS Disclosures – Week of 9-26-20

This week we have ten vendor disclosures for products from WAGO (3), IBM, Bosch, B&R Automation (2), Moxa, BD, and Philips.

WAGO Advisories

CERT-VDE published an advisory describing an improper authentication and authorization vulnerability in the WAGO 750-8XX series PLCs. The vulnerability was reported by Maxim Rupp. WAGO has new firmware versions that mitigate the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

CERT-VDE published an advisory describing an improper authentication and access control vulnerability in the WAGO 750-36X and WAGO 750-8XX series PLCs. The vulnerability was reported by Maxim Rupp. WAGO has new firmware versions that mitigate the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

CERT-VDE published an advisory describing an improper neutralization of input during web page generation vulnerability in the Web-UI for WAGO 750-88X and WAGO 750-89X series PLCs. This vulnerability was reported by Secuninja. WAGO has new firmware versions that mitigate the vulnerability. There is no indication that Secuninja has been provided an opportunity to verify the efficacy of the fix.

IBM Advisory

IBM published an advisory describing an authentication bypass vulnerability in their Maximo Asset Management product. The vulnerability is being self-reported. IBM has updates that mitigate the vulnerability.

Bosch Advisory

Bosch published an advisory describing three vulnerabilities in their PRAESIDEO Network Controller and the PRAESENSA System Controller products. The vulnerabilities were reported by Gjoko Krstic of Applied Risk. Bosch has software updates for the supported products that mitigate the vulnerabilities. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Cross-site scripting - CVE-2020-6777,

• Cross-site request forgery - CVE-2020-6776, and

• Nonce reuse attack - CVE-2020-15688

NOTE: The last is a third-party vulnerability (GoAhead web server).

B&R Advisories

B&R published an advisory describing four vulnerabilities in their GateManager product. These vulnerabilities were reported by NCCIC-ICS on July 28th as being for the Secomea GateManager.

B&R published an advisory describing six vulnerabilities in their SiteManager and GateManager procucts. These vulnerabilities were reported by NCCIC-ICS last Tuesday, but the B&R advisory was not available when I published my blog post. It is not clear if the Secomea versions of these products are also affected by these vulnerabilities.

Moxa Advisory

Moxa published an advisory describing a device information leak vulnerability in their EDR-810 Series Industrial Secure Routers. The vulnerability was reported by the National Security Agency (yep, that is what the advisory says). Moxa has provided generic workarounds to mitigate the vulnerability.

BD Advisory

BD published an advisory describing a remote code execution vulnerability (CVE-2020-1147) in a third-party component (Microsoft) of a long list of their products. BD is working on testing and validation of the Microsoft patch.

Philips Advisory

Philips published an advisory describing a privilege elevation vulnerability (CVE-220-1472) in a third-party component (Microsoft) of an undisclosed number of Philips products. No mitigation information has been provided.

Friday, October 2, 2020

Bills Introduced – 10-1-20

Yesterday, with both the House and Senate in session (an unusual October session in an election year), there were 67 bills introduced. One of those bills will receive additional coverage in this blog:

S 4795 A bill to require the Secretary of Energy to establish a voluntary Cyber Sense program to test the cybersecurity of products and technologies intended for use in the bulk-power system, and for other purposes. Sen. Rosen, Jacky [D-NV] 

It is unusual for this bill to be introduced this late in the session when the House just passed their version of the bill this week. It will be interesting to see what the differences are between this bill and HR 360.

 
/* Use this with templates/template-twocol.html */