Thursday, November 12, 2020

2 Advisories Published – 11-12-20

Today the CISA NCCIC-ICS published one control system security advisory for products from Mitsubishi and one medical device security advisory for products from BD.

Mitsubishi Advisory

This advisory describes an uncontrolled resource consumption vulnerability in the Mitsubishi MELSEC iQ-R series CPU modules. The vulnerability was reported by Xiaofei.Zhang of China ICS-CERT. Mitsubishi has new firmware versions that mitigate the vulnerability. There is no indication that Ziaofei has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to cause a denial-of-service condition for the affected products.

BD Advisory

This advisory describes an improper authentication vulnerability in the BD Alaris 8015 PC Unit and BD Alaris Systems Manager. The vulnerability was reported by Medigate. BD has versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to lead to a drop in the wireless capability of the Alaris PC Unit. According to the BD advisory, the attacker “would need access to the customer's wireless network”.

NOTE: NCCIC-ICS did not provide a link to the BD advisory.

Wednesday, November 11, 2020

ISCD Updates 15 FAQ Responses – 11-11-20

Today the CISA Infrastructure Security Compliance Division (ISCD) updated the responses to 15 frequently asked questions (FAQs) on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center web page.

The following FAQ responses were revised:

FAQ #1275 What needs to be done with the facility ID in the Chemical Security Assessment Tool (CSAT) when a covered chemical facility is bought or sold?

FAQ #1481 What factors does a facility need to account for when calculating whether a facility possesses the screening threshold quantity (STQ) for a theft/diversion chemical of interest (COI)?

FAQ #1489 Can a covered facility have contractors or lawyers fill out their Security Vulnerability Assessment (SVA)/Site Security Plan (SSP)?

FAQ #1490 Must all employees involved in filling out the Top-Screen, Security Vulnerability Assessment (SVA), or Site Security Plan (SSP) at my facility be Chemical-terrorism Vulnerability Information (CVI) Authorized Users?

FAQ #1554 Does the Cybersecurity and Infrastructure Security Agency (CISA) have enforcement authority to fine noncompliant facilities, to include shutting down a facility?

FAQ #1620 How does an individual report a possible security concern involving the Chemical Facility Anti-Terrorism Standards (CFATS) regulation at one’s facility or another facility?

FAQ #1633 What is a proposed measure and why would a facility include one in their Site Security Plan (SSP)?

FAQ #1635 The Risk-Based Performance Standards (RBPS) for "Shipping, Receipt and Storage" (RBPS 5) and for "Theft and Diversion" (RBPS 6) in the Chemical Facility Anti-Terrorism Standards (CFATS) regulation (6 CFR §§ 27.230(a)(5) and (a)(6)) refer to "hazardous materials" and to "dangerous chemicals," respectively. Do those terms include any chemicals other than chemicals of interest (COI) listed in Appendix A of the CFATS regulation?

FAQ #1653 If a facility is in a location where another entity provides certain security measures (e.g., industrial park, co-located facility: office park, etc.), can the facility include these security measures as part of its Security Vulnerability Assessment (SVA)/Site Security Plan (SSP)?

FAQ #1724 How do National Terrorism Advisory System (NTAS) Alerts and Bulletins affect a CFATS facility’s RBPS 13 compliance responsibilities?

FAQ #1735 How can a corporation with multiple facilities regulated under the Chemical Facility Anti-Terrorism Standards (CFATS) request the corporate approach and what benefits does this provide the corporation?

FAQ #1738 What is the difference between the Expedited Approval Program (EAP) and the Chemical Facility Anti-Terrorism Standards (CFATS) program?

FAQ #1745 If a facility has submitted a Site Security Plan (SSP) or an Alternative Security Program (ASP) in lieu of an SSP, but does not yet have approval, can it still be part of the Expedited Approval Program (EAP)?

FAQ #1750 What happens after I submit my Expedited Approval Program Site Security Plan (EAP SSP)?

FAQ #1751 If my facility has been issued a “letter of acceptance” through the Expedited Approval Program (EAP), but then the Cybersecurity and Infrastructure Security Agency (CISA) discovers that the measures in the Site Security Plan (SSP) insufficiently meet the risk-based performance standards (RBPS) during a Compliance Inspection, what happens?

NOTE: The links provided for the FAQs in this post were copied from the CFATS Knowledge Center but may not work when followed from your machine. This is an artifact of that web site. If the links do not take you to the referenced FAQ you will have to use the ‘Advanced Search’ function on the page to link to the FAQ or download the ‘All FAQs’ document at the bottom of the ‘Advanced Search’ page.

The following changes were made in the referenced responses:

#1275 Editorial change to address – Changed ‘Chemical Security’ to ‘Office of Chemical Security’,

#1481 Editorial change to Question – Added ‘?’ at the end of the question,

#1489 Editorial change to Answer – Changed ‘(high risk)’ to ‘(high-risk)’,

#1490 Editorial change to Answer – In first paragraph changed ‘with regards to the SVA development’ to read ‘with regards to the development of the facility's Top-Screen, SVA, or SSP’,

#1554 Editorial change to Answer – In first paragraph changed ‘specified time frame’ to read ‘specified timeframe’,

#1620 Editorial change to Answer – In second paragraph changed type on email address to BOLD,

#1633 Editorial change to Answer – Added period at the end of each sentence in the subparagraphs,

#1635 Editorial change to Question – Changed ‘Risk-based’ to ‘Risk-Based’,

#1653 No apparent change,

#1724 Editorial change to Answer – In first paragraph changed ‘businesses and governments’ to read ‘businesses, and governments’,

#1735 Editorial change to Answer – In second paragraph changed ‘Chief of Regulatory Compliance’ to ‘Chief of Chemical Security’,

#1738 Editorial change to Answer – Changed ‘meets the applicable’ to read ‘meet the applicable’,

#1745 No apparent change,

#1750 Editorial change to Answer – In second paragraph changed ‘if DHS fails’ to read ‘if CISA fails’,

#1751 Editorial change to Question – Changed ‘Cyber Infrastructure Security Agency (CISA)’ to “Cybersecurity Infrastructure Security Agency (CISA).

Tuesday, November 10, 2020

5 Advisories and 2 Updates Published – 11-20-20

Today the CISA NCCIC-ICS published five control system security advisories for products from Siemens (2), Schneider, and OSIsoft. They also published updates for two advisories for products from Siemens.

SCALANCE Advisory

This advisory describes an improper input validation vulnerability in the Siemens SCALANCE W 1750D. The vulnerability is self-reported. The Siemens advisory notes that this is a third-party (Aruba Instant) vulnerability that was originally reported by Aruba in 2016 as three separate CVE’s (CVE-2016-2031, CVE-2016-0801, and CVE-2016-0802); there are publicly available exploits for the first two CVE’s. Siemens reports that they consolidated the vulnerabilities to a single CVE. Siemens has a new firmware version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to achieve remote code execution.

NOTE: Looking at the Aruba advisory and associated exploit reports it looks to me like there is more at risk here.

SIMATIC Advisory

This advisory describes an uncontrolled resource consumption vulnerability in the Siemens SIMATIC S7-300 CPUs and SINUMERIK Controller. The vulnerability was reported by WangFangLi from Beijing Winicssec Technology. Siemens is providing generic workarounds while working on appropriate updates.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow an attacker to cause a denial-of-service condition.

Schneider Advisory

This advisory describes an improper check for unusual or exceptional conditions vulnerability in the Schneider PLC Simulator for EcoStruxure Control Expert. The vulnerability was reported by Parity Dynamics Research Team. The Schneider advisory describes three additional vulnerabilities and two addition reporting research teams. Schneider has a new version that mitigates all four vulnerabilities. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The four vulnerabilities reported by Schneider are:

• Classic buffer overflow - CVE-2020-7559,

• Improper check for unusual or exceptional conditions - CVE-2020-7538,

• Incorrect authorization - CVE-2020-28211, and

• Download of code without integrity check - CVE-2020-28213

NCCIC-ICS reports (for their single vulnerability) that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial-of-service condition, which could result in a failure of the EcoStruxture Control Expert Simulator.

PI Vision Advisory

This advisory describes two vulnerabilities in the OSIsoft PI Vision 2020. The vulnerabilities are self-reported. OSIsoft has a new version that mitigates the vulnerabilities.

The two reported vulnerabilities are:

• Cross-site scripting - CVE-2020-25163, and

• Incorrect authorization - CVE-2020-25167

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow a remote attacker with write access to the PI ProcessBook files to inject code that is imported into PI Vision, or disclose information to a user with insufficient privileges.

PI Interface Advisory

This advisory describes a numeric errors vulnerability in the OSIsoft PI Interface. The vulnerability is self-reported. OSIsoft has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker-controlled OPC XML-DA Server to respond with a crafted XML message and exploit the PI Interface for OPC XML-DA, resulting in code execution.

UMC Stack Update

This update provides additional information on an advisory that was originally published on July 14th, 2020 and most recently updated on September 8th, 2020. The new information includes providing updated affected version information and mitigation measures for SIMOCODE ES.

SIMATIC Update

This update provides additional information on an advisory that was originally published on September 8th, 2020 and most recently updated on October 13th, 2020. The new information includes a corrected CVSS Score for CVE-2020-15791.

Other Advisories and Updates

Siemens published two additional updates today. Schneider published six additional advisories and five updates today. I will cover these this weekend.

Treasury Department Publishes TRIA Update NPRM to Include Cyber Insurance

Today the Treasury Department published a notice of proposed rulemaking in the Federal Register (85 FR 71588-71593) concerning “Updated Regulations in Light of  the Terrorism Risk Insurance Program Reauthorization Act of 2019”. This rulemaking would implement technical changes to the TRIP mandated by the Terrorism Risk Insurance Program Reauthorization Act of 2019 which was included as Title V, Division I of PL 116-94 (the second of the FY 2020 spending bills, HR 1856).

Cyber Incident Coverage

PL116-94 did not specifically require the Treasury Department to cover cyber incidents under the TRIP. Rather §502(d) {133 STAT. 3027} required a study and report on cyber terrorism that included a requirement to make “recommendations on how Congress could amend the Terrorism Risk Insurance Act of 2002 (15 U.S.C. 6701 note) to meet the next generation of cyber threats” {§502(d)(2)}. That report is not directly referenced in this rulemaking.

What the rulemaking would do is to incorporate into the regulations guidance that the Department issued in 2016 to address the application of TRIA and the Program regulations to certain cyber risk insurance policies. This is specifically addressed by adding the following language to the definition of ‘property and casualty insurance’ in 31 CFR 50.4(w)(1): “a stand-alone cyber liability policy falling within Line 17”.

The coverage under this program is still limited to ‘terrorist attacks’ certified by the Treasury Department and only apply to Federal guarantees to insurers. The TRIP is designed to insure that a major terrorist attack does not bankrupt insurance companies.

Public Comments

The Department is soliciting public comments on this NPRM. Comments may be submitted through the Federal eRulemaking Portal (www.Regulations.gov; Docket # TREAS_FRDOC_0001-0380). Comments should be submitted by January 11th, 2021.

FAA Sends UAS Limited Recreational Operation NPRM to OMB

Yesterday the DOT’s Federal Aviation Administration (FAA) sent a notice of proposed rulemaking to the OMB’s Office of Information and Regulatory Affairs (OIRA) on “Exception for Limited Recreational Operations of Unmanned Aircraft” for review. This rulemaking has not been published in the Unified Agenda, so it is difficult to determine the intended scope of the rulemaking. I suspect that this deals with exceptions to the “Remote Identification of Unmanned Aircraft Systems” final rule that was sent to OIRA in October.

Monday, November 9, 2020

ISCD Updates 4 FAQ Responses – 11-9-20

Today the CISA Infrastructure Security Compliance Division (ISCD) updated the responses to two frequently asked questions (FAQs) on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center web page.

The following FAQ responses were revised:

FAQ #81 How do I register for the Chemical Security Assessment Tool (CSAT)?

FAQ #1194 Are facilities, particularly colleges and universities, able to avoid reporting certain chemical(s) of interest (COI) in their Top-Screen?

FAQ #1228 How is the screening threshold quantity (STQ) calculated for ammonium nitrate (AN) [with more than 0.2 percent combustible substance, including any organic substance calculated as carbon, to the exclusion of any other added substance]?

FAQ #1274 How can a person contact the Chemical Security Assessment Tool (CSAT) Help Desk?

NOTE: The links provided for the FAQs in this post were copied from the CFATS Knowledge Center but may not work when followed from your machine. This is an artifact of that web site. If the links do not take you to the referenced FAQ you will have to use the ‘Advanced Search’ function on the page to link to the FAQ or download the ‘All FAQs’ document at the bottom of the ‘Advanced Search’ page.

The following changes were made in the referenced responses:

FAQ #81 Editorial substitution of ‘follow’ for ‘following’ in first sentence,

FAQ #1194 Editorial addition of ‘)’ after first CFR site,

FAQ #1228 Editorial removal of second ‘.’ after “5,000 pounds” in second paragraph, and

FAQ #1274 No apparent change except for date.

Sunday, November 8, 2020

2020 Election and 117th Congress

While the results are not technically official, the great 2020 election count is essentially over. Baring something strange (and this is 2020), 2021 will see a Biden Administration take office. The House will still be in control of the Democrats and the Senate will (probably) remain in the nominal control of the Republicans. So, what does this all mean for control system security legislation and chemical security legislation in the 117th Congress?

The Trump Effect

While Trump lost the election, one thing is clear, he has lots of support in the hinterlands of this country. Republican politicians are going to have to acknowledge their anti-government and anti-liberal outlook as they look forward to the 2022 election cycle. How much those congresscritters are going to be willing to work with the Biden Administration will depend in a large amount on Donald Trump. If Trump continues to defy political traditions and maintains an active commentary on political matters, then the Republicans in Congress will have a harder time justifying to their base any cooperation on bipartisan legislation. If Trump folds up his tent and returns to his previous business interests, then moderate, bipartisan legislation will have some chance for success.

Spending

Any legislation, security and otherwise, that calls for significant new spending is going to run into strong opposition in the fiscal conservative faction of the Republican Caucus in the Senate. McConnel had to have their support in the 116th Congress to keep the Caucus together. If the Trump Effect disappears, McConnel will have more leeway to work with the Democrats. Large spending programs are still going to face serious opposition.

Cybersecurity

With no major cybersecurity attacks on the election system in 2020, there is going to be a lesser demand in Congress to pass major cybersecurity legislation. Republican opposition to government mandates on businesses will continue to insure that any cybersecurity legislation will only call for voluntary compliance with any cybersecurity standards and processes established by legislation. Cybersecurity in industrial control systems will continue to be a low priority area of legislation, unless, of course, there is a significant attack on an industrial system that leads to loss of life, major physical destruction or the shutdown of major services. An attack of that sort would lead to a knee jerk reaction in any Congress that could result in significant (and probably ineffective) mandatory controls being placed on industrial control systems.

One area that will see continued support in Congress will be development of a ‘Cyber Sense’ program in DOE similar to that seen in this session’s HR 360 that was passed in the House. This sort of cybersecurity certification program for industrial control system components used in the grid infrastructure will look like an effective way to ensure security of the grid. What will be overlooked is that the replacement of ‘insecure’ components with cybersecurity certified devices will take years to accomplish if it is actually attempted, something that is far from certain without a specific (and well-funded) mandate. Further, the unfortunate information sharing limitations are sure to have the unintended consequence of impeding researchers from finding new vulnerabilities in these systems.

Additional programs could be seen to be called for in medical device security and automated transportation systems. A cyber sense program for automated transportation systems could probably be the most effective since there is not currently a large installed-device inventory that would have to be replaced. Unfortunately, the most appropriate agency to be tasked with overseeing such a program, the National Highway Transportation Safety Administration (NHTSA) does not have a cybersecurity infrastructure to call upon to oversee such a program. Adding that capability would call for a significant increase in NHTSA funding.

Ransomware

Ransomware is going to continue to be a long-term, high-profile problem going forward that may see a legislative program that actually contains some sort of mandatory provisions. Unfortunately, the prevention of these attacks will not be effective as long as the potential for making money in successful attacks remains so high. Well-funded attackers are going to be able to find ways to subvert security controls. Federal rules will be most effective in mandating reporting requirements, though there will be increasing calls for the prohibition of paying the ransoms. There will also be suggestions that the military, particularly the National Guard cyber units, be given authority to take down ransomware networks that attack State, local, Tribal and Territorial government agencies. How far legislative provision go will depend in large part in how effective ransomware attacks remain.

Chemical Security

When Congress extended the authorization for the Chemical Facility Anti-Terrorism Standards (CFATS) program this year it was for three years. That means that there will not be a major push to make changes to that program in the 117th Congress. Even if there were a need to reauthorize the program, it is unlikely that the 2020 election would have had any significant change in the ability of the 117th Congress to agree to what sort of changes are required in the program. The House Democrats could not agree on legislative language for a reauthorization bill in the 116th Congress, this has been a continuing problem with the differences in outlook between the Homeland Security Committee and the Energy and Commerce Committee.

One area that may see some legislative movement is a relook at the mandate for an Ammonium Nitrate Security Program. Congress passed a mandate for DHS to establish a program to regulate the sale and transfer of ammonium nitrate (a ‘popular’ precursor for large improvised explosive devices). Unfortunately, DHS has been unable to come up with a cost-effective method of implementing that mandate. DHS has quietly suggested that Congress relook at the mandate, removing the costly registration requirements and extending the coverage to other precursor chemicals. The Biden Administration may be more vocal in supporting such a change and we could see some congressional hearings on the topic in the 117th Congress. I would be surprised to see any such regulation passed in this session. Unless, of course, if there is a large IED detonated successfully in the United States, then I would expect to see quick, over-reactive legislation calling for an expansion of the current mandate.

 
/* Use this with templates/template-twocol.html */