Sunday, January 17, 2021

CISA Publishes 2020 Chemical Security Presentations

This week the Cybersecurity and Infrastructure Security Agency (CISA) updated their Chemical Security Summit web site to include links to most of the presentations that were made last month in the three-day virtual summit. For the first time, I was able to watch many of these presentations live (well… online in real time).

The available presentations include:

CFATS Personnel Surety Program Demonstration and Lessons Learned,

CFATS Risk-Based Performance Standards Deep Dive and Best Practices,

Chemical Sector Security Awareness Training,

Cyber and Physical Security in Manufacturing Environments,

Cybersecurity Evaluation Tool (CSET),

Federal Emergency Management Agency (FEMA) Response: Hurricanes, Wildfires, Floods, and Pandemics,

Incentivizing Facility Security: A Nonregulatory Approach,

Jack Rabbit III Initiatives, and

Transportation Security Administration Surface Operations Overview

As is usual with these Summit presentations, what you get is the slides not the audio portion and the real detail of most of these presentations is in the audio. I know, those audio files would be huge, but it would be much more informative and a better representation of the work that went into these presentations.

I was really surprised that CISA included Annie Hunziker Boyer’s presentation on the ongoing development of the voluntary chemical security program in the Infrastructure Security Compliance Division. Since she emphasized multiple times that this program was still ‘under development’ and would likely change before it was finally implemented, I was sure that the government lawyers were going to insist that the publication of these slides be withheld. Now that these slides are available, I will probably do a post on this initiative.

I was disappointed that one of the other presentations from the December 16th session was not included in this list of provided presentations, “Infrastructure Visualization Tools”. This presentation by the CISA Infrastructure Visualization Platform (IVP) Team was a good look at a new tool developed by the team to provide an interactive visual look at an infrastructure location; think Google Street View® that includes inside the gates with interior shots. This would be a great training tool for emergency personnel prepping for high-risk facility responses.

Public ICS Disclosure – Week of 1-9-21 – Part 2

In the second part of this week’s ‘Public ICS Disclosure’ we have two vendor disclosures from Schneider that were missed by NCCIC-ICS. We also have five updates from Schneider (4) and Siemens. There were two end-of-life notices published by Honeywell. There is also a researcher report about products from FreyrSCADA.

Schneider Advisories

Schneider published an advisory describing an improper input validation vulnerability in their EcoStruxure™ Operator Terminal Expert and Pro-face BLUE products. The vulnerability is self-reported. Schneider has a new service pack that mitigates the vulnerability.

 

Schneider published an advisory describing a heap-based buffer overflow in their Sepam ACE850 communications interface. This is a third-party (Treck) vulnerability. Schneider provides generic workarounds to mitigate the vulnerability.

NOTE: Schneider is reporting just one of the four latest Treck vulnerabilities reported by NCCIC-ICS.

Schneider Updates

Schneider published an update for their general Ripple20 advisory  that was originally published on June 23, 2020 and most recently updated on December 8th, 2020. The new information includes adding mitigation measures for PowerLogic PM5000 Series Power Meters.

 

Schneider published an update for their APC Ripple20 advisory that was  originally published on June 23, 2020 and most recently updated on December 18th, 2020. The new information includes updating the mitigation measures for their Uninterruptible Power Supply (UPS) using NMC3.

 

Schneider published an update for their EcoStruxure™ Operator Terminal Expert advisory that was originally published on November 10th, 2020. The new information includes adding Pro-face BLUE and WinGP to the list of affected products.

 

Schneider published an update for their Modicon advisory that was originally published on November 10th, 2020 and most recently updated on December 8th, 2020. The new information includes adding M100/M200 to the list of affected products.

NOTE: NCCIC-ICS published their report (ICSA-20-334-04) on these vulnerabilities for the previous Schneider revision, so I suppose they should have updated their advisory, but it is getting kind of confusing here.

Siemens Update

Siemens published an update for their CodeMeter advisory that was that was originally published on September 8th, 2020 and most recently updated on November 10th, 2020. The new information includes updating mitigation measures for PCS neo and SPPA T3000.

Honeywell End-of-Life Notices

Honeywell published an end-of-life notice [.PDF download link] for PRO3200 Series Access Control Boards.

Honeywell published an end-of-life notice [.PDF download link] for PW6000 Series Access Control Boards.

NOTE: I think that it is commendable that Honeywell takes the time to publish end-of-life notices for their now unsupported equipment. This means that any new vulnerabilities discovered in these products will not be fixed. Owners of this equipment should definitely start considering replacing them with newer products.

FreyrSCADA Report

Talos published a report describing a comparison of incompatible type vulnerability in the FreyrSCADA IEC104 server simulator. It is a coordinated disclosure with FreyrSCADA reportedly providing a patch to mitigate the vulnerability. The Talos report includes proof-of-concept code.

Saturday, January 16, 2021

Public ICS Disclosure – Week of 1-9-21 – Part 1

This week we have six vendor disclosures from Advantech, PEPPERL+FUCHS, WAGO, Philips, RUCKUS, and Rockwell (2). We have five vendor updates from Carestream, Mitsubishi, Rockwell, Siemens, and Software Toolbox.

Advantech Advisory

Advantech published an advisory describing six vulnerabilities in their Spectre RT ERT351 and

B+B SmartWorx ERT351 products. The vulnerabilities were reported by Vlad Komarov of ScadaX, and Evgeniy Druzhinin and Ilya Karpov of Rostelecom-Solar. Advantech has new firmware versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Improper neutralization of input during web page generation - CVE-2019-18233,

• Cleartext transmission of sensitive information - CVE-2019-18231,

• Improper restriction of excessive authentication attempts - CVE-2019-18235 (Linux vuln),

• Insufficiently protected credentials (no CVE number),

• Usage of broken or risky cryptographic algorithm - CVE-2019-18237,

• Use of vulnerable third-party software - CVE-2019-18239 (OpenSSH and OpenSSL)

PEPPERL+FUCHS Advisory

CERT VDE published an advisory describing a deserialization of untrusted data vulnerability in the PEPPERL+FUCHS PACTware product. This is a third-party (fdtCONTAINER component by M&M Software GmbH) vulnerability. The vulnerability was reported by M&M Software. The vulnerability will be corrected in a version to be released in the second quarter.

WAGO Advisory

CERT VDE published an advisory describing a deserialization of untrusted data vulnerability in unnamed WAGO workstations. This is the same third-party (M&M Software) vulnerability described above.

Philips Advisory

Philips published an advisory describing an undescribed vulnerability on products running on their older Haswell workstations. Philips has a patch that mitigates the vulnerability.

RUCKUS Advisory

RUCKUS published an advisory describing two vulnerabilities in the LLDP module of Ruckus Network’s AP products. These are third-party library vulnerabilities originally reported by Florian Weimer (see links below for original reporting). RUCKUS has patches that mitigate the vulnerabilities.

The two reported vulnerabilities are:

• Classic buffer overflow - CVE-2015-8011, and

• Reachable assertion - CVE-2015-8012

Rockwell Advisories

Rockwell published an advisory describing a side-channel leakage vulnerability in the NXP 7x Secure Authentication Microcontrollers. This is a third-party (Google Titan Security Key) vulnerability reported by NinjaLab. Rockwell provides generic mitigation measures.

NOTE: This is going to be an interesting one for a variety of vendors.

 

Rockwell published an advisory describing the third-party (M&M Software) fdtCONTAINER vulnerability described above in their FactoryTalk AssetCentre products. Rockwell has a software update that mitigates the vulnerability.

NOTE: Third-party vulnerabilities strike far and wide (SIGH).

Carestream Update

Carestream published an update [.PDF download link] for their Bad Neighbor advisory that was originally published on October 15th, 2020. The new information includes:

• A list of unaffected products, and

• A list of two affected products (Image Suite and Omni) with mitigation measures.

Mitsubishi Update

Mitsubishi published an update for their MC Works 64 advisory that was originally published on June 18th, 2020 and most recently updated on December 8th, 2020. The new information includes adding mitigation measures for MC Works64 Version 2.00A - 2.02C.

NOTE: NCCIC-ICS published an advisory for these vulnerabilities back in June but has not yet updated it for any of the updates that Mitsubishi has published. This is probably due to a failure by Mitsubishi to inform NCCIC-ICS of the updates.

Rockwell Update

Rockwell published an update for their FactoryTalk Linx advisory that was originally published on December 27th, 2020. The new information includes links to mitigation measures for three of the vulnerabilities.

Siemens Update

Siemens published an out-of-zone update for their SolidEdge advisory that was originally published on January 12th, 2021. The new information includes additional mitigation information for SolidEdge SE2020.

Software Toolbox Update

Software Toolbox published an update for their TopServer advisory that was originally published on December 9th, 2020. The new information includes adding the CVE numbers for the included vulnerabilities.

NOTE: This advisory was included in  ICSA-20-352-02. This update will probably not be mentioned by NCCIC-ICS since the link provided in their advisory takes one to this update.

Thursday, January 14, 2021

2 Updates Published – 1-14-21

Today CISA’s NCCIC-ICS published updates for two control system security advisories for products from Mitsubishi.

FA Engineering Products Update

This update provides additional information for an advisory that was originally published on July 30th, 2020 and most recently updated on November 5th, 2020. The new information includes updated affected version information and links for mitigation measures for:

• MELSOFT iQ AppPortal,

• MX Component, and

• MX Sheet

Factory Automation Update

This update provides additional information for an advisory that was originally published on July 30th, 2020. The new information includes updated affected version information and links for mitigation measures for:

• MELSOFT iQ AppPortal,

• MX Component, and

• MX Sheet

NOTE: Mitsubishi also published an update today for another advisory (ICSA-20-170-02) that NCCIC-ICS did not address today. I will discuss it this weekend.

Wednesday, January 13, 2021

7 Updates Published – 1-12-21

Yesterday CISA’s NCCIC-ICS published seven updates for control system security advisories for products from Siemens.

PROFINET Update

This update provides additional information on an advisory that was originally published on October 10th, 2019 and most recently updated on September 8th, 2020. The new information includes:

• Updating affected version information and adding mitigation measures for or SIMATIC ET200SP IM155-6 PN HA, and

• Listing ecoPN model (6ES7148-6JG00-0BB0) as not affected.

TIA Portal Update

This update provides additional information on an advisory that was originally published on January 14th, 2020 and most recently updated on April 14th, 2020. The new information includes updating affected version information and adding mitigation measures for TIA Portal V14.

Simatic PCS 7 Update

This update provides additional information on an advisory that was originally published on February 11th, 2020 and most recently updated on September 8th, 2020. The new information includes adding mitigation measures for SIMATIC WinCC (TIA Portal) V14.

SCALANCE Update

This update provides additional information on an advisory that was originally published on April 14th, 2020 and most recently updated on September 8th, 2020. The new information includes removing the SCALANCE S-600 family as it is not affected.

SIMOTICS Update

This update provides additional information on an advisory that was originally published on April 14th, 2020. The new information includes updating affected versions and adding mitigation measures for:

• Desigo PXC, and

• Desigo PXM20

SIMATIC Update

This update provides additional information on an advisory that was originally published on July 9th, 2020 and most recently updated on December 8th, 2020. The new information includes updating affected versions and adding mitigation measures for:

• SIMATIC STEP 7 (TIA Portal) V14, and

• SIMATIC WinCC Runtime Professional V14

Opcenter Update

This update provides additional information on an advisory that was originally published on July 14th, 2020 and most recently updated on August 11th, 2020. Then new information includes:

• Adding an insufficiently protected credentials vulnerability - CVE-2020-28390, and

• Updating mitigation measures

 

Additional Siemens Advisory

 

Siemens published one additional advisory that was not addressed by NCCIC-ICS yesterday. I will address that this weekend.

Tuesday, January 12, 2021

6 Advisories Published – 1-12-21

Today the CISA NCCIC-ICS published five control system security advisories for products from Siemens (4) and Schneider Electric. They also published a medical device security advisory for products from SOOIL Developments. NCCIC-ICS also updated seven advisories today. I will report on them separately.

SCALANCE Advisory #1

This advisory describes three vulnerabilities in the Siemens SCALANCE X Products. The vulnerabilities are self-reported. Siemens has updates for several of the affected products.

The three reported vulnerabilities are:

• Missing authentication for critical function - CVE-2020-15799, and

• Heap-based buffer overflow (2) - CVE-2020-15800 and CVE-2020-25226

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause denial-of-service conditions and further impact the system through heap and buffer overflows.

Solid Edge Advisory

This advisory describes six vulnerabilities in the Siemens Solid Edge. The vulnerabilities was reported by rgod via the Zero Day Initiative. Siemens has an updated version that mitigates the vulnerability. There is no indication that rgod has been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Out-of-bounds write (4) - CVE-2020-28381, CVE-2020-28382, CVE-2020-28383, and CVE-2020-28386, and

• Stack-based buffer overflow (2) - CVE-2020-28384 and CVE-2020-26989

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to allow arbitrary code execution on an affected system.

JT2Go Advisory

This advisory describes eighteen vulnerabilities in the Siemens JT2Go and Teamcenter Visualization products. The vulnerabilities was reported by rgod via ZDI. Siemens has new versions that mitigate the vulnerabilities. There is no indication that rgod has been provided an opportunity to verify the efficacy of the fix.

The eighteen reported vulnerabilities are:

Type confusion - CVE-2020-26980, CVE-2020-26990,

• Improper restriction of XML external entity reference - CVE-2020-26981,

• Out-of-bounds write (7) - CVE-2020-26982, CVE-2020-26983, CVE-2020-26984, CVE-2020-26988, CVE-2020-26995, CVE-2020-26996, and CVE-2020-28383,

• Heap-based buffer overflow (4) - CVE-2020-26985, CVE-2020-26986, CVE-2020-26987, and CVE-2020-26994,

• Stack-based buffer overflow (3) - CVE-2020-26989, CVE-2020-26992, and CVE-2020-26993,

• Untrusted pointer dereference - CVE-2020-26991,

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to lead to arbitrary code execution.

SCALANCE Advisory #2

This advisory describes two use of hard-coded cryptographic key vulnerabilities in the Siemens SCALANCE X200, X200IRT, X300 switch families. The vulnerabilities are self-reported. Siemens has updates for some of the affected products which mitigate the vulnerabilities.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to execute a man-in-the-middle attack and decrypt previously captured traffic.

Schneider Advisory

This advisory describes two unrestricted upload of file with dangerous type vulnerabilities in the Schneider EcoStruxure Power Build – Rapsody products. The vulnerabilities were reported by rgod via ZDI. Schneider is working on mitigation measures.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to  allow a local attacker to upload a malicious SSD file, resulting in a use-after-free condition or a stack-based buffer overflow.

SOOIL Advisory

This advisory describes nine vulnerabilities in the SOOIL Dana Diabecare Insulin Pumps. The vulnerabilities were reported by Julian Suleder, Birk Kauer, Raphael Pavlidis, and Nils Emmerich of ERNW Research GmbH. SOOIL has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The nine reported vulnerabilities are:

• Use of hard-coded credentials - CVE-2020-27256,

• Insufficiently protected credentials - CVE-2020-27258,

• Insufficiently random values - CVE-2020-27264,

• Use of client-side authentication - CVE-2020-27266,

• Client-side enforcement of server-side security - CVE-2020-27268,

• Authentication bypass by capture-replay - CVE-2020-27269,

• Unprotected transport of credentials - CVE-2020-27270,

• Key exchange without entity authentication - CVE-2020-27272, and

• Authentication bypass spoofing - CVE-2020-27276

NHTSA Publishes Cybersecurity Request for Comments

Today the DOT’s National Highway Transportation Safety Administration (NHTSA) published a request for comments in the Federal Register (86 FR 2481-2486) on its draft update [.PDF Download] for their “Cybersecurity Best Practices for the Safety of Modern Vehicles”. This is an update of the 2016 version of the document based upon ongoing research and comments received from government agencies, industry and the public on the original document [.PDF download].

In today’s notice NHTSA makes it clear that it continues to believe that adoption of these best practices should be voluntary. They also specifically note that they deal with safety aspects of cybersecurity. Safety is the NHTSA mandate not privacy.

New Guidance

The new draft includes the following ‘new’ best practices:

[G.6] Manufacturers should consider the risks associated with sensor vulnerabilities and potential sensor signal manipulation efforts such as GPS spoofing, road sign modification, Lidar/Radar jamming and spoofing, camera blinding, or excitation of machine learning false positives.

[G.9] Clear cybersecurity expectations should be specified and communicated to the suppliers that support the intended protections.

[G.10] Manufacturers should maintain a database of operational software components used in each automotive ECU, each assembled vehicle, and a history log of version updates applied over the vehicle's lifetime; and Manufacturers should track sufficient details related to software components, such that when a newly identified vulnerability is identified related to an open source or off-the-shelf software, manufacturers can quickly identify what ECUs and specific vehicles would be affected by it.

[G.12] Manufacturers should evaluate all commercial off-the-shelf and open-source software components used in vehicle ECUs against known vulnerabilities.

[G.22] Best practices for secure software development should be followed, for example as outlined in NIST 8151 and ISO/SAE 21434.

[G.23] Manufacturers should actively participate in automotive industry-specific best practices and standards development activities through Auto-ISAC and other recognized standards development organizations.

[G.30] Commensurate to assessed risks, organizations should have a plan for addressing newly identified vulnerabilities on consumer-owned vehicles in the field, inventories of vehicles built but not yet distributed to dealers, vehicles delivered to dealerships but not yet sold to consumers, as well as future products and vehicles.

[G.40] Any connection to a third-party device should be authenticated and provided with appropriate limited access.

[T.7] The use of global symmetric keys and ad-hoc cryptographic techniques for diagnostic access should be minimized.

[T.8] Vehicle and diagnostic tool manufacturers should control tools' access to vehicle systems that can perform diagnostic operations and reprogramming by providing for appropriate authentication and access control.

[T.12] Such logs that can be aggregated across vehicles should be periodically reviewed to assess potential trends of cyber-attacks.

[T.13] Manufacturers should treat all networks and systems external to a vehicle's wireless interfaces as untrusted and use appropriate techniques to mitigate potential threats.

[T.22] Maintain the integrity of OTA updates, update servers, the transmission mechanism and the updating process in general.

[T.23] Take into account, when designing security measures, the risks associated with compromised servers, insider threats, men-in-the-middle attacks, and protocol vulnerabilities.

Public Comments

NHTSA is soliciting public comments on this draft document. Comments may be submitted via the Federal eRulemaking Portal (www.regulations.gov; Docket #NHTSA-2020-0087). Comments should be submitted by March 15th, 2020.

Commentary

Guidance documents such as this have two major shortcomings. First, and foremost, since they are self-pronouncedly voluntary, there is no way to ensure that they are being followed. Second, even if a company were to try to adhere to this guidance, without an outside eye to watch over how the guidance is implemented to ensure that the company really understands what it is doing or trying to do from a cybersecurity perspective, there will be significant gaps in the resulting cybersecurity coverage.

This is not privacy or money that NHTSA is trying to protect. You can not go back and require a company that failed to adequately implement these best practices make an affected customer whole by replacing mangled limbs or reanimating dead bodies. Lack of cybersecurity in moving vehicles is going to have physical consequences in the real world. Monetary damages from lawsuits are not going to be an adequate (and will be a very delayed) response to cybersecurity failures.

 
/* Use this with templates/template-twocol.html */