Wednesday, December 15, 2021

Reader Comment – Another Log4Shell Advisory and Update

Early this morning (not so early in Israel) I had a reader DM me over on LinkedIn (FYI www.linkedin.com/in/patrickcoyle) about a couple of other vendor notifications about Log4Shell. One was one I had covered in an earlier post (but it was updated yesterday) and the other was new to me. So, I appreciate the information and will share it here. Oh, and this leads down an interesting rabbit hole.

Prosys OPC

Proxyx OPC published a blog post about the Log4Shell vulnerability. They do not have advisories, per se, they use their blogging function to also serve that purpose. In any case, while not as stylized as an advisory the post does provide listings of affected products, unaffected products, and available mitigation measures.

Siemens Update

Siemens published an update for their Log4Shell advisory that was originally published on December 12th, 2021. The new information includes:

• Adding additional potentially affected products,

• Adding additional mitigation measures,

• Added CVE-2021-45046 (see discussion below), and

• Updated mitigation measures for new CVE.

Log4Shell2

Okay, the cute name is mine, but it looks like it may be appropriate. According to the NVD.NIST.gov entry for CVE-2021-45046: “It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations.” Please see my TWEET® reply from yesterday morning.

According to the Apache Log4j Security Vulnerabilities page, this new vulnerability was reported to them by Kai Mindermann of iC Consult. That page also notes that:

“Other insufficient mitigation measures are: setting system property log4j2.formatMsgNoLookups or environment variable LOG4J_FORMAT_MSG_NO_LOOKUPS to true for releases >= 2.10, or modifying the logging configuration to disable message lookups with %m{nolookups}, %msg{nolookups} or %message{nolookups} for releases >= 2.7 and <= 2.14.1.

“The reason these measures are insufficient is that, in addition to the Thread Context attack vector mentioned above, there are still code paths in Log4j where message lookups could occur: known examples are applications that use Logger.printf("%s", userInput), or applications that use a custom message factory, where the resulting messages do not implement StringBuilderFormattable. There may be other attack vectors. [emphasis added]

“The safest thing to do is to upgrade Log4j to a safe version, or remove the JndiLookup class from the log4j-core jar.”

Maybe we want to change the name to “Log4Hell”.

Tuesday, December 14, 2021

Review - 2 Advisories and 1 Update Published – 12-14-21

Today, CISA’s NCCIC-ICS published two control system security advisories for products from Schneider Electric and Advantech. They also updated a medical device security advisory for products from Hillrom.

Schneider Advisory - This advisory describes a cross-site scripting vulnerability in the Schneider Rack Power Distribution Unit (PDU).

Advantech Advisory - This advisory describes 26 vulnerabilities in the Advantech R-SeeNet.

NOTE: I briefly reported on these vulnerabilities on November 27th, 2021.

Hillrom Update - This update provides additional information on an advisory that was originally published on June 1st, 2021.

For additional details on these advisories, including links to the researcher reports wit POC code, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-1-update-published-ade - subscription required.

Review - Public ICS Disclosures - Log4Shell Advisories – 12-14-21

Today I am taking an out-of-band look at ICS vendor disclosures for the Log4Shell vulnerability. I have not looked at my list of medical device vendors for this post, I may look at those later this week. For this post we have 20 vendor disclosures from Aruba, Broadcom, CODESYS, Dell, GE (2), HMS (5), HPE, Hitachi Energy, Johnson Controls, QNAP, Rockwell, Ruckus, SonicWall (update), VMware and Wind River. I am using a slightly different format for this post, separating advisories into four groups; not affected, still looking, affected products list, and mitigation.

Not Affected

CODESYS published a notice that none of their products are affected.

HMS published an advisory reporting that their Argos and HMS Hub web services are not affected.

HMS published an advisory reporting that their Ixxat products are not affected.

Vendors Still Looking at the Vulnerability

GE published a generic Log4Shell advisory.

GE published an advisory.

HMS published an advisory for their Anybus product line.

HMS published an advisory for their WEBfactory product line.

Hitachi Energy published an advisory.

Meinberg published an advisory.

QNAP published an advisory.

Johnson Controls published an advisory.

Vendors With Affected Product Lists

Aruba published an advisory.

HPE published an advisory.

Ruckus published an advisory.  

SonicWall published an update for an advisory that was originally published on December 10th, 2021.

Wind River published an advisory.

Vendors With Mitigation Measures

Broadcom published an advisory.

Dell published an advisory for their Dell Wyse Management Suite.

HMS published an advisory for their EWON products.

Rockwell published an advisory.

VMware published an update for their advisory was originally published on December 10th, 2021.

For more details about these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-log4shell - subscription required.

Reader Comment – CSB Hemorrhaging

Yesterday Rosearray, a long-time reader of this blog, left a comment on my blog post about the two recent CSB confirmations. Richard made the point (with lots of supporting evidence, please see his comment) that the staff of the CSB is in near complete disarray. His closing comment summed up the situation neatly:

“What the heck! It sure looks to me like the CSB is flat out hemorrhaging personnel.”

This situation, as one might hope, is well known to the leadership of the CSB. Chair Lemos discussed it in her recent testimony before the House Energy and Commerce Committee’s Oversight and Investigations Subcommittee on September 29th, 2021. She noted:

“After accepting this role last year, I was shocked to learn of the low staff numbers. Our agency is critical to the safety and well-being of our workers, the public, communities, and environment.

“To address this, we have prioritized hiring a robust, diverse, and engaged Mission Product Team. Right now, we are completing the hiring of four investigators, and will follow shortly by bringing on additional hires to round out the technical team. By year end FY23, our plan is to have an all-time high number of investigation and technical specialists on the Mission Product Team.

“We also have increased technical contractor support, with expertise in specialized fields, such as metallurgy, blast modeling, and equipment testing. This enhances our capability, agility and reach without the need for employing all subject matter experts in-house.

The Trump Administration’s attempting to defund the CSB did little to help the Board overcome a number of internal problems that it had been facing for a number of years. People have little incentive to stick around when they keep hearing that the program could be defunded in the next year. So, it should be no surprise to anyone that there would be numerous vacancies at the CSB. But these problems take time to fix, and it is hard for a Board of One to get a lot of proactive work done. We need to give Lemos, Owns and Johnson some breathing room to fix these problems.

Review - OCS Publishes CFATS Monthly Update – 12-13-21

Yesterday, CISA’s Office of Chemical Security (OCS) updated their Chemical Facility Anti-Terrorism Standards (CFATS) Monthly Statistics page to show the summary of chemical security inspector (CSI) activities for the month of November and the status of facilities covered by the program at the end of the month. The total number of CSI activities was up from the previous month and there was a large drop in the number of covered facilities.

CSI Activities

The table below shows the activity levels for the CSI over the last four months.

Inspection Data

Aug- 21

Sep-21

Oct-21

Nov-21

Authorization Inspections

19

22

8

10

Compliance Inspections

219

154

126

182

Compliance Assistance

76

73

65

44

Compliance Audit

0

0

0

0

CFATS Facility Status

The table below shows the status of facilities in the CFATS program at the end of each of the last four months.

Facility Status

Aug-21

Sep-21

Oct-21

Nov-21

Tiered

97

83

80

57

Authorized

113

110

112

125

Approved

3070

3078

3082

3073

Total

3280

3271

3274

3255

For a more detailed analysis of the data reported, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/ocs-publishes-cfats-monthly-update - subscription required.

Monday, December 13, 2021

Siemens Publishes Log4Shell Advisory

Today, (1 day before the 2nd Tuesday tranche of Siemens advisories) Siemens published an advisory discussing the Log4Shell vulnerability in their products. Siemens has provided a preliminary list of affected products. They have fixed their cloud-based products (okay, this may be an argument for having cloud based control systems) and have provided updates for some of the affected products. They have also provided workarounds to mitigate the vulnerabilities.

I expect we will be seeing more Log4Shell advisories from other vendors. I reported briefly on Saturday on early advisories from SonicWall and VMware.

It is disappointing the NCCIC-ICS has not yet published an advisory for this vulnerability, but they may have been waiting for an advisory like this from Siemens that provides actual mitigation measures (the SonicWall and VMware advisories were of the “we are looking at it” type with no mitigation measures). It will be interesting to see how NCCIC-ICS deals with this tomorrow.

Review – S 3282 Introduced - Water Infrastructure Modernization

Last month, Sen Kelly (D,AZ) introduced S 3282, the Water Infrastructure Modernization Act of 2021. This bill provides for two new grant programs to support the modernization of wastewater and drinking water treatment facilities in the United States. HR 6068, with an identical short title, only addresses the drinking water treatment program with identical language to that found in Title II of this bill. This bill would authorize $25 million for each of the two grant programs.

Kelly is a member of the Senate Environment and Public Works Committee to which this bill was assigned for consideration. This means that there may be enough influence to see this bill considered in Committee. Beyond the cost of the two grant programs, I do not see anything in this bill that would engender any specific opposition. If this bill were considered in Committee, there would probably be bipartisan support for the bill.

Commentary

This bill has the same problem that I identified in HR 6088; it provides for the use of advanced controls technology without providing a requirement to protect those systems from cyberattacks. The same language that I proposed for adding to HR 6088 should be added to Title II of this bill. Similar language, see below, should be added to subsection (a) of the proposed §228.

(3) Any program for which a grant is provided under this section will include a comprehensive cybersecurity program to protect the operation of the smart wastewater infrastructure technology funded by the grant. That cybersecurity program will include, as a minimum:

(i) virtual and physical network segmentation separating the smart water infrastructure technology from the business networks of the agency being supported,

(ii) least privilege access controls for the smart water infrastructure networks, including two-factor authentication for remote access, and

(iii) an annual third-party audit of cybersecurity controls, software updates, internal system log reviews and incident response reports.

For more details about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-3282-introduced - subscription required.

 
/* Use this with templates/template-twocol.html */