Thursday, February 10, 2022

Review – 6 Advisories Published – 2-10-22

Today, CISA’s NCCIC-ICS published 6 control system security advisories for products from Siemens.

NOTE: They also published 12 updates for Siemens’ advisories. I will cover those in a separate post.

Spectrum Power Advisory - This advisory describes a cross-site scripting vulnerability in the Siemens SINEMA Spectrum Power 4.

SICAM Advisory - This advisory describes a use of hard-coded credentials vulnerability in the Siemens SICAM TOOLBOX II software platform.

SINEMA Advisory - This advisory describes an open redirect vulnerability in the Siemens SINEMA Remote Connect Server.

Simcenter Advisory - This advisory describes 11 vulnerabilities in the Siemens Simcenter Femap advanced simulation application.

WinCC and PCS Advisory - This advisory describes two vulnerabilities in the Siemens SIMATIC WinCC and PCS.

NOTE: The Siemens advisory reports that there are no fixes planned for the following products:

• SIMATIC PCS 7 V8.2 and earlier, and

• SIMATIC PCS 7 V9.0:

Industrial Products Advisory - This advisory describes three vulnerabilities in the Siemens SIMATIC Industrial Products. The vulnerabilities were reported by Gao Jian.

Other Siemens Advisories - Siemens published three other new advisories on Tuesday. I will be covering them this weekend.

 

For more details about these advisories, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-published-2-10-22 - subscription required.


Bills Introduced – 2-9-22

Yesterday, with both the House and Senate in Washington, there were 82 bills introduced. One of those bills may receive additional coverage in this blog:

S 3618 A bill to amend the Federal Cybersecurity Enhancement Act of 2015 to require Federal agencies to obtain exemptions from certain cybersecurity requirements in order to avoid compliance with those requirements, and for other purposes.

I suspect that this is a housekeeping bill and will probably not be covered here, but I will be watching it for language and definitions that would include control system security issues within the scope of the bill.

Wednesday, February 9, 2022

Review - HR 6571 Introduced – TSA Enrollments

Last week Rep Smith (D,WA) introduced HR 6571, the TSA Security Threat Assessment Application Modernization Act. The bill would require TSA to standardize the enrollment and renewal processes for the TWIC, HAZMAT endorsement and the TSA PreCheck program. No funding is authorized by this bill.

Moving Forward

While Smith is not a member of the House Homeland Security Committee to which this bill was assigned for consideration, two of his cosponsors {Rep Katko (R,NY) and Rep Luria (D,VA)} are members of the Committee. This means that there may be sufficient influence to see the bill considered in Committee. I suspect that the bill would receive bipartisan support. The bill would probably be considered under the suspension of the rules process if it were adopted in Committee.

Commentary

In early stages of these three TSA security threat assessment programs there were certainly problems that holders of one of the credentials had when applying for one of the other credentials. Those problems have been reduced in recent years. According to the TSA’s HAZMAT Endorsement web site, States are already authorized “to issue an HME on a state-issued CDL to a driver who holds a valid” TWIC. Similarly, TSA announced in 2020 that: “TWIC® and HME holders can obtain TSA PreCheck expedited screening by entering the identification numbers printed on their TWIC® card or state-issued CDL during the airline reservation process.”

All of this does not mean that there is a centralized location (real or virtual) where there is one stop shopping for all three credentials. One thing that this bill does not address is the fact that there are still eight states (Florida, Kentucky, Maryland, New York, Pennsylvania, Texas, Virginia and Wisconsin) where CDL holders must apply at a State DMV office to apply for their HME.

For more details about this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-6571-introduced - subscription required.

Bills Introduced – 2-8-22

Yesterday, with both the House and Senate in session, there were 32 bills introduced. One of those bills may receive additional coverage in this blog:

S 3600 A bill to improve the cybersecurity of the Federal Government, and for other purposes. Sen. Peters, Gary C. [D-MI] 

I will be watching this blog for language and definitions that would include control system security within the scope of its provisions.

Tuesday, February 8, 2022

HR 6617 Passed in House – FY 2022 CR

This afternoon, the House passed HR 6617, the Further Additional Continuing Appropriations Act by a moderately bipartisan vote of 272 to 162. The bill will extend the current level of government spending through March 11th, 2021. The bill will probably be taken up later this week. The current spending authorization expires February 18th, 2022. The House took up the bill this week because they are scheduled to be working remotely next week.

Review - 2 Updates Published – 2-8-22

Today, CISA’s NCCIC-ICS updated two control system security advisories for products from Mitsubishi.

Mitsubishi Update #1 - This update provides additional information on an advisory that was originally published on July 30th, 2020 and most recently updated on November 18th, 2021.

Mitsubishi Update #2 - This update provides additional information on an advisory that was originally published on February 18th, 2021 and most recently updated on November 16th, 2021.

 

For more details about these updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-updates-published-2-8-22 - subscription required.

House to Consider HR 6617 – FY 2022 CR

The House is scheduled to take up HR 6617, the Further Additional Ex5 tending Government Funding Act. The bill would extend the current continuing resolution thru March 11th. This is a relatively ‘clean’ CR. It does add funds for response and clean up of the military fuel leakage in Hawaii. Division B of the bill provides extensions a number of different authorities, including the scheduling of fentanyl-related substances as schedule I controlled substances, through March 11th.

The bill will be considered under a closed rule, 1-hour of debate and no amendments. The bill is likely to pass with at least some bipartisan support. It will likely be taken up in the Senate later this week. The current CR expires on February 18th, 2022.

 
/* Use this with templates/template-twocol.html */