Tuesday, March 15, 2022

Bills Introduced – 3-14-22

NOTE: Corrected date in title (3-16-22, 0702 EDT)

Yesterday, with just the Senate in session (the House returns to Washington today), there were 15 bills introduced. Two of those bills may receive additional coverage here:

S 3830 A bill to require original equipment manufacturers of digital electronic equipment to make available certain documentation, diagnostic, and repair information to independent repair providers, and for other purposes. Sen. Lujan, Ben Ray [D-NM] 

S 3834 A bill to strengthen medical device supply chains. Sen. Braun, Mike [R-IN] 

I will be watching S 3830 for language and definitions that would indicate cybersecurity coverage in the provision of this bill.

I will be watching S 3834 for language and definitions that could include cybersecurity concerns in supply chain requirements.

Monday, March 14, 2022

Review - HR 6812 Introduced – SBA Cybersecurity Grant Pilot

Last month, Rep Joyce (R,OH) introduced HR 6812, the Small Business Cybersecurity Assistance Pilot Program Act. The bill would provide continued funding for the Cybersecurity Assistance Pilot Program through 2025 at the rate of $3 million per year. The bill also contains congressional reporting requirements.

Moving Forward

While Joyce is not a member of the House Small Business Committee to which this bill was assigned for consideration, one of his cosponsors {Rep Garbarino (R,NY)} is a member. This means that there may be sufficient influence to see this bill considered in Committee. I see nothing in this bill that would engender any organized opposition. Even the authorization provision, which frequently impedes consideration of bills like this, should not be a problem since the Appropriations Committee is obviously already on board.

I suspect that the bill would receive significant bipartisan support in Committee and that that support should be large enough to allow this bill to be considered under the suspension of the rules process.

Commentary

This is a rather small ‘pilot’ grant program, but it still deserves better documentation of the purpose and scope of the program than the mention in passing in two separate spending bill explanatory statements that has been the sole documentation of the authorization of this program.

For more details on the history of this program and provisions of the bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-6812-introduced - subscription required.

FDA Sends Medical Device Cybersecurity Guidance to OMB

On Friday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice from the FDA on “Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions; Draft Guidance for Industry and Food and Drug Administration Staff”. This guidance document was not listed in the Fall 2021 Unified Agenda (guidance documents are not typically listed there), but this looks like it may be an update of the 2018 Draft Guidance: Content of Premarket Submissions for Management of Cybersecurity in Medical Devices.

Sunday, March 13, 2022

Reader Comment – Misinformation in OT

In response to my post yesterday about the upcoming meeting of the CISA Cybersecurity Advisory Committee (CSAC), Vytautas Butrimas left the following comment on LinkedIn:

“Reading one of the bullets – ‘Protecting Critical Infrastructure from Misinformation and Disinformation Subcommittee’ - one may wonder what their definition of critical infrastructure is. Any room for safety and process control issues or will the focus be on email, websites and social media?”

The short and quick answer to the question looks like the target of this Subcommittee will be information system misinformation. I say this based upon the report from the first meeting of the CSAC. The page 3 discussion about this Subcommittee reads thus:

“On the topic of Protecting Critical Infrastructure from Misinformation & Disinformation, Dr. Kate Starbird, University of Washington, noted that the level of disinformation being spread across information systems has been increasing dramatically in recent years. She noted that it was used in 2020 to undermine the U.S. election system and that it has also made it difficult for Governments to address crisis events like the COVID-19 pandemic. She said that the solution to addressing this is to teach people to care about whether what they're sharing is true or false. Mr. Chesney noted that it might be very difficult to get people to unlearn bad behavior like that as, after a while, it becomes an entrenched cognitive bias. He suggested that working with the various social media platforms to address the problem might be the best approach. Mr. Stamos and Ms. Allison noted that Government agencies are very bad at using their authority and platforms to push back against disinformation. Ms. Allison suggested that CISA create a playbook for agencies to use in responding to the spread of disinformation.”

Truthfully, none of the subcommittees would seem to be specifically directed at operational technology cybersecurity issues. The closest we get is the Building Resilience and Reducing Systemic Risk to Critical Infrastructure Subcommittee. The summary of the discussion about that Subcommittee area give us this statement:

“Mr. Fanning stated that one of the biggest impediments to industry and Government working together to address systemic risk is identifying the truly critical elements in critical infrastructure. He said CISA can help develop solutions, but that industry will need to take the lead in working with the Government to address the problem. Mr. Fanning noted that there are a number of models that CISA and industry could build on, such as the Analysis and Resilience Center for Systemic Risk developed by the Finance and Energy sectors. He closed by stating that, because industry controls the vast majority of critical infrastructure in the United States, the end goal should be for the Government to provide industry the tools to defend themselves.”

While the overall statement is ambiguous as to the scope of coverage of control system security issues, the final sentence is a good reminder that we are unlikely to see much in the way specific help on OT security issues.

Having said that, it is early in the life of the CSAC and perhaps we can still influence the direction they will take as they move forward. The best way to do that would be to actively participate in the considerations of the Committee. The easiest way to do this would be to begin sending proposals for the Subcommittees to consider, targeting the reducing systemic risk subcommittee. I will start that process by proposing two activities to be considered.

Proposing the formal establishment of the NCCIC-ICS as the office within CISA that is responsible for receiving, coordinating and publishing reports of control system vulnerabilities.

Proposing that the subcommittee start work on developing the regulatory structure for setting up the recently passed cyber incident reporting requirement.

I’ll have more discussion about these two potential ideas in future posts.

Review – Public ICS Disclosures – Week of 3-5-22 – Part 3

 Finally, this week we have six more vendor disclosures from Schneider (3) and Siemens (3). Then we have sixteen updates from Schneider (6) and Siemens (10).

Schneider Advisory #1 - Schneider published an advisory describing two vulnerabilities in their EcoStruxure™ Control Expert and EcoStruxure™ Process Expert products.

Schneider Advisory #2 - Schneider published an advisory (NOTE: this is a .ZIP link that downloads two .PDF versions of this advisory, one in Chinese and the other in English) describes three vulnerabilities in their APC Smart-UPS uninterruptable power supply devices.

Schneider Advisory #3 - Schneider published an advisory describing an information exposure vulnerability in their Ritto Wiser™ Door.

Siemens Advisory #1 - Siemens published an advisory discussing an improper restriction of operations within the bounds of a memory buffer vulnerability in their RUGGEDCOM product line.

Siemens Advisory #2 - Siemens published an advisory describing an improper access control vulnerability in their Mendix Studio Pro.

Siemens Advisory #3 - Siemens published an advisory discussing an out-of-bounds write vulnerability in their RUGGEDCOM ROX devices.

Schneider Update #1 - Schneider published an update for their Log4Shell advisory that was originally published on December 13th, 2021.

Schneider Update #2 - Schneider published an update for their AT&T Labs’ Compressor advisory that was originally published on August 10th, 2021.

Schneider Update #3 - Schneider published an update for their EcoStruxureTM Control Expert advisory that was originally published on September 14th, 2021.

NOTE: NCCIC-ICS has not updated their advisory (ICSA-21-259-02).

Schneider Update #4 - Schneider published an update for their PrintNightmare advisory that was originally published on November 9th, 2021.

Schneider Update #5 – Schneider published an update for their EcoStruxureTM Control Expert advisory that was originally published on July 13th, 2021.

NOTE: NCCIC-ICS has not updated their advisory (ICSA-21-194-01).

Schneider Update #6 – Schneider published an update for their Ripple20 advisory that was originally published on June 23, 2020 and most recently updated on November 18th, 2021.

Siemens Update #1 - Siemens published an update for their OpenSSL advisory that was originally reported on July 13th, 2021 and most recently updated on February 17th, 2022.

Siemens Update #2 – Siemens published an update for their Insyde Bios advisory that was originally published on February 22nd, 2022.

Siemens Update #3 – Siemens published an update for their GNU/Linux advisory that was originally published in 2018 and most recently updated on February 8th, 2022.

Siemens Update #4 – Siemens published an update for their Controllers CPU 1518 MFP advisory that was originally published on May 11th, 2021.

NOTE: NCCIC-ICS has not updated their advisory (ICSA-21-131-15).

Siemens Update #5 – Siemens published an update for their Amnesia:33 advisory that was originally published on March 9th, 2021 and most recently updated on February 8th, 2022.

Siemens Update #6 – Siemens published an update for their general Log4Shell advisory that was originally published on December 13th, 2021 and most recently updated on February 8th, 2022.

Siemens Update #7 – Siemens published an update for their Industrial PCs advisory that was originally published on May 11th, 2021 and most recently updated on August 10th, 2021.

Siemens Update #8 – Siemens published an update for their RUGGEDCOM advisory that was originally published on March 8th, 2022.

NOTE: NCCIC-ICS has not updated their advisory (ICSA-22-069-12)

Siemens Update #9 – Siemens published an update for their their SegmentSmack advisory that was originally published on April 14th, 2020 and most recently updated on February 8th, 2022.

NOTE: NCCIC-ICS has not updated their advisory (ICSA-20-105-08) for this information.

Siemens Update #10 – Siemens published an update for their RUGGEDCOM advisory that was originally published on March 8th, 2022.

NOTE: NCCIC-ICS has not updated their advisory (ICSA-22-069-01) for this information.

 

For more details on these disclosures, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-918 - subscription required.

Saturday, March 12, 2022

Cybersecurity Advisory Committee Meeting Notice – 3-31-22

Yesterday CISA published a Federal Advisory Committee meeting notice in the Federal Register (87 FR 14027) for a meeting of the CISA Cybersecurity Advisory Committee. The meeting will be held via a public conference call on March 31st, 2022, from 2:00 pm to 4:00 pm EDT. This will be the second meeting the CISA CAC; the first was held on December 10th, 2021.

The meeting agenda includes reports from the six sub-committees:

• Transforming the Cyber Workforce Subcommittee,

• Turning the Corner on Cyber Hygiene Subcommittee,

• Igniting the Hacker Community Subcommittee,

• Protecting Critical Infrastructure from Misinformation and Disinformation Subcommittee,

• Building Resilience and Reducing Systemic Risk to Critical Infrastructure Subcommittee, and

• Strategic Communications Subcommittee

Documents to be considered at the meeting will be available on the Committee web site by March 16th, 2022. Public comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket #CISA-2021-0022) by March 29th, 2022. Personnel wishing to participate in the teleconference should contact CISA_CybersecurityAdvisoryCommittee@cisa.dhs.gov by the same date.

Review – Public ICS Disclosures – Week of 3-5-22 – Part 2

For Part 2 we have fourteen more vendor disclosures from HP (2), HPE (4), Medtronic, Palo Alto Networks (2), Philips (2), Softing (2), and Yokogawa. We also have updates from Axis and HPE. There is also an end-of-life notice from Honeywell. Finally, there are also two exploits for products from Siemens and the DirtyPipe vulnerability. Part 3 will be the Siemens and Schneider 2nd Tuesday advisories and updates not covered by NCCIC-ICS.

HP Advisory #1 - HP published an advisory describing eleven vulnerabilities in the system BIOS of certain HP PC products.

HP Advisory #2 - HP published an advisory describing an out-of-bounds write vulnerability in various HP PC products.

HPE Advisory #1 - HPE published an advisory discussing seven vulnerabilities with multiple public exploits in their HPE Cray System Software.

HPE Advisory #2 - HPE published an advisory discussing two vulnerabilities with multiple publicly available exploits in their HPE B-Series SANnav Management Software.

HPE Advisory #3 - HPE published an advisory discussing the PwnKit vulnerability in their PE Nimble Storage and HPE Alletra 6000 Peer Persistence Witness OVA products.

HPE Advisory #4 - HPE published an advisory discussing the PwnKit vulnerability in their Virtualized Converged NonStop X NS2 VHOST CLIMs.

Medtronic Advisory - Medtronic published an advisory discussing the Access:7 vulnerabilities.

Moxa Advisory - Moxa published an advisory discussing the PwnKit vulnerability.

Palo Alto Advisory #1 - Palo Alto published an advisory describing a use of password has with insufficient computational effort vulnerability in their PAN-OS.

Palo Alto Advisory #2 - Palo Alto published an advisory discussing an out-of-bounds read vulnerability (with a known exploit) in their PAN-OS.

Philips Advisory #1 - Philips published an advisory discussing the Access:7 vulnerabilities.

Philips Advisory #2 - Philips published an advisory discussing the TLStorm vulnerabilities.

Softing Advisory #1 - Softing published an advisory describing an improper input validation vulnerability in their OPC UA C++ SDK products.

Softing Advisory #2 - Softing published an advisory describing an improper input validation vulnerability in their OPC UA C++ SDK products.

Yokogawa Advisory - Yokogawa published an advisory describing three vulnerabilities in their CENTUM VP product. The vulnerabilities were reported by FSTEC of Russia.

Axis Update - Axis published an update for their AXIS IP Utility advisory that was originally published on February 14th, 2022.

HPE Update - HPE published an update for their HPE SAN Switches advisory that was originally published on July 22nd, 2021.

Honeywell EOL Notice - Honeywell published an EOL notice for their OmniAssure Touch Readers.

Siemens Exploit - RoseSecurity published an exploit for an unauthenticated Siemens S7-1200 CPU Start/Stop Command.

DirtyPipe Exploit - Max Kellermann  published a Metasploit module for the DirtyPipe vulnerability.

 

For more details about these disclosures, including links to third-party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-873 - subscription required.

 
/* Use this with templates/template-twocol.html */