Tuesday, April 12, 2022

Information System Technical Advisory Committee Meeting – 4-27-22

The DOC’s Bureau of Information and Security (BIS) published a revision notice in the Federal Register (87 FR 21614) revising the meeting date information for the April 27th, 2022 meeting of the Information Systems Technical Advisory Committee (ISTAC) that was published on Friday. The meeting was changed from two days to a single day. I missed Friday’s notice.

The agenda for the public portion of the meeting includes:

• Welcome and Introductions,

• Working Group Reports,

• Ideas for Wassenaar Proposals 2023,

• Old Business.

I tried to dive into the ISTAC web site to figure out what the working group reports might be covering, but the ISTAC web site is almost two years out-of-date. Still, any insight into what might end up in the 2023 Wassenaar agreement could be interesting.

The public is invited to join the public portion of the teleconference. Personnel wishing to participate should contact Ms. Yvette Springer at Yvette.Springer@bis.doc.gov by April 20, 2022.

Review – 5 Advisories Published – 4-12-22

Today, CISA’s NCCIC-ICS published five control system security advisories for products from Aethon, Mitsubishi Electric (2), Inductive Automation, and Valmet.

Aethon Advisory - This advisory describes five vulnerabilities in the Aethon TUG Home Base Server (a server used to control and communicate with autonomous mobile robots).

Mitsubishi Advisory #1 - This advisory discussing the FragAttacks WiFi vulnerabilities  in the Mitsubishi Wireless LAN communication unit GT25-WLAN in GOT2000 Series GT25 or GT27.

Mitsubishi Advisory #2 - This advisory discusses a heap-based buffer overflow vulnerability in the MELSEC-Q Series C Controller Module.

NOTE: I briefly discussed this vulnerability on Sunday.

Inductive Automation Advisory - This advisory describes a path traversal vulnerability in the Inductive Automation Ignition software.

Valmet Advisory - This advisory describes an inadequate encryption strength vulnerability in the Valmet DNA, distributed control system.

 

For more details on these advisories, including links to researcher reports and notes about other items of potential interest to OT cybersecurity community, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-published-4-12-22 - subscription required.

Monday, April 11, 2022

Review - EPA’s Worst-Case Discharge NPRM – Substantial Harm

This is the next post in my series on the recent notice of proposed rulemaking (NPRM) from the EPA for “Clean Water Act Hazardous Substance Worst Case Discharge Planning Regulations”. Earlier posts in this series were:

EPA Publishes Worst Case Discharge NPRM (Subscription version)

EPA’s Worst-Case Discharge NPRM – Affected Facilities (Subscription version)

Substantial Harm Requirement

Any facility that meets the threshold quantity and proximity to navigable waters screening thresholds of the rule then needs to determine if they meet the substantial harm standards that would lead to the facility being subject to the worst-case discharge planning requirements. Facilities meet the substantial harm standards if they fill any one of the following conditions:

Ability to cause injury to fish, wildlife, and sensitive environments (FWSE),

Ability to adversely impact a public water system,

Ability to cause injury to public receptors, or

Reportable discharge history

Alternative Methodologies

While the NPRM provides specific methodologies for determining if a facility meets one or more of the ‘substantial harm requirements’, the EPA has identified some alternative methods for making those determinations. The EPA provides a discussion for each of those alternatives and is seeking public comment on those procedures. The alternatives include:

• Alternative toxic end point methods discussed here and here,

• Determining public water system affects discussed here and here, and

• Determining a reportable discharge quantity that are discussed here, here, and here.

PHMSA Publishes Rupture Detection Standards Final Rule

On Friday, the DOT’s Pipeline and Hazardous Material Safety Administration published a final rule in the Federal Register (87 FR 20940-20992) for “Pipeline Safety: Requirement of Valve Installation and Minimum Rupture Detection Standards”. The notice of proposed rulemaking for this rule was published in February 2020.

According to the Summary of this final rule in the preamble this rule will:

• Revise the Federal Pipeline Safety Regulations applicable to most newly constructed and entirely replaced onshore gas transmission, Type A gas gathering, and hazardous liquid pipelines with diameters of 6 inches or greater,

• Require operators of these lines to install rupture-mitigation valves or alternative equivalent technologies, and establishes minimum performance standards for those valves' operation to prevent or mitigate the public safety and environmental consequences of pipeline ruptures,

• Establish requirements for rupture-mitigation valve spacing, maintenance and inspection, and risk analysis,

• Require operators of gas and hazardous liquid pipelines to contact 9-1-1 emergency call centers immediately upon notification of a potential rupture and conduct post-rupture investigations and reviews, and

• Require operators to incorporate lessons learned from such investigations and reviews into operators' personnel training and qualifications programs, and in design, construction, testing, maintenance, operations, and emergency procedure manuals and specifications.

The preamble to the rule provides a section-by-section analysis of the changes made to 49 CFR Part 192 for gas pipelines and Part 195 for hazardous liquid pipelines.

The effective date for this rule is October 5th, 2022.

Sunday, April 10, 2022

Review – Public ICS Disclosures – Week of 4-2-22 – Part 2

In Part 2 we have 14 additional vendor disclosures from HPE (3), Meinberg, Milestone, Mitsubishi, Philips (2), SonicWall, VMware (3), and Xylem. We also have eight vendor updates from Bosch, Carrier, HP (4), Palo Alto Networks, and QNAP. Finally, we have an exploit for products from Barco.

HPE Advisory #1 - HPE published an advisory describing two vulnerabilities in the Aruba Instant On 1930 switch.

HPE Advisory #2 - HPE published an advisory discussing the SpringShell vulnerabilities in Aruba products.

HPE Advisory #3 - HPE published an advisory describing an escalation of privilege vulnerability in their Superdome Flex Server.

Meinberg Advisory - Meinberg published an advisory discussing ten vulnerabilities in their LANTIME-Firmware.

Milestone Advisory - Milestone published an advisory discussing the SpringShell vulnerabilities.

Mitsubishi Advisory - Mitsubishi published an advisory discussing an out-of-bounds write vulnerability in their MELSEC C Controller Module.

Philips Advisor #1 - Philips published an advisory discussing a code injection vulnerability in the VMWare Spring Cloud Function.

Philips Advisory #2 - Philips published an advisory discussing the SpringShell vulnerabilities.

SonicWall Advisory - SonicWall published an advisory describing an inadequate access control vulnerability in their Capture Security Center - Cloud Security Management Service.

VMware Advisory #1 - VMware published an advisory describing eight vulnerabilities in their Workspace ONE Access, Identity Manager and vRealize Automation products.

VMware Advisory #2 - VMware published an advisory describing two privilege escalation vulnerabilities in their Horizon Client for Linux.

VMware Advisory #3 - VMware published an advisory discussing a remote code execution vulnerability in multiple products.

Xylem Advisory - Xylem published an advisory discussing the SpringShell vulnerabilities

Bosch Update - Bosch published an update for their Recovery Image advisory that was originally published on March 30th, 2022.

Carrier Update - Carrier published an update for their LAPSUS$ attack on Octa advisory that was originally published on March 30th, 2022.

HP Update #1 - HP published an update for their PC BIOS advisory that was originally published on March 8th, 2022 and most recently updated on March 25th, 2022.

HP Update #2 - HP published an update for their PC BIOS advisory that was originally published on February 28th, 2022 and most recently updated on March 25th, 2022.

HP Update #3 - HP published an update for their IPU BIOS advisory that was originally published on November 9th, 2021 and most recently updated on February 3rd, 2022.

HP Update #4 - HP published an update for their MEBx firmware advisory that was originally published on February 8th, 2022.

Palo Alto Networks Update - Palo Alto Networks updated their OpenSSL advisory that was originally published on March 31st, 2022

QNAP Update - QNAP published an update for their DirtyPipe advisory that was originally published on March 14th, 2022.

Barco Exploit - Murat Aydemir of Accenture Cyber Security Team published an exploit for a directory traversal vulnerability in the Barco Control Room Management Suite.

 

For more information on these disclosures, including links to 3rd party advisories and researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4 - subscription required.

Saturday, April 9, 2022

Review - FDA Publishes Draft Medical Device Cybersecurity Guidance

Yesterday, the FDA published a notice of availability in the Federal Register (87 FR 20878-20875) for a Draft Guidance Document on “Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions”. The draft guidance can be downloaded from the Federal eRulemaking Portal.

According to the Summary in the Notice:

“This draft guidance is intended to further emphasize the importance of ensuring that devices are designed securely, are designed to be capable of mitigating emerging cybersecurity risks throughout the Total Product Life Cycle, and to clearly outline FDA's recommendations for premarket submission content to address cybersecurity concerns.”

The summary goes on to remind folks that: “This draft guidance is not final nor is it for implementation at this time.”

Comment Solicitation

The FDA is soliciting comments on this draft guidance. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket FDA-2021-D-1158). Comments should be submitted by July 7th, 2022.

Commentary

First off, I am not a doctor, not even a medical device engineer, nor have I played one on TV. Having said that, it seems to me that there may be a little too much focus on cybersecurity in this guidance document. I know, that is what the document is about, but it seems to miss the fact that it is not really cybersecurity that we are concerned about when we talk about medical devices, it should primarily be protecting patient safety, secondarily about protecting patient information and confidentiality, and only then protecting the device and medical network.

While a Secure Product Development Framework is certainly important in any software development cycle, it is not sufficient, since we know that what people design is going to be imperfect. This means that there will be vulnerabilities in even well-designed systems. Whenever safety is an issue, and it certainly is in medical devices, we need to go beyond SPDF and look at Consequence-driven Cyber-informed Engineering (CCE). This methodology developed at the Idaho National Laboratory (INL) concentrates on identifying the safety consequences of system errors and vulnerabilities and working to mitigate those consequences. This methodology should be included in any discussion about cybersecurity for medical devices.

For more details about the draft guidance document, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/fda-publishes-draft-medical-device - subscription required.

Senate Agrees to House Amendments to S 658 – Cybersecurity Consortium

On Thursday, the Senate took up the House message on S 658, the National Cybersecurity Preparedness Consortium Act. That message notified the Senate of the amendment to the bill passed in the House. By unanimous consent, the Senate accepted the amendment. The amended bill now goes to the President for signature.

Again, this bill authorizes existing CISA programs.

 
/* Use this with templates/template-twocol.html */