Friday, May 13, 2022

Review – 11 Updates Published – 5-12-22

Yesterday, CISA’s NCCIC-ICS published eleven control system security advisories for products from Siemens (10) and Mitsubishi. Siemens published five additional updates that were not covered yesterday by NCCIC-ICS. I will be covering them this weekend.

Industrial Products Update #1 - This update provides additional information on an advisory that was originally published on September 10th, 2019 and most recently updated on March 10th, 2022.

Industrial Products Update #2 - This update provides additional information on an advisory that was originally published on July 13th, 2021 and most recently updated on April 14th, 2022.

Industrial Products Update #3 - This update provides additional information on an advisory that was originally published on April 14th, 2014.

TIA Portal Update - This update provides additional information on an advisory that was originally published on January 14th, 2020 and most recently updated on December 16th, 2021.

SIMOTICS Update - This update provides additional information on an advisory that was originally published on April 14th, 2020 and most recently updated on April 14th, 2022

SIMATIC Update #1 - This update provides additional information on an advisory that was originally published on June 8th, 2021 and most recently updated on April 14th, 2022.

SIMATIC Update #2 - This update provides additional information on an advisory that was originally published on November 11th, 2021 and most recently updated on April 14th, 2022.

Nucleus RTOS Update - This update provides additional information on an advisory that was originally published on November 11th, 2021 and most recently updated on April 14th, 2022.

Mitsubishi Update - This update provides additional information on an advisory that was originally published on April 12th, 2022.

 

For more information on these updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/11-updates-published-5-12-22 - subscription required.


Thursday, May 12, 2022

Review – 16 Advisories Published – 5-12-22

Today, CISA’s NCCIC-ICS published sixteen control system security advisories for products from Siemens (12), Cambium Networks, Inkscape, Mitsubishi Electric, and Delta Electronics.

Teamcenter Advisory - This advisory describes two vulnerabilities in the Siemens Teamcenter product lifecycle management software.

OpenV2g Advisory - This advisory describes a classic buffer overflow vulnerability in the OpenV2G open-source implementation of the ISO/IEC vehicle-to-grid communication interface (V2G CI) standard (Siemens is an initiator of OpenV2G).

Simcenter Advisory - This advisory describes an out-of-bounds write vulnerability in the Siemens Simcenter Femap advanced simulation application.

Industrial Devices Advisory - This advisory discusses two vulnerabilities (both with known exploits) in the Siemens Industrial devices.

Industrial Products Advisory #1 - This advisory discusses an improper restriction of operations within the bounds of a memory buffer in OPC Foundation Local Discovery Server of several Siemens industrial products.

Industrial Products Advisory #2 - This advisory discusses a NULL pointer dereference vulnerability (with known exploit) in the Siemens SIMATIC NET PC, SITOP Manager, and TeleControl Server Basic products.

SIMATIC Advisory #1 - This advisory describes an uncontrolled resource consumption vulnerability in the Siemens SIMATIC CP 442-1 RNA and CP 443-1 RNA communications processors.

SIMATIC Advisory #2 - This advisory describes an insecure default initialization of resource vulnerability in the Siemens SIMATIC PCS and WinCC products.

Desigo Advisory - This advisory describes eight vulnerabilities in the Siemens Desigo PXC and DXR building automation devices.

JT2GO Advisory - This advisory describes six vulnerabilities in the Siemens JT2GO and Teamcenter Visualization products.

SICAM Advisory - This advisory describes eleven vulnerabilities in the Siemens SICAM P850 and SICAM P855 electrical variable measuring devices.

Industrial PCs Advisory - This advisory discusses four vulnerabilities in the Siemens Industrial PCs and CNC devices.

NOTE: This advisory is based upon a Siemens update of an  advisory that was originally published on May 11th, 2021 and most recently updated on March 8th, 2022.

Cambium Advisory - This advisory describes seven vulnerabilities in the Cambium cnMaestro On-Premises network management system.

Inkscape Advisory - This advisory describes three vulnerabilities in the Inkscape open-source graphics editor.

NOTE: NCCIC-ICS is apparently concerned that this will be a third-party vulnerability in multiple ICS products. They provide a link to one such affected product, the Ecava SAGE eXtension SCADA animation graphic editor. The linked page only refers to the corrected version of Inkscape and does not mention these vulnerabilities.

Mitsubishi Advisory - This advisory discusses eight vulnerabilities in the Mitsubishi ELSOFT iQ AppPortal.

Delta Advisory - This advisory describes two vulnerabilities in the Delta CNCSoft software management platform.

 

For additional information on these advisories, including links to third-party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/16-advisories-published-5-12-22 - subscription required.

Review - Changes in TSA Rail Security Burden Estimation

On Tuesday, I reported that the TSA had published a 30-day ICR extension notice in the Federal Register. I noted that there was a minor discrepancy in the reported burden number. Since then, the OMB’s Office of Information and Regulatory Affairs (OIRA) has published the supporting document submitted by TSA in their extension request for this ICR. While this information explains the burden discrepancy, the total data submission to OIRA makes it clear that this is an ICR revision, not a simple extension.

The table below shows the data abstracted from Section 12 of both the submitted supporting data document and the supporting document for the currently approved ICR.

 

Proposed Estimate

Current Estimate

# Responses

Burden

# Responses

Burden

Security Coordinator

                  475

           475

                  475

           475

Location Reporting

                  327

           164

                  655

           328

Security Concerns

              4,961

       4,961

              4,961

       4,961

Chain of Custody

          214,000

   107,000

          214,000

   107,000

Total

          219,763

   112,600

          220,091

   112,764

While there is nothing nefarious about the discrepancies in the changes made in the supporting information for this information collection revision, the TSA continues to have substantial problems with their ICR documentations. While the recent Federal Register notice classified this as an extension of a currently approved collection, this is clearly a revision of the ICR. TSA has provided OIRA with an adequate explanation for the revision, but TSA continues to be sloppy and vague about their public reporting about their ICRs. Unfortunately, OIRA will undoubtedly approve the changes to this ICR, as they have so often in the past.

For more details about the change in burden estimate, as well as other changes in the information collection request, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/changes-in-tsa-rail-security-burden - subscription required.

Wednesday, May 11, 2022

HR 7077 Passed in House – Fire Investigations

Yesterday, the House began consideration of HR 7077, the Empowering the U.S. Fire Administration Act, under the House suspension of the rules process. After limited debate, a vote was demanded and subsequently postponed until today. This afternoon, the vote on the bill was held and the bill was approved by a significantly bipartisan vote of 379 to 37.

During yesterday’s debate, there was no one that spoke in opposition to the bill. In addition to the typical praise for the leadership of the House Homeland Security Committee for their bipartisan work on the bill, there were four letters in support of the bill read into the record. Those letters were from:

• Fire Department of New York City,

• International Association of Fire Chiefs,

• National Association of State Fire Marshals, and

• The International Association of Fire Fighters.

The bill now goes to the Senate for consideration. This bill will not be considered under regular order. There is a chance that it could proceed under the unanimous consent process, but it is more likely to be added to another bill as an amendment. Then again, it could suffer the same fate that so many bills fall to when they are presented to the ‘other’ house of Congress. Without an influential sponsor to move them forward they simply gather legislative dust on the desk of the Clerk.

Bills Introduced – 5-10-22

Yesterday, with both the House and Senate in session, there were 50 bills introduced. One of those bills may receive additional attention in this blog:

S 4166 A bill to authorize preparedness programs to support communities containing technological hazards and emerging threats. Sen. Portman, Rob [R-OH]

Okay, the wording of this description (‘support communities containing technological hazards and emerging threats’???) confuses me, but on the off chance the ‘technological hazards and emerging threats’ include cybersecurity issues, I will be watching this bill when it is published. But seriously, I doubt that I will mention this here again.

Tuesday, May 10, 2022

S 2201 Passed in House – Supply Chain Risk Training

Today, the House took up S 2201, the Supply Chain Security Training Act of 2021, and passed it by a voice vote with only seven minutes of ‘debate’. Since the same version of the the bill passed in the Senate, the bill now heads to President Biden for signature. There is no indication that the President has concerns about the bill, so it will probably be signed later this week.

The bill would require the General Services Administration to develop “a training program for officials with supply chain risk management responsibilities at executive agencies.” While the term ‘supply chain risk’ is not defined in the legislation, with both CISA and NIST referred to as coordination targets, I would suspect that the crafters were at least partially considering protecting hardware and software against unauthorized manipulation in transit between the manufacturer and the Federal user.

NOTE: S 1097, the Federal Rotational Cyber Workforce Program Act of 2021, also passed in the House this afternoon. Since this is purely a federal workforce issue with little or no potential effect on control system cybersecurity, I have not covered this bill. It also going to Biden for signature.

Review – Six Advisories Published – 5-10-22

Today, CISA’s NCCIC-ICS published six control system security advisories for products from Mitsubishi Electric, AVEVA, Eaton (3), and Adminer.

Mitsubishi Advisory - This advisory discusses two vulnerabilities in the Mitsubishi MELSOFT GT OPC UA Client.

AVEVA Advisory - This advisory describes an exposure of resources to wrong sphere vulnerability in the AVEVA InTouch Access Anywhere and AVEVA Plant SCADA Access Anywhere HMI products.

NOTE: I briefly reported on this vulnerability last Saturday.

Eaton Advisory #1 - This advisory describes a cross-site scripting vulnerability in the Eaton Intelligent Power Manager (IPM).

NOTE: I briefly reported on this vulnerability on March 5th, 2022.

Eaton Advisory #2 - This advisory describes three vulnerabilities in the Eaton Intelligent Power Manager Infrastructure. This product is EOL.

Eaton Advisory #3 - This advisory describes a cross-site scripting vulnerability in the Eaton Intelligent Power Protector (IPP).

NOTE: I briefly reported on this vulnerability on March 5th, 2022.

Adminer Advisory - This advisory describes a files or directories accessible to external parties vulnerability (with two known exploits) in Adminer, a PHP SQL database management tool

NOTE: Apparently CISA expects this to be potential third-party vulnerability for multiple control system products. They have started a list of affected products with a link to Advantech’s R-SeeNet product.

 

For more details on these advisories, including links to third-party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/six-advisories-published-5-10-22 - subscription required.

 
/* Use this with templates/template-twocol.html */