Saturday, June 18, 2022

GAO Reports – DOD Cybersecurity Management

This week the Government Accountability Office published a report on DOD’s management of cybersecurity and supply chain risks. While this report is a look at the business management of unclassified information technology systems, it does look at some cybersecurity risk management issues at DOD. Like a note on the report’s landing page that seven of the 25 major DOD business IT programs reported “not having a system security plan that addresses [information and communications technology] ICT supply chain risk management and did not plan to develop one”.

No problems here, keep moving, nothing to see…

STB Updates Emergency ICR for Urgent Rail Service Issues

On Friday, the Surface Transportation Board published an amended notice for an emergency information collection request approval in the Federal Register (87 FR 36569-36571) for “Urgent Rail Service Issues”. This notice supplements an earlier request for an emergency ICR on the same topic that was published on June 3rd, 2022. The original request was to support the STB’s reporting requirements ordered on May 6th, 2022. Friday’s revised request comes as a result of the STB’s concerns about inadequate information provided by the four largest Class I railroads ordered to provide service recovery plans. A subsequent order was issued by the STB on June 13th, 2022 explaining those information deficiencies and requiring those railroads to provide more specific details about those plans. This amended ICR notice addresses those increased information requirements.

The STB is soliciting public comments on the ICR notice (not the underlying order). Comments may be submitted via email to PRA@stb.gov. Comments should be submitted by July 1st, 2022.

Review – Public ICS Disclosures – Week of 6-11-22 – Part 1

This is another busy second-Tuesday disclosure week. For Part 1 we have 23 vendor disclosures from ABB, AUMA, Genetec, Hitachi Energy, HP (2), HPE (6), OPC UA (5), PROSYS OPC, QNAP, Tanzu, TI, and VMware (2).

ABB Advisory - ABB published an advisory that describes five privilege escalation vulnerabilities in their Automation Builder, Drive Composer and Mint WorkBench products.

AUMA Advisory - CERT-VDE published an advisory that discusses a classic buffer overflow vulnerability in the AUMA SIMA² Master Station.

Genetec Advisory - Genetec published an advisory that discusses the recently reported vulnerabilities in HID Mercury controllers.

Hitachi Energy Advisory - Hitachi Energy published an advisory that discusses an insecure method vulnerability in their PROMOD IV product.

HP Advisory #1 - HP published an advisory that discusses four information disclosure vulnerabilities in multiple HP products.

HP Advisory #2 - HP published an advisory that discusses an improper input validation vulnerability in multiple notebook products.

HPE Advisory #1 - HPE published an advisory that discusses four information disclosure vulnerabilities in their Synergy Servers.

HPE Advisory #2 - HPE published an advisory that discusses four information disclosure vulnerabilities in their Storage Products.

HPE Advisory #3 - HPE published an advisory that discusses four information disclosure vulnerabilities in their ProLiant DX Servers.

HPE Advisory #4 - HPE published an advisory that discusses four information disclosure vulnerabilities in their Moonshot/Edgeline Servers.

HPE Advisory #5 - HPE published an advisory that discusses four information disclosure vulnerabilities in their Superdome Flex Servers.

HPE Advisory #6 - HPE published an advisory that discusses four information disclosure vulnerabilities in their ProLiant BL/DL/ML/XL/MicroServer and Apollo Servers.

OPC UA Advisory #1 - OPC UA published an advisory that describes an uncontrolled resource consumption vulnerability in their .NET Standard Stack.

OPC UA Advisory #2 - OPC UA published an advisory that describes an incorrect implementation of authentication algorithm vulnerability in their .NET Standard Stack.

OPC UA Advisory #3 - OPC UA published an advisory that describes an uncontrolled resource consumption vulnerability in their .NET Standard Stack.

OPC UA Advisory #4 - OPC UA published an advisory that describes a memory allocation with excessive size value vulnerability in their .NET Standard Stack.

OPC UA Advisory #5 - OPC UA published an advisory that describes an infinite loop vulnerability in their .NET Standard Stack.

PROSYS OPC Advisory - PROSYS published an advisory that discusses a security feature bypass vulnerability (with publicly available exploit) in their OPC products.

QNAP Advisory - QNAP published an advisory that discusses a ransomware campaign that appears to target QNAP NAS devices running outdated versions of QTS 4.x.

Tanzu Advisory - Tanzu published an advisory that describes a denial of service vulnerability in their Spring Cloud product.

TI Advisory - TI published an advisory that describes missing ECC input validations on CC1310 and CC1350 devices.

VMware Advisory #1 - VMware published an advisory that describes an information disclosure vulnerability in their HCX product.

VMware Advisory #2 – VMware published an advisory that discusses four information disclosure vulnerabilities in their ESXi product.


For more details about these disclosures, including links to researcher reports, 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-446 - subscription required.

Friday, June 17, 2022

TSA Publishes Request for Applicants for STSAC Membership

Today the TSA published a request for applicants notice in the Federal Register (87 FR 36522-36523) for membership in the Surface Transportation Security Advisory Committee (STSAC). The STSAC's mission is to provide advice, consultation, and recommendations to the TSA Administrator on improving surface transportation security matters, including developing, refining, and implementing policies, programs, initiatives, rulemakings, and security directives pertaining to surface transportation security, while adhering to sensitive security guidelines.

STSAC has 40 voting members representing each mode of surface transportation, such as passenger rail, freight rail, mass transit, pipelines, highways, over-the-road bus, school bus industry, and trucking. Members must represent one of the constituencies specified below to be eligible for appointment:

• Associations representing such modes of surface transportation,

• Labor organizations representing such modes of surface transportation,

• Groups representing the users of such modes of surface transportation, including asset manufacturers, as appropriate,

• Relevant law enforcement, first responders, and security experts, and

• Such other groups as the Administrator considers appropriate.

Applications can be emailed to STSAC@tsa.dhs.gov by July 18th, 2022. Applications should include:

• Complete professional resume.

• Statement of interest and reasons for application, including the membership category and how you represent a significant portion of that constituency, and

• Home and work addresses, telephone number, and email address.

Bills Introduced – 6-16-22

Yesterday, with both the House and Senate preparing to leave Washington for the weekend, there were 72 bills introduced. One of those bills may receive additional coverage in this blog:

HR 8127 To reauthorize the Water Infrastructure Finance and Innovation Act of 2014, and for other purposes. Rep. Schrier, Kim [D-WA-8]

I will be watching this bill for language and definitions that would include water system cybersecurity requirements within the scope of the bill.

Review – 17 Updates Published – 6-16-22

Yesterday, CISA’s NCCIC-ICS published updates for 17 control system security advisories for products from Siemens. Siemens published an additional 14 updates that were not covered yesterday by NCCIC-ICS, I will cover them this weekend.

BACnet Update - This update provides additional information on an advisory that was originally published on October 12th, 2017.

TIA Portal Update - This update provides additional information on an advisory that was originally published on January 14th, 2020 and most recently updated on May 12th, 2022.

SCALANCE Update - This update provides additional information on an advisory that was originally published on January 14th, 2020 and most recently updated on February 10th, 2022.

PROFINET-IO Update - This update provides additional information on an advisory that was originally published on February 11th, 2020 and most recently updated on April 14th, 2022.

SIMATIC Update #1 - This update provides additional information on an advisory that was originally published on April 14th, 2020 and most recently updated on March 9th, 2021.

SIMATIC Update #2 - This update provides additional information on an advisory that was originally published on August 10th, 2021.

SIMATIC Update #3 - This update provides additional information on an advisory that was originally published on September 14th, 2021.

Linux-based Products Update - This update provides additional information on an advisory that was originally published on May 11th, 2021 and most recently updated on December 16th, 2021.

Industrial Products Update - This update provides additional information on an advisory that was originally published on July 11th, 2021 and most recently updated on August 10th, 2021.

Solid Edge Update - This update provides additional information on an advisory that was originally published on February 10th, 2022 and most recently updated on April 14th, 2022.

RUGGEDCOM Update - This update provides additional information on an advisory that was originally published on March 10th, 2022 and most recently updated on April 14th, 2022.

Mendix Update - This update provides additional information on an advisory that was originally published on April 14th, 2022.

PROFINET Update - This update provides additional information on an advisory that was originally published on April 14th, 2022.

Teamcenter Update - This update provides additional information on an advisory that was originally published on May 12th, 2022.

Industrial Devices Update - This update provides additional information on an advisory that was originally published on May 12th, 2022.

Desigo Update - This update provides additional information on an advisory that was originally published on May 12th, 2022.

SIMATIC WinCC Update - This update provides additional information on an advisory that was originally published on May 12th, 2022.

 

For additional information on these updates, including a brief description of the changes, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/17-updates-published-6-16-22 - subscription required.

Thursday, June 16, 2022

OCS Updates CFATS FAQ – 6-15-22

Yesterday, CISA’s Office of Chemical Security (OCS) updated the responses to one of the Frequently Asked Questions (FAQ) on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center. The revision updates a URL used in the response to FAQ #1738 to provide information on the CFATS Expedited Approval Program:

FAQ #1738 What is the difference between the Expedited Approval Program (EAP) and the Chemical Facility Anti-Terrorism Standards (CFATS) program?

NOTE: The link provided for the FAQ in this post was copied from the CFATS Knowledge Center but may not work when followed from your machine. This is an artifact of that web site. If the links do not take you to the referenced FAQ, you will have to use the ‘Advanced Search’ function on the page to link to the FAQ or download the ‘All FAQs’ document at the bottom of the ‘Advanced Search’ page.

The new version of the FAQ provides a ‘new’ link to the CFATS Expedited Approval Program (EAP) page. The last time that I looked at this page it had an August 14th, 2018 ‘last published date’ marked on the page. There is no date on the current page (CISA very seldom provides dates for their web site pages). The only change on that newer page is the address to be used for the notification letter:

Chemical Security, Associate Director

CISA – CHR STOP 0609

Cybersecurity and Infrastructure Security Agency

1310 N. Courthouse Rd.

Arlington, VA 20598-0609

That address was added to unrelated FAQs, in February 2021, so the new EAP page probably dates from about the same time.

 
/* Use this with templates/template-twocol.html */