Saturday, August 13, 2022

Latest BIS IFR Does Not Affect Cybersecurity Devices

The DOC’s Bureau of Industry and Security published an interim final rule in Monday’s (available on line today) Federal Register (87 FR 49979-49986) on “Implementation of Certain 2021 Wassenaar Arrangement Decisions on Four Section 1758 Technologies”. I wrote about this rulemaking being approved by OMB’s Office of Information and Regulatory Affairs earlier this month, without knowing what matter would be covered. The four technologies covered in this rulemaking have nothing to do with cybersecurity.

These Wassenaar rules are implementations of international agreements reached under the Wassenaar Arrangement on Export Controls for Conventional Arms and Dual-Use Goods and Technologies. This particular rule deals with four technologies that meet the criteria of Section 1758 of the Export Control Reform Act (50 USC 4817). It makes the changes to the following Export Control Classification Numbers:

• Adds to ECCN 3C001 new paragraphs .e for Ga2O3 and .f for diamond,

• Amends ECCN 3C005 by adding Ga2O3 and diamond to ECCN 3C005 paragraphs .a and .b, respectively,

• Adding new ECCN 3D006 to the CCL to control ECAD “software” “specially designed” for the “development” of integrated circuits having any GAAFET structure and meeting the parameters set forth in ECCN 3D006, and

• Adds paragraph [ECCN] 9E003.a.2.e to control development and production technology for combustors utilizing `pressure gain combustion' that are not described on the USML.

Review - HR 8403 Introduced – Federal Cybersecurity Initiatives

Last month, Rep Swalwell (D,CA) introduced HR 8403, the Proactive Cyber Initiatives Act of 2022. The bill would establish requirements for proactive cybersecurity measures such as penetration testing and deceptive defense processes for federal information systems. It would require reports to Congress on penetration testing, active defense and proactive cybersecurity initiatives. No new funding is authorized by the bill.

Moving Forward

Swalwell is not a member of either the Oversight and Reform Committee or Armed Services Committee to which this bill was assigned for consideration. This means that there is not likely to be sufficient influence to see this bill considered in either committee. I see nothing in the bill that would engender any organized opposition. I suspect that the bill would receive bipartisan support in either committee. The bill would probably be considered in the House under the suspension of the rules process.

Swalwell is a member of the House Homeland Security Committee and I suspect that he figured that the bill would be assigned to that committee for consideration. To be fair, that is the committee to which I would have expected it to be assigned. I suspect that the Oversight and Reform assignment is a political attempt to expand the cybersecurity oversight responsibility of that Committee. The secondary assignment to the Armed Services Committee is required because of the DOD study and report requirements in Section 7.

Commentary

The active defense report requirements in Section 6 seem to be rather bland until you go back and look at the definition of ‘active defense’ in Section 2. That definition includes feeding false information to an attacker, presumably through some sort of honeypot, and the use of “proportional action taken in response to an unlawful breach”. Typically, that phrase is used as a less confrontational way of describing limited ‘hack back’ actions. This is why the report is required to address “analysis of whether there are legislative, regulatory, or resource burdens” that need to be addressed before such actions can be undertaken. What is missing from that analysis is requirement is a specific need to identify the limits that would have to be imposed on such activities. I would change §6(b)(3) to read:

“(3) An analysis of whether there are legislative, regulatory, or resource burdens that prevent such techniques from being effectively utilized, including the resources necessary to implement such techniques, and a reasonable set of limitations that should be imposed on using such techniques.”


For more details about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-8403-introduced - subscription required.

OMB Approves EPA RMP Release Prevention NPRM

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice of proposed rulemaking from the EPA on “Accidental Release Prevention Requirements: Risk Management Program Under the Clean Air Act; Retrospection”. According to the abstract in Spring 2022 Unified Agenda listing for the rulemaking:

“The Environmental Protection Agency (EPA) is considering revising the Risk Management Program (RMP) regulations, which implement the requirements of section 112(r)(7) of the 1990 Clean Air Act amendments. The RMP requires facilities that use listed extremely hazardous substances above specified threshold quantities to develop a Risk Management Plan. The EPA is reviewing the RMP rule in accordance with Executive Order 13990: Protecting Public Health and the Environment and Restoring Science to Tackle the Climate Crisis, which directs federal agencies to review existing regulations and take action to address the Administration’s priorities, including bolstering resilience to the impacts of climate change and prioritizing environmental justice.”

We are likely to see the NPRM published this coming week.

Review – Public ICS Disclosures – Week of 8-6-22 – Part 1

This Saturday after the second Tuesday we have a large slate of disclosures to look at. For Part 1, we have 24 vendor disclosures from Auma, Fujitsu, HP (7), HPE (6), Keysight Technologies, Palo Alto Networks (2), PcVue, Schneider (4), and Sick.

Auma Advisory - CERT-VDE published an advisory that discusses 73 vulnerabilities in the Auma SIMA Master Station.

Fujitsu Advisory - Fujitsu published an advisory that discusses three vulnerabilities in a number of Fujitsu products.

HP Advisory #1 - HP published an advisory that discusses 14 vulnerabilities in a wide variety of their PCs, notebooks and workstations.

HP Advisory #2 - HP published an advisory that discusses an improper restriction of XML external entity reference vulnerability in a wide variety of their PCs, notebooks and workstations.

HP Advisory #3 - HP published an advisory that discusses an improper restriction of XML external entity reference vulnerability (with a known exploit) in a wide variety of their PCs, notebooks and workstations.

HP Advisory #4 - HP published an advisory that discusses four vulnerabilities in a wide variety of their PCs, notebooks and workstations.

HP Advisory #5 - HP published an advisory that discusses three vulnerabilities in in a wide variety of their PCs, notebooks and workstations.

HP Advisory #6 - HP published an advisory that discusses four vulnerabilities in a wide variety of their PCs, notebooks and workstations.

HP Advisory #7 - HP published an advisory that discusses an information disclosure vulnerability in a wide variety of their PCs, notebooks and workstations.

HPE Advisory #1 - HPE published an advisory that discusses a privilege escalation vulnerability in their HPE ProLiant DL Servers.

HPE Advisory #2 - HPE published an advisory that discusses an information disclosure vulnerability in their ProLiant DL/ML Servers.

HPE Advisory #3 - HPE published an advisory that discusses an information disclosure vulnerability in their ProLiant DX Servers.

HPE Advisory #4 - HPE published an advisory that discusses a privilege escalation vulnerability in their Synergy Servers.

HPE Advisory #5 - HPE published an advisory that discusses an information disclosure vulnerability in their Synergy Servers.

HPE Advisory #6 - HPE published an advisory that discusses a privilege escalation vulnerability ProLiant DX Servers.

Keysight Advisory - INCIBE-CERT published an advisory that describes two vulnerabilities in the Keysight Sensor Management Server.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory that describes a reduced effectiveness of their Cortex XDR Agent anti-ransomware endpoint protection module.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that describes a reflected amplification DOS vulnerability in their PAN-OS.

PcVue Advisory - PcVue published an advisory that describes a clear-text storage of sensitive information in their PcVue OAuth web service.

Schneider Advisory #1 - Schneider published an advisory that describes a weak password recovery vulnerability in their EcoStruxure™ Control Expert , EcoStruxure™ Process Expert, Modicon M580 and M340 products.

Schneider Advisory #2 - Schneider published an advisory that describes an integer underflow vulnerability in their Modicon PAC Controllers.

Schneider Advisory #3 - Schneider published an advisory that describes an improper restriction of operations within the bounds of a memory buffer.

Schneider Advisory #4 - Schneider published an advisory that describes an information disclosure vulnerability in their Modicon PAC Controllers.

Sick Advisory - Sick published an advisory that discusses an infinite loop vulnerability in their SIM products. This is a third-party (OpenSSL).

 

For more details on these advisories, including links to third-party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-8-e7f - subscription required.

Friday, August 12, 2022

Review - S 4521 Introduced – Catastrophe Planning

Last month, Sen Cornyn (R,TX) introduced S 4521, the Keeping Everyone Safe and Securing Lives by Emergency Readiness (KESSLER) Act. The bill would require the President to develop a strategy to ensure the health, safety, and general welfare of the civilian population of the United States in case of catastrophic incidents. The bill does not provide any authorization for funding of the required program.

Moving Forward

While Cornyn is not a member of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned for consideration, his sole cosponsor {Sen Padilla (D,CA)}. This may provide enough influence to see the bill considered in Committee. This bill would be seen by the right wing of the Republican Party as an attempt to set up a scenario where the Government could declare a national emergency, impose martial law, and take away all civil liberties. Their opposition would be sufficient to stop this bill from receiving a 50%+1 vote to move the bill out of Committee. There is no way that this bill would be able to make it to the floor of the Senate for consideration.

Commentary

The bill does not really define the extent of the catastrophe for which this strategy and implantation plan are intended. In Section 2 of the bill (‘findings’), however, it does make the statement that: “the Federal Government must prepare Federal, State, and local governments, along with the people of the United States, to promote the general welfare of the civilian population of the United States even if most or all critical infrastructure sectors are impacted by catastrophic events”. An event of that scope is almost by definition beyond the scope of any reasonable emergency response planning effort.

The money necessary to stockpile food, water, medicine and clothing alone (forget housing and transportation) for that scope of incident would be inflationary in the extreme and removing that amount of material from commerce would have a major depressive effect on the economy. The implementation of the stockpiling effort would likely be a trigger of the event being considered.

Furthermore, the United States would not be able to rely on any significant foreign support in such an incident. Again, that amount of support would beyond the capabilities of any reasonable coalition of nations, especially because an incident of that scope, even if it only directly affected the United States, would have cascading catastrophic effects on the economy of the rest of the world. Other countries would be spending too much of their resources responding to their problems at home to be able to provide the United States with more than pro forma support.

 

For more details about the provisions of the bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-4521-introduced - subscription required.

Coast Guard Publishes NCTSAC Vacancy Notice

Today, the Coast Guard published a notice in the Federal Register (87 FR 40876-49877) announcing that there are currently eight vacancies in the National Chemical Transportation Safety Advisory Committee. The CG is soliciting applications for those vacancies.

Under the bylaws of the Committee, applicants for these positions would represent one of the following:

• Chemical manufacturing entities,

• Entities related to marine handling or transportation of chemicals,

• Vessel design and construction entities,

• Marine safety or security entities, and

• Marine environmental protection entities.

Applicants for these positions should submit an email to Ethan.T.Beard@uscg.mil by September 12th, 2022. The application should include:

• A cover letter expressing interest in an appointment to the National Chemical Transportation Safety Advisory Committee,

• A resume detailing the applicant's relevant experience, and

• A brief biography of the applicant.

Review – 14 Updates Published – 8-11-22

Yesterday, CISA’s NCCIC-ICS published one medical device security update for products from Baxter and 13 control system security updates from Siemens. Siemens published 24 additional updates this week and Schneider published four advisories and seven updates. I will be covering those this weekend.

Baxter Update - This update provides additional information on an advisory that originally reported on June 18th, 2020 and most recently updated on June 23rd, 2020.

SRCS VPN Update - This update provides additional information on an advisory that was originally published on July 14th, 2022.

Simcenter Update - This update provides additional information on an advisory that was originally published on July 14th, 2022.

RUGGEDCOM Update - This update provides additional information on an advisory that was was originally published on July 14th, 2022.

Industrial Products Update #1 - This update provides additional information on an advisory that was originally published on May 12th, 2022 and most recently updated on July 14th, 2022.

Industrial Products Update #2 - This update provides additional information on an advisory that was originally published on April 9th, 2019 and most recently updated on April 14th, 2022.

Industrial Products Update #3 - This update provides additional information on an advisory that was originally published on July 11th, 2021 and most recently updated on June 16th, 2022.

Industrial Products Update #4 - This update provides additional information on an advisory that was originally published on August 10th, 2021 and most recently updated on July 14th, 2022.

Teamcenter Update #1 - This update provides additional information on an advisory that was originally published on May 12th, 2022 and most recently updated on June 16th, 2022.

Teamcenter Update #2 - This update provides additional information on an advisory that was originally published on June 16th, 2022.

TIA Portal Update - This update provides additional information on an advisory that was originally published on January 14th, 2020 and most recently updated on June 16th, 2022.

Datalogics Update - This update provides additional information on an advisory that was originally published on July 14th, 2022.

Linux Products Update - This update provides additional information on an advisory that was originally published on May 11th, 2021 and most recently updated on June 16th, 2022.

SIMATIC Update - This update provides additional information on an advisory that was was originally published on July 14th, 2022.

 

For more details on these updates, including summary of changes made, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/14-updates-published-8-11-22 - subscription required.

 
/* Use this with templates/template-twocol.html */