Sunday, October 16, 2022

Short Takes – 10-16-22

The Russian Space Program Is Falling Back to Earth. TheAtlantic.com article. Pull quote: “If Russia were to jump ship early, it would have no spaceflight program to speak of. “We must bear in mind that if we discontinue manned flights for several years, it will be very difficult to restore what we have achieved afterwards,” Vladimir Solovyov, a former cosmonaut and the flight director for the Russian side of the ISS, said in a Roscosmos interview this summer.”

National Space-Based Positioning, Navigation, and Timing Advisory Board; Meeting. Federal Register meeting notice. 2-day meeting: November 16th and 17th, 2022.

Digital license plates approved for all vehicles in California. ARSTechnia.com article. Pull quote: “The revised legislation sets out the conditions for using an e-ink plate (referred to in the bill as an "alternative device"). For example, a malfunctioning digital license plate would be a correctable violation—the law also requires "a process for frequent notification" if the digital plate breaks or needs replacing. And altering, forging, counterfeiting, or other hacking of the plates will be a felony.”

Shelter in place lifted in Westlake, no injuries in Sasol chemical fire. KPLCTV.com article. Pull quote: “Early this afternoon, Sasol had a fire at its Lake Charles Chemical Complex Ziegler alcohol unit. Our on-site emergency response team responded swiftly, and the fire is contained. Our primary concern is the safety of our employees and the community. All Sasol employees are accounted for with no reported injuries associated with the fire. There were no off-site impacts and no call to action for the nearby community.” Shelter-in-place order is an off-site impact.


Review – Public ICS Disclosures – Week of 10-8-22 – Part 2

For Part 2 this week we have five additional vendor disclosures from Schneider (4), and WAGO. We also have sixteen updates from Fanuc, HPE, Omron (2), Schneider (8), and Siemens (4). We have nine researcher reports for products from CCCERT (2), Robustel (6), and VMware.

Schneider Advisory #1 - Schneider published an advisory that describes six vulnerabilities in their EcoStruxure™ Operator Terminal Expert and Pro-face BLUE products.

Schneider Advisory #2 - Schneider published an advisory that discusses two vulnerabilities (one with known exploit) in their EcoStruxure Panel Server Box (PAS900).

Schneider Advisory #3 - Schneider published an advisory that discusses two vulnerabilities in their SAGE RTU products.

Schneider Advisory #4 - Schneider published an advisory that describes an improper input validation vulnerability in their s EcoStruxure™ Power Operation and Power SCADA Operation software.

WAGO Advisory - CERT-VDE published an advisory that describes an uncontrolled resource consumption vulnerability in the FTP server in WAGO 750 series controllers.

Fanuc Update - Fanuc published an update for their ROBOGUIDE advisory that was originally published on April 8th, 2022 and most recently updated on June 29th, 2022.

HPE Update - HPE published an update for their Integrated Lights-Out 5 that was originally published on September 15th, 2022.

Omron Update #1 - Omron published an update for their NJ/NXseries Machine Automation Controllers advisory that was originally published on July 1st, 2022.

Omron Update #2 - Omron published an update for their NJ/NXseries Machine Automation Controllers advisory that was originally published on July 1st, 2022.

Schneider Update #1 - Schneider published an update for their Log4Shell advisory.

Schneider Update #2 - Schneider published an update for their Modicon PAC Controllers advisory that was originally published on August 9th, 2022 and most recently updated on September 6th, 2022.

Schneider Update #3 - Schneider published an update for their EcoStruxureTM Control Expert advisory that was originally published on August 9th, 2022 and most recently updated on September 6th, 2022.

Schneider Update #4 - Schneider published an update for their EcoStruxureTM Control Expert advisory that was originally published on July 13th, 2021 and most recently updated on September 6th, 2022.

Schneider Update #5 - Schneider published an update for their Modicon PAC Controllers advisory that was originally published on August 10th, 2021 and most recently updated on September 6th, 2022.

Schneider Update #6 - Schneider published an update for their BadAlloc advisory that was originally published on November 9th, 2021 and most recently updated on September 13th, 2022.

Schneider Update #7 - Schneider published an update for their Modicon Controllers advisory that was originally published on September 26th, 2019 and most recently updated on September 6th, 2022.

Schneider Update #8 - Schneider published an update for their Embedded FTP Servers advisory that was originally published on March 22nd, 2018 and most recently updated on September 13th, 2022.

Siemens Update #1 - Siemens published an update for their GNU/Linux subsystem advisory that was originally published in 2018 and most recently updated on September 13th, 2022.

Siemens Update #2 - Siemens published an update for their Insyde BIOS advisory that was originally published on February 22nd, 2022 and most recently updated on August 9th, 2022.

Siemens Update #3 - Siemens published an update for their SpringShell advisory that was originally published on April 19th, 2022 and most recently updated on June 14th, 2022.

Siemens Update #4 - Siemens published an update for their OpenSSL advisory that was originally reported on July 13th, 2021 and most recently updated on August 9th, 2022.

CCCERT Report #1 - BDU published a report of an open redirect vulnerability in the CCCERT VINCE program.

CCCERT Report #2 - BDU published a report of an open redirect vulnerability in the CCCERT VINCE program.

NOTE: The CCCERT VINCE program is the vulnerability reporting program run by CCCERT and used by NCCIC-ICS.

Robustel Report #1 - TALOS published a report discussing a command injection vulnerability in the Robustel R1510 Lite Industrial IoT Gateway.

Robustel Report #2 - TALOS published a report describing eleven denial of service vulnerabilities in the Robustel R1510.

Robustel Report #3 - TALOS published a report describing a firmware update vulnerability in the Robustel R1510. The report contains proof-of-concept code.

Robustel Report #4 - TALOS published a report describing a directory traversal vulnerability in the Robustel R1510. The report contains proof-of-concept code.

Robustel Report #5 - TALOS published a report discussing an OS command injection vulnerability in the Robustel R1510.

Robustel Report #6 - TALOS published a report discussing an OS command injection vulnerability in the Robustel R1510. The report contains proof-of-concept code.

VMware Report - TALOS published a report describing a deserialization of untrusted data vulnerability in the VMware vCenter Server Platform Services.

 

For more details on these disclosures, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-8b0 - subscription required.


Saturday, October 15, 2022

Review – Public ICS Disclosures – Week of 10-8-22 – Part 1

This is a moderately busy Saturday after 2nd Tuesday. For Part 1 this week, we have fifteen vendor disclosures from Aruba, Bentley (3), Eaton, GE Healthcare, Hitachi Energy, HP, Palo Alto Networks, Phoenix Contact, PulseSecure, Softing (2), TandD, and VMware.

Aruba Advisory - Aruba published an advisory describing three vulnerabilities in their EdgeConnect Enterprise Orchestrator.

Bentley Advisory #1 - Bentley published an advisory that describes an out-of-bounds read vulnerability in their MicroStation And MicroStation-Based Applications.

Bentley Advisory #2 - Bentley published an advisory that describes a stack-based buffer overflow vulnerability in their MicroStation And MicroStation-Based Applications.

Bentley Advisory #3 - Bentley published an advisory that describes an out-of-bounds read vulnerability in their MicroStation and MicroStation-Based Applications.

Eaton Advisory - Eaton published an advisory that describes an unrestricted file upload vulnerability in their Foreseer EPMS.

GE Healthcare Advisory - GE published an advisory that provides guidance on securing serial ports in medical devices.

Hitachi Energy Advisory - Hitachi published an advisory that discusses two vulnerabilities in their MicroSCADA X DMS600

product.

HP Advisory - HP published an advisory that discusses eleven vulnerabilities in their GPU Display Driver.

Palo Alto Networks Advisory - Palo Alto Networks published an advisory that describes an authentication bypass vulnerability in their Pan-OS product.

Phoenix Contact Advisory - CERT-VDE published an advisory that discusses 83 vulnerabilities in the Phoenix Contact PLCnext Control.

PulseSecure Advisory - PulseSecure published an advisory that describes two denial of service vulnerabilities in their Ivanti Connect Secure products.

Softing Advisory #1 - Softing published an advisory that describes a use after free vulnerability in their OPC UA C++ SDK and OPC Suite products.

Softing Advisory #2 - Softing published an advisory that describes an input validation vulnerability in their OPC UA C++ SDK, Secure Integration Server, edgeConnector, edgeAggregator, uaGate and OPC Suite products.

TandD Advisory - TandD published an advisory that describes a denial-of-service vulnerability in their TR4 Series devices

NOTE: TandD does not call this a ‘vulnerability’ they call it a problem “whereby internal communication between components fails” which kind of sounds like a ‘denial-of-service’ vulnerability to me.

VMware Advisory - VMware published an advisory that describes an arbitrary file read vulnerability in their VMware vRealize Operations product.

 

For more information on these disclosures, including links to third-party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-c00 - subscription required.


Bills Introduced – 10-14-22

Yesterday, with the House and Senate meeting in pro forma session, there were 25 bills introduced. One of those bills may receive additional attention in this blog:

HR 9182 To establish a national network of electric vehicle charging stations, and for other purposes. Levin, Andy [Rep.-D-MI-9]

I will be watching this bill for language and definitions that specifically include cybersecurity requirements for vehicle charging stations within the scope of the bill.


Friday, October 14, 2022

Short Takes – 10-14-22

Here's the next phase of Biden's plan to fortify industry cyberdefenses. WashingtonPost.com article. Pull quote: “The Environmental Protection Agency (EPA) plans to incorporate cybersecurity in sanitation reviews of water utilities under a “creative” interpretation of existing law, Neuberger said. In late July, Neuberger said the EPA would take that action “shortly.” Officials are aiming for the end of the year.”

A Flurry of Regulatory Action and the Need for SBOMs. Adolus.com blog post. Pull quote: “Depending on who you ask, you’ll get different answers regarding the necessary elements of an SBOM and if they should include vulnerabilities. The current SBOM standard advanced by CISA does not include vulnerability information; it is simply a comprehensive, nested list of ingredients. Vulnerability information — including whether or not a vulnerability is exploitable — is communicated via a separate companion document called VEX (Vulnerability Exploitability eXchange).” Interesting insights to SBOM issues.

Florida agriculture has been slammed by Hurricane Ian. NPR.org article. Pull quote: “He says flooded pastures mean the grass is no longer good for grazing, and cattle that have been standing in water could lead to disease, including foot rot. And high water is lingering. Coddington says the south end of the Longino Ranch is not accessible.”

Prevention of Significant Deterioration (PSD) and Nonattainment New Source Review (NNSR): Reconsideration of Fugitive Emissions Rule. Federal Register NPRM. Would repeal 2008 fugitive emissions rule. Pull quote: “As a result of the proposed changes, all existing major stationary sources would be required to include fugitive emissions in determining whether a physical or operational change constitutes a “major modification,” requiring a permit under the Prevention of Significant Deterioration (PSD) or Nonattainment New Source Review (NNSR) programs.” Comments due December 13th, 2022.

6 projects show how infrastructure spending is remaking the country. WashingtonPost.com article. Pull quote: “The package handed Buttigieg and his team $120 billion to invest in projects around the country, an unusually high amount of discretion in a system that tends to leave most transportation decisions to state and local leaders. The U.S. Department of Transportation is prioritizing projects that would improve safety amid a spike in crash deaths, help to reduce carbon emissions and create a fairer transportation system, especially in Black and Hispanic communities that have historically been overlooked.”


Review – 9 Updates Published – 10-13-22

Yesterday, CISA’s NCCIC-ICS published nine control system security advisory updates for products from Mitsubishi (2) and Siemens (7). Mitsubishi updated one additional advisory yesterday and Siemens updated four more on Tuesday, I will cover those this weekend.

Mitsubishi Update #1 - This update provides additional information on an advisory that was originally published on September 7th, 2021.

Mitsubishi Update #2 - This update provides additional information on an advisory that was originally published on October 14th, 2021.

PROFINET Update - This update provides additional information on an advisory that was originally published on April 14th, 2022 and most recently updated on August 11th, 2022.

SINEC Update - This update provides additional information on an advisory that was originally published on March 13th, 2022.

SCALANCE Update #1 - This update provides additional information on an advisory that was originally published on October 14th, 2021.

SCALANCE Update #2 - This update provides additional information on an advisory that was originally published on November 11th, 2021.

Apache Update - This update provides additional information on an advisory that was originally published on June 16th, 2022.

OpenSSL Update - This update provides additional information on an advisory that was originally published on June 16th, 2022 and most recently updated on September 15th, 2022.

Industrial Products Update - This update provides additional information on an advisory that was originally published on May 12th, 2022 and most recently updated on August 16th, 2022.

 

For more information on these updates, including a brief summary of the changes made, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/9-updates-published-10-13-22 - subscription required.


Thursday, October 13, 2022

Short Takes – 10-13-22

NHTSA Safety Research Portfolio Public Meeting: Fall 2022. Federal Register meeting notice. Pull quote: “NHTSA will hold a Public Meeting from November 1-3, 2022, as a joint effort between the Agency's Vehicle Safety Research and Behavioral Safety Research offices to share information on activities within the Agency's research programs. The meeting will be held in a virtual format with representatives from across the two research offices presenting the information in a panel format. Questions from the audience will be accepted following presentations.” Zoom meeting.

Photochemistry enables safer method for reprocessing plutonium and uranium mixtures. ChemistryWorld.com article. Pull quote: “‘Future work to get light into a larger scale separation process may well be able to piggyback on the work being done by the catalysis community to scale up their light-assisted reactions,’ says Arnold. ‘In the meantime, it is exciting to consider how we could use these cheap, blue LEDs to help reprocess our small and valuable stocks of rare isotopes that we need for research.’”

Automotive Security Threats Are More Critical Than Ever. SecurityWeek.com article. Pull quote: “As vehicles become more connected and autonomous and a part of our everyday life, the need to secure them only grows more critical — and complex. The role of testing becomes even more critical to the success of the next generation of vehicles on the market. Better managing the cybersecurity needs of these cars starts at the beginning of the design process and continues throughout the life of the vehicle. With a committed industry, we can mitigate threats as they emerge and let everyone enjoy these truly incredible machines.”

Didn’t Realize Your New Koi Can Live to 80? Call Fish Rescue. WSJ.com article. Pull quote: “Sterling Animal Shelter in Sterling, Mass., built a rescue pond several years ago. Adoptions have been rising ever since, said Executive Director Leigh Grady.”


 
/* Use this with templates/template-twocol.html */