Tuesday, January 17, 2023

To Legislate or Not, that is the Question

Maybe you saw a news report yesterday (here for example) about a legislative attempt to ban the sales of electric vehicles in Wyoming. The attempt to protect the crude oil production industry in the State sounded serious and fit in with various anti-environmental, anti-wokism politics that are receiving national attention right now. Only according to a Washington Post article published today, the legislators were not really serious, it was more about responding to a recent law passed in California outlawing the sale of gasoline powered vehicles in that State by 2035.

I have frequently pointed out in this blog that the introduction of a piece of legislation does not mean that the bill will become law, the vast majority do not. I have also noted on occasion that the introduction does not mean that the sponsor ever had any intention to see the bill passed. Sometimes it is simply an effort to get their colleagues (or the public) to start looking at a problem. More frequently, unfortunately, it is more of a fund-raising effort, making it look like the sponsor is working on a favorite issue of a high-spending contributor or significant voting block.

Similarly, a small majority in the House (currently the Republicans, but of course the Democrats did the same) will pass a controversial bill knowing full well that it has no chance to be considered in the Senate (where consideration of a bill can be blocked by 41 Senators), and if it were (through some legislative miracle) it would never be signed by the President. It makes it look like the small majority is doing something, it fires up the conservative (liberal) base, and keeps money coming in to the campaign coffers. So, maybe in two years, the small majority will become big enough to ‘actually accomplish something’.

This is one of the reasons that when I look at a piece of legislation here in this blog, I always try to look not only on what it attempts to accomplish, but its chance of making it through the legislative process.

Sunday, January 15, 2023

Short Takes – 1-15-23

Japan is reacting to Russia and China rationally. It is only the beginning. WashingtonPost.com article. Japanese counter strike capability. Pull quote: “China is in the early stages of what might be the biggest military buildup in history. Russia’s invasion of Ukraine effectively ended the post-Cold War era. Japan is reacting to those developments rationally. But beware: As the global order frays, the chain of action and reaction is only beginning.”

Mass-market military drones: 10 Breakthrough Technologies 2023. TechnologyReview.com article. Pull quote: “Most important is simply its availability. US-made drones like the Reaper are more capable but costlier and subject to stiff export controls. The TB2 is there for any country that wants it.”

The James Webb Space Telescope Is Finding Too Many Early Galaxies. SkyAndTelescope.org article. New information always raises questions about current knowledge. Pull quote: “As the James Webb Space Telescope views swaths of sky spotted with distant galaxies, multiple teams have found that the earliest stellar metropolises are more mature and more numerous than expected. The results may end up changing what we know about how the first galaxies formed.”

Flood watch covers nearly all of California amid severe storms. WashingtonPost.com article. Pull quote: “Gov. Gavin Newsom (D) asked the public to prepare for the ninth atmospheric river that is set to hit Sunday night going into Monday. He added that erosion and tree damage that will continue even after rainfall stops.”

Joe Biden and Kevin McCarthy, wary opponents, prepare to work together. WashingtonPost.com article. A slightly contrarian view of the political future. Pull quote: ““Since he has become president, he hasn’t had us down very often,” McCarthy told reporters last year when asked about his relationship with Biden. “I think that will change now. Look, the election is over. I can work with anybody who wants to work to make America better.””

Review - Public ICS Disclosures – Week of 1-7-23 – Part 2

For Part 2 this week we have eight additional vendor disclosures from Schneider (6) and Siemens (2). We also have 19 additional vendor updates from Schneider (3) and Siemens (16). Just a reminder, NCCIC-ICS announced this week that they were no longer going to be updating Siemens advisories, apparently the workload just got to be too much.

Vendor Disclosures

Schneider Advisory #1 - Schneider published an advisory that describes an out-of-bounds write vulnerability in their EcoStruxureTM Machine Expert.

Schneider Advisory #2 - Schneider published an advisory that describes two vulnerabilities in the EcoStruxure TM Geo SCADA Expert.

Schneider Advisory #3 - Schneider published an advisory that discusses an access of unitialized pointer vulnerability in their EcoStruxure™ products.

Schneider Advisory #4 - Schneider published an advisory that describes an exposure of resource to wrong sphere vulnerability in the EcoStruxure™ Power SCADA Anywhere product.

Schneider Advisory #5 - Schneider published an advisory that describes an improper check for unusual or exceptional conditions vulnerability in their s EcoStruxure™ Control Expert, EcoStruxure™ Process Expert, and Modicon PLCs.

Schneider Advisory #6 - Schneider published an advisory that describes an authentication bypass vulnerability in their EcoStruxure™ Control Expert, EcoStruxure™ Process Expert, and Modicon M340, M580 and M580 CPU Safety products.

Siemens Advisory #1 - Siemens published an advisory that describes three vulnerabilities in their JT Open, JT Utilities and Solid Edge products.

NOTE: The first two vulnerabilities were reported in other Siemens products in December of 2021.

Siemens Advisory #2 - Siemens published an advisory that discuses twelve vulnerabilities in their SINEC Infrastructure Network Services (INS).

Vendor Updates

Schneider Update #1 - Schneider published an update of their CODESYS Runtime advisory that was originally published on January 11th, 2022 and most recently updated on July 12th, 2022.

Schneider Update #2 - Schneider published an update of their BadAlloc advisory that was originally published on November 9th, 2021 and most recently updated on December 13th, 2022.

Schneider Update #3 - Schneider published an update of their Modicon Controllers advisory that was originally published on September 26th, 2019 and most recently updated on September 13th, 2022.

Siemens Update #1 - Siemens published an update of their OpenSSL advisory that was originally published on June 16th, 2022 and most recently updated on December 13th, 2022.

Siemens Update #2 - Siemens published an update of their SCALANCE advisory that was originally published on August 9th, 2022 and most recently updated on September 13th, 2022.

Siemens Update #3 - Siemens published an update of their TCP Even Service advisory that was originally published on October 11th, 2022.

Siemens Update #4 - Siemens published an update of their SegmentSmack advisory that was originally published on April 14th, 2020 and most recently updated on December 13th, 2022.

Siemens Update #5 - Siemens published an update of their Industrial Products advisory that was originally published on March 20th, 2018 and most recently updated on August 9th, 2022.

Siemens Update #6 - Siemens published an update of their SCALANCE advisory that was originally published on February 11th, 2020 and most recently updated on December 13th, 2022.

Siemens Update #7 - Siemens published an update of their SIMATIC WinCC advisory that was originally published on December 13th, 2022.

Siemens Update #8 - Siemens published an update of their Industrial Products advisory that was originally published on April 9th, 2019 and most recently updated on August 9th, 2022.

Siemens Update #9 - Siemens published an update of their Industrial Controllers advisory that was originally published on November 8th, 2022 and most recently updated on December 13th, 2022.

Siemens Update #10 - Siemens published an update of their PROFINET devices advisory that was originally published on October 10th, 2019 and most recently updated on December 13th, 2022.

Siemens Update #11 - Siemens published an update of their PROFINET stack advisory that was originally published on April 14th, 2022 and most recently updated on December 13th, 2022.

Siemens Update #12 - Siemens published an update of their SIMATIC S7 advisory that was originally published on February 11th, 2020 and most recently updated on August 9th, 2022.

Siemens Update #13 - Siemens published an update of their Industrial Products advisory that was originally published on December 13th, 2022.

Siemens Update #14 - Siemens published an update of their Industrial Real Time Devices advisory that was originally published on October 10th, 2019 and most recently updated on February 8th, 2022.

Siemens Update #15 - Siemens published an update of their Mendix workflow advisory that was originally published on December 13th, 2022.

Siemens Update #16 - Siemens published an update of their SIMATIC S7-400 advisory that was originally published on November 13th, 2018, and most recently updated on August 9th, 2022.

 

For more details on these disclosures, including links to third-party advisories, exploits and a brief summary of update changes, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-39e - subscription required.

Saturday, January 14, 2023

Short Takes – 1-14-23

Why Russia is fighting so hard for Ukraine’s Bakhmut. TheHill.com article. Pull quote: “John Herbst, the senior director of the Eurasia Center for the Atlantic Council, said the fighting in Bakhmut and Soledar is almost entirely being conducted by the Wagner Group, a mercenary outfit led by Yevgeny Prigozhin, a close ally of Russian President Vladimir Putin.”

Makiivka and Bakhmut: The Impact of Russian Casualties. SAMF.Substack.com article. Interesting if lengthy discussion. Pull quote: “When we step back from the daily news the underlying trends of this war favour Ukraine. It is learning to cope with the repeated Russian attacks on its critical infrastructure, and once spring comes the impact will decline, while it has been getting bolder in its attacks on facilities on Russian territory. The energy shock has not turned the West away from supporting Ukraine and instead they are offering support for future land offensives. Here lies the biggestdanger for Putin - more retreats rather than more casualties - and a developing aura of futility. The question of what it takes to get Russia to abandon its war of conquest remains unanswered but that does not mean that no answer will ever be found.”

U.S. Will Hit Debt Limit on Thursday, Yellen Tells Congress. NYTimes.com article. Extraordinary measures begin Thursday. Pull quote: “That [bipartisan] group includes the entire Democratic caucus in the House and Senate, plus a handful of Republicans needed to pass bills in both chambers. Such a coalition could employ a rare tactic in the House, called a discharge petition, to force a floor vote on raising the limit. But the move would take weeks or even months to produce a bill that Mr. Biden could sign into law, which could threaten default if lawmakers misjudge the date when Treasury can no longer pay the nation’s bills.”

Journey to the NIST Cybersecurity Framework (CSF) 2.0 | Workshop #2. NIST.gov announcement. Pull quote: “Join NIST and expert panelists and leaders on February 15, 2023, for this second virtual workshop to discuss potential updates to the Cybersecurity Framework. This event will discuss potential significant changes to the Framework as outlined in the CSF Concept Paper, as well as build on feedback from the 2022 NIST Cybersecurity Request for Information (RFI) and the first workshop. This upcoming workshop will help to improve the CSF by engaging with a wide and diverse community of experts (the first CSF 2.0 workshop was attended by 4,000 participants from 100 countries).”

The Center of Gravity for Chemical Threats. HomelandSecurityNewsWire.com article. Background piece by Director of Chemical Security Analysis Center (CSAC). Pull quote: “This NDAA authorization acknowledges the enduring importance of laboratory-based chemical security research and analysis. But more importantly, it reinforces to our DHS customers and partners that CSAC will continue to do the science that remains crucial to executing the homeland security mission.”

You Get a Special Counsel, and You Get a Special Counsel, Everyone Gets a Special Counsel! StatusKuo.Substack.com article. This guy has a very interesting take on matters legal, sign up for his Substack. Pull quote: “The same goes for Hur. It didn’t take long for Republicans to realize they had been outmaneuvered, to furrow their brows, and then to come out awkwardly against the appointment—which seems odd until you realize that they really wanted to make the next few months all about Biden’s classified documents. Speaker Kevin McCarthy grumbled, “We don't think there needs to be a special prosecutor but I think Congress has a role to look at it.””

House Republicans prepare emergency plan for breaching debt limit. WashingtonPost.com article. Oh the games congresscritters play…. Pull quote: “In the preliminary stages of being drafted, the GOP proposal would call on the Biden administration to make only the most critical federal payments if the Treasury Department comes up against the statutory limit on what it can legally borrow. For instance, the plan is almost certain to call on the department to keep making interest payments on the debt, according to four people familiar with the internal deliberations who spoke on the condition of anonymity to describe private conversations. House Republicans’ payment prioritization plan may also stipulate that the Treasury Department should continue making payments on Social Security, Medicare and veterans benefits, as well as funding the military, two of the people said.”

BIS Publishes Marine Toxins Final Rule

The DOC’s Bureau of Industry and Security published a final rule in Tuesday’s (available on line today) Federal Register (88 FR 2507-2517) for “Implementation of Australia Group Decisions From 2021 and 2022 Virtual Meetings: Controls on Marine Toxins, Plant Pathogens and Biological Equipment”. The rule makes a number of technical changes to the DOC’s Export Control Lists including adding four naturally occurring, dual-use marine toxins (specifically, brevetoxins, gonyautoxins, nodularins and palytoxin) and removing cholera toxin, thus the ‘Marine toxins’ of the title.

I have been following this rulemaking to see if it makes significant definitional changes in the biotoxins rules to reflect the fact (from rulemaking abstract) that they “are now capable of being more easily isolated and purified due to novel synthesis methods and equipment”. This would make these biotoxins more like chemical weapons and thus potentially coverable under the Chemical Facility Anti-Terrorism Standards (CFATS) program. This final rule does not do that.

It does, however, make a minor change to the DOC regulations dealing with chemical weapon precursors. It makes a change to Technical Note 3 to ECCN (Export Classification Control Number) 1C350 (pg 960), changing the first sentence to read:

“Precursor chemicals in ECCN 1C350 are listed by name, Chemical Abstract Service (CAS) number and CWC Schedule (where applicable). Precursor chemicals of the same structural formula (e.g., hydrates, isotopically-labeled forms or all possible stereoisomers [added language]) are controlled by ECCN 1C350, regardless of name or CAS number.”

This does not technically change the various Chemical Weapons Convention lists of chemical weapon precursors that DHS used as a basis for some listings in the DHS chemicals of interest list (COI). This export control list change is almost certainly not sufficient to suggest a similar change in the COI list.

CRS Reports – 1-14-23 – Grid Security

This week the Congressional Research Service published a report on “Electric Grid Physical Security: Recent Developments”. It provides a brief overview of recent physical attacks on power distribution substations as well as a description of the current regulatory framework regarding physical security for grid facilities, specifically noting that electric distribution substations are not subject to federal regulation by FERC and NERC.

The important part of any CRS report is the discussion of options that Congress has for addressing the issues identified in the report. Here, CRS notes that:

“The 118th Congress may continue to be concerned about the state of electric grid physical security, including the security of grid infrastructure not currently subject to NERC’s existing security standards. Among many specific issues of potential interest, Congress may consider the evolving physical threat environment, oversight of physical security implementation, the relationship between federal and state grid security initiatives, and the cost-effectiveness of any future security requirements. Congress may also examine tradeoffs between investments to “harden” grid infrastructure (e.g., physical barriers) and investments to make the grid more resilient to physical attacks (e.g., additional transmission lines). As CIP-014 implementation and other physical security initiatives proceed, Congress also may be concerned about the power sector’s overall progress in securing its infrastructure, including organizational and structural changes supporting physical security as a corporate priority.”


Review: Public ICS Disclosures – Week of 1-7-23 – Part 1

This is a moderately busy Saturday after Cyber Tuesday. For Part 1 this week we have seventeen vendor disclosures from GE Grid Solutions (8), HP, HPE, Moxa, Omron (2), WAGO, Westermo, and Western Digital (2). We also have two vendor updates from BD and HPE. I will look at the Schneider and Siemens advisories and updates in Part 2.

Vendor Advisories

GE Grid Advisories - GE Grid Solutions published eight advisories this week. The advisories are only available to registered users.

HP Advisory - HP published an advisory that discusses three vulnerabilities in the AMD Client UEFI Firmware used in a variety of HP products.

HPE Advisory - HPE published an advisory that discusses a privilege escalation vulnerability in their SimpliVity 380 Gen9 Servers.

Moxa Advisory - Moxa published an advisory that discusses a hard-coded credential vulnerability (with known exploit) in their TN-4900 Series routers.

Omron Advisory #1 - JPCERT published an advisory that describes an active debug code vulnerability in the OMRON CP1L-EL20DR-D PLC.

Omron Advisory #2 - JPCERT published an advisory that describes an uninitiated pointer vulnerability in the OMRON CX-Motion-MCH application.

WAGO Advisory - CERT-VDE published an advisory that describes a missing authentication for critical function vulnerability in multiple products from WAGO.

Westermo Advisory - Westermo published an advisory that discusses an unnamed vulnerability in their Ibex software where SNMP v3 is enabled.

Western Digital Advisory #1 - Western Digital published an advisory that describes a Host Boot ROM code vulnerability. This is a vulnerability in the UFS Host implementation.

NOTE: So, this is not a Western Digital vulnerability, but one that they discovered in an industry standard service. This could get ugly.

Western Digital Advisory #2 - Western Digital published an advisory that describes four vulnerabilities in their My Cloud OS 5 devices.

Vendor Updates

BD Update - BD published an update to their Totalys™ MultiProcessor advisory that was originally published on October 4th, 2022.

NOTE: NCCIC-ICS has not yet updated their advisory (ICSMA-22-277-01) for this information.

HPE Update - HPE published an update for their Nonstop advisory that was originally published on July 18th, 2022.

 

For more details on these disclosures, including links to third-party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-b04 - subscription required.

 
/* Use this with templates/template-twocol.html */