Saturday, July 22, 2023

CRS Reports – Week of 7-15-23 – Cybersecurity Strategy

This week, the Congressional Research Service (CRS) published an updated version (.pdf download link) of their report on “The National Cybersecurity Strategy—Going Where No Strategy Has Gone Before”. The report looks at the Biden Administration’s version of the National Cybersecurity Strategy, providing an annotated overview of the strategy and only a cursory mention of the new implementation plan.


Note: Corrected date in title on 11:00 pm EDT 7-22-23

Chemical Incident Reporting – Week of 7-15-23

NOTE: See here for series background.

Brazoria County, Texas – 7-13-23

Local news reports: Here, here, and here.

Two pipelines were damaged in a release of ethylene and propylene with resulting explosion and fire. No injuries, valve site destroyed.

May be a CSB reportable. Typically, CSB does not cover pipeline incidents, those are addressed by NTSB. But this was at a pump and storage station which may be covered as a stationary source.

Iberville Parish, La – 7-15-23

Local news reports: Here, here, and here.

Fire and explosions in ethylene glycol unit at refiner.

No deaths, no injuries, no damage estimates yet.

Probably a CSB reportable, depending of damage estimates. I would be very surprise if this does not reach the $1 million statutory floor for reporting.

Review – Public ICS Disclosures – Week of 7-15-22

This week we have nine vendor disclosures from Aqua eSolutions, Beldon, HP (2), SEL (2), Sierra Wireless, Splunk, and Zyxel. There are two vendor updates from AMI and HPE. We also have three researcher reports about vulnerabilities in products from Tesla. Finally, we have two exploits for products from ABB and Hikvision.

Advisories

Aqua Advisory - Incibe CERT published an advisory that describes a relative path traversal vulnerability in their Aqua Drive.

Belden Advisory - Beldon published an advisory that discusses an undescribed JavaSE vulnerability in several of their Belden and Hirschmann products.

HP Advisory #1 - HP published an advisory that discusses two vulnerabilities in their Security Manager and Web Jetadmin products.

HP Advisory #2 - HP published an advisory that describes an elevation of privilege vulnerability in their LaserJet Pro print products.

SEL Advisory #1 - SEL published a new version notice for their SEL-5030 acSELerator QuickSet software that addresses seven briefly described cybersecurity issues.

SEL Advisory #2 - SEL published a new version notice for their SEL-5036 acSELerator Bay Screen Builder Software that addresses a software validation issue.

Sierra Wireless Advisory - Sierra Wireless published an advisory that briefly discusses a Cl0p ransomware attack on a Sierra Wireless corporate server.

Splunk Advisory - Splunk published an advisory that discusses two vulnerabilities in their SOAR product.

Zyxel Advisory - Zyxel published an advisory that describes seven vulnerabilities in their firewall and WLAN controllers.

Updates

AMI Update - AMI published an update for their -MegaRAC SPX advisory that was originally published on July 5th, 2023.

HPE Update - HPE published an update for their ArubaOS-CX 8000 Series Switches advisory that was originally published on February 2nd, 2022.

Researcher Reports

Tesla Reports - The Zero Day Initiative published three reports about individual vulnerabilities in the Tesla Model 3 that were discovered as part of a Pwn2Own competition.

Exploits

ABB Exploit - Paul Smith published an exploit for an exposure of sensitive information to an unauthorized actor vulnerability in the ABB FlowX product.

Hikvision Exploit - Thurein Soe published an exploit for a command injection vulnerability in the Hikvision Hybrid SAN Ds-a71024 product.

Commentary

I would like to commend Sierra Wireless on their advisory about the potential consequences of their recent Cl0p ransomware attack. Ransomware attacks are a big problem, but frequently overlooked in attacks on vendors is that information may have been discovered by the attacker that could be used to exploit product vulnerabilities in their customers. Reports like this one provide customers a heads up about potential attacks on their equipment.

 

For more details about these disclosures, including links to researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-c81 - subscription required.

Friday, July 21, 2023

Short Takes – 7-21-23

Extraterrestrial 'technical supremacy' top concern, Pentagon UFO investigator says. ABC7Chicago.com article. A bit of a clickbait title. Pull quote: “Asked whether he believes intelligent extraterrestrial life exists, Kirkpatrick said: "I think it's statistically unrealistic to think it isn't" and that finding it would be "probably the best outcome of this job."”

‘We are not prepared’: Disasters spread as climate change strikes. Politico.com article. Pull quote: “From a nearly depleted federal disaster fund to state insurance markets that are faltering under the weight of multiple catastrophes, extreme weather is testing the ability of even a rich nation like the United States to withstand the warming that has arrived faster than many scientists expected. So are the torrential rains flooding Northeastern states like Vermont, the shriveling Colorado River that has prompted a multistate brawl over dividing the water, the record temperatures that have raised worries about the stability of the electric grid, and the Canadian wildfire smoke that has repeatedly blanketed D.C. and other parts of the U.S. in recent weeks.”

Special Conditions: Textron Aviation, Inc. Model 560XL(XLS+) Airplane; Electronic System Security Protection From Unauthorized External Access. Federal Register FAA Final Special Conditions. Pull quote: “These special conditions are issued for the Textron Aviation, Inc. (Textron) Model 560XL(XLS+) airplane. This airplane will have a novel or unusual design feature when compared to the state of technology envisioned in the airworthiness standards for transport-category airplanes. This design feature is associated with the installation of an electronic networks system architecture that will allow increased connectivity to and access from external sources (e.g., operator networks, wireless devices, internet connectivity, service provider satellite communications, electronic flight bags, etc.) to the airplane's previously isolated electronic assets (networks, systems, and databases). The applicable airworthiness regulations do not contain adequate or appropriate safety standards for this design feature. These special conditions contain the additional safety standards that the Administrator considers necessary to establish a level of safety equivalent to that established by the existing airworthiness standards.”

Special Conditions: Textron Aviation, Inc. Model 560XL(XLS+) Airplane; Electronic System Security Protection From Unauthorized Internal Access. Federal Register FAA Final Special Conditions. Pull quote: “These special conditions are issued for the Textron Aviation, Inc. (Textron) Model 560XL(XLS+) airplane. This airplane will have a novel or unusual design feature when compared to the state of technology envisioned in the airworthiness standards for transport-category airplanes. This design feature is associated with the installation of a digital system that contains a wireless and hardwired network with hosted application functionality that allows access, from a source internal to the airplane, to the airplane's internal electronic component. The applicable airworthiness regulations do not contain adequate or appropriate safety standards for this design feature. These special conditions contain the additional safety standards that the Administrator considers necessary to establish a level of safety equivalent to that established by the existing airworthiness standards.”

CSB Updates Investigation Backlog Recovery

Yesterday, the Chemical Safety Board provided updated information on their investigation backlog clearance, noting that it had eliminated two-thirds of the agency’s backlog during the last twelve months. They also updated their closure plan graphic, showing the five investigations remaining in their backlog identified in November 2021.

Commentary

While the CSB is to be commended on their diligent work to overcome the legacy mismanagement issues that created this backlog, it must be remembered that it has come at the cost of failing to initiate new investigations. Only one new investigation has been started in the more than a year and a half since the agency’s letter to Congress vowing to correct the backlog. I understand why this has been necessary, but it is a cost of the previous mismanagement of the agency, mismanagement that Congress was slow to recognize because of it’s ineffective oversight.

As the CSB nears clearance of their backlog, it is perhaps more important for the EPA IG, the Government Accounting Office, and Congress to work together (perhaps with an outside investigation) to identify how the agency fell so far behind in their investigation work, and what oversight steps should have been able to identify the problem earlier.

We need the insights that the Chemical Safety Board brings to these investigations to help make chemical manufacturing and handling safer in this country. We need to ensure the efficacy of the Board management going forward.

Bills Introduced – 7-20-23

Yesterday, with both the House and Senate in session (and preparing to depart Washington for a four day weekend), there were 122 bills introduced. Three of those bills may receive additional coverage in this blog:

S 2437 An original bill making appropriations for the Departments of Transportation, and Housing and Urban Development, and related agencies for the fiscal year ending September 30, 2024, and for other purposes. Schatz, Brian [Sen.-D-HI]

S 2438 An original bill making appropriations for the Department of State, foreign operations, and related programs for the fiscal year ending September 30, 2024, and for other purposes. Coons, Christopher A. [Sen.-D-DE] 

S 2443 An original bill making appropriations for energy and water development and related agencies for the fiscal year ending September 30, 2024, and for other purposes. Feinstein, Dianne [Sen.-D-CA]

I will be covering S 2437 and S 2443.

I will be watching S 2438 for language that includes coverage of control system cybersecurity issues and chemical safety and security issues. I do not typically find any in the State Department spending bill.

Thursday, July 20, 2023

Short Takes – 7-20-23

We could get large amounts of water from the moon by directing the sun at it.Phys.org article.  Pull quote: “Other risks also abound, including uncertainty about the total amount and location of water on the moon. There is undoubtedly some in the PSRs, but it might be that there isn't enough close to the surface, where it can be gathered by thermal mining, to support long-term human habitation, and water and other "volatiles" have to shipped in from Ceres or elsewhere in the asteroid belt. If that's the case, there is still an argument that the underlying thermal mining technique could be useful—it just might not be profitable.”

A Vast Lake Has Captivated California Where Farms Stood a Year Ago. NYTimes.com article. Pull quote: “First a trickle, then a flood, the water that coursed into the lake bed over a handful of months swallowed one of the nation’s largest and most valuable stretches of cropland in about the time it takes to grow a tomato. Thirty square miles, then 50. Then 100. Then more.”

Self-healing metal? It's not just the stuff of science fiction. Reuters.com article. Pull quote: “Scientists on Wednesday described how pieces of pure platinum and copper spontaneously healed cracks caused by metal fatigue during nanoscale experiments that had been designed to study how such cracks form and spread in metal placed under stress. They expressed optimism that this ability can be engineered into metals to create self-healing machines and structures in the relatively near future.”

As the world sizzles, China says it will deal with climate its own way. WashingtonPost.com article. Pull quote: “Still, Beijing made it clear that domestic concerns would shape its approach to energy. China’s world-leading emissions totaled 11.4 billion tons of carbon dioxide in 2022, according to the Global Carbon Project, a decline of less than 1 percent from 2021 levels.”

Ukraine counter-offensive is far from failure - US general. Reuters.com article. Pull quote: “"I think there's a lot of fighting left to go and I'll stay with what we said before: This is going to be long. It's going be hard. It's going to be bloody," Milley told reporters.”

Hotel-Sized Asteroid Undetected Until Two Days After Close Pass By Earth. Forbes.com article. Pull quote: “This asteroid [2023 NT1] was hard to see earlier because it approached Earth from the direction of the sun, just like the Chelyabinsk bolide, which was never noticed by humans until it was breaking up over Russia and sending out a shock wave that shattered glass and a few walls, injuring hundreds.”

House approves FAA reauthorization bill. TheHill.com article. Pull quote: “The measure [HR 3935] — formally titled the Securing Growth and Robust Leadership in American Aviation Act — passed in a bipartisan 351-69 vote. It now heads to the Senate, where lawmakers are considering their bill to reauthorize the FAA.”

 
/* Use this with templates/template-twocol.html */