Tuesday, February 20, 2024

FMCSA-PHMSA Publishes Nurse-Tank Safety Advisory

Earlier this month, DOT Federal Motor Carrier Safety Administration (FMCSA) and Pipeline and Hazardous Materials Safety Administration (PHMSA) published a Safety Advisory for “Possible Catastrophic Failure of Nurse Tanks and Recommendation for Periodic Testing”. The two agencies are recommending that owners of Anhydrous Ammonia Nurse Tanks manufactured by American Welding & Tank (AWT) between 2007 and 2011 “conduct voluntary periodic visual inspection in accordance with 49 CFR §173.315(m)(2)(i); thickness testing in accordance with 49 CFR §173.315(m)(2)(ii), and pressure testing in accordance with 49 CFR §173.315(m)(2)(iii).”

Generally speaking, anhydrous ammonia nurse tanks, that are considered an implement of husbandry transporting anhydrous ammonia and operated by a private motor carrier exclusively for agricultural purposes are exempted from periodic inspection requirements as long as the tank is marked with a valid, and legible ASME plate. For the purposes of this advisory, however, FMCSA and PHMSA are recommending periodic (every five years) voluntary testing in accordance with §173.315(m)(2)(iv).

According to the Safety Advisory:

“On August 23, 2023, a 2009 AWT nurse tank containing anhydrous ammonia experienced a catastrophic failure in a farm co-op lot, resulting in the release of all product. The failure caused the tank shell to “rocket” over 300 feet from its original location. While no injuries were reported, this event is an indicator of potential continuing problems with AWT nurse tanks that have now been in service for over a decade.

As a result of this incident, the owner of the nurse tank involved contracted with a third-party testing company to examine their AWT nurse tanks that were manufactured between 2008 and 2012. Radiographic testing showed that 7 of 8 the nurse tanks tested had extreme stress corrosion cracking, porosity, and inclusions/voids in the welds where the heads and shells of the nurse tanks were joined. Only the 2012 tank passed. The nurse tank owner submitted these results to engineering experts who were involved in previous research funded by FMCSA into similar issues with this series of AWT nurse tanks.1 Based on the test results and the review by the experts, the owner voluntarily placed the nurse tanks out-of-service. The parent company of the farm co-op subsequently conducted similar radiographic testing on 142 AWT nurse tanks manufactured between 2007 and 2012, and 100 failed the test. All 2012 tanks passed.”

The advisory also reports that:

“This notice focuses on nurse tanks manufactured from January 1, 2007, through December 31, 2011, by American Welding and Tank (AWT) at its Fremont, Ohio plant. Nurse tanks manufactured by AWT from 2009 to 2010 were the subject of a prior FMCSA investigation and enforcement action in response to improper manufacturing procedures.” (FMCSA press release here; AWT press release here)

NHC Publishes New Product Update for 2024 Hurricane Season

Today, NOAA’s National Hurricane Center published a New Product Update, explaining new sources of information and changes to information presentation for the 2024 Hurricane Season. It provides information on the following topics:

• Spanish language advisory text products,

• Issuance of U.S. watches and warnings on Intermediate advisories,

• Extension of tropical storm (39 mph, 34 kt) and 58 mph, 50 kt)) wind radii forecasts to days 4 and 5,

• Weblinks in the Public Advisory,

• Change to the time zone reference in the eastern Pacific,

• Experimental Cone Graphic with a depiction of inland watches and warnings for the United States,

• Experimental international tropical cyclone rainfall graphics,

• New Marine Forecast Product “Offshore Waters Forecast for the southwestern North Atlantic Ocean”,

• Pronunciation of storm names,

• Social Media, and

• Find us on the Web

Review – 3 Advisories Published – 2-20-24

Today, CISA’s NCCIC-ICS published three control system security advisories for products from Mitsubishi Electric, CISA and Commend.

Advisories

Mitsubishi Advisory - This advisory discusses an improper input validation vulnerability in the Mitsubishi Electrical discharge machines.

CISA Advisory - This advisory describes two vulnerabilities in the CISA Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin.

Commend Advisory - This advisory describes three vulnerabilities in the Commend WS203VICM video door station.

 

For more details about these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-published-2-20-24 - subscription required.

Review - HR 7190 Introduced – Fentanyl as WMD

Earlier this month, Rep Boebert (R,CO) introduced HR 7190, the Fentanyl is a WMD Act. The very short (two sentences) bill would require the DHS Assistant Secretary for the Countering Weapons of Mass Destruction (CWMD) Office to “treat illicit fentanyl as a weapon of mass destruction for purposes of title XIX of the Homeland Security Act of 2002” (6 USC 590 et seq). No spending is authorized by this legislation.

Moving Forward

Boebert is not a member of the House Homeland Security Committee to which this bill was assigned for consideration, nor are any of her eleven cosponsors. This means that there is likely insufficient influence to see the bill considered in Committee. I would expect there to be significant bipartisan opposition to the bill were it to be considered.

Commentary

While fentanyl may broadly fall within the scope of the definition of the term ‘weapon of mass destruction’, there is nothing within the current scope or mission of the Countering Weapons of Mass Destruction Office that would help the federal government reduce the flow of that drug into this country. Either the sponsors of this bill are unaware of the mission of the CWMD Office, or this legislation is just another bit of political grandstanding. In my opinion, while I would not be surprised at these particular congresscritters being uniformed, I suspect the latter.

 

For more details about the CWMD Office and its mission with respect to the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-7190-introduced - subscription required.

Monday, February 19, 2024

Short Takes – 2-19-24

Plutonium to carbon double bond a first. ChemistryWorld.com article. More than a bit chem-geeky. Pull quote: “The first organo-plutonium complex (Pu(C5H5)3) was reported in 1965 but research into the fundamental properties of plutonium has been held back due to experimental difficulties and availability of the element. ‘Uranium is probably the last element in the periodic table where you can work in a normal laboratory,’ explains Steve Liddle, head of inorganic chemistry at the University of Manchester and one of the researchers on the study. ‘Go one place to the right and you need a completely different radiological lab setup.’”

QR Phishing. Fact or Fiction? PenTestPartners.com blog post. Pull quote: “The embedded QR code [in an email] will be shown and with a suitable lure, the email can direct the victim to move from the secure endpoint to a less secure mobile platform. The link is unlikely to have been scanned by URL filters due to it not being a link at the time of scanning.”

QNAP vulnerability disclosure ends up an utter shambles. TheRegister.com article. Pull quote: “Unit 42's assessment, on the other hand, was the polar opposite: "These remote code execution vulnerabilities affecting IoT devices exhibit a combination of low attack complexity and critical impact, making them an irresistible target for threat actors. As a result, protecting IoT devices against such threats is an urgent task."”

German battery maker Varta halts production after cyberattack. BleepingComputer.com article. Can you say ‘Network Segmentation’??? Pull quote: “"This affects the five production plants and the administration. The IT systems and, thus, production were proactively shut down temporarily for security reasons and disconnected from the internet."”

It’s already hurricane season in the waters of the Atlantic. That could spell danger with La Niña coming. CNN.com article. Pull quote: “It’s difficult to know what the combination of near-record ocean warmth and a La Niña could be capable of, since there has been no other hurricane season in which temperatures were this extreme, Klotzbach said.”

Technological McCarthyism in 2024's s/UAS Industry. LinkedIn.com commentary. Contrarian view on Chinese drone threat. Pull quote: “In this light, the debate over banning Chinese drones should prompt us to ask deeper questions about our national approach to technology, security and global competitiveness. It's time to move beyond fear-driven policies and embrace a strategy that actually unlocks the dawn of a new day where America is undoubtedly leading the way in the s/UAS industry; not by closing our doors, but by opening our minds to the possibilities of what we can create and achieve. What users actually demand from these tools. Not marketing and roadshows; actual commercial market demand + consumption.”

Why no one knows quite when a descending satellite will hit Earth this week. TheNextWeb.com article. Pull quote: “ESA’s latest prediction — revealed this morning — is that the re-entry will take place at 12:14 CET on February 21. There’s an uncertainty window, however, of about two-thirds of a day (+/- 15.06 hours) — which is typical at this point.”

Potential new weapon in battle against superbugs. News.Harvard.edu article.  Pull quote: ““While we don’t yet know whether cresomycin and drugs like it are safe and effective in humans, our results show significantly improved inhibitory activity against a long list of pathogenic bacterial strains that kill more than a million people every year, compared with clinically approved antibiotics,” Myers said.”

Review - HR 7073 Introduced – Next-Gen Pipelines

Last month, Rep Weber (R,TX) introduced HR 7073, the Next Generation Pipelines Research. The bill would require the Department of Energy to establish a new grant program to “carry out demonstration projects on low- to mid-technology readiness level subjects to achieve deployment of technologies”. It would also require DOE and DOT to conduct a joint R&D program to carry out basic research projects. Finally, the bill would require DOE to establish the National Pipeline Modernization Center. Also incluces a new NIST pipeline metrology program. The bill would authorize $50-million, $30-million, $15-million, and $1.5 million through 2028 for the four new programs.

This bill is very similar to HR 9349 [removed from paywall] introduced by Webber in the 117th Congress. Most of the changes are editorial in nature; §4 of the earlier bill, for instance, is changed to include the earlier language in a new §40344 to be added to the Infrastructure Investment and Jobs Act (PL 117-158). The major change, however, is that a new §8 has been added to the bill that would provide an off-set for the new spending authorized in the bill by reducing funding in §10771, Department of Energy research, development, and demonstration activities, of the Research and Development, Competition, and Innovation Act (PL 117-167), after extending that spending authorization through 2028. The new version of the bill also adds a new §7, NIST Pipeline Metrology, authorized at $2.5-million per year through 2028.

HR 9349 was introduced too late in the 117th Congress for any action to be taken.

Moving Forward

Webber and his three cosponsors {Rep Caraveo (D,CO), Rep Lucas (R,CO), and Rep Obernolte (R,CA)} are all members of the House Science, Space, and Technology Committee to which this bill was assigned for consideration. This means that there may be sufficient influence to see this bill considered in Committee. I do not see anything in the legislation that would engender organized opposition. I suspect that there would be bipartisan support for the bill, but I am not sure that it would be sufficient to allow the bill to move to the floor of the House under the suspension of the rules process.

Commentary

Webber’s staff has done an interesting job of neutralizing the money problem with this bill. Since no new monies are authorized, the fiscal hawks are less likely to object to the bill. The extension of the existing spending authorizations (albeit at somewhat reduced levels), give the environmental folks a reason to support the bill. And, of course, industry is sure to support federal funding of pipeline research efforts.

 

For more details about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-7073-introduced - subscription required.

Saturday, February 17, 2024

Review – Public ICS Disclosures – Week of 2-10-24 – Part 2

For Part 2 we have four additional vendor disclosures from Schneider (3) and WatchGuard. There are also ten vendor updates from Dell, Schnieder, and Siemens (8). Finally, we have two exploits for products from Vimesa and Splunk.

Advisories

Schneider Advisory #1 - Schneider published an advisory that describes three vulnerabilities in multiple Schneider products.

Schneider Advisory #2 - Schneider published an advisory that describes an improper authentication vulnerability in their Harmony Relay NFC products.

Schneider Advisory #3 - Schneider published an advisory that describes a use of hard-coded credentials vulnerability in their EcoStruxure IT Gateway product.

Updates

Dell Update - Dell published an update for their Wyse Management Suite advisory that was originally published on December 19th, 2022.

Schneider Update - Schneider published an update for their Modicon Controllers advisory that was originally published on May 14th, 2019 and most recently updated on March 14th, 2023.

Siemens Update #1 - Siemens published an update for their User Management Component advisory that was originally published on December 12th, 2023 and most recently updated on January 9th, 2024.

Siemens Update #2 - Siemens published an update for their Linux Kernel of the SIMATIC S7-1500 advisory that was originally published on June 13th, 2023 and most recently updated on January 9th, 2024.

Siemens Update #3 - Siemens published an update for their OPC UA Implementations advisory that was originally published on September 12th, 2023 and most recently updated on January 9th, 2024.

Siemens Update #4 - Siemens published an update for their GNU/Linux subsystem of the SIMATIC S7-1500 that was originally published on November 27th, 2018 and most recently updated on December 12th, 2023.

Siemens Update #5 - Siemens published an update for their DHCP Client of Nucleus RTOS advisory that was originally published on November 12th, 2023.

Siemens Update #6 - Siemens published an update for their GNU/Linux subsystem of the SIMATIC S7-1500 CPU advisory that was originally published on December 12th, 2023 and most recently updated on January 9th, 2024.

Siemens Update #7 - Siemens published an update for their Siemens Industrial Products advisory that was originally published on August 10th, 2021 and most recently updated on November 14th, 2023.

Siemens Update #8 - Siemens published an update for their IPv6 Stack of Nucleus RTOS advisory that was originally published on April 13th, 2021 and most recently updated on November 9th, 2021.

Exploits

Vimesa Exploit - LIQUIDWORM published an exploit for a denial of service vulnerability in the Vimsea Blue Plus VHF/FM radio transmitter.

Splunk Exploit - Parsa Rezaie Khiabanloo published an exploit for an information disclosure vulnerability in Splunk.

 

For more information about these disclosures, including a brief summary of changes made in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-2-d2a - subscription required.

 
/* Use this with templates/template-twocol.html */