Saturday, April 20, 2024

CRS Reports – Week of 4-13-24 – Congressional Disapproval

This week, the Congressional Research Service (CRS) published a report on “The Congressional Review Act: Defining a “Rule” and Overturning a Rule an Agency Did Not Submit to Congress”. The 118th Congress has been fairly active in submitting and passing bills to overturn agency actions. This report outlines the processes under the Congressional Review Act (5 USC 801 thru 808) for overturing agency actions, specifically it discusses the process for congressional action in the small number of cases where the agency does not pre-submit a copy of a rule to Congress.

Transportation Chemical Incidents – Week of 3-16-24

Reporting Background

See this post for explanation, with an update here (removed from paywall).

Data from PHMSA’s online database of transportation related chemical incidents that have been reported to the agency.

Incidents Summary

• Number of incidents – 470 (460 highway, 9 air, 1 rail)

• Serious incidents – 4 (3 Bulk release, 0 injuries, 0 deaths, 3 major arteries closed)

• Largest container involved – 30190-gal DOT DOT117R100W railcar (Alcohols, N.O.S.), improperly tightened bolts on manway cover. 5-gal spilled.

• Largest amount spilled – 440-lbs (Calcium Hypochlorite, Hydrated or Calcium Hypochlorite, Hydrated Mixtures, With Not Less Than 5.5% But Not More Than 16% Water) plastic container damaged in material handling.

Most Interesting Chemical: Tetrahydrofuran: Used as a solvent. A clear colorless liquid with an ethereal odor. Less dense than water. Flash point 6°F. Vapors are heavier than air. May form explosive peroxides when exposed to air, may be stabilized with butylated hydroxytoluene (BHT) to prevent the formation of peroxides. Involved in four incidents in the covered week.



Review – Public ICS Disclosures – Week of 4-13-24

This week we have nine vendor disclosures from Hitachi, HPE (4), Peplink, Philips, and Rockwell (2). There are also five vendor updates from B&R (2), Contec, HPE, and Palo Alto Networks. We also have eleven researcher reports about vulnerabilities in products from Elber (10) and Silicon Labs. Finally, we have two exploits for products from Palo Alto Networks.

NOTE: HP reports that they have an update for their NVIDIA GPU Display Driver advisory that was originally published on March 12th, 2024, but the link currently goes to a blank page.

Advisories

Hitachi Advisory - Hitachi published an advisory that discusses an allocation of resources without limit or throttling vulnerability in their JP1 product.

HPE Advisory #1 - HPE published an advisory that discusses an out-of-bounds write vulnerability in their Superdome Flex, Superdome Flex 280 and Compute Scale-up Server 3200 Servers.

HPE Advisory #2 - HPE published an advisory that discusses an improper restriction of operations within the bounds of a memory buffer vulnerability in their Compute Scale-up Server 3200 server.

HPE Advisory #3 - HPE published an advisory that discusses five vulnerabilities (three with exploits available) in their Telco IP Mediation E-Media product.

HPE Advisory #4 - HPE published an advisory that describes an insertion of sensitive information into a logfile vulnerability in their Compute Scale-up Server 3200 Server.

Peplink Advisory - Peplink published an advisory that describes five vulnerabilities in their Smart Reader access control product.

Philips Advisory - Philips published an advisory that discusses a CISA report of a compromise of Sisense Customer Data.

Rockwell Advisory #1 - Rockwell published an advisory that describes an improper input validation vulnerability in their 5015-AENFTXT product.

Rockwell Advisory #2 - Rockwell published an advisory that discusses a deserialization of untrusted data vulnerability {listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog} in their FactoryTalk Production Centre product.

Updates

B&R Update #1 - B&R published an update for their Docker Engine advisory that was originally published on April 10th, 2024.

B&R Update #2 - B&R published an update for their LOGO Fail advisory that was originally published on April 11th, 2024.

Contec Update - JP-CERT published an update for their SolarView Compact advisory that was originally published on June 9th, 2022 and most recently updated on February 10th, 2023.

HPE Update - HPE published an update for their Superdome Flex advisory that was originally published on January 23rd, 2024 and most recently updated on March 8th, 2024.

Palo Alto Networks Update - Palo Alto Networks published an update for their PAN OS command injection advisory that was originally published on March 12th, 2024.

Researcher Reports

Elber Report #1 - Zero Science published two reports of vulnerabilities in the Elber Signum DVB-S/S2 controller for satellite equipment.

Elber Report #2 - Zero Science published two reports of vulnerabilities in the Elber Cleber/3 Broadcast Multi-Purpose Platform.

Elber Report #3 - Zero Science published two reports of vulnerabilities in the Elber Reble610 M/ODU XPIC IP-ASI-SDH Microwave Link.

Elber Report #4 - Zero Science published two reports of vulnerabilities in the Elber DVB-S/S2 Satellite Receiver. Microwave Link.

Elber Report #5 - Zero Science published two reports of vulnerabilities in the Elber Wayber Analog/Digital Audio STL.

Silicon Labs Report - Talos published a report about a NULL pointer dereference vulnerability in the Silicon Labs Gecko Platform software design kit.

Exploits

Palo Alto Networks Exploit #1 - H4x0r-dz published an exploit for a command injection vulnerability in the Palo Alto Networks PAN-OS.

Palo Alto Networks Exploit #2 - W01fh4cker published an exploit for a command injection vulnerability in the Palo Alto Networks PAN-OS.

 

For more details about these disclosures, including links to researcher report, 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-ac1 - subscription required.

Friday, April 19, 2024

Short Takes – 4-19-24

The Trump Jury Has a Doxing Problem. Wired.com article. To be fair, should read ‘… Potential Doxing Problem’. Pull quote: “Armed with basic personal details about jurors and certain tools and databases, “an OSINT researcher could potentially uncover a significant amount of personal information by cross-referencing all this together,” Diachenko says. “That's why it's crucial to consider the implications of publicly revealing jurors' personal information and take steps to protect their privacy during criminal trials.””

The great commercial takeover of low Earth orbit. TechnologyReview.com article. Lengthy article, lots of interesting information. Pull quote: ““Within two to three years, I could send a graduate student to space with Axiom,” Ekblaw says. “It requires a little creative fundraising, but I think that that is opening up a realm of possibility.” In the past, she explains, a doctoral researcher would be unbelievably fortunate to have research fly as part of a single flight mission.Today, however, researchers even in a master’s program can fly experiments repeatedly because of the increased opportunities afforded by commercial spaceflight.In the future, rather than relying on career NASA astronauts—who have myriad responsibilities in orbit and spend a good amount of time as guinea pigs themselves—scientists could go up personally to run their own research projects in greater depth.”

Notice Pesticide Registration Review; Draft Human Health and Ecological Risk Assessments for Formaldehyde and Paraformaldehyde; Notice of Availability. Federal Register EPA notice. Summary: “This notice announces the availability of EPA's draft human health and ecological risk assessments for the registration review of formaldehyde and paraformaldehyde and opens a 60-day public comment period on this document.”

Ratification of Security Directives. Federal Register DHS OSPP notice. Summary: “The Department of Homeland Security (DHS) is publishing official notice that the Transportation Security Oversight Board (TSOB) ratified Transportation Security Administration (TSA) Security Directive Pipeline-2021-01C and Security Directive Pipeline-2021-02D, applicable to owners and operators of critical hazardous liquid and natural gas pipeline infrastructure (owner/operators). Security Directive Pipeline-2021-01C, issued on May 22, 2023, extended the requirements of the Security Directive Pipeline-2021-01 series for an additional year. Security Directive Pipeline-2021-02D, issued on July 26, 2023, extended the requirements of the Security Directive Pipeline-2021-02 series for an additional year and amended them to strengthen their effectiveness and address emerging cyber threats.”

Recommendation Regarding Emergency Action in Aviation. Federal Register DHS OSPP notice. Summary: “DHS is publishing official notice that the Transportation Security Oversight Board (TSOB) has recommended to the Transportation Security Administration (TSA) that a cybersecurity emergency exists that warrants TSA's determination to expedite the implementation of critical cyber mitigation measures through the exercise of emergency regulatory authority.”

Siemens Publishes Out-of-Zone Advisory – 4-19-24

Today, ten days after the publication of their monthly tranche of security advisories and updates, Siemens published a control system security advisory that discusses a command injection vulnerability in their RUGGEDCOM APE1808 devices configured with Palo Alto Networks Virtual NGFW. This is a third-party (Palo Alto Networks) vulnerability that is listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog.

Siemens recommends that users disable the GlobalProtect gateway and GlobalProtect portal. They report that that these features are disabled by default in RUGGEDCOM APE1808 deployments. They also recommend that users follow the recommendations in the Palo Alto Networks advisory. There is no mention that the owners of affected Palo Alto Networks products have seen this vulnerability widely exploited.

OMB Approves DOE’s Foreign Entity Final Rule

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a final rule for the DOE on “U.S. Department of Energy Interpretation of Foreign Entity of Concern”. The rule was submitted to OIRA on March 21st, 2024. This rulemaking was not listed in the Fall 2023 Unified Agenda.

This rulemaking will probably be published next week.

OMB Approves EPA’s Methylene Chloride Final Rule

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a final rule for the EPA on “Methylene Chloride (MC); Regulation Under the Toxic Substances Control Act (TSCA)”. The final rule was submitted to OIRA on January 24th, 2024. The notice of proposed rulemaking was published on May 3rd, 2023.

According to the Fall 2023 Unified Agenda entry for this rulemaking:

“On May 5, 2023, EPA proposed a rule under the Toxic Substances Control Act (TSCA)  to address the unreasonable risk of injury to human health from methylene chloride. TSCA requires that EPA address by rule any unreasonable risk of injury to health or the environment identified in a TSCA risk evaluation and apply requirements to the extent necessary so that the chemical no longer presents unreasonable risk. Methylene chloride, also known as dichloromethane, is acutely lethal, a neurotoxicant, a likely human carcinogen, and presents cancer and non-cancer risks following chronic exposures as well as acute risks. Central nervous system depressant effects can result in loss of consciousness and respiratory depression, resulting in irreversible coma, hypoxia, and eventual death, including 85 documented fatalities from 1980 to 2018, a majority of which were occupational fatalities. Nevertheless, methylene chloride is still a widely used solvent in a variety of consumer and commercial applications including adhesives and sealants, automotive products, and paint and coating removers. To address the identified unreasonable risk, EPA proposed to: prohibit the manufacture, processing, and distribution in commerce of methylene chloride for consumer use; prohibit most industrial and commercial uses of methylene chloride; require a workplace chemical protection program (WCPP), which would include a requirement to meet inhalation exposure concentration limits and exposure monitoring for certain continued conditions of use of methylene chloride; require recordkeeping and downstream notification requirements for several conditions of use of methylene chloride; and provide certain time-limited exemptions from requirements for uses of methylene chloride that would otherwise significantly disrupt national security and critical infrastructure. The Agency’s development of this rule incorporated significant stakeholder outreach and public participation, including public webinars and over 40 external meetings as well as required Federalism, Tribal, and Environmental Justice consultations and a Small Businesses Advocacy Review Panel. EPA's risk evaluation, describing the conditions of use is in docket EPA-HQ-OPPT-2019-0437, with the 2022 unreasonable risk determination and additional materials in docket EPA-HQ-OPPT-2016-0742.”

The EPA maintains a methylene chloride risk management web site.

We could see the final rule published in the Federal Register in the next couple of weeks. I do not expect to cover the final rule in any depth, but I will announce its publication on the appropriate ‘Short Takes’ post.


 
/* Use this with templates/template-twocol.html */