This week, the Congressional Research Service (CRS)
published a report on “The Congressional Review Act: Defining a “Rule” and Overturning
a Rule an Agency Did Not Submit to Congress”. The 118th Congress has
been fairly active in submitting and passing bills to overturn agency actions.
This report outlines the processes under the Congressional Review Act (5 USC
801 thru 808) for overturing agency actions, specifically it discusses the process
for congressional action in the small number of cases where the agency does not
pre-submit a copy of a rule to Congress.
Saturday, April 20, 2024
CRS Reports – Week of 4-13-24 – Congressional Disapproval
Transportation Chemical Incidents – Week of 3-16-24
Reporting Background
See this post for explanation, with an update here (removed from paywall).
Data from PHMSA’s online database of transportation related chemical incidents that have been reported to the agency.
Incidents Summary
• Number of incidents – 470 (460
highway, 9 air, 1 rail)
• Serious incidents – 4 (3 Bulk
release, 0 injuries, 0 deaths, 3 major arteries closed)
• Largest container involved – 30190-gal
DOT DOT117R100W railcar (Alcohols, N.O.S.), improperly tightened bolts on
manway cover. 5-gal spilled.
• Largest amount spilled – 440-lbs (Calcium Hypochlorite, Hydrated or Calcium Hypochlorite, Hydrated Mixtures, With Not Less Than 5.5% But Not More Than 16% Water) plastic container damaged in material handling.
Most Interesting Chemical: Tetrahydrofuran: Used as a
solvent. A clear colorless liquid with an ethereal odor. Less dense than water.
Flash point 6°F. Vapors are heavier than air. May form explosive peroxides when
exposed to air, may be stabilized with butylated hydroxytoluene (BHT) to prevent
the formation of peroxides. Involved in four incidents in the covered week.
Review – Public ICS Disclosures – Week of 4-13-24
This week we have nine vendor disclosures from Hitachi, HPE (4), Peplink, Philips, and Rockwell (2). There are also five vendor updates from B&R (2), Contec, HPE, and Palo Alto Networks. We also have eleven researcher reports about vulnerabilities in products from Elber (10) and Silicon Labs. Finally, we have two exploits for products from Palo Alto Networks.
NOTE: HP reports that they have an update for their NVIDIA GPU Display Driver advisory that was originally published on March 12th, 2024, but the link currently goes to a blank page.
Advisories
Hitachi Advisory - Hitachi published an
advisory that discusses an allocation of resources without limit or
throttling vulnerability in their JP1 product.
HPE Advisory #1 - HPE published an
advisory that discusses an out-of-bounds write vulnerability in their Superdome
Flex, Superdome Flex 280 and Compute Scale-up Server 3200 Servers.
HPE Advisory #2 - HPE published an
advisory that discusses an improper restriction of operations within the
bounds of a memory buffer vulnerability in their Compute Scale-up Server 3200
server.
HPE Advisory #3 - HPE published an
advisory that discusses five vulnerabilities (three with exploits available)
in their Telco IP Mediation E-Media product.
HPE Advisory #4 - HPE published an
advisory that describes an insertion of sensitive information into a
logfile vulnerability in their Compute Scale-up Server 3200 Server.
Peplink Advisory - Peplink published an advisory that describes five vulnerabilities in
their Smart Reader access control product.
Philips Advisory - Philips published an advisory
that discusses a CISA report
of a compromise of Sisense Customer Data.
Rockwell Advisory #1 - Rockwell published an
advisory that describes an improper input validation vulnerability in their
5015-AENFTXT product.
Rockwell Advisory #2 - Rockwell published an advisory that discusses a deserialization of untrusted data vulnerability {listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog} in their FactoryTalk Production Centre product.
Updates
B&R Update #1 - B&R published an
update for their Docker Engine advisory that was originally published on
April 10th, 2024.
B&R Update #2 - B&R published an
update for their LOGO Fail advisory that was originally published on April
11th, 2024.
Contec Update - JP-CERT published an update for their
SolarView Compact advisory that was originally published on June 9th,
2022 and most recently updated on February 10th, 2023.
HPE Update - HPE published an
update for their Superdome Flex advisory that was originally published on
January 23rd, 2024 and most recently updated on March 8th,
2024.
Palo Alto Networks Update - Palo Alto Networks published an update for their PAN OS command injection advisory that was originally published on March 12th, 2024.
Researcher Reports
Elber Report #1 - Zero Science published two reports of vulnerabilities in the
Elber Signum DVB-S/S2 controller for satellite equipment.
Elber Report #2 - Zero Science published two reports of vulnerabilities in the
Elber Cleber/3 Broadcast Multi-Purpose Platform.
Elber Report #3 - Zero Science published two reports of vulnerabilities in the
Elber Reble610 M/ODU XPIC IP-ASI-SDH Microwave Link.
Elber Report #4 - Zero Science published two reports of vulnerabilities in the
Elber DVB-S/S2 Satellite Receiver. Microwave Link.
Elber Report #5 - Zero Science published two reports of vulnerabilities in the
Elber Wayber Analog/Digital Audio STL.
Silicon Labs Report - Talos published a report about a NULL pointer dereference vulnerability in the Silicon Labs Gecko Platform software design kit.
Exploits
Palo Alto Networks Exploit #1 - H4x0r-dz published an
exploit for a command injection vulnerability in the Palo Alto Networks PAN-OS.
Palo Alto Networks Exploit #2 - W01fh4cker published an
exploit for a command injection vulnerability in the Palo Alto Networks PAN-OS.
For more details about these disclosures, including links to
researcher report, 3rd party advisories and exploits, see my article
at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-ac1
- subscription required.
Friday, April 19, 2024
Short Takes – 4-19-24
The Trump Jury Has a Doxing Problem. Wired.com article. To be fair, should read ‘… Potential Doxing Problem’. Pull quote: “Armed with basic personal details about jurors and certain tools and databases, “an OSINT researcher could potentially uncover a significant amount of personal information by cross-referencing all this together,” Diachenko says. “That's why it's crucial to consider the implications of publicly revealing jurors' personal information and take steps to protect their privacy during criminal trials.””
The great commercial takeover of low Earth orbit. TechnologyReview.com article. Lengthy article, lots of interesting information. Pull quote: ““Within two to three years, I could send a graduate student to space with Axiom,” Ekblaw says. “It requires a little creative fundraising, but I think that that is opening up a realm of possibility.” In the past, she explains, a doctoral researcher would be unbelievably fortunate to have research fly as part of a single flight mission.Today, however, researchers even in a master’s program can fly experiments repeatedly because of the increased opportunities afforded by commercial spaceflight.In the future, rather than relying on career NASA astronauts—who have myriad responsibilities in orbit and spend a good amount of time as guinea pigs themselves—scientists could go up personally to run their own research projects in greater depth.”
Notice Pesticide Registration Review; Draft Human Health and Ecological Risk Assessments for Formaldehyde and Paraformaldehyde; Notice of Availability. Federal Register EPA notice. Summary: “This notice announces the availability of EPA's draft human health and ecological risk assessments for the registration review of formaldehyde and paraformaldehyde and opens a 60-day public comment period on this document.”
Ratification of Security Directives. Federal Register DHS OSPP notice. Summary: “The Department of Homeland Security (DHS) is publishing official notice that the Transportation Security Oversight Board (TSOB) ratified Transportation Security Administration (TSA) Security Directive Pipeline-2021-01C and Security Directive Pipeline-2021-02D, applicable to owners and operators of critical hazardous liquid and natural gas pipeline infrastructure (owner/operators). Security Directive Pipeline-2021-01C, issued on May 22, 2023, extended the requirements of the Security Directive Pipeline-2021-01 series for an additional year. Security Directive Pipeline-2021-02D, issued on July 26, 2023, extended the requirements of the Security Directive Pipeline-2021-02 series for an additional year and amended them to strengthen their effectiveness and address emerging cyber threats.”
Recommendation Regarding Emergency Action in Aviation.
Federal Register DHS OSPP notice.
Summary: “DHS is publishing official notice that the Transportation Security
Oversight Board (TSOB) has recommended to the Transportation Security
Administration (TSA) that a cybersecurity emergency exists that warrants TSA's
determination to expedite the implementation of critical cyber mitigation
measures through the exercise of emergency regulatory authority.”
Siemens Publishes Out-of-Zone Advisory – 4-19-24
Today, ten days after the publication of their monthly tranche of security advisories and updates, Siemens published a control system security advisory that discusses a command injection vulnerability in their RUGGEDCOM APE1808 devices configured with Palo Alto Networks Virtual NGFW. This is a third-party (Palo Alto Networks) vulnerability that is listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog.
Siemens recommends that users disable the GlobalProtect
gateway and GlobalProtect portal. They report that that these features are
disabled by default in RUGGEDCOM APE1808 deployments. They also recommend that
users follow the recommendations in the Palo Alto Networks advisory. There
is no mention that the owners of affected Palo Alto Networks products have seen
this vulnerability widely exploited.
OMB Approves DOE’s Foreign Entity Final Rule
Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a final rule for the DOE on “U.S. Department of Energy Interpretation of Foreign Entity of Concern”. The rule was submitted to OIRA on March 21st, 2024. This rulemaking was not listed in the Fall 2023 Unified Agenda.
This rulemaking will probably be published next week.
OMB Approves EPA’s Methylene Chloride Final Rule
Yesterday, the OMB’s Office of Information and Regulatory
Affairs (OIRA) announced
that it had approved a final rule for the EPA on “Methylene Chloride (MC);
Regulation Under the Toxic Substances Control Act (TSCA)”. The final rule was
submitted to OIRA on January 24th, 2024. The notice of proposed
rulemaking was
published on May 3rd, 2023.
According to the Fall 2023 Unified Agenda entry for this rulemaking:
“On May 5, 2023, EPA proposed a rule under the Toxic Substances Control Act (TSCA) to address the unreasonable risk of injury to human health from methylene chloride. TSCA requires that EPA address by rule any unreasonable risk of injury to health or the environment identified in a TSCA risk evaluation and apply requirements to the extent necessary so that the chemical no longer presents unreasonable risk. Methylene chloride, also known as dichloromethane, is acutely lethal, a neurotoxicant, a likely human carcinogen, and presents cancer and non-cancer risks following chronic exposures as well as acute risks. Central nervous system depressant effects can result in loss of consciousness and respiratory depression, resulting in irreversible coma, hypoxia, and eventual death, including 85 documented fatalities from 1980 to 2018, a majority of which were occupational fatalities. Nevertheless, methylene chloride is still a widely used solvent in a variety of consumer and commercial applications including adhesives and sealants, automotive products, and paint and coating removers. To address the identified unreasonable risk, EPA proposed to: prohibit the manufacture, processing, and distribution in commerce of methylene chloride for consumer use; prohibit most industrial and commercial uses of methylene chloride; require a workplace chemical protection program (WCPP), which would include a requirement to meet inhalation exposure concentration limits and exposure monitoring for certain continued conditions of use of methylene chloride; require recordkeeping and downstream notification requirements for several conditions of use of methylene chloride; and provide certain time-limited exemptions from requirements for uses of methylene chloride that would otherwise significantly disrupt national security and critical infrastructure. The Agency’s development of this rule incorporated significant stakeholder outreach and public participation, including public webinars and over 40 external meetings as well as required Federalism, Tribal, and Environmental Justice consultations and a Small Businesses Advocacy Review Panel. EPA's risk evaluation, describing the conditions of use is in docket EPA-HQ-OPPT-2019-0437, with the 2022 unreasonable risk determination and additional materials in docket EPA-HQ-OPPT-2016-0742.”
The EPA maintains a methylene chloride risk management web site.
We could see the final rule published in the Federal
Register in the next couple of weeks. I do not expect to cover the final rule
in any depth, but I will announce its publication on the appropriate ‘Short
Takes’ post.
