Thursday, August 22, 2024

Review – 4 Advisories and 1 Update Published – 8-22-24

Today, CISA’s NCCIC-ICS published four control system security advisories for products from Avtec Connect, MOBOTIX, and Rockwell Automation (2). They also updated an advisory for products from Mitsubishi.

Advisories

Avtec Advisory - This advisory describes two vulnerabilities in the Avtec Outpost 810 and Outpost Uploader Utility.

MOBOTIX Advisory - This advisory describes an improper neutralization of expression/command delimiters vulnerability in MOBOTIC P3 and MX6 IP cameras.

Rockwell Advisory #1 - This advisory describes an improper input validation vulnerability in the Rockwell 5015 AENFTXT, a part of the FLEXHA 5000 I/O Modules.

Rockwell Advisory #2 - This advisory describes an externally controlled reference to a resource in another sphere vulnerability in the Rockwell Emulate3D Digital Twin technology.

Updates

Mitsubishi Update - This update provides additional information on the MELSEC iQ-R Series advisory that was originally published November 19th, 2020 and most recently updated on December 16th, 2021.

 

For more information on these advisories, and a brief discussion about CISA’s recent change in the link CISA uses to provide additional information on CVE’s, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/4-advisories-and-1-update-published-23b - subscription required.

 

Short Takes – 8-22-24 – Space Geek Edition

An alternative Mars Sample Return program. TheSpaceReview.com article. Pull quote: “So, let’s deal a new deck of cards, abandon the current MSR architecture, and focus MSR on using Starship. The ability of Starship to land on a large planet has already been more extensively demonstrated (that is, a Starship has landed on the Earth) than any of the proposed MSR hardware, which exists only in PowerPoint slides. And the current NASA Artemis plan of record assumes rapid progress in Starship development, including multiple Moon landings.”

Blue Origin’s New Glenn rocket program reportedly faces failures during testing. GeekWire.com article. Pull quote: “No injuries were reported in either incident, according to Bloomberg. One incident was said to involve the crumpling of a section of a New Glenn rocket that was destined for the second launch, in part due to worker error. The other incident reportedly involved an upper rocket portion for the third scheduled launch that failed during stress testing, resulting in an explosion.”

Notice of Commercial Space Transportation Advisory Committee Meeting. Federal Register FAA meeting notice. Background: “The U.S. Department of Transportation created the Commercial Space Transportation Advisory Committee under the Federal Advisory Committee Act (FACA) in accordance with Public Law 92-463. Since its inception, industry-led COMSTAC has provided information, advice, and recommendations to the U.S. Department of Transportation through the FAA regarding technology, business, and policy issues relevant to oversight of the U.S. commercial space transportation sector.” Virtual meeting date: September 16th, 2024.

Against all odds, an asteroid mining company appears to be making headway. ArsTechnica.com article. Pull quote: “After the original vehicle failed vibration testing, which ensures it can survive the rigors of launch, AstroForge decided to bring forward a spacecraft being developed internally for the company's third flight and use that for the Odin mission. To remain on track for a launch this year, the company had to complete vibration testing of the new, 100-kg Odin vehicle by August 1. AstroForge made that deadline but still must complete several other tests before shipping Odin to the launch pad.

Space mining startup AstroForge aims to launch historic asteroid-landing mission in 2025. Space.com article. Pull quote: “AstroForge's second mission, called Odin, is scheduled to launch later this year, as a secondary payload on Intuitive Machines' IM-2 moon mission. Odin will pave the way for Vestri, collecting imagery of the asteroid that Vestri will land on. (AstroForge has not yet announced the identity of the target space rock.)”

Japan's Astroscale wins contract for space junk harvesting robotic arm. TheRegister.com article. Phase II demonstration mission. Pull quote: “That satellite – ADRAS-J2 – will be equipped with a robotic arm to capture and deorbit the rocket parts. The debris [used JAXA H-IIA rocket] is categorized as a non-cooperative object, meaning it does not actively communicate or provide location data and may tumble or move unpredictably.

'Rocket flames began shooting sideways then the sound wave hit'. BBC.com article. Description of recent test-fire catastrophic failure. Pull quote: “The purpose of the test was, he said, was to ignite all nine helix engines simultaneously, make sure they ran in a stable manner and then shut them off in safe and controlled manner.”

Review - FAA Publishes Transport Aircraft Cybersecurity NPRM

Yesterday, the DOT’s Federal Aviation Administration (FAA) published a notice of proposed rulemaking in the Federal Register (89 FR 67564-67572) on “Equipment, Systems, and Network Information Security Protection”. The proposed regulations would replace the current ad hoc cybersecurity requirements that the agency has been implementing on an as needed basis. The preamble notes:

“These changes would introduce type certification and continued airworthiness requirements to protect the equipment, systems, and networks of transport category airplanes, engines, and propellers against intentional unauthorized electronic interactions (IUEI) that could create safety hazards.”

Public Comments

The FAA is soliciting public comments on this proposed rulemaking. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # FAA-2024-1398). Comments should be submitted by October 21st, 2024.

Commentary

One complaint that has come up in the past (see my post on the Hummingbird UA airworthiness final rule, removed from paywall) has been the lack of specificity on the standards. The FAA continues in this rulemaking to provide very generic, vaguely worded cybersecurity standards. In the earlier Hummingbird rule, the FAA responded that:

“The level of detail regarding the assessment of failures and the required protection level of equipment, systems, and networks will be addressed in the means of compliance (MOC) to these airworthiness criteria.”

I am sure that the FAA would have a similar response to complaints about the broad, generic standards proposed in this NPRM.

 

For more details about the provisions of this rulemaking, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/faa-publishes-transport-aircraft - subscription required.

Review - CSB Updates Status on 10 Accident Investigation Recommendations – 8-15-24

Yesterday, the Chemical Safety Board (CSB) updated their “Recent Recommendation Status Updates” web page to reflect status change actions the Board took on August 15th, 2024. Five recommendations were closed with an ‘acceptable response’ or an ‘acceptable alternative response’ status and five remain open with a ‘no response received’ status.

The closed recommendations were:

2011-06-I-HI-R4, Donaldson Enterprises, Inc. Fatal Fireworks Disassembly Explosion and Fire, Hawaii Dept of Treasury,

2021-02-I-WV-R10, Optima Belle LLC Explosion and Fire, Richman Chemical Inc. (RCI),

2019-04-I-PA-R2, Philadelphia Energy Solutions (PES) Refinery Fire and Explosion, US EPA,

2020-02-I-TX-R4, TPC Port Neches Explosions and Fire, American Chemistry Council (ACC), and

2020-02-I-TX-R5, TPC Port Neches Explosions and Fire, American Chemistry Council (ACC),

 

For more information on the actions that led to the Boards updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/csb-updates-status-on-10-accident - subscription required.

Wednesday, August 21, 2024

CISA Adds 2 IP Camera Vulnerabilities to KEV Catalog – 8-21-24

Today, CISA announced that it had added four vulnerabilities to their Known Exploited Vulnerabilities (KEV) Catalog. These vulnerabilities included two authentication bypass vulnerabilities (CVE-2021-33044 and CVE-2021-33045) for 19 different Dahua Security IP cameras. The vulnerabilities were publicly disclosed (with proof-of-concept code) by bashis on October 6th, 2021. That disclosure was a coordinated disclosure with Dahau reportedly having a new firmware version available that mitigated the two vulnerabilities.

CISA noted in their announcement that:

Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.”

Review - HR 8065 Introduced – NASA Cybersecurity

Last month, Rep Frost (D,FL) introduced HR 8065, the Spacecraft Cybersecurity Act. The bill would require NASA acquisition processes to include guidelines and controls for managing cybersecurity risks. No new funding would be authorized by this bill.

Moving Forward

Frost is a member of the House Science, Space, and Technology Committee to which this bill was assigned for consideration. This means that there may be sufficient influence to see the bill considered in Committee. I see nothing in this bill that would engender any organized opposition. I suspect that there would be bipartisan support for the bill to be approved in Committee. There should be sufficient support for it to move to the floor of the House under the suspension of the rules process.

 

For more information on the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-8065-introduced - subscription required.

 

BIS Sends ICTS Connected Vehicle NPRM to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking (NPRM) from the DOC’s Bureau of Industry and Security (BIS) on “Securing the Information and Communications Technology and Services Supply Chain: Connected Vehicles”. BIS published [removed from paywall] an advanced notice of proposed rulemaking (ANPRM) on this topic on March 1st, 2024.

According to the Spring 2024 Unified Agenda entry for this rulemaking:

“The Department of Commerce’s Bureau of Industry and Security (BIS) published an advance notice of proposed rulemaking (ANPRM) on March 1, 2024, to seek public comment on questions related to transactions involving information and communications technology and services integral to connected vehicles that are designed, developed, manufactured, or supplied by persons owned, controlled, or subject to the jurisdiction or direction of foreign countries or foreign non-government persons identified at 15 CFR 7.4, pursuant to Executive Order (E.O.) 13873. BIS is reviewing comments and working to implement a proposed rule to assist BIS in better determining the technologies and market participants most appropriate for regulation pursuant to E.O. 13873 [link added] regarding connected vehicles.”

 
/* Use this with templates/template-twocol.html */