Saturday, September 21, 2024

Bills Introduced – 9-20-21

Yesterday, with just the House in session, there were 40 bills introduced. Two of those bills will receive additional attention in this blog:

HR 9720 To direct the Director of the National Institute of Standards and Technology to update the national vulnerability database to reflect vulnerabilities to artificial intelligence systems, study the need for voluntary reporting related to artificial intelligence security and safety incidents, and for other purposes. Ross, Deborah K. [Rep.-D-NC-2]

HR 9737 To improve the tracking and processing of security and safety incidents and risks associated with artificial intelligence, and for other purposes. Ross, Deborah K. [Rep.-D-NC-2]

Review – Public ICS Disclosures – Week of 9-14-24

This week we have 16 vendor disclosures from CIRCUTOR, Dell, Dassault Systems (2), GE Vernova, Hitachi, HP (2), Moxa, Philips (3), SEL, Softing, Supermicro, and VMware. There are also two updates from HPE and Moxa. Finally, we also have six researcher reports for products from OpenPLC (3), Riello, and Supermicro (2).

Advisories

CIRCUTOR Advisory - Incibe-CERT published an advisory that describes six vulnerabilities in the CIRCUTOR Q-SMT and TCP2RS+ substation equipment.

Dell Advisory - Dell published an advisory that discusses seven vulnerabilities (three with publicly available exploits) in their ThinOS products.

Dassault Systems Advisory #1 - Dassault Systems published an advisory that describes a cross-site scripting vulnerability in their 3DEXPERIENCE product.

Dassault Systems Advisory #2 - Dassault Systems published an advisory that describes a cross-site scripting vulnerability in their 3DEXPERIENCE product.

GE Vernova Advisory - GE Vernova published an advisory that describes six vulnerabilities in their ControlST platform.

HPE Advisory #1 - HPE published an advisory that discusses five vulnerabilities in their StoreEasy Servers.

HPE Advisory #2 - HPE published an advisory that describes three vulnerabilities in their Aruba Networking Controller and Gateway-Based AOS.

Moxa Advisory - Moxa published an advisory that describes three vulnerabilities in their MXview One and MXview One Central Manager Series.

Philips Advisory #1 - Philips published an advisory that discusses the recent Fortinet breach.

Philips Advisory #2 - Philips published an advisory that discusses the recent VMware vulnerabilities.

Philips Advisory #3 - Philips published an advisory that discusses the recent Windows Update Downgrade Attack Advisory.

SEL Advisory - SEL published a version update notice for their SEL-5032 acSELerator Architect Software.

Softing Advisory - Softing published an advisory that describes a missing release of memory vulnerability in their uaToolkit Embedded and smartLink products.

Supermicro Advisory - Supermicro published an advisory that discusses two vulnerabilities in their Denverton platform.

VMware Advisory - VMware published an advisory that describes two vulnerabilities in their vCenter Server.

Updates

HPE Update - HPE published an update for their HPE ProLiant DL/ML/XL, Synergy, and Edgeline Servers advisory that was originally published on September 16th, 2024.

Moxa Update - Moxa published an update for their  regreSSHion vulnerability advisory that was originally published on August 2nd, 2024 and most recently updated on September 10th, 2024.

Researcher Reports

OpenPLC Report #1 - Talos published a report that describes a stack-based buffer overflow vulnerability in the OpenPLC OpenPLC _v3.

OpenPLC Report #2 - Talos published a report that describes two out-of-bounds read vulnerabilities in the OpenPLC OpenPLC _v3.

OpenPLC Report #3 - Talos published a report that describes two incorrect type or cast vulnerabilities in the OpenPLC OpenPLC _v3.

Riello Report - CyberDanube published a report describing two vulnerabilities in the Riello Netman 204 network communications card.

Supermicro Report #1 - Binarly published a report that describes a use of hard-coded credentials vulnerability in the Supermicro BMC Firmware.

Supermicro Report #2 - Binarly published a report that describes an insecure RSA signing key used in multiple Supermicro servers.

 

For more details about these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-9-ed6 - subscription required.

Friday, September 20, 2024

Short Takes – 9-20-24

This Windows PowerShell Phish Has Scary Potential. KrebsOnSecurity.com article. Pull quote: “Still, it wouldn’t hurt to share this article with the Windows users in your life who fit the less-savvy profile. Because this particular scam has a great deal of room for growth and creativity.”

Flu season is coming—and so is the risk of an all-new bird flu. TechnologyReview.com article. Pull quote: “Even if every farm worker were to be vaccinated, not all of them would be fully protected against getting sick with flu. The flu vaccine used in the US in 2019-2020 was 39% effective, but the one used in the 2004-2005 flu season was only 10% effective.”

5 people displaced from accidental fire caused by combustible potting soil. WUSA9.com article. Pull quote: ““Spontaneous combustion can happen when a decomposing, organic material, such as mulch or potting soil, generates enough heat to ignite without an outside source,” said Assistant Chief of Operations James Williams. “As a result, a large or compacted area of these materials can create sufficient heat to spontaneously combust."”

Health care worker is third person to become ill after contact with Missouri patient who had bird flu. CNN.com article. Pull quote: ““It is imperative that we identify any and all cattle herds that may have H5 in all states,” she said. “It is ridiculous that this information is still not known this many months after the first cattle cases were identified.””

HR 9469 Introduced – TSA Pipeline Security

Earlier this month, Rep Garcia (D,CA) introduced HR 9469, the Pipeline Security Act. The bill would amend 49 USC 114 to specifically add pipeline security to the list of responsibilities of the Transportation Security Administration. No new funding is authorized by this legislation.

Moving Forward

Garcia is a member of the House Homeland Security Committee to which this bill was assigned for consideration. This means that there could be sufficient influence to see the bill considered in Committee. There will be some Republican opposition to the call for security directives or regulations for pipeline security, but I suspect that there will be at least some level of bipartisan support for the bill. Unfortunately, this late in the session, the bill is not likely to be considered.

Commentary

The reality is that this bill is going to codify responsibility for actions that TSA is already taking. Even the security directive and regulation section would not require TSA to take any actions beyond that which it has already taken. Bills such as this, however, are important in that they provide a legal backstop for charges that the agency has exceeded its authority. The current authority under §114 is broadly written and could be argued to support the agencies security directives and current rulemaking process. This would make that argument unnecessary.


For more information on the provisions of the legislation, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-9469-introduced - subscription required.


Bills Introduced – 9-20-24

Yesterday, with both the House and Senate in session, there were 91 bills introduced. One of those bills will receive additional coverage in this blog:

HR 9689 To amend the Homeland Security Act of 2002 to establish a DHS Cybersecurity Internship Program, and for other purposes. Clarke, Yvette D. [Rep.-D-NY-9]

Transportation Chemical Incidents – Week of 8-17-24

Reporting Background

See this post for explanation, with the most recent update here (removed from paywall).

Data from PHMSA’s online database of transportation related chemical incidents that have been reported to the agency.

Incidents Summary

• Number of incidents – 637 (589 highway, 43 air, 4 rail, 1 water)

• Serious incidents – 2 (1 Bulk release, 0 evacuation, 1 injury, 0 death, 1 major artery closed, 0 fire/explosion, 44 no release)

• Largest container involved – 23,740-gal DOT 111A100W3 Railcar {Elevated Temperature Liquid, N.O.S., At Or Above 100 C And Below Its Flash Point} Improperly secured manway cover.

• Largest amount spilled – 250-gal DOT 406 Trailer {Gasoline Includes Gasoline Mixed With Ethyl Alcohol, With Not More Than 10% Alcohol} Overfilled.

Most Interesting Chemical: Dichloroisocyanuric Acid, Dry Dichloroisocyanuric acid, solid is a white crystalline solid with an odor of chlorine. The material itself is noncombustible but if contaminated with a combustible material ignition can result. It will accelerate the burning of combustible materials. Contact with ammonium compounds or hydrated salts can cause a very vigorous chemical reaction. It may vigorously react with small quantities of water releasing chlorine gas.  (Source: CameoChemicals.NOAA.gov).

 



OMB Approves BIS Connected Vehicle NPRM

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice of proposed rulemaking (NPRM) on “Securing the Information and Communications Technology and Services Supply Chain: Connected Vehicles”. The proposed rule was sent to OIRA on August 20th, 2024. An advanced notice of proposed rulemaking (ANPRM) on this topic was published [removed from paywall] March 1st, 2024.

According to the Spring 2024 Unified Agenda entry for this rulemaking:

“The Department of Commerce’s Bureau of Industry and Security (BIS) published an advance notice of proposed rulemaking (ANPRM) on March 1, 2024, to seek public comment on questions related to transactions involving information and communications technology and services integral to connected vehicles that are designed, developed, manufactured, or supplied by persons owned, controlled, or subject to the jurisdiction or direction of foreign countries or foreign non-government persons identified at 15 CFR 7.4, pursuant to Executive Order (E.O.) 13873. BIS is reviewing comments and working to implement a proposed rule to assist BIS in better determining the technologies and market participants most appropriate for regulation pursuant to E.O. 13873 regarding connected vehicles.”

I will probably not be covering this rulemaking in any detail. At the very least I will mention its publication in the next week or two in the appropriate Short Takes post.

 
/* Use this with templates/template-twocol.html */