Thursday, May 4, 2017

ICS-CERT Publishes 4 Advisories

Today the DHS ICS-CERT published 4 control system security advisories for products from Rockwell, Advantech, Dahua Technology and Hikvision. The Rockwell advisory was previously published on the NCCIC Portal on April 4, 2017.

ICS-CERT also published the latest version of their ICS-CERT Monitor. Not worth reviewing, but it is out there.

Rockwell Advisory


This advisory describes a resource exhaustion vulnerability in Rockwell ControlLogic and CompactLogic controllers. This vulnerability was apparently self-reported. Rockwell has provided updated versions to mitigate the vulnerability.

ICS-CERT reports that an uncharacterized attacker could remotely exploit the vulnerability to cause the device that the attacker is accessing to become unavailable.

Advantech Advisory


This advisory describes an absolute path traversal vulnerability in the Advantech WebAccess. The vulnerability was reported by Zhou Yu via ZDI. Advantech has produced a new version to mitigate the vulnerability. ICS-CERT reports that Yu has verified the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to traverse the file system and gain access to files or directories, which could result in the device becoming unavailable.

Dahua Technology Advisory


This advisory describes two password vulnerabilities in the Dahua Digital Video Recorders and IP Cameras. Bashis disclosed these vulnerabilities without coordination with ICS-CERT (see Brian Krebs and ThreatPost articles for more information).

The two reported vulnerabilities are:

• Use of password hash instead of password for authentication - CVE-2017-7927; and
• Password in configuration file - CVE-2017-7925

ICS-CERT reports that a relatively low skilled attacker could use publicly available exploits to remotely exploit the vulnerabilities to allow the attacker to obtain user credentials, including password hashes, and use these credentials to bypass authentication.

Hikvision Advisory


This advisory describes two password vulnerabilities in the Hikvision cameras. The vulnerability was reported by IPcamtalk user “Montecrypto”. Hikvision has published a new version to mitigate one of the two vulnerabilities. There is no indication that Montecrypto was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper authentication - CVE-2017-7921; and
• Password in configuration file - CVE-2017-7923

In Passing



Please remember that when ICS-CERT publishes their 2017 stats that they will almost certainly include the Dahua and Hikvision vulnerabilities in their count of control system advisories for the year.

House Passes HR 244 – FY 2017 Spending

After a nearly party-line vote on the resolution adopting the rule for consideration of  HR 244, the House passed the Consolidated Appropriations Act, 2017 by a bipartisan vote of 309 to 118 (with 103 Republicans voting Nay). The Democratic opposition to the rule vote was an attempt to open consideration of HR 244 to the amendment process on the floor of the House.

Cybersecurity


The rule for consideration of HR 244 also added a new division to HR 244. The new Division N is the Intelligence Authorization Act for Fiscal Year 2017. As I have mentioned on a couple of occasions the House has passed various versions of this bill in both the 114th and 115th Congress, but the Senate has not taken up any version of this bill.

The version now included in HR 244 does not include any specific cybersecurity provisions beyond a reporting requirement; Sec. 614. Report on cybersecurity threats to seaports of the United States and maritime shipping. I have previously discussed this provision on a couple of occasions, the most recently here.

Moving Forward



The Senate is scheduled to debate HR 244 today and vote on cloture on Friday morning. The current plan for consideration in the Senate does not include a floor amendment process.

Tuesday, May 2, 2017

ICS-CERT Publishes 3 Advisories

Today the DHS ICS-CERT published three control system security advisories for products from Advantech, CyberVision and Schneider.

Advantech Advisory


This advisory describes a client-side authentication vulnerability in the Advantech B+B SmartWorx MESR901. The vulnerability was originally reported by Maxim Rupp. ICS-CERT reports that Advantech is unable to provide mitigations for this product and is working to replace the product with a new model.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to bypass authentication and access restricted pages.

CyberVision Advisory


This advisory describes a code injection vulnerability in the CyberVision Kaa IoT Platform. The vulnerability was reported Jacob Baines from Tenable Network Security. ICS-CERT reports that CyberVision has been unresponsive to multiple contact requests and has produced no mitigations for this vulnerability.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to allow for the creation of files with custom content, movement of files, and execution of arbitrary OS commands.

Schneider Advisory


This advisory describes an Improper XML Parser Configuration in the Schneider Wonderware Historian Client. The vulnerability was reported by Andrey Zhukov from USSC. Schneider has an update that mitigates the vulnerability. ICS-CERT reports that Zhukov has verified the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker (no discussion of access requirements) to cause denial of service of trend display or to disclose arbitrary files from the local file system to a malicious web site. The Wonderware Security Bulletin reports that a social engineering attack would be required to get an authorized user to load a malicious XML settings file.

Commentary


At this late date it is very disconcerting to see two ICS-CERT advisories reporting that vendors are not fixing reported vulnerabilities. I am disappointed in not seeing ICS-CERT report why Advantech is choosing to not fix their SmartWorx MESR901. I suspect that this is an end-of-life issue, but the product is still being actively advertised on the Advantech web site.


More disturbing is the failure of CyberVision to even respond to ICS-CERT about the reported vulnerability. The Kaa project is advertised as an open-source IOT platform. We have enough problems with IOT security issues without having people acknowledge and try to fix specifically identified security issues with their product.

ISCD Updates Another FAQ

Today the DHS Infrastructure Security Compliance Division (ISCD) updated the response to one of the frequently asked questions (FAQ) on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center. The FAQ in question was:


This is a complete re-write to the FAQ response, but very little information was actually changed. The two most important changes were the addition of links to three different sections of the CFATS regulations and a change to the name of the person to whom letters requesting determinations should be sent. The original FAQ response showed Amy Graydon as the acting Director of ISCD, that has long since changed to David Wulf as the Director.


This points out a common problem that is seen frequently in the FAQ responses. The addresses given in the various FAQs should only include position titles, not the name of the person currently holding that position. That way the FAQ’s do not need to be updated when personnel change.

HR 244 – DHS Spending

This is the second in a short series of blog posts about HR 244, the Consolidated Appropriations Act, 2017. The initial post in the series was:


This post deals with Division F of the bill, the Department of Homeland Security Appropriations Act, 2017. This Division is generally based upon the earlier appropriations bills from 114th Congress (HR 5634 and S 3001). As is typical with DHS appropriations bill, the programs of specific interest to readers of this blog do not draw much in the way of specific mention in the actual spending bill (or Division F in this instance). To gather much in the way of information we have to look at the Explanatory Statement for Division F, that effectively updates the Committee reports on the earlier bills.

Cybersecurity


Cybersecurity is now a major reporting category under Title III, Protection, Preparedness, Response, And Recovery, under the National Preparedness and Programs Directorate. Table 1 below lays out the cybersecurity operations and support funding outlined on pages 40-41. The CERT figures probably include ICS-CERT and are part of the NCCIC funding.


Budget Estimate
Final Bill
Cyber Readiness


NCCIC Operations
$116,168,000
$108,402,000
(CERT)
(94,134,000)
(86,368,000)
NCCIC Planning
92,683,000
88,502,000
(CERT)
(65,788,000)
(61,607,000)
Cyber Infrastructure


Cybersecurity Advisors
13,535,000
12,970,000
Enhanced Cybersecurity Services
16,830,000
16,950,000
Cybersecurity Education and Awareness
7,886,000
14,133,000
Federal Cybersecurity
435,235,000
428,457,000
Total
$682,340,000
$669,414,000
Table 1: Cybersecurity Spending

The budget numbers are from the Trump budget. The breakout from the last Obama budget does not track well with these categories so it is not reasonable to try to compare the two sets of numbers. Even where there are similar category titles (CERT Operations for example) it is not necessarily the same set of budget numbers.

There are no specific control system security related comments in the Explanatory Statement. This is somewhat disappointing since the Senate Report on S3001 that noted (pg 98) increased spending (+$5 Million) on the ICS-CERT ‘Training and Assessment’ account. I suspect that there will still be an increase, but how much of that earlier amount remains to be seen.

Chemical Security


Again, the Chemical Facility Anti-Terrorism Standards (CFATS) program is not large enough to be mentioned in HR 244. It does get a line item in the Explanatory Statement and the numbers do mesh from the previous bills; see Table 2.


Obama Budget
Trump Budget
Final
Infrastructure Security Compliance
$78,667,000
$76,876,000
$69,557,000
Table 2: Chemical Security

There is no explanation why the negotiators reduced the CFATS program spending to levels below the $72 Million found in both of the earlier House and Senate Reports. Congress has had problems recently with ISCD being able to fill the authorized Chemical Security Inspector slots, but that may not explain this decrease; it may simply be cutting minor programs to provide money’s for increasing other programs.

Surface Transportation


Surface transportation security falls under two different agencies in DHS. The Coast Guard deals with the security of water transportation and its related land based facilities under the Maritime Transportation Security Act (MTSA). There is no mention of that program in either HR 244 or the Explanatory Statement. On the government side this is a very inexpensive program (relatively speaking).

The TSA is responsible for all of the other very limited DHS surface transportation security programs. For purposes of this blog, this includes pipeline, rail and truck transportation security. There is just a single line item to cover all of the TSA surface transportation security spending:


Obama Budget
Trump Budget
Final
Surface Transportation Security
$122,716,000
$122,716,000
$122,716,000
Table 3: Surface Transportation Security


It really looks like everyone is just marking time on TSA surface transportation operations. Kind of scary looking at the history of attacks on surface transportation across the world.

Monday, May 1, 2017

Committee Hearings – Week of 4-20-17

With it looking like the FY 2017 spending issue is fixed the House and Senate start to expand their work agenda with many hearings scheduled this week. Three of these may be of specific interest to readers this week; hearings concerning cybersecurity, maritime regulations, and EMP.

Cybersecurity


The House Science, Space, and Technology committee will hold a markup hearing on HR 2105, the NIST Small Business Cybersecurity Act of 2017. I did not cover HR 2105 because it sadly does not address control system security issues. Maybe this markup will change that.

Maritime Regulations


The Coast Guard and Maritime Transportation Subcommittee of the House Transportation and Infrastructure Committee will hold a hearing on “Maritime Transportation Regulatory Issues”. The witness list includes:

• Paul F. Thomas, United States Coast Guard
• Michael A. Khouri, Federal Maritime Commission
• Todd Schauer, American Salvage Association
• Steven Candito, National Response Corporation
• Nicholas Nedeau, Rapid Ocean Response Corporation
• Norman “Buddy” Custard, Alaska Maritime Prevention and Response Network
• Thomas Allegretti, American Waterways Operators
• Peter Ford, Ports America
• John Butler, World Shipping Council


We might see some discussion on pending regulatory issues related to MTSA, chemical transportation safety and cybersecurity. Do not expect much in the way of details.

EMP Policy


The Senate Energy and Natural Resources Committee will be holding a hearing on the threat posed by electromagnetic pulse and policy options to protect energy infrastructure and to improve capabilities for adequate system restoration. A witness list is not yet available.


HR 244 – FY 2017 Continuing Resolution

News reports (here for example) last night indicate that Congressional negotiators had reached agreement on a final spending bill for the remainder of FY 2017. A quick look at the House Rules Committee web page show that HR 244, the Hire Vets Act, is going to be used as the vehicle for the Consolidated Appropriations Act, 2017.

The 1665-page text of the revised bill can be found here. More importantly, for detailed explanations of the provisions of the bill the Rules Committee has provided links to the explanatory statements for each of the Divisions of the bill. The Division of specific interest to readers of this bill (with link to the explanatory statement) are:

• Department of Defense Appropriations ACT, 2017 (Division C)
• Department of Homeland Security Appropriations Act, 2017 (Division F)
• Transportation, Housing and Urban Development, and Related Agencies Appropriations Act, 2017 (Division K)

These explanatory notes contain a huge number of references back to House and Senate comments on the bill. These refer back to 114th Congress Committee Reports on the original appropriations bills that form the basis for each of the Divisions. I have previously commented on some of those spending bill reports when there were items of specific interest (see the table below), where I have not, I am providing links to the report.


House
Senate
DOD
DHS
THAD


The Rules Committee is scheduled to meet on HR 244 on Tuesday to develop the rule for the consideration of this bill. Since the negotiations have been so involved, there is no chance that the Rules Committee will provide for anything but a closed rule on this bill. There will be limited debate (probably 1 hour) and no amendments authorized. The final House vote on the bill will probably come Wednesday and the Senate on Thursday. If things go well (an increasingly big IF) this should get to the President well before the Midnight Friday deadline.


More on specific provisions in later posts…. It is a lot of reading.
 
/* Use this with templates/template-twocol.html */