Tuesday, December 5, 2017

ICS-CERT Publishes 1 Advisory and 1 Update

Today the DHS ICS-CERT published a control system security advisory for a product from Siemens. It also updated a previously issued advisory for products from Siemens.

Siemens Advisory


This advisory describes an improper input validation vulnerability in the Siemens Industrial Products. The vulnerability was reported by George Lashenko of CyberX. Siemens has produced a firmware update that mitigates the vulnerability. There is no indication that Lashenko was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to conduct a denial-of-service (DoS) attack. The Siemens security advisory notes that the attacker requires network access to the affected devices.

Siemens Update


This update provides additional information for an advisory that was originally published on November 14th, 2017. The new information is updated affected version and mitigation information for:

• SCALANCE W-700 (IEEE 802.11n): All versions prior to V6.2.1

The associated Siemens updated security advisory also provides additional mitigating factors for:

• SCALANCE W-700 devices operated in Access Point;
• RUGGEDCOM RX1400 and RS9xxW;

KRACK Rant


The first vendor has now published a fix for the Key Reinstallation Attack – (KRACK) set of vulnerabilities that make control systems utilizing wireless systems using WPA2 security vulnerable to man-in-the-middle attacks; this is good news. Unfortunately, ICS-CERT still has not issued an alert outlining the extent of the vulnerability to the control system community. Nor have they even provided links to either the KRACK web site or the original paper describing the vulnerabilities. So much for ICS-CERT being interested in keeping the ICS community up to date on wide ranging vulnerabilities.

Bills Introduced – 12-04-17

Yesterday with both the House and Senate back in Washington after a real 2-day weekend break, there were 28 bills introduced. Of those, one may be of specific interest to readers of this blog:

HJ Res 123 Making further continuing appropriations for fiscal year 2018, and for other purposes. Rep. Frelinghuysen, Rodney P. [R-NJ-11]

The official version of this continuing resolution (CR) is currently available. It would extend the current continuing resolution (PL 115-56) from December 8th, 2017 to December 22nd, 2017. It also addresses the lack of funding for the Children’s Health Insurance Program (CHIP) for the first quarter of FY 2018.

The House Rules Committee will meet this afternoon to formulate the rule to consider this bill. It will almost certainly be a closed rule with limited debate and no floor amendments. The bill will be considered on Wednesday to allow the Senate time to take up the bill before the Friday current Friday deadline.


There is a news report that the expiration date on this CR may be changed to December 30th. That change would be addressed in today’s Rules Committee Hearing.

Sunday, December 3, 2017

OMB Approves PHMSA EPC Decision

On Friday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved the DOT’s Pipeline and Hazardous Material Safety Administration (PHMSA) notice on the status of electronically controlled pneumatic (ECP) breaks on highly-hazardous flammable trains (EFFT).

Yes, this is the same notice that was submitted to OIRA on Thursday. Such one-day turnaround of an OIRA approval is highly unusual and typically reflects an impending legal deadline. As I noted last Friday this PHMSA action has a congressionally mandated deadline of December 4th to complete this action. PHMSA will miss that deadline since Monday’s Federal Register has already been published and this notice was not included.


The OIRA notice classifies this as a ‘Pre-Rule’ action. I would have expected it to be classified a ‘Final Rule’ or at least a ‘Notice of Proposed Rule’ designation if this were to be an action to vacate the ECP requirements in 49 CFR 174.310(a)(3)(ii). I suspect that this will be the regulatory impact analysis notice required in §7311(c)(1)(B) of the 2015 FAST Act (PL 114-94). This notice would come with a 30-day public notice requirement before DOT could proceed with any action.

Saturday, December 2, 2017

NIST Mapping Framework Core to NIST SP 800-171

This week the National Institute of Standards and Technology published a new supporting document for the Cybersecurity Framework on the CSF web page. This is a Excel spread sheet mapping CSF Subcategories to NIST SP 800-171, Revision 1, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations.

A disclaimer in spread sheet notes that:

“NIST SP 800-171 focuses on protecting the confidentiality of Controlled Unclassified Information (CUI) in nonfederal systems and organizations, and recommends specific security requirements to achieve that objective. The requirements recommended for use in SP 800-171 are derived from FIPS Publication 200 and the moderate security control baseline in NIST Special Publication 800-53 and are based on the CUI regulation (32 CFR Part 2002, Controlled Unclassified Information). The tailoring criteria applied to the FIPS Publication 200 security requirements and the NIST Special Publication 800-53 security controls is not an endorsement for the elimination of those requirements and controls—rather, the tailoring criteria focuses on the protection of CUI from unauthorized disclosure in nonfederal systems and organizations.”

This is another effort by NIST to expand the usefulness of the CSF.


NOTE: The disclaimer cell in the spread sheet is overly large, making it difficult to see the mapping cells. To be able to see a reasonable number of mapping lines, reduce the height of line 2 of the spread sheet or even hide it.

Public ICS Disclosure – Week of 11-25-17

This week there were two industrial control system vulnerability disclosures on the Full Disclosure web site. They addressed products from Hikvison and CODESYS.

Hikvision Vulnerability


This report by IOT Sec describes a Wi-Fi access vulnerability in Hikvision Wi-Fi IP Cameras installed in a wired configuration. A default wireless SSID exists in the products with a setting of no WiFi encryption or authentication.

This disclosure was coordinated with Hikvision. No fix has been reported but a work around was described.

The disclosure timeline reported by IOT Sec includes an unsuccessful attempt to coordinate the vulnerability with ICS-CERT {as recommended by (US-?)CERT}. While IP cameras are only industrial control systems in the broadest sense, ICS-CERT has posted advisories for these products in the recent past (including some of the specific devices included in this report). I am very surprised that ICS-CERT did not respond to IOT Sec; I would hope that this was due to miscommunications issues, not bureaucratic inaction.

CODESYS Vulnerability



This report by SEC Consult describes an improper authentication vulnerability in the CODESYS WAGO PFC 200 Series. This appears to be an extension of a previously reported vulnerability. ICS-CERT reported on that advisory that it would affect products from as many as 260 other vendors that used the affected code. This disclosure was a coordinated with CODESYS and SEC Consult reports that CODESYS will release a patch next month.

Friday, December 1, 2017

PHMSA Sends ECP Breaking Decision to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received from DOT’s Pipeline and Hazardous Material Safety Administration (PHMSA) their Notice of the Department of Transportation's Decision on ECP Braking for review.

While this was not published in the 2017 Unified Agenda update, it appears that this has been prepared in response to a congressional mandate in 2015 FAST Act (PL 114-94). In §7311 Congress addressed the PHMSA rule {174.310(a)(3)(ii)} on the use of electronically controlled pneumatic (ECP) breaks on highly-hazardous flammable trains (HHFT); requiring additional testing of the efficacy of ECP breaking systems in preventing damage to railcars used to transport crude oil.

While the National Academy of Sciences final letter report was not able to make a conclusive statement “concerning the emergency performance of ECP breaks relative to other breaking systems” (pg ii), congress mandated {§7311(c)(2)} that by December 4th of this year DOT would either publish a notice of why the ECP mandate was justified or, if not justified, repeal the requirement.


It will be interesting to see how the anti-regulatory Trump administration comes down on this decision.

ICS-CERT Publishes 2 Advisories and 3 Updates

Yesterday the DHS ICS-CERT published two control system security updates for products from Geovap and Siemens. They also updated three previously published control system security advisories, all for products from Siemens.

Geovap Advisory


This advisory describes a cross-site scripting vulnerability in the Geovap Reliance SCADA software management platform. The vulnerability was reported by Can Demirel. Geovap has released a new version that mitigates the vulnerability. There is no indication that Demirel has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability to inject arbitrary JavaScript in a specially crafted URL request that may allow for read/write access.

NOTE: The Geovap update notes for this new version would seem to indicate that they also fixed one or more vulnerabilities in the Reliance Smart Client.

Siemens Advisory


This advisory describes multiple vulnerabilities in the Siemens SWT 3000 Teleprotection system. The vulnerabilities are self-reported. Siemens has produced updated firmware that mitigates the vulnerability.

The reported vulnerabilities are:

• Improper authentication (2) - CVE-2016-4784, CVE-2016-4785;
• Authentication bypass using an alternate path or channel (2) - CVE-2016-4785, CVE-2016-7114; and
• Improper input validation - CVE-2016-7113

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to perform a denial-of-service attack. The Siemens security advisory notes that network access to the devices is required for exploitation.

OPC/UA Update


This update provides new information on an advisory that was originally published on 8-31-17 and updated on October 3rd, 2017. The update provides new version information and mitigation measures for:

• SIMATIC IT Production Suite: Versions between V6.5 and V7.1

SIPROTEC Update


This update provides new information on an advisory that was originally published on July 6th, 2017, and updated on July 18th, on July 28th, and then again on October 10th. The update provides new version information and mitigation measures for:

• SIPROTEC 7SD686: All versions prior V4.05

The Siemens updated security advisory explains why there are two separate affected versions for SIPROTEC 7SD686. Versions before 4.05 are affected by vulnerability #6 and versions before 4.03 are also affected by vulnerability #2.

SIMATIC Update


This update provides new information on an advisory that was originally published on February 14th, 2017 and updated on June 15th,  and again on July 6th. The update provides new version information and mitigation measures for:


• SIMATIC IT: All versions prior to V7.1
 
/* Use this with templates/template-twocol.html */