Thursday, August 8, 2019

1 Update Published – 08-08-19


Today the DHS NCCIC-ICS published an update for a previously issued control system security advisory for products from Wind River.

The update provides additional information on an advisory that was originally published on July 30th, 2019. The new information is the addition of two new vendor advisories concerning the VxWorks vulnerabilities:

Draeger (advisory not published on Draeger site?)

I reported the Schneider advisory last Saturday, along with advisories from Siemens, ABB, and Belden that were not included in this update.

Wednesday, August 7, 2019

Bills Introduced – 08-06-19


Yesterday with both the House and Senate meeting in proforma sessions (almost everyone was back home or on the road, raising money or connecting with local voters) there were 15 bills introduced. Two of those may receive future attention in this blog:

HR 4166 To improve technology and address human factors in aviation safety, and for other purposes. Rep. DeSaulnier, Mark [D-CA-11]

HR 4170 To preempt State data security vulnerability mandates and decryption requirements. Rep. Lieu, Ted [D-CA-33] 

Both are a bit of a stretch for coverage here, but they may contain specific language relating to control system security issues.

I will note in passing that it seems odd for a Democrat to introduce federal preemption language; that is usually a ploy to limit the ability of States to be more proactive and business constricting. I may cover this bill even if it does not include ICS language.

2019 CSSS Presentations Available


Yesterday the DHS Cybersecurity and Infrastructure Security Agency (CISA) updated both the Chemical Facility Anti-Terrorism Standards (CFATS) landing page and the Chemical Sector Security Summit (CSSS) web site to provide a link to the presentations page for the 2019 CSSS. As is usual for the CSSS, even given the advent of live web casts of many of the presentations, the presentations page just provides copies of the slides used during the CSSS, not the voice or text of the actual presentation, so many of the details have been lost to posterity.

The list of presentations, however, is impressive (see the presentation page for links to the documents):

• Air Domain Awareness           522.67 KB
• Assessing the Risk from Stolen or Diverted Toxic Industrial Chemicals 2.61 MB
• Building an International Network of Chemical Security Practitioners   994.41 KB
• CFATS and the Personnel Surety Program (PSP) Overview      1.74 MB
• CFATS Deep Dive     2.3 MB
• CFATS Personnel Surety Program      781.18 KB
• Chemical Sector 101  2.81 MB
• Chemical Security Analysis Center (CSAC) Overview 3.55 MB
• CISA Regional Service Delivery Model           2.02 MB
• Compliance Requirements for Release Chemicals        2.13 MB
• Dow Incident and Crisis Management 420.26 KB
• Extreme Weather Impacts       3.29 MB
• Federal Emergency Management Agency's Chemical, Biological, Radiological, and Nuclear (CBRN) Office: Chemical Portfolio Overview    1.44 MB
• Industrial Control Systems Vulnerabilities and Resources         1.63 MB
• International Chemical Security Framework     831.89 KB
• International Supply Chain Protection Challenges and Solutions           1.85 MB
• Introduction to the Maritime Transportation Security Act (MTSA)        2.12 MB
• Jack Rabbit II Update and Impacts      2.65 MB
• Little Arc-Flash: How Digital Attacks Can Cause Physical Ramifications          1.45 MB
• Multidisciplinary Partnerships in Chemical Security and Preparedness  1.68 MB
• Office for Bombing Prevention (OBP) Overview         417.7 KB
• Reducing the Threat of Improvised Explosive Device Attacks by Restricting Access to Explosive Precursor Chemicals        737.28 KB
• Supply Chain Risk Management         1.63 MB
• U.S. Coast Guard Cyber Risk Management      1.17 MB
• Waterside Security of Especially Hazardous Cargoes (EHC)     1.83 MB
• Weather Hazard Preparedness 5.12 MB
• What to Expect During a CFATS Inspection    1.01 MB

I have not had a chance to do a detailed review, or even look at all of the presentations, but a quick review of the CFATS Deep Dive presentation shows that the slides may contain a great deal of useful information for CFATS facilities and chemical facilities that are not currently involved in the CFATS program but are concerned about their facility security. Interesting bits of information from this presentation include:

Shipping/Receiving COI slide contains note about “In-Transit Security and Tracking”;
Response slide contains note that: “Local Emergency Planning Committees (LEPC) may be contacted by local Chemical Security Inspectors to verify that facilities have developed plans for emergency notification, response, evacuation, etc.”;
Good detail in Crisis Management slide;
Outreach with Local Responders slide includes note to: “Invite Local Law Enforcement and Responders to DHS Inspections”;
Cybersecurity slide provides brief discussion of what computer systems might be covered under CFATS program;
Personnel Surety slide contains a good ‘Hiring Checklist’, but missed the opportunity to provide a similar ‘departure checklist’ (maybe it was discussed in the actual presentation?);
Annual Audit Example slide contains a detailed example of how to record (and by inference conduct) an annual audit of the facility’s CFATS program;

I really like the idea of inviting off-site response personnel to CFATS inspections. It helps keep them involved in the process, aware of what is going on, and should provide some chemical security training that is missing from most professional training programs for these personnel. A copy of invite letters should be kept in the facility’s CFATS records to demonstrate positive outreach to these folks, even if they do not participate.

I hope to get to do more detailed reviews of some of the presentations here over the next couple of weeks.

Saturday, August 3, 2019

Public ICS Disclosures – Week of 07-27-19


It has been a very busy week in the ICS disclosure arena. We have vendor disclosures about the VxWorks vulnerabilities announced earlier this week; disclosures from Siemens, ABB, Schneider and Belden. We also have vendor disclosures from 3S and an update from Rockwell. Finally, we have new Metasploit module for a previously disclosed vulnerability from Schneider.

VxWorks Vulnerability


The Wind River OS vulnerabilities were just reported this week and we already have three (major) ICS vendors adding their advisories to the list of vulnerable products:

Siemens (in an out-of-cycle report);
Schneider; and
ABB, in:
AC 800PEC;
Belden

It will be interesting to see if NCCIC-ICS updates their advisory for each new vendor that adds to the list of covered products. Unfortunately, I do not expect NCCIC-ICS to provide any information about future updates (and there will be many as fixes are further applied) to the advisories published.

3S Advisories


This week, as earlier noted, 3S published 8 advisories for their CODESYS operating system, two of which NCCIC-ICS has reported. The remaining six advisories are covered below:

OPC UA Server Advisory

3S published an advisory describing a null pointer dereference vulnerability in the CODESYS Control V3 OPC UA Server. The vulnerability is self-reported. 3S has an update available to mitigate the vulnerability.

Communications Server Advisory

3S published an advisory describing a detection of error condition without action vulnerability in CODESYS V3 products containing a CODESYS communication server. The vulnerability was reported by Martin Hartmann from cirosec GmbH. 3S has a new version that mitigates the vulnerability. There is no indication that Hartmann has been provided an opportunity to verify the efficacy of the fix.

Library Manager Advisory

3S published an advisory describing a cross-site scripting vulnerability in the CODESYS V3 Library Manager. The vulnerability was reported by Heinz Füglister of WRH Walter Reist Holding AG. 3S has an update that mitigates the vulnerability. There is no indication that Füglister has been provided an opportunity to verify the efficacy of the fix.

On-Line User Management Advisory

3S published an advisory describing an incorrected inherited permissions vulnerability in the CODESYS Control V3 online user management. The vulnerability was reported by Martin Hartmann from cirosec GmbH. 3S has updates available that mitigate the vulnerability. There is no indication that Martin has been provided an opportunity to verify the efficacy of the fix.

Channel Management Advisory

3S published an advisory describing an uncontrolled memory allocation vulnerability in CODESYS Gateway V3 memory management. The vulnerability was reported by Martin Hartmann from cirosec GmbH. 3S has an update available that mitigates the vulnerability. There is no indication that Martin has been provided an opportunity to verify the efficacy of the fix.

Web Server Advisory

3S published an advisory describing a directory traversal vulnerability in the CODESYS V3 web server. The vulnerability was reported by Ivan Cheyrezy of Schneider Electric. 3S has an update that mitigates the vulnerability. There is no indication that Cheyrezy has been provided an opportunity to verify the efficacy of the fix.

Rockwell Update


Rockwell published an update to their advisory on PanelView 5510 Graphic Terminals that was originally published on July 9th, 2019. The update includes:

Modified description of the vulnerability;
Revision of the recommended work arounds; and
Provided a link for CVE-2019-10970

Schneider Metasploit


Lucas Dinucci published a Metasploit module for a previously disclosed vulnerability in the Schneider Electric Pelco Endura NET55XX webUI.

Friday, August 2, 2019

6 Advisories Published – 08-01-19


Yesterday the DHS NCCIC-ICS published six control system advisories for products from Leão Consultoria e Desenvolvimento de Sistemas (LCDS), Rockwell, 3S (2), Fuji Electric and Advantech.

LCDS Advisory


This advisory describes two vulnerabilities in the LCDS LAquis SCADA software. The vulnerabilities were reported by Francis Provencher (PRL) via the Zero Day Initiative. LCDS has an update available that mitigates the vulnerability. There is no indication that Provencher has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Out-of-bounds read - CVE-2019-10994; and
Type confusion - CVE-2019-10980


NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to obtain confidential information or execute remote code.

Rockwell Advisory


This advisory describes two vulnerabilities in the Rockwell Arena Simulation Software. The vulnerabilities were reported by kimiya of 9SG Security Team via ZDI. Rockwell has a new version that mitigates the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

Use after free - CVE-2019-13510; and
Information exposure - CVE-2019-13511

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to cause a current Arena session to fault or enter a denial-of-service (DoS) state, allowing the attacker to run arbitrary code.

First CODESYS Advisory


This advisory describes an insufficiently protected credentials vulnerability in the CmpUserMgr component of 3S CODESYS products. The vulnerability was reported by JunYoung Park. 3S will correct this vulnerability in a new version to be released in February. The 3S advisory strongly recommends activating and using encryption of online communication whenever possible.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow for an attacker with access to PLC traffic to obtain user credentials.

NOTE: Is it just me or is this advisory just a seven-month zero-day announcement?

Second CODESYS Advisory


This advisory describes two vulnerabilities in the CmpGateway component of the 3S CODESYS products. These vulnerabilities are self-reported. 3S has a new version that mitigates the vulenrabilities.

The two reported vulnerabilities are:

Unverified ownership - CVE-2019-9010; and
Uncontrolled memory allocation - CVE-2019-9012 

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow a remote attacker to close existing communication channels or to take over an already established user session to send crafted packets to a PLC.

NOTE 1: There were six other advisories published by 3S at the same time as the two referenced in these two NCCIC-ICS advisories. I will address them this weekend.

NOTE 2: A reminder that the CODESYS operating system is used in a wide variety of devices and systems. These vulnerabilities will have widespread application. Few vendors are expected to publish updates referencing these vulnerabilities.

Fuji Advisory


This advisory describes and out-of-bounds read vulnerability in the Fuji  FRENIC Loader. The vulnerability was reported by kimiya of 9SG Security Team via ZDI. Fuji has a new version that mitigates the vulnerability. There is no indication that the kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow information disclosure.

Advantech Advisory


This advisory describes an out-of-bounds write vulnerability in the Advantech WebAccess HMI Designer. The vulnerability was reported by Mat Powell via ZDI. Advantech has a new version that mitigates the vulnerability. There is no indication that Powell has been provided an opportunity to verify the efficacy of the fix.

Thursday, August 1, 2019

Bills Introduced – 07-31-19


Yesterday with just the Senate in session, there were 77 bills introduced. One of those bills will see future coverage in this blog:

S 2402 A bill to enhance the safety of Class 3 flammable liquid transportation by rail, and for other purposes. Sen. Wyden, Ron [D-OR]

Bills Introduced – 07-30-19


On Tuesday with the Senate in Washington and the House meeting in proforma session, there were 94 bills introduced. Three of those bills may receive additional coverage here in this blog:

HR 4091 To amend the America COMPETES Act to reauthorize the ARPA-E program, and for other purposes. Rep. Johnson, Eddie Bernice [D-TX-30]

S 2318 A bill to amend the Homeland Security Act of 2002 to authorize the Secretary of Homeland Security to establish a continuous diagnostics and mitigation program in the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, and for other purposes. Sen. Cornyn, John [R-TX]

S 2333 A bill to provide for enhanced energy grid security. Sen. Cantwell, Maria [D-WA] 

I will be watching HR 4091 to see if it includes language specifically authorizing grid cybersecurity research programs.

I will be watching S 2318 to see if it includes authorization to provide CDM coverage to private sector critical infrastructure facilities.

 
/* Use this with templates/template-twocol.html */