Tuesday, November 5, 2019

1 Advisory and 2 Updates Published


Today the CISA NCCIC-ICS published a control system advisory for products from Omron. They also updated two previously published security advisories for products from Omron and Interpeak (medical device advisory).

Omron Advisory


This advisory describes a use of obsolete function vulnerability in the Omron CX-Supervisor. The vulnerability was reported by Michael DePlante of the Zero Day Initiative. Omron has a new version that mitigates the vulnerability. There is no indication that DePlante has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to result in information disclosure, total compromise of the system, and system unavailability.

Omron Update


This update provides additional information on an advisory that was originally published on May 14th, 2019. The new information includes the announcement of a new version that mitigates the vulnerability.


Interpeak IPnet (medical device) Update


This update provides additional information on an advisory that was originally published on October 1st, 2019 and last updated on October 10th. The new information is the addition of Hillrom to the list of vendors that have also released security advisories related to their affected products. Unfortunately, the link provided takes one to a generic responsible disclosure page with no mention of security advisories.


S 2714 Introduced – ARPA-E Reauthorization


Last week Sen Van Hollen (D,MD) introduced S 2714, the ARPA–E Reauthorization Act of 2019. The bill is very similar to HR 4091 that was adopted in Committee last month.

The Senate version of the bill does not include the radioactive waste addition to the ARPA-E goals (42 USC 16538(c) that was included in the House version, but it did include the broad ‘security’ provision that I discussed in my post about the introduction of HR 4091.

Most of the other changes to §16538 made by this version of the bill are similar to those made in the House version. The spending authorizations are the same as were included in the managers amendment to HR 4091 that was included in the Committee’s approval of that bill.

Moving Forward


Van Hollen is not a member of the Senate Energy and Natural Resources Committee to which this bill was assigned for consideration. His one cosponsor, Sen Alexander (R,TN), is, however, so it is reasonable to suspect that this bill could be considered in Committee. I would suspect that it would receive the same bipartisan support as was seen in the House for HR 4091.

As I noted earlier today, this bill was included in the list of bills that will be addressed tomorrow in a legislative hearing before the Committee. That does not mean that the bill will automatically be considered in a markup, but it is very likely.

Committee Hearings – Week of 11-3-19


This week just the Senate will be in session; the House is working (campaigning? Or just explaining impeachment?) in their districts. There are two cybersecurity related hearings scheduled; one a markup and one a DOE look at legislation.

Markup Hearing


On Wednesday the Senate Homeland Security and Governmental Affairs Committee will be holding a business meeting that includes marking up 16 bills (plus 11 postal naming bills and four nominations). Only one of those bills is of interest here:

HR 1589, the CBRN Intelligence and Information Sharing Act of 2019

The House passed this bill by a voice vote back in April. I would not normally expect the Committee to make any substantive changes to this bill in this type of crowded hearing.

Legislative Hearing


On Wednesday the Energy Subcommittee of the Senate Energy and Natural Resources Committee will hold a legislative hearing looking at 11 Department of Energy related bills. There is only one witness scheduled; Daniel Simmons from DOE. Two of those bills are of interest here:

S 2556 – Protecting Resources On The Electric grid with Cybersecurity Technology Act of 2019
S 2714 – ARPA-E Reauthorization Act

The language for S 2714 has just become available. I hope to be able to review it in detail before tomorrow’s hearing.

Monday, November 4, 2019

S 2731 Introduced – Skinny NDAA


Last week Sen. Inhofe (R,OK) introduced S 2731, the Essential National Security Authorities Act for Fiscal Year 2020. This is a ‘skinny’ national defense authorization act (NDAA), with the bare minimum authorization requirements needed to keep the defense apparatus of the United States in operation through FY 2020. Both the House (HR 2500) and Senate (S 1790) passed expanded versions of this bill earlier in the year, but have not yet been able to work out a compromise version of the bill in conference committee.

Cybersecurity


This ‘skinny’ NDAA only contains 2 of the 49 cybersecurity sections found in Title XVI, Division A of the original bill:

§1627. Authority to use operation and maintenance funds for cyber operations-peculiar capability development projects.
§1639. Extension of authorities for Cyberspace Solarium Commission.

Moving Forward


The NDAA is a ‘must pass’ bill. While there is still a chance that the conference committee will work out their differences on the previously passed versions, Inhofe is concerned enough to offer up this bill as a minimum workable solution. I suspect that this bill could be passed in the Senate under their unanimous consent process if the failure of the conference committee became obvious enough; though I would have been more hopeful if Sen Reed (D,RI), the Ranking Member of the Senate Armed Services Committee had signed on as a cosponsor of the bill.

There is also a chance that the conference committee could use this language as a new starting point for working out a compromise version of the NDAA.

Commentary


There is an interesting set of remarks [pg S6246] by Inhofe in the Congressional Record on the introduction of this bill. He explains the dangers of a ‘must pass bill’; everyone wants to add on language that probably would not pass on its own. If that tendency is not adequately controlled, we end up in our current apparent stalemate.

This also provides a good point for the discussion of the term ‘control of the Congress’. Typically, most people mean that a party controls Congress when it has a majority of the elected legislators in both the House and the Senate. That is not exactly the case. Under current rules, the Senate requires a vote of 60 Senators to begin consideration of most legislation. Thus, a minority of 41 Senators can block legislation in that body. True legislative control of the Senate (again under current rules) requires a party to have 60 Senators.

There have been frequent calls for doing away with, or at least restricting, this requirement for a super majority to pass legislation in the Senate. The majority party frequently complains that they are being hamstrung in their efforts to pass legislation that they have promised their voters. And, to be fair, this is frequently true.

Unfortunately, we have seen in recent years what the probable outcome would be if this supermajority requirement were removed or even seriously restricted. Whenever the opposition party gained control of the Senate it would spend a great deal of its time and effort repealing laws and rules established by the other party. Now there are certainly instances where one could fairly describe this as a good thing, but business and society both require a certain amount of stability in the rules and regulations under which they operate. If the Senate could unwrite laws and regulations every two-years, nothing would ever get done and we would have regulatory anarchy.

Saturday, November 2, 2019

Public ICS Disclosures – Week of 10-26-19


This week we have four vendor disclosures from Phoenix Contact, ABB, Johnson Controls, and BD. There are three vendor updates from 3S, Yokogawa, and Belden. There are also three exploit reports from researchers for products from Carel and Intelligent Security Systems. The later may be a 0-day exploit.

Phoenix Contact Advisory


Phoenix Contact published an advisory [.PDF download link] describing an unauthorized access vulnerability in their FL NAT industrial ethernet switch/router. The vulnerability is self-reported. Phoenix Contact provides generic mitigation measures pending the development of new firmware.

ABB Advisory


ABB published an advisory describing an authentication bypass vulnerability in their Power Generation
Information Manager. The vulnerability was reported by Rikard Bodforss at CS3STHLM. ABB has a new version that mitigates the vulnerability. Bodforss has verified the efficacy of the fix.

NOTE: The disclosure blog post by Bodforss has an excellent discussion about the vulnerability disclosure dilemma from the viewpoint of a researchers. Well worth reading.

Johnson Controls Advisory


Johnson Controls has published an advisory describing two vulnerabilities in their FX Supervisory Controller. The vulnerabilities were reported in the third-party QNX operating system. Johnson Controls has patches to mitigate the vulnerability and a new version to be released later this month will fully address the problems.

The two reported vulnerabilities are:

• Information exposure - CVE-2019-8998; and
• Improper authorization - CVE-2019-13528

NOTE 1: I wonder if NCCIC-ICS will update their Tridium advisory to provide a link to this advisory? Nah.

NOTE 2: Just another case of wondering what other vendors use the same vulnerable operating system?

BD Advisory


BD has published an advisory for the DejaBlue remote desktop vulnerabilities in their products. BD has provided generic work arounds while it continues to test and validate the Microsoft patch for BD products.

3S Update


3S published an update of their CODESYS ENI server advisory that was originally published on September 12, 2019. The new information includes:

Additional mitigation measure;
Mitigated version updated; and
CVE added

Yokogawa Update


Yokogawa published an update of their unquoted service path advisory that was originally published on September 27th, 2019 and most recently updated on October 24th. The new information is another change to the Exaquantum mitigation.

Belden Update


Belden published an update of their URGENT/11 advisory that was originally published on July 11th, 2019 and most recently updated on September 5th. The new information includes updated mitigation information for their EAGLE and EAGLE one products.

Carel Exploits


Red Team Pentesting published exploit code for an unsafe storage of credentials vulnerability in the Carel pCOWeb card. This vulnerability was previously reported in the Rittal Chiller using the pCOWeb card. Red Team Pentesting reports that Carel consideres this product obsolete and no longer provides updates for the firmware.

Red Team Pentesting published exploit code for an unauthenticated access to modbus interface vulnerability in the Carel pCOWeb card. This vulnerability was previously reported in the Rittal Chiller using the pCOWeb card. Red Team Pentesting reports that Carel consideres this product obsolete and no longer provides updates for the firmware.

Intelligent Security System Exploit


Alberto Vargas published exploit code for an unquoted service path vulnerability in the Intelligent Security System SecurOS Enterprise. There is no indication that this disclosure was coordinated with the vendor so this may be a 0-day exploit.

Friday, November 1, 2019

Senate Amends and Passes HR 3055 – First Senate Minibus


Yesterday the Senate passed an amended version of HR 3055, the first Senate FY 2020 spending minibus by a bipartisan vote of 84 to 9. They first adopted 48 amendments including the substitute language offered by Sen. Shelby (R,MS); only one amendment considered was rejected.

None of the 49 amendments considered specifically addressed chemical safety, chemical security or cybersecurity concerns. Forty-five of the amendments were considered en bloc [pg S6311] under the unanimous consent process with no debate.

Next week the House may consider the Senate version of the bill. When they do, they will probably ‘insist’ on their version. A conference committee will then take up the two versions and try to work out a compromise version. There is a slight chance that this will happen before the current continuing resolution runs out on November 21st.

It seems unlikely that the full 12 spending bills (four were included in the Senate version of HR 3055) will be passed by the 21st. This means that we will likely (depending on the President) see another continuing resolution to keep the government working past that date. Various news reports (see here for example) claim that the CR under consideration behind closed doors will continue into next year.

HR 4792 (S 2664) Introduced – Cyber Shield Program


Last week Rep. Lieu (D,CA) introduced HR 4792, the Cyber Shield Act of 2019. The bill {and its companion bill, S 2664; introduced by Sen Markey (D,MA)} would establish require the Department of Commerce to establish the Cyber Shield Program; a program for the voluntary certification and labeling of products that meet industry-leading cybersecurity and data security benchmarks to enhance cybersecurity and protect data.

The products referenced in the bill only apply to ‘consumer facing objects’ that {§2(3)}:

Connect to the internet or other network; and
Collect, send, or receive data; or
Control the actions of a physical object or system

Commentary


Presumably the ‘consumer facing’ portion of the definition excludes industrial control systems but may apply to certain medical devices. Unfortunately, the FDA is not specifically mentioned as one of the federal agencies to be consulted with on establishing standards in this program. Nor is the Cybersecurity and Infrastructure Security Agency (CISA) mentioned; surprising in that they would certainly have an interest in cybersecurity certifications of consumer products used by federal agencies.

In general, these bills are weak on definitions; no definition of the key term ‘cybersecurity’ for instance. They also fail to address the issue of coordination of vulnerability reporting or even take into account the fact that independent researchers are the most common source for reporting vulnerabilities.

The basic premise is helpful, but this implementation is weak to say the least. This is surprising since Lieu and Markey have both tried to position themselves as cybersecurity gurus in Congress.

 
/* Use this with templates/template-twocol.html */