Tuesday, November 12, 2019

1 Update Published – 11-12-19



Today the CISA NCCIC-ICS published an update to an industrial control system security advisory for products from Siemens.

Siemens Update


This update provides additional information on an advisory that was originally published on August 15th, 2019. The new information includes updated version data and mitigation measures for SINAMICS SL150 V4.7.

Other Siemens Advisories


Siemens also published 3 new advisories and an additional four updates today as part of their monthly advisory drop. NCCIC-ICS will probably address some of them on Thursday. The remainder I will discuss Saturday.

Committee Hearings – Week of 11-10-19


This week both the House and Senate will be in Washington. Of course impeachment hearings will be all in the news, but there are two cybersecurity hearings that may be of interest; one a markup and one an oversight hearing.

Cybersecurity Markup


On Wednesday the Senate Commerce, Science, and Technology Committee will hold a business meeting where 22 bills, four nominations and a routine Coast Guard promotion list will be considered. Among the bills being considered in HR 2775, the Harvesting American Cybersecurity Knowledge through Education (HACKED) Act of 2019.

This bill was introduced last week, and the official copy of the language has yet to be printed. The hearing page has a link to a committee print of the bill. It addresses a wide range of existing cyber training programs. I have not had a chance to peruse it in detail, but there is little in the way of specific reference to control system security training issues beyond a brief mention of issues with automated driving systems.

Cybersecurity Oversight


On Thursday the Technology Modernization Subcommittee of the House Veterans Affairs Committee will hold an oversight hearing on “Cybersecurity Challenges and Cyber Risk Management at the Department of Veterans Affairs.” A witness list has not yet been published.

The hearing web page notes that: “The purpose of the hearing is to assess how the Department of Veterans Affairs (VA) manages its cybersecurity program, including controlling access to confidential data, supply-chain management, and the safeguarding of information technology assets.” I guess that means that medical device security issues will not be a major (probably not even a minor) issue in the hearing.

Saturday, November 9, 2019

Public ICS Disclosures – Week of 11-02-19


This week we have two vendor notifications from PEPPERL+Fuchs and Moxa. We also have a 0-day vulnerability report for products from Siemens. Plus there is an interesting look at the out-of-service problem and a follow-up to the ABB advisory I discussed last week.

PEPPERL+Fuchs Advisory


CERT VDE published an advisory describing a use after free vulnerability in the PEPPERL+Fuchs ecom Mobile Devices. The vulnerability was reported by Maddie Stone from Google Project Zero. This is a previously reported third-party (Linux) vulnerability in the underlying Android operating system. The vulnerable products are out of support.

NOTE: Other vendors using Android based devices will likely have similar vulnerabilities.

Moxa Advisory


Moxa published an advisory describing two GET command vulnerabilities in the Moxa EDS-405A Series Ethernet Switches. The vulnerabilities are self-reported. Moxa has a patch available to mitigate the vulnerabilities.

Siemens Vulnerability


There is an interesting article over on DARKReading.com (thanks to @PatrickCMiller for pointing me at the article) describing an interesting feature/vulnerability in the Siemens Siemens' S7-1200 PLCs. The article notes that Siemens has been notified (okay, so not technically a 0-day), but there has not yet been an advisory or fix from Siemens. I expect we may see an advisory on Tuesday during the monthly Siemens advisory drop.

If it ain’t broke don’t fix it Department


There is an interesting announcement from Omron about the pending ‘out-of-support’ status for Windows 7®. The information is rather generic and references no specific Omron products. It does, however, provide a unique view of why it may be difficult for control system owners to transfer systems to newer versions of the Windows® operating system (or any updating to any new OS for that matter).

Omron notes that:

When upgrading an old control system including obsolete PCs and operating systems make sure you consider the following:
• Which Operating System should you upgrade to - the next OS or the latest OS?
• Will your PC hardware (CPU, disk space etc) support your new OS or will you need to purchase new hardware too?
• Will your existing software applications support your new OS or will you need to purchase a software upgrade?

Given the fact that industrial control systems are custom installations, potentially involving large numbers of vendors, it is easy to see that upgrading to a supported OS could get to be quite expensive in time and money. It is no wonder that we still have large numbers of systems operating on Windows XP®.

ABB Follow-up


An interesting tweet and associated blog post from Rikard Bodfros on last week’s ABB vulnerability report.

Friday, November 8, 2019

Bills Introduced – 11-07-19


Yesterday with just the Senate in session there were 30 bills introduced. One of these bills will receive future coverage in this blog:

S 2818 A bill to require the Secretary of the Interior to issue regulations to ban the venting and flaring of gas in oil and gas production operations in the United States, and for other purposes. Sen. Markey, Edward J. [D-MA]

Okay, I will admit to a viscerally horrified objection to this bill when I read the descriptive title above, but we will have to see what the wording of the prohibition actually is before we can tell if this is a totally misguided attempt to prohibit a legitimate and necessary safety process. I understand that methane gas is a powerful greenhouse gas and that venting it as a ‘waste disposal process’ is probably an insanely wasteful environmental mistake, but there are severe safety issues that must be taken into account.

Enough of the rant, I will wait for the bill to be published and report accordingly.

4 Advisories and 1 Update Published – 11-07-19


Yesterday the CISA NCCIC-ICS published two control system security advisories for products from Fuji Electric and Mitsubishi Electric; and two medical device security advisories for products from Medtronic (2). The also updated a previously published medical device advisory for products from Philips.

Fuji Advisory


This advisory describes a heap-based buffer overflow vulnerability in the Fuji V-Server. The vulnerability was reported by kimiya of 9SG via the Zero Day Initiative. Fuji has a new version that mitigates the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to crash the device being accessed; several heap-based buffer overflows have been identified.

Mitsubishi Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the Mitsubishi MELSEC-Q Series and MELSEC-L Series CPU Modules. The vulnerability was reported by Tri Quach of Amazon’s Customer Fulfillment Technology Security (CFTS) group. Mitsubishi has a new firmware version that mitigates the vulnerability. There is no indication that Tri has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to prevent the FTP client from connecting to the FTP server on MELSEC-Q Series and MELSEC-L Series CPU module. Only FTP server function is affected by this vulnerability.

Medtronic Advisory #1


This advisory describes two RFID security vulnerabilities in the Medtronic Valleylab energy and electrosurgery products. The vulnerabilities are self-reported. Medtronic has a patch available to mitigate the vulnerabilities.

The two reported vulnerabilities are:

• Improper authentication - CVE-2019-13531; and
• Protection mechanism failure - CVE-2019-13535

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to connect inauthentic instruments to the affected products by spoofing RFID security mechanisms. This may lead to a loss of performance integrity and platform availability due to incorrect identification of instrument and associated parameters.

Medtronic Advisory #2


This advisory describes four vulnerabilities in the Medtronic Valleylab energy products. The vulnerabilities are self-reported. Medtronic has patches available to mitigate the vulnerability.

The four reported vulnerabilities are:

• Use of hard-coded credentials - CVE-2019-13543;
• Reversible one-way hash - CVE-2019-13539; and
• Improper input validation (2) - CVE-2019-3464, and CVE-2019-3463.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to  allow an attacker to overwrite files or remotely execute code, resulting in a remote, non-root shell on the affected products. By default, the network connections on these devices are disabled. Additionally, the Ethernet port is disabled upon reboot. However, it is known that network connectivity is often enabled.

Philips Update


This update provides new information for and advisory that was originally reported on April 30th, 2019.
The new information includes:

• Revised (increased) overall CVSS score;
• Information exposure vulnerability added;
• Added Tasy WEbPortal to affected product list;
• Added Trabalho Médico IT Department as a vulnerability reporter; and
• Reported that a new version mitigates the vulnerabilities.

Thursday, November 7, 2019

Senate Committee Amends and Adopts HR 1589 – CBRN Intelligence

Yesterday the Senate Homeland Security and Governmental Affairs Committee held a business meeting where they considered HR 1589, the CBRN Intelligence and Information Sharing Act of 2019. The Committee adopted substitute language and ordered the bill reported favorably by a voice vote.

The Revisions


For the most part the substitute language adopted by the Committee was a technical re-wording of the House bill with little or no change in intent. For example, see the differences below in the wording of the proposed §210F(a):

HOUSE - ‘‘(a) IN GENERAL.— The Office of Intelligence and Analysis of the Department of Homeland Security shall—”

SENATE - ‘‘(a) IN GENERAL.—The Secretary, acting through the Undersecretary for Intelligence and Analysis, and working with the intelligence components of the Department, shall—”

In this case (and in most of the bill) the two versions really mean the same thing; they just reflect a different editorial style. There are a couple of places that substantive changes have been made in the bill. For example, the House version of §210F(a)(5) reads:

‘‘(5) share information and provide tailored analytical support on such threats to State, local, Tribal, and territorial authorities, and other Federal agencies, as well as relevant national biosecurity and biodefense stakeholders, as appropriate; and”

The Senate version of the same paragraph deletes the phrase: “, as well as relevant national biosecurity and biodefense stakeholders”.

The other significant change is found in the complete re-write of §210F(b). The House version reads:

‘‘(b) COORDINATION.—Where appropriate, the Office of Intelligence and Analysis shall coordinate with other relevant Department components, including the Countering Weapons of Mass Destruction Office and the National Biosurveillance Integration Center, agencies within the intelligence community, including the National Counter Proliferation Center, and other Federal, State, local, Tribal, and territorial authorities, including officials from high-threat urban areas, State and major urban area fusion centers, and local public health departments, as appropriate, and enable such entities to provide recommendations on optimal information sharing mechanisms, including expeditious sharing of classified information, and on how such entities can provide information to the Department.”

The Senate version changes this subsection to read:

‘‘(b) COORDINATION.—Where appropriate, the Undersecretary for Intelligence and Analysis shall—
‘‘(1) coordinate with—
‘‘(A) other Departmental components, including the Countering Weapons of Mass Destruction Office, the Cybersecurity and Infrastructure Security Agency, the Science and Technology Directorate; and
‘‘(B) other Federal, State, local, and Tribal entities, including officials from high-threat urban areas, State and major urban area fusion centers, and local public health departments; and
‘‘(2) enable such components and entities to provide recommendations on—
‘‘(A) optimal information sharing mechanisms, including expeditious sharing of classified information; and
‘‘(B) how such components and entities can provide information to the Undersecretary and other components of the Department.”

Moving Forward


As soon as the Committee publishes their report on this bill, it could be considered by the full Senate. The bill was adopted as part of an en bloc consideration of a large number of bills. The voice vote heard for that en bloc vote in the video of the hearing did not include any ‘No’ votes. Given this bipartisan support I would suspect that the bill would be considered under the Senate’s unanimous consent process. I doubt that it could make it to the floor under regular order; there is just too much going on for the Senate to take up debate and procedural time on this bill.

I suspect that the House could accept the changes proposed by the Committee if the leadership allowed the language to come to an open vote.

Commentary


I think that the two substantive changes that I described above have made a major change in the focus of this bill. I have maintained that the House wording, with its specific references to biosecurity and biodefense, made this bill a biosecurity bill and not a chemical, biological, radiological and nuclear security bill. The changes made by the Committee return this to a more balanced look at all four of these threats.

Wednesday, November 6, 2019

Bills Introduced – 11-04-19


Yesterday with the Senate in Washington and the House meeting in pro forma session there were 33 bills introduced. Two of those bills may receive future coverage in this blog:

HR 4987 To provide first responders with planning, training, and equipment capabilities for crude oil-by-rail and ethanol-by-rail derailment and incident response, and for other purposes. Rep. Herrera Beutler, Jaime [R-WA-3]

S 2775 A bill to improve the cyber workforce of the United States, and for other purposes. Sen. Wicker, Roger F. [R-MS]

Herrera-Beutler is an outspoken critic of oil trains, especially ones that traverse her district. It will be interesting to see if this bill drifts over into being designed to being an impediment to oil train formation or whether it remains a well-considered emergency response measure.

As always with cyber related bills I will be watching S 2775 for language and definitions to see if this bill specifically addresses control system security training.

 
/* Use this with templates/template-twocol.html */