Tuesday, December 10, 2019

7 Advisories and 6 Updates Published – 12-10-19


Today the DHS NCCIC-ICS published seven control system security advisories for products from Siemens and six updates for products from Siemens (5) and Interpeak.

EN100 Ethernet Module Advisory 


This advisory describes three vulnerabilities in the Siemens EN100 Ethernet Module. The vulnerabilities are self-reported. Siemens has a new version that mitigates the vulnerability.

The three reported vulnerabilities are:

• Improper restriction of operations within the bounds of a memory buffer - CVE-2019-13942;
• Cross-site scripting - CVE-2019-13943; and
• Relative path traversal CVE-2019-13944

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to execute remote code, cause a denial-of-service condition, and obtain sensitive information about the device.

SIMATIC S7-1200 Advisory


This advisory describes two vulnerabilities in the Siemens SIMATIC S7-1200 and S7-1500 CPU families. The vulnerabilities were reported by Eli Biham, Sara Bitan, Aviad Carmel, and Alon Dankner from Faculty of Computer Science, Technion Haifa; Uriel Malin and Avishai Wool from School of Electrical Engineering, Tel-Aviv University; and Artem Zinenko from Kaspersky. Siemens has updates that mitigate the vulnerabilities. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Use of a broken or risky cryptographic algorithm - CVE-2019-10929; and
• Missing support for integrity check - CVE-2019-10943

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to modify network traffic or impact the perceived integrity of the user program stored on the CPU.

NOTE: Siemens originally published their advisory for these vulnerabilities back in August, but NCCIC-ICS never reported on it. Siemens published an update for their advisory today.

XHQ Operations Intelligence Advisory


This advisory describes three vulnerabilities in the Siemens XHQ Operations Intelligence. The vulnerabilities are self-reported. Siemens has a new version that mitigates the vulnerabilities.

The three reported vulnerabilities are:

• Cross-site request forgery - CVE-2019-13930;
• Improper neutralization of script-related HTML tags in a web page - CVE-2019-13931; and
• Improper input validation - CVE-2019-13932

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to read or modify contents of the web application.

SIMATIC Products Advisory


This advisory describes a use of broken or risky cryptographic algorithm vulnerability in the Siemens SIMATIC products. The vulnerability was reported by Eli Biham, Sara Bitan, Aviad Carmel, and Alon Dankner from Faculty of Computer Science, Technion Haifa; and Uriel Malin and Avishai Wool from the School of Electrical Engineering, Tel-Aviv University, reported this vulnerability to Siemens. Siemens has updates for three of the affected products. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

An uncharacterized attacker could remotely exploit this vulnerability to allow an attacker already in a man-in-the-middle position to modify network traffic exchanged on Port 102/TCP. The Siemens advisory notes that the attack must conduct a man-in-the-middle attack to exploit the vulnerability.

RUGGEDCOM ROS Advisory


This advisory describes two vulnerabilities in the Siemens RUGGEDCOM ROS. The vulnerabilities are self-reported. Siemens has provided generic workarounds to mitigate the vulnerabilities.

The two reported vulnerabilities are:

• Improper restriction of operations within the bounds of a memory buffer - CVE-2018-18440; and
• Resource management errors - CVE-2019-13103

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to allow a denial-of-service condition or arbitrary code execution. The Siemens advisory reports that an attacker must have local access to exploit these vulnerabilities.

SiNVR Advisory


This advisory describes seven vulnerabilities in the Siemens SiNVR 3 video management solution. The vulnerabilities were reported by Raphaël Rigo from Airbus Security Lab. Siemens has provided generic workarounds for the vulnerabilities.

The seven reported vulnerabilities are:

• Cleartext storage of sensitive information in GUI - CVE-2019-13947;
• Improper authentication (2) - CVE-2019-18337 and CVE-2019-18341;
• Relative path traversal - CVE-2019-18338;
• Missing authentication for critical function - CVE-2019-18339;
• Weak cryptography for passwords - CVE-2019-18340; and
Exposed dangerous method or function - CVE-2019-18342

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to read (and reset) passwords of other SiNVR 3 CCS (Central Control Server) users, read the CCS and SiNVR users database including the passwords of all users in obfuscated cleartext, list arbitrary directories or read files outside of the CCS application context, extract device configuration files and passwords from the user database, read data from the EDIR directory, read or delete arbitrary files, or access other resources on the same CCS server.

SCALANCE Advisory


This advisory describes an improper enforcement of message integrity during transmission in a communication channel vulnerability in the Siemens SCALANCE W700 and W1700 wireless communication devices. The vulnerabilities are self-reported.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to access confidential data. The Siemens advisory notes that the attacker must be within wireless range of the device to exploit the vulnerability.

SCALANCE Update


This update provides additional information on an advisory that was originally published on May 24th, 2013. The new information includes:

• Added Scalance X-200 switch family;
• Updated CVSS Scores from CVSSv2 to CVSSv3.1; and
• SIPLUS devices now explicitly mentioned in the list of affected products

SIMATIC CP 343-1 Update


This update provides additional information on an advisory that was originally published on November 11th, 2016 and most recently updated on March 21st, 2017. The new information includes SIPLUS devices now explicitly mentioned in the list of affected products.

NOTE: Siemens most recently updated their advisory last month and those corrections about the S7-400 CPUs are not included in the NCCIC-ICS update. Unfortunately none of the versions (except the latest) of the Siemens advisory are listed on the Siemens CERT page and I did not see last month’s update.

SIPROTEC 5 Update


This update provides additional information on an advisory that was originally published on July 9th, 2019 and most recently updated on August 13th, 2019. The new information includes an update for SIPROTEC 5 relays with CPU variants CP200 and the respective Ethernet communication modules.

SINAMICS Update


This update provides additional information on an advisory that was originally published on August 15th, 2019 and most recently updated on November 11th, 2019. The new information includes updated version information and mitigation links for:

• SINAMICS SM120 V4.7; and
• SINAMICS SM120 V4.8

Industrial Products Update


This update provides additional information on an advisory that was originally published on September 10th, 2019 and most recently updated on November 14th, 2019. The new information includes:

• Added solution for SCALANCE W700; and
• SIPLUS devices now explicitly mentioned in the list of affected products

Interpeak (ICS) Update


This update provides additional information on an advisory that was originally published on October 1st, 2019 and most recently updated on October 10th, 2019. The new information is the addition for links to vendor advisories for:


NOTE: Both advisory links are to updates published today of Siemens advisories that were published earlier; August 2nd, 2019 and September 10th, 2019 respectively.

Additional Siemens Advisories


Siemens published one additional new advisory and two updates today that did not show up on the NCCIC-ICS page. We will probably see the other new advisory covered on Thursday.

House Passes Two Threat Analysis Bills – HR 3318 and HR 4402


Yesterday the House took up two homeland security bills related to threat analysis; HR 3318, the Emerging Transportation Security Threats Act of 2019; and HR 4402, the Inland Waters Security Review Act. Both bills were considered under the suspension of the rules process and were passed by a voice vote. There was very limited debate with nary a voice raised in opposition to either bill.

Both bills will probably be taken up in the Senate in the coming year. If considered in that body they would be handled under the Senate’s unanimous consent process with no debate and no actual vote. If even a single Senator objected to the bill, the bill would die a quite death. Neither bill is important enough to justify the time necessary to process the bill under regular order.


Monday, December 9, 2019

HR 4432 Reported in House – UAS Threat Assessment


Last month the House Homeland Security Committee published their report on HR 4432, the Protecting Critical Infrastructure Against Drones and Emerging Threats Act along with the amended version of that bill.

An interesting thing happened on the way to the Government Printing Office. Section 2(c) of the original bill seems to have disappeared. Readers will remember that I complained about that section of the bill that would have exempted DHS from the Information Collection Request requirements of the Paperwork Reduction Act. Now changes made to a bill after it has been approved in Committee are not too unusual, but there is language in the Report’s ‘Section-by-Section Analysis of the Legislation’ (pg 6, last paragraph). It will be interesting to see if the language is in the bill when it is passed in the House.

Yes, the bill will almost certainly be passed in the House after it is taken up under the suspension of the rules process and it will pass with a substantial bipartisan vote.

Saturday, December 7, 2019

Public ICS Disclosures – Week of 11-30-19


This week we have three vendor disclosures for products from BD, GE and Johnson Controls and an URGENT/11 update from Belden. There are also three exploit code reports for products from Fronius, Salto and YachtControl.

BD Advisory


BD published an advisory describing and anti-virus bypass vulnerability in BD products with workstations running CylancePROTECT®. The third-party vulnerability was originally reported by Skylight. BD recommends updating the CylancePROTECT product.

NOTE: I wonder what other ICS vendors bundle CylancePROTECT as a cybersecurity tool? Since the product does not need to do signature updates it would seem to be a tool designed for control system security.

GE Advisory


GE published an advisory describing two privilege escalation vulnerabilities in the GE Digital HMI/SCADA iFIX product. The vulnerability was reported by Applied Risk. GE provides generic mitigation guidance for the vulnerability.

Johnson Controls Advisory


Johnson Controls published an advisory describing vulnerabilities in a third-party component of their Software House C•CURE 9000 application. The vulnerabilities in the Flexera FlexNet Publisher licensing manage have been previously reported. Johnson Controls has an update that mitigates the vulnerability.

Belden Update


Belden published an update of their URGENT/11 advisory that was originally published July 29th, 2019 and most recently updated on October 30th, 2019. The new information includes update information for Hirschmann HiOS RSPE TSN.

Fronius Expliot


SEC Consult published a report containing exploit code for four vulnerabilities in the solar inverter series of Fronius. This is reportedly a coordinated disclosure. Fronius has a firmware patch that mitigates the vulnerabilities. There is no indication that SEC Consult has been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Unencrypted communication;
• Authenticated path traversal - CVE-2019-19229;
• Backdoor account - CVE-2019-19228; and
• Outdated and vulnerable software components

NOTE: This is the first time that I have seen an easter-egg included in a vulnerability report.

Salto Exploit


SEC Consult published a report containing exploit code for six vulnerabilities in the Salto ProAccess Space management software for an access control system. This is reportedly a coordinated disclosure. Salto has a patch that mitigates the vulnerabilities. There is no indication that SEC Consult has been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Path traversal - CVE-2019-19458;
• Arbitrary file write - CVE-2019-19459;
• Stored cross-site scripting - CVE-2019-19457;
• Webserver running as Windows Service per default - CVE-2019-19460;
• Authorization issues; and
• Cleartext transmission of sensitive data

Yachtcontrol Exploit


Hodorsec published exploit code for a remote code execution vulnerability in the Yachtcontrol web application. The report includes a CVE number so this may be a coordinated disclosure.

Thursday, December 5, 2019

2 Advisories Published – 12-05-19


Today the CISA NCCIC-ICS published two control system security advisories for products from Weidmueller and Thales.

Weidmueller Advisory


This advisory describes 5 vulnerabilities in the Weidmueller Industrial Ethernet Switches. The vulnerabilities are self-reported. Weidmueller has firmware patches that mitigate the vulnerabilities.

The five reported vulnerabilities are:

• Improper restriction of excessive authentication attempts - CVE-2019-16670;
• Uncontrolled resource consumption - CVE-2019-16671;
• Missing encryption of sensitive data - CVE-2019-16672;
• Unprotected storage of credentials - CVE-2019-16673; and
• Predictable from observable state - CVE-2019-16674

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow a remote attacker to gain unauthorized access to the device, affecting the confidentiality, integrity, and availability of the device the attacker is targeting.

Thales Advisory


This advisory describes a link following vulnerability in the Thales SafeNet Sentinel LDK License Manager Runtime. The vulnerability was reported by Ryan Wincey of Blizzard Entertainment. Thales has a new version that mitigates the vulnerability. There is no indication that Wincey has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with local access could exploit the vulnerability to allow a local attacker to escalate privileges.

NOTE: I briefly addressed this vulnerability back in October.

Wednesday, December 4, 2019

S 2877 Introduced – TRIA Reauthorization


Last month Sen Tillis (R,NC) introduced S 2877, the Terrorism Risk Insurance Program Reauthorization Act of 2019. This bill contains essentially the same language adopted by the House in HR 4634 four days after this bill was introduced. The bill does include the language calling for the GAO to conduct a study on cyber terrorism and its coverage under the TRIA program.

Yesterday the bill was reported favorably without amendment or written report by the Senate Banking, Housing, and Urban Affairs Committee. I suspect that the House version of the bill will be taken up in the Senate under the unanimous consent process; maybe before the end of the year. This process will not allow for debate or an actual vote.

Tuesday, December 3, 2019

2 Advisories Published – 12-03-19


Today the CISA NCCIC-ICS published two control system security advisories for products from Moxa and Reliable Controls.

Moxa Advisory


This advisory describes 14 vulnerabilities in the Moxa AWK-3121 wireless access point. The vulnerabilities were reported by Samuel Huntley. This product has reached end-of-life and is no longer supported.

The 14 reported vulnerabilities are:

• Cleartext transmission of sensitive information (3) - CVE-2018-10690, CVE-2018-10694 and CVE-2018-10698;
• Sensitive cookie without ‘HTTPONLY’ flag - CVE-2018-10692;
• Improper restriction of operations within the bounds of a memory buffer (4) - CVE-2018-10693, CVE-2018-10695, CVE-2018-10701 and CVE-2018-10703;
• Cross-site request forgery - CVE-2018-10696;
• Command injection (3) - CVE-2018-10697, CVE-2018-10699 and CVE-2018-10702; and
• Cross-site scripting - CVE-2018-10700;

NCCIC-ICS reports that a relatively low-skilled attacker could remotely use publicly available exploits to allow an attacker to view sensitive information, cause availability issues, and execute remote code.

Reliable Controls Advisory


This advisory describes an unquoted search path or element vulnerability in the Reliable Controls License Manager. The vulnerability was reported by Gjoko Krstic of Applied Risk. Reliable Controls has a new version that mitigates the vulnerability. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to crash the system, view sensitive data, or execute arbitrary commands.

NOTE: Both of these product vulnerabilities were publicly reported back in June by the listed researcher. It appears that in at least one of the cases (probably both) the vendor did not reply or adequately address the researchers concerns even after there was public disclosure. The researchers then apparently turned to NCCIC-ICS for assistance.

 
/* Use this with templates/template-twocol.html */