Thursday, March 5, 2020

1 Advisory Published – 3-5-20


Today the CISA NCCIC-ICS published a control system security advisory for products from WAGO.

WAGO Advisory


This advisory describes nine vulnerabilities in the WAGO I/O-CHECK Series PFC100 and Series PFC200. The vulnerabilities were reported by Kelly Leuschner of Cisco Talos. WAGO has new firmware that mitigates the vulnerability. There is no indication that Leuschner has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to change settings, delete the application, run remote code, cause a system crash, cause a denial-of-service condition, revert to factory settings, and overwrite MAC addresses.

NOTE: I briefly discussed these vulnerabilities back in December. In that post I provided links to the individual vulnerability reports from Talos; many of those reports included proof-of-concept exploit code.

ICSJWG 2020 Spring Meeting


Yesterday @ICSCERT announced that the 2020 Spring Meeting would be held in Salt Lake City, UT on April 14th thru 15th. Unfortunately, the link provided in the TWEET is incomplete and returns a 404 message. There is no message about this on the ‘ICS-CERT Announcements’ page.

S 3343 Introduced – Medical Supply Chain Security


Last week Sen Hawley (R,MO) introduced S 3343, the Medical Supply Chain Security Act. The bill would add medical devices to the requirements for reporting discontinuance or interruption in the production of life-saving drugs.

Amendments


Section 2(a) of the bill would amend 21 USC 356c, Discontinuance or interruption in the production of life-saving drugs. Essentially every place the current §356c says ‘drug’ the bill would change it to say ‘drug and device’. It would also add a new paragraph (j), Additional manufacturer reporting for essential drugs and devices. This would add an annual reporting requirement for the following details about drugs and devices under §356c {new §356c(j)(1)}:

• All locations of production;
• The sourcing of all component parts;
• The sourcing of any active pharmaceutical ingredients; and
• The use of any scarce raw materials.

Section 2(b) of the bill would amend 21 USC 356c-1, Annual reporting on drug shortages. These changes would substitute the words ‘drug or device shortages’ for the word ‘drug shortages’.

Moving Forward


Hawley is not a member of the Senate Health, Education, Labor, and Pensions Committee so it is unlikely that this bill will be considered in Committee. I see nothing in this bill that would engender any specific opposition. If this bill were considered in Committee, I expect that it would receive bipartisan support.

Commentary


This bill, as I suspected, has nothing to do with cybersecurity issues (more on that later) and I would not normally cover this bill in my blog for that reason. But it does provide me another chance to talk about a chemical safety issue.

Hawley’s reason for crafting this bill almost certainly has to do with discussions about the expected shortage of a class of medical devices known as respirators. This discussion is related to the expected problems associated with the CODIV19 virus that is starting to affect this country. In the most serious cases of respiratory disease that are a result of a relatively small percentage of cases of the disease associated with CODIV19 patients require the breathing assistance provided by mechanical respirators.

As I have noted in a number of blog posts about responding to many large-scale chemical releases, there are a relatively limited number of respirators available at each hospital. They are expensive pieces of equipment to buy and maintain and are not needed that often in the normal course of events. Each hospital has enough of these devices on-hand to meet their normal needs. When there is a radical increase in the number of cases of respiratory injuries or disease that require the use of respirators, hospitals end up having to make triage decisions about which cases will have access to those respirators.

When the number of patients requiring the use of respirators to survive exceeds the number of available respirators, patients are going to have an increasing number of complications and many will die. If CODIV19 reaches epidemic proportions in the United States, it is very likely that we will see a large-number patients die because of the lack of respirators.

The reporting requirements of this bill will have very little impact on this situation. We will not need an increased number of respirators until there are enough severe COVID19 cases to exceed the number of available respirators. Reporting at that point will identify the problem after it is too late to do something about the issue. Respirators take time to produce and there is only a limited amount of production capability.

So, this bill will help in the finger pointing after the COVID19 outbreak is over. There is another way that his bill could be improved and that is adding a medical device cybersecurity component to the reporting requirements. That will not have anything to do with the current projected problem with the COVID19 virus, but it could help the FDA track cybersecurity issues.

The new §366c(j) could be modified by rewording (j)(1)(B) to read:

(B) the sourcing of all component parts, including software;

I will not be covering this bill any further.

Wednesday, March 4, 2020

1 Alert and 4 Advisories Published – 3-3-20

Yesterday the CISA NCCIC-ICS published a control system security alert for products from SweynTooth and four security advisories for products form Moxa, Omron, Phoenix Contact, and Emerson.

SweynTooth Alert


This alert describes multiple Bluetooth Low Energy (BLE) vulnerabilities known as the SweynTooth vulnerabilities. The vulnerabilities were reported by Matheus E. Garbelini, Sudipta Chattopadhyay, and Chundong Wang of the Singapore University of Technology and Design. NCCIC-ICS is coordinating with chip vendors on a resolution of these vulnerabilities.

Last month I briefly reported on an advisory issued by Philips for these vulnerabilities.

Moxa Advisory


This advisory describes twelve vulnerabilities in the Moxa Moxa AWK-3131A wireless networking appliance. The vulnerabilities were reported by Jared Rittle, Carl Hurd, Patrick DeSantis, and Alexander Perez Palma of Cisco Talos. Moxa has a patch that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker using publicly available code could remotely exploit the vulnerabilities to allow an attacker to gain control of the device and remotely execute arbitrary code.

NOTE: Last Saturday I reported briefly on these vulnerabilities and provided links to the individual Talos reports that provide the proof-of-concept exploit code for these vulnerabilities.

Omron Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the Omron PLC CJ Series. The vulnerability was reported by Jipeng You (XDU). Omron provided generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial-of-service condition.

Phoenix Contact Advisory


This advisory describes an incorrect permission assignment for critical resource vulnerability in the Phoenix Contact Emalytics Controller ILC 2050 BI(L). The Phoenix Contact advisory notes that the vulnerability was reported by Anil Parmar. Phoenix Contact has a new version that mitigates the vulnerability. There is no indication that Parmar has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to change the device configuration and start or stop services.

NOTE: I briefly reported on this vulnerability last month.

Emerson Advisory


This advisory describes an improper access control vulnerability in the Emerson ValveLink. The vulnerability is self-reported. Emerson has a new version that mitigates the vulnerability.


NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow arbitrary code execution.

Tuesday, March 3, 2020

Bills Introduced – 3-2-20


Yesterday with both the House and Senate in session there were 34 bills introduced. Two of those bills may receive additional attention in this blog:

HR 6049 To amend the Federal Food, Drug, and Cosmetic Act to provide enhanced security for the medical supply chain. Rep. Gallagher, Mike [R-WI-8] 

S 3372 A bill to amend the Public Health Service Act to provide for treatment of certain respiratory protective devices as covered countermeasures for purposes of targeted liability protections for pandemic and epidemic products and security countermeasures, and for other purposes. Sen. Fischer, Deb [R-NE] 

HR 6049 looks like it may be related to S 3343 that was introduced last week. Still waiting to review that bill. Will be looking for language that includes medical device security issues.

This will probably be the last mention of S 3372. It looks like it might address surgical mask product liability issues in the current lead up to a CODIV19 outbreak in the US, but the inclusion of the phrase “and security countermeasures” makes me want to take a closer look at this bill.

Monday, March 2, 2020

COVID19and CFATS


The ‘novel corona virus’ (COVID19) that is currently slowing down in China is starting to appear more frequently on the world stage. While it is way too early to predict its effect on the United State, the impact in China certainly provides a worst-case scenario that bears consideration. DHS and the Cybersecurity and Infrastructure Security Agency (ISCD) are not yet talking publicly about potential security implications of COVID19, but security managers should start thinking about how a worst-case scenario could affect their operations.

To be clear COVID19is not directly a security issue, the virus is not going to ‘attack’ chemical facilities and release toxic agents into the air. But large numbers of personnel out with the virus or hiding out at home attempting to avoid the virus, or, worst-case, being sent-home by the government to stop the spread of the virus could have potential effects on facility security plans. And there are various wacko groups here in the United States that could be counted upon to try to take advantage of the situation to attack the ‘oppressive, illegal government operations’ trying to stem the spread of the disease.

Facility Shutdowns


We are already starting to see supply chain effects in the United States from the shutdown of many manufacturing facilities in China. This combined with the movement of much basic chemical manufacturing to China over the last 20 years or so is beginning to have some effect on chemical manufacturing in the United States. As stockpiles of chemicals sole-sourced from China begin to dry up we are going to begin to see chemical manufacturing facilities slowing and even stopping production in the US.

While many companies will use this as an opportunity to catchup on maintenance and upgrade activities, more will begin to reduce work weeks or even shut the front gates until the supply reopens. There will even be a number of companies that will go under because of the supply chain issues. As these plants sit idle, the lack of a work force on site will reduce the number of eyes that are on the lookout for suspicious activities. Facilities will need to increase their internal guard-force patrolling to off-set this reduction of eyes-on-scene.

Security managers probably need to start talking with their guard companies about ensuring adequate coverage during sickouts. And conversations with local law enforcement agencies about increased security patrolling during reduced guard-force coverage would also be a good idea.

Closed Facilities


As facilities close due to bankruptcy or lack of business there is seldom any incentive to get rid of existing chemical inventories. In instances where facilities close with inventories of DHS chemicals of interest, specific interest should be made to properly sell or dispose of these inventories.

ISCD should take special interest where CFATS covered facilities close abruptly. Chemical inspectors should visit the site to ensure that the COI inventory is no longer on site. Where it remains on site, ISCD is going to have to figure out how to ensure that those inventories receive adequate security pending their disposal. We do not need a repeat of the Cook Slurry Company closure or the abandoned hydrofluoric acid tank. And congress might want to think about providing authority to take specific types of action at abandoned CFATS facilities when they get around to reauthorizing the program (that will be a future blog post).

Potential Threat Increase


If security issues due to manpower problems are not a big enough concern, there is a potential for an increased threat of attacks against facilities that have theft/diversion security issue COI on hand.

The whole issue of mandatory quarantines raises some interesting legal issues about freedom of assembly and habeas corpus. While this has not yet caused any problems with the isolation of returned travelers, any expansion of quarantines within the country is certain to upset people in the sovereign citizen movement and right-wing militias. The fringes of both groups are well known for employing violence to make their political statements.

With their increased frustration about the denial of liberties and the increased confusion in the communities as we potentially approach the China case, there is going to be an increased interest on the part of these groups for employing weapons of mass destruction as part of their ‘protests’. This puts facilities that house theft/diversion COI at an increased threat of attack when they are potentially having to address internal security issues due to reduced manpower.

Again, security managers are going to have to start thinking about these issues now and talking with their security companies and local law enforcement about the issue. ISCD is also going to have to think about some proactive engagement with the National Guard Bureau about the issue. Talking about this potential problem early is going to be the key to staying ahead of the issue.

Moving Forward


We are well ahead of the potential problems describe here, but they could happen sooner rather than later. It is not clear that DHS is going to be allowed to engage in any advanced planning on these issues as the Administration appears to be more concerned with preventing stock market problems than really addressing the medical issues at hand. We can only hope that advanced security planning will be allowed to proceed at the federal level.

But security managers are going to have to take a hard look at how this potential epidemic could effect their security posture and start thinking and talking about how they could deal with these issues before they actually arise.

Committee Hearings – Week of 3-1-20


This week with both the House and Senate in Washington the FY 2021 Budget and CODV-19 will be two big topics for congressional hearings. There will also be a 5G supply chain security hearing and a DHS resources hearing.

Budget Hearings


Agency
House
Senate
DHS
3-3-20 HS

EPA
3-4-20 A-AER

Cyber Command
3-4-20 AS-S

TSA

3-3-20 A-DHS
DOE

3-3-20 ENR
DOT

3-4-20 A-THUD
DOE

3-4-20 A-EWR
DOD

3-4-20 AS




HS – Homeland Security Committee
A-AER – Appropriations AER Subcommittee
AS-S – Armed Services Subcommittee
A-DHS – Appropriations DHS Subcommittee
A-THUD – Appropriations THUD Subcommittee
A-EWR – Appropriations EWR Subcommittee
ENR – Energy and Natural Resources Committee
Armed Services Committee

5G Supply Chain


On Wednesday the Senate Commerce, Science, and Transportation Committee will hold a hearing looking at “5G Supply Chain Security: Threats and Solutions”. The witness list includes:

• Steven Berry, Competitive Carriers Association;
• Rick Corker, Nokia;
• Jason Boswell, Ericsson; and
• James Lewis, Center for Strategic and International Studies

DHS Resources


On Wednesday the Senate Homeland Security and Governmental Affairs committee will hold a hearing on “Resources and Authorities Needed to Protect and Secure the Homeland”. Chad Wolf, the Acting Secretary, will be the sole witness.

I am hoping to hear questions about the reauthorization of the CFATS program in light of the President’s proposed zeroing out of funding for the program.

Sunday, March 1, 2020

CFATS Sodium Chlorate Exemption


Yesterday I briefly mentioned the 2015 exemption letter from the CISA Infrastructure Security Compliance Division that ‘temporarily’ exempted certain products containing sodium chlorate (CAS# 7775-09-9) from Top Screen reporting requirement under the Chemical Facility Anti-Terrorism Standards (CFATS) program. Today I would like to take a little closer look at this issue.

Sodium Chlorate


The PubCHem website describes sodium chlorate (NaClO3):

“Sodium chlorate appears as an odorless pale yellow to white crystalline solid. It is appreciably soluble in water and heavier, so may be expected to sink and dissolve at a rapid rate. Although it is not itself flammable, the solid product and even 30% solutions in water are powerful oxidizing agents. Contact with wood, organic matter, ammonium salts, sulfur, sulfuric acid, various metals, and other chemicals may result in fires or explosions, particularly if any solid materials are finely divided. Excessive heat, as in fires, may cause evolution of oxygen gas that may increase the intensity of fires and may also result in explosions. Mixtures with combustible materials are very flammable and may be ignited by friction. It is used for making herbicides, explosives, dyes, matches, inks, cosmetics, pharmaceuticals, defoliants, paper, and leather.”

Personal Note: I remember a high school chemistry class where the Dr. Dunston (yes, we had a PhD chemist teaching high school chemistry; he was mostly retired from industry and was ‘giving back’ to the science that he loved) placed some NaClO3 crystals on some newspaper. He then placed an ice cube on the crystals and the newspaper burst into flames. No wonder I love chemistry. Anyway….

Sodium chlorate is listed in Appendix A to 6 CFR 27 (the CFATS regulations) as a Theft – EXP/IEDP security measure chemical. It has a 400-lb screening threshold quantity and it has a reportable concentration of ‘ACG’; a commercial grade. That was defined in the preamble to Appendix final rule as “any quality or concentration of a chemical of interest offered for commercial sale that a facility uses, stores, manufactures, or ships.”

The Exemption


In late 2014 or early 2015 someone apparently contacted ISCD about specific products that contained sodium chlorate in a commercial grade. They presented some sort of evidence to ISCD that convinced the agency that it would be significantly more difficult to produce explosive materials or improvised explosive devices from the sodium chlorate in these products than regular commercial grade sodium chlorate. The specific products were:

• Defol 5
• Defol 750
• Pramitol 5 PS
• BareSpot Monobor-Chlorate
• BareSpot Weed and Grass
• BareSpot Ureabor
• BareGround Ultra

ISCD looked at the evidence presented and agreed with the presenter that, at a minimum, the information merited more investigation and that ISCD was satisfied that the risk for these products being used by terrorists was low enough that they did not merit immediate consideration under the CFATS program. On April 20th, 2015 ISCD Director Wulf sent the letter included in the CISA guidance document to every facility that had included the listed products in their Top Screen submission.

This letter was not made public in 2015. I assume that the reason for this was that, ISCD still wanted to know what facilities possessed these products in the event that they subsequently decided that they were no longer exempt from the Top Screen submission requirement. If that decision were made ISCD would have a list of facilities (with security contact information) available to send a new letter telling them that they would have to submit a new Top Screen listing these products that were on hand at over 400-lbs.

The Products


The products listed in the letter are all herbicides and they can be found (except 1) listed on Breenbook.net, a crop protection information site. That site provides links to EPA product labels and Safety Data Sheets. The SDS and product labels provide information and those, in turn, provide composition information. The table below shows some of that information. The product links are to either the SDS or EPA label from which I took the data.

Product
State
% NaClO3
Slurry
42.3%
Slurry
52.0%
Solid
39.8%
Solid
30.0%
Solid
30.0%
Solid
30.0%
BareGround Ultra



I cannot find BareGround Ultra in a quick internet search. I suspect that it is no longer an authorized product for herbicide use.

The ‘solid’ material is described as pellets. Some of the products contain urea and/or Sodium Metaborate. Some also contain a variety of other pesticides. None of the products are regulated as hazardous materials by the DOT’s Pipeline and Hazardous Materials Administration. Sodium Chlorate is regulated (pg 289) as an Oxidizer, UN 1946, 5.2, PG II. With the other products not being regulated, it should mean that they have been tested against the oxidizer standard, 49 CFR 173.127. This would also suggest that these products could not be used as a direct substitute for sodium chlorate in the manufacture of explosives or IEDs.

ISCD would not only be concerned about direct substitution but would also want to take into account how easily the sodium chlorate portion of the mixture could be separated out from the product and then be used in the manufacture of explosives or IEDs. While an impossible separation would be the ideal case a more reasonable standard would find that a separation process that required the use of a significant chemical processing facility to accomplish would effectively prevent their use by terrorists clandestinely making explosives.

Commentary


There have been complaints from the start of the program about the way DHS established the minimum concentration of the chemicals on the chemicals of interest (COI) list (Appendix A), setting arbitrary limits that may not directly reflect the potential hazard. This is especially true for chemicals in the theft/diversion security issue. One of the concerns is that some mixtures are no longer able to be used by terrorists to develop weapons.

This concern was most recently addressed in the language of HR 3256. Section 14 of that bill would require DHS to “prescribe regulations to enact a process through which the Secretary can be petitioned to exclude a product or mixture”. Looking at this letter, it would seem that ISCD already has an informal procedure in place to address this issue. The question is why is this an informal process that has not been formally published, probably as a guidance document?

The way that Wulf handled the letter notifications in this case provides an insight into their though process. Since the letter was only sent out to facilities that had already submitted Top Screens, ISCD effectively had location information on all of the facilities that were subject to the exemption. If subsequent information (and I doubt that ISCD is actually looking for such information) turned up information showing that the products did actually present a real terrorist hazard, ISCD would be able to ensure that those facilities take appropriate efforts to protect those chemicals.

The public presentation of this guidance document changes that situation. New facilities coming into possession of these chemicals could reasonably expect that they are not required to submit a Top Screen. ISCD no longer has a reason to keep this process under wraps.

 
/* Use this with templates/template-twocol.html */