Friday, April 23, 2021

Bills Introduced – 4-22-21

Yesterday, with both the House and the Senate preparing to depart Washington for the weekend, there were 168 bills introduced. Three of those bills may receive additional coverage in this blog:

S 1316 A bill to amend the Homeland Security Act of 2002 to authorize the Secretary of Homeland Security to make a declaration of a significant incident, and for other purposes. Sen. Peters, Gary C. [D-MI] 

S 1324 A bill to establish a Civilian Cyber Security Reserve as a pilot project to address the cyber security needs for the United States with respect to national security, and for other purposes. Sen. Rosen, Jacky [D-NV]

S 1359 A bill to establish the Foundation for Energy Security and Innovation, and for other purposes. Sen. Coons, Christopher A. [D-DE] 

I will be watching S 1316 for language and definitions that specifically include cybersecurity incidents in potential ‘significant incident’ declaration authority.

I will be watching S 1324 for language and definitions that would specifically include industrial control systems in the ‘cybersecurity needs’ of the United States.

I suspect that S 1359 is a green-energy bill with ‘energy security’ equating to energy supply needs. I will be watching for anything that addresses cybersecurity issues.

Thursday, April 22, 2021

2 Advisories Published – 4-22-21

Today CISA’s NCCIC-ICS published two control system security advisories for products from Mitsubishi Electric and Horner Automation.

Mitsubishi Advisory

This advisory describes an improper authentication vulnerability in the Mitsubishi GOT products. The vulnerability is self-reported. Mitsubishi provides generic mitigation measures pending development of an updated version.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow an attacker to gain unauthorized access.

Horner Advisory

This advisory describes two vulnerabilities in the Horner Automation Cscape control system application programming software. The vulnerabilities were reported by Sharon Brizinov of Claroty. Horner has a new version that mitigates the vulnerability. There is no indication that Brizinov has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper input validation - CVE-2021-22678, and

• Improper access control - CVE-2021-22682

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerability to allow code execution in the context of the current process or locally escalate privileges.

Source of CPE Numbers

There was an interesting Twitversation yesterday about CPE numbers. It started with Ron Brash complaining about the Rockwell advisory that I talked about Tuesday. I contributed a less than helpful comment because I ‘read’ his comment as being about CVE numbers not CPE’s. That misunderstanding caused me to do some research into Ron’s complaint.

What’s a CPE?

First, let’s look at the better known ‘CVE’, Common Vulnerabilities and Exposures. The CVE is actually a list of vulnerabilities maintained by MITRE. In common use ‘a CVE’ is the unique, numbered record for a specific vulnerability. The National Institute of Standards and Technology (NIST) maintains a database of the CVE list called the National Vulnerability Database (NVD).

To make it easy for organizations to determine what CVE’s apply to a particular piece of software, NIST developed the Common Platform Enumeration (CPE) Dictionary. This allows for the creation of a unique standard identifier (CPE number) for any specific version of any piece of listed software. This allows for searching of the NVD for vulnerabilities related to that specific version without having to worry about how to type in the name and version number of the software of concern with all of the I’s dotted and T’s crossed, a common problem in database searches.

NIST maintains a CPE dictionary to aid users in finding the proper CPE number for their searches.

CPE and CVE Relationship

To see how the CVE’s and CPE’s work in practice let’s look at one of the vulnerabilities Rob was complaining about. The NCCIC-ICS advisory for the Rockwell Automation Stratix Switches lists eight vulnerabilities in five separate Stratix products affecting a number of different versions of each product. The first of the eight is an insufficiently protected credentials vulnerability - CVE-2021-1392. If we look a the NVD record for that vulnerability.

Today we see that the vulnerability is in certain products from CISCO with no mention of Rockwell Automation. In the coming days we should (hopefully) see the addition of a reference to the Rockwell advisory from NCCIC-ICS under the ‘References to Advisories, Solutions, and Tools’ heading on the page.

Down towards the bottom of the page we see the ‘Known Affected Software Configurations’ section, a listing of CPE’s of individual versions of affected software. For this particular CVE there are 214 CPE’s listed. And as Rob noted in his initial TWEET yesterday, not a single Rockwell product is listed.

The Problem

The CVE Numbering Authority (CNA) reporting the vulnerability to MITRE/NVD is responsible for submitting all of the requisite information for the CVE. Presumably, this includes the affected CPE’s. In this case the CNA for CVE-2021-1392 is CISCO. While CISCO notified Rockwell of the vulnerability, they have no idea about which versions of which Rockwell products would be affected by that particular CVE, so they cannot provide the CPE’s of those affected Rockwell products. CISA’s NCCIC-ICS, the agency issuing the new advisory should be providing the Rockwell unique information including CPE’s.

Ooops. The MITRE CNA rules for CVE Entry Requirements do not say anything about CPE’s. Of course, this is because CPE’s are an NVD artifact, not technically part of the CVE process. So, somebody should be communicating with NIST/NVD and it still could not and should not be CISCO in this case. The reporting body should still be CISA’s NCCIC-ICS that published the Rockwell advisory.

I cannot tell from the outside if this is a failure of NCCIC-ICS to report information to NIST/NVD (if there even is a requirement/mechanism for such a report), or if this is a data processing backlog at NIST/NVD. Remember COVID-19 has messed up a lot of admin stuff and it will take a while to recover.

Easy Solution – New CVEs

The easy way to fix this going forward is that instead of re-using the CVE’s for the CISCO vulnerabilities, NCCIC-ICS should have just issued new CVE’s for the Rockwell vulnerabilities. The system for assigning CPE’s for new vulnerabilities appears to be working fine; simple. After all, CISCO fixing their vulnerability does not directly fix the Rockwell problem, Rockwell is going to have to make some sort of change to implement the CISCO fix.

There is a minor drawback to that solution. To understand it we need to look at my blog post from March 18th, 2020 where I discussed another set of third-party vulnerabilities in the eSOMS product from Hitachi ABB Power Grids. Again, the NCCIC-ICS advisory used the original CVE numbers for the seven vulnerabilities in the Hitachi ABB product. Using those CVE’s, I was able to determine that there were publicly available exploits for three of the vulnerabilities, raising their potential risk. Without the link to the original CVE, I would have had a much harder time tracking down those exploits.

As Ron pointed out in a subsequent TWEET®, software bills of material will provide a longer term solution to the problem. A software vendor could provide CPE’s for each of the components that are included in their software and an owner/operator could search for both the component and end product CPE’s to remain aware of potential vulnerabilities in their software. But, again, this relies on CNA’s, MITRE and NIST/NVD all ensuring that the appropriate CPE’s get into the databases.

WARNING: My twisted mind has come up with other potential problems with CPE’s. More on that later.

NOTE: Corrected Ron's name (sigh) 4-22-21 2032 EDT

Wednesday, April 21, 2021

Reader Comment – IOD from the Inside

An interesting comment over on LinkedIn about yesterday’s blog post on CISA’s Integrated Operations Division. The commentor is Wade W. Gough, a senior chemical security inspector with the Chemical Facility Anti-Terrorism Standards (CFATS) program. His insider-based feedback is always welcomed. He notes:

“Great discussion on our inner workings. Having worked in more complex environments under more competing command authorities, this hasn’t been an issue to me as IOD understands very well the regulatory nature of CFATS. With that & in my experience, working in a Regional office with IOD has plusses & some neagtives but nothing I would describe as a conflict or real concern & certainly nothing that conflicts w/ the CFATS program & its ability to do its job.”

I would not read too much into his ‘plusses and some negatives’ comment. There is no such thing as a perfect organization, and it is well known that DHS as a whole has had more than its share of negative feedback from its employees over the years. It is, however, heartening to hear that he has not seen anything that “conflicts w/ the CFATS program & its ability to do its job.” He obviously cannot publicly complain too much about agency operations while being publicly identified as a CSI, but there is no reason to question his unsolicited positive comments.

I do stand by my suggestion, however, that this is an organizational situation that is ripe with potential for conflicts. While good people with honorable intentions will certainly be able to make the system work, a single person with a conflicting agenda or a need for personal power could cause all sorts of problems in this type of situation. Again, someone outside of the two agencies needs to keep a periodic eye on the situation to ensure nothing untoward happens. The CFATS program had enough management problems in its early years, it does not need any new organizational blemishes.

Bills Introduced – 4-20-21

Yesterday, with both the House and Senate in session, there were 100 bills introduced. Two of those bills may receive additional coverage in this blog:

HR 2685 To direct the Assistant Secretary of Commerce for Communications and Information to submit to Congress a report examining the cybersecurity of mobile service networks, and for other purposes. Rep. Eshoo, Anna G. [D-CA-18] 

HR 2697 To establish a task force on developing a 21st century surface transportation workforce, and for other purposes. Rep. Langevin, James R. [D-RI-2]

I will be watching HR 2685 for language and definitions that would require the report to address 5G communications used to support IoT and IIoT devices.

I will be watching HR 2697 for language and definitions that would specifically address transportation security and/or cybersecurity training requirements.

Tuesday, April 20, 2021

House Passes HR 397 - CBRN Intelligence and Information Sharing Act of 2021

Today the House finished their consideration of HR 397, the CBRN Intelligence and Information Sharing Act of 2021, in an unusual ‘bulk’ vote on 15 bills that were debated yesterday under the House suspension of the rules process. The bulk vote required a 2/3 super majority for passage and was passed with a significantly bipartisan 355 to 69. That is the same 2/3 majority that would have been required on a typical suspension of the rules vote on HR 397.

Elements of the Republican party demanded votes on each of the bills when they were considered yesterday. This has been a common occurrence in the 117th Congress as more radical elements of the minority party have made a concerted effort to slow the operation of the House to keep the Democrats from completing their agenda.

The one vote for 15 bills process was outlined as a one-time effort by the House Rules Committee in their rule (H Res 330) for the consideration of three other bills being considered under normal order. That resolution passed by a straight party-line vote as do most rule resolutions when the bills to be considered under the rule are partisan bills.

While the Democrats have demonstrated a readily repeatable technique to counter the radical Republican delay tactics, the protestors countered with another unusual parliamentary delaying tactic. When the proforma motion to ‘reconsider’ the vote was offered, the standard reply to table the motion was made. Normally that motion to table is agreed to in a voice vote, but in this case Rep Biggs (R,AZ) demanded a recorded vote. That recorded vote was postponed until tomorrow. Technically, that vote could lead to invalidating today’s vote on the 15-bills, but it is highly unlikely. But, it will take up time on the floor of the House tomorrow, and that was the point of the exercise.

HR 397 will be sent to the Senate. It could be considered there under the Senate’s unanimous consent process with no debate and no amendments. One Senator, could stop that proceeding by objecting to the consideration of the bill, and that objection would not have to have anything to do with the provisions in the bill. The bill would not make it to the floor of the Senate under regular order; it is not important enough to take up the Senate’s time with debate and an amendment process.

7 Advisories and 3 Updates Published – 4-20-21

Today CISA’s NCCIC-ICS published seven control system security advisories for products from Siemens, Eaton, Delta Electronics (2), Delta Industrial, Rockwell Automation, and Hitachi ABB Power Grids. They also published three control system security updates for products from Siemens, Mitsubishi and Hitachi ABB.

Siemens Advisory

This advisory describes an improper privilege management vulnerability in the Siemens sold Mendix products. This is a third-party (Mendix) vulnerability. Siemens has new versions for some of their affected products.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to  allow a non-administrative user to gain administrative privileges.

NOTE: I reported on this out-of-zone advisory by Siemens last Thursday.

Eaton Advisory

This advisory describes six vulnerabilities in the Eaton Intelligent Power Manager (IPM). The vulnerabilities were reported by Amir Preminger from Claroty. Eaton has a new version that mitigates the vulnerabilities. There is no indication that Preminger has been provided an opportunity to verify the efficacy of the fix.

The six vulnerabilities reported are:

• SQL injection - CVE-2021-23276,

• Eval injection - CVE-2021-23277,

• Improper input validation (2) - CVE-2021-23278 and CVE-2021-23279,

• Unrestricted upload of file with dangerous type - CVE-2021-23280, and

• Code injection - CVE-2021-23281

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow attackers to change certain settings, upload code, delete files, or execute commands.

CNCSoft-B Advisory

This advisory describes two vulnerabilities in the Delta Electronics CNCSoft-B. The vulnerability was reported by Natnael Samson via the Zero Day Initiative. Delta has an updated version that mitigates the vulnerability. There is no indication that Samson has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Out-of-bounds read - CVE-2021-22660, and

• Out-of-bounds write - CVE-2021-22664

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerability to lead to arbitrary code execution.

CNSSoft Advisory

This advisory describes an out-of-bounds read vulnerability in the Delta Electronics CNCSoft ScreenEditor. The vulnerability was reported by Natnael Samson via ZDI. Delta has an updated version that mitigates the vulnerability. There is no indication that Samson has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerability to allow arbitrary code execution.

Delta Industrial Advisory

This advisory describes a stack-based buffer overflow vulnerability in the Delta Industrial Automation COMMGR communication management software, and accompanying PLC simulators. The vulnerability was reported by Peter Cheng from CyberSpace Non-Attack Research Institute of Elex CyberSecurity. Delta has a new version that mitigates the vulnerability. There is no indication than Cheng has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulenrabilty to allow for remote code execution or cause the application to crash, resulting in a denial-of-service condition in the application server.

Rockwell Advisory

This advisory describes eight vulnerabilities in the Rockwell Stratix Switches. These are third-party vulnerabilities (Cisco). Rockwell has new versions that mitigate the vulnerabilities.

The eight reported vulnerabilities are:

• Insufficiently protected credentials - CVE-2021-1392,

• Insufficient verification of data authenticity - CVE-2021-1403,

• Use of out-of-range pointer offset - CVE-2021-1352,

• Insertion of sensitive information into log file - CVE-2021-1442,

• OS command injection - CVE-2021-1452,

• Command injection - CVE-2021-1443, and

• Improper input validation (2) - CVE-2021-1220 and CVE-2021-1356

NOTE 1: Links above are to the Cisco advisories.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to result in denial-of-service conditions, unauthorized privilege escalation, web socket hijacking, relative path traversal, or command injection.

NOTE 2: I briefly reported on these vulnerabilities back in March.

Hitachi ABB Advisory

This advisory describes a cross-site scripting vulnerability in the Hitachi ABB Ellipse APM. The vulnerability is self-reported. Hitachi ABB has new versions that mitigate the vulnerabilty.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an authenticated user or integrated application to inject malicious data into the application that can then be executed in a victim’s browser.

Siemens Update

This update provides additional information on an advisory that was originally published on March 10th, 2020. The new information includes:

• Adding a partial solution for SiNVR/SiVMS Video Server, and

• Removing information for Control Center Server (CCS), which is now addressed in SSA-761844

NOTE: I briefly reported on the Siemens update on Sunday.

Mitsubishi Update

This update provides additional information on an advisory that was originally published on June 9th, 2020 and most recently updated on November 5th, 2020. The new information includes clarifying in the vulnerability overview that the resource exhaustion is effected at the Ethernet port by sending a

specially crafted packet.

Hitachi ABB Update

This update provides additional information on an advisory that was originally published on April 6th, 2021. The new information includes updating affected versions and providing mitigation measures for Relion 670 series version 2.0. Hitachi ABB updated their advisory.

 
/* Use this with templates/template-twocol.html */