Tuesday, May 4, 2021

2 Advisories Published – 5-4-21

Today CISA’s NCCIC-ICS published two control system security advisories for products from Delta Electronics and Advantech.

Delta Advisory

This advisory describes an out-of-bounds write vulnerability in the Delta CNCSoft ScreenEditor. The vulnerability was reported by kimiya via the Zero Day Initiative. Delta has an updated version that mitigates the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to crash the device, and an out-of-bounds write may allow remote code execution.

Advantech Advisory

This advisory describes a use of hard-coded credentials vulnerability in the Advantech WISE-PaaS/RMM products. The vulnerability was reported by Chizuru Toyama of TXOne IoT/ICS Security Research Labs via ZDI. Advantech considers the product end-of-life and offers no mitigation measures beyond replacing the device.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to  allow an attacker to obtain sensitive information.

GPO Behind the 8-Ball

Yesterday in my post about the introduction of HR 1607, I noted that there was a problem with the printing of the official language of introduced bills. I would like to take this opportunity to look into the problem in a little more depth.

The Problem

As of 09:50 EDT today a search of the Congress.gov web site shows that these are the latest bills that have had language published:

• HR 1605 (introduced 3-8-21) and

• S 1072 (introduced 4-12-21)

There may be isolated bills that have text available that were introduced later, but that is typically done when the bill is considered ‘politically important’ and are scheduled to be considered in the respective house of Congress where it was introduced. Similarly, there are earlier bills for which the text is not yet available, but that generally reflects a problem with the text submitted to the GPO which that organization is attempting to resolve with the appropriate staff.

As of last Friday (the last day that bills were introduced) the House had introduced 2952 bills and the Senate 1527.

When a bill has been introduced, but does not yet have text available the following notice is printed on the Congress.gov page for that bill (here from S 1073):

“Bills are generally sent to the Library of Congress [the owners of the Congress.gov site] from GPO, the Government Publishing Office, a day or two after they are introduced on the floor of the House or Senate. Delays can occur when there are a large number of bills to prepare or when a very large bill has to be printed.”

Before the advent of the pandemic last year that ‘day or two’ (which should more appropriately be ‘a business day or two’) had slipped a bit to three or four days on all but the rarest occasions.

The Cause?

As I mentioned yesterday, part of the problem is obviously the pandemic, but it is not clear exactly how that is causing the problem. I suspect that the GPO editors that are responsible for converting the text documents (all should be electronic documents, so this should not be an typing issue) provided by the introducing congresscritter’s staff into official .txt and .pdf documents are working from home. There could be a productivity issue here, but no one is (or probably should be) complaining about that issue given the pandemic. Another part of the working from home problem could be a bandwidth issue related to so many folks working from home in the greater DC area. That could delay both research and document transmission; this should not be a significant delay on a per document basis, but it could contribute to the overall problem.

I suspect (no data available that I can see) that a significant part of the problem was the draw down in employees in the executive branch over the last four years. Part of this was a direct result of Trump’s intent to ‘drain the swamp’. At the document editor level in the GPO, this should not have been a direct problem, editors have little effect on policy. There could have been a daisy chain effect as we saw in may agencies. With executive appointed positions staying empty for so long, there were a lot of people moved up the chain to fill in as acting whatevers. This reached down into middle and even low-level management in many cases. Again, this should not have affected editor level jobs very much, but it could have affected supervision and work allocation; that could have affected productivity.

Another part of the federal employee draw down was caused by longtime employees that saw the Trump Administration as being less than friendly to the federal workforce. For better or worse a number of agencies have reported a significant exodus of employees. I have not heard anything in this regards about the GPO, but I would not be surprised if this were part of the problem.

Consequences

Until the text of the bill becomes available, it is impossible to tell exactly what legislative action is being proposed. From time-to-time a legislator will make a copy of their draft of a bill available to the press, but that is an unusual occurrence. Even legislator press releases leave much to be desired since they usually omit critical exceptions and caveats and all of the subtle nuances of the legislation. And those press releases are becoming less common as the number of introduced bills becomes larger and larger.

If a bill is scheduled to be considered in committee before the text is published at Congress.gov, the Committee will typically post a copy of the text to Committee web site, but this may happen only a day or two before the markup is scheduled.

Friendly lobbyists may have access to draft language of bills, most frequently because they had a major hand in its crafting, but that is seldom shared with the public, less-than-friendly congresscritters or the press.

In any case, the late availability of the text of bills makes it hard to propose changes to the language that might make the bill more effective or more palatable to a larger audience.

OCS Publishes CFATS Monthly Update – April 2021

Yesterday CISA’s Office for Chemical Security (OCS) updated their CFATS Monthly Statistics page, providing continuing information about the activities of the chemical security inspectors (CSI) and the status of facilities in the Chemical Facility Anti-Terrorism Standards (CFATS) program. The figures show that OCS continues to carry out a vigorous inspection program while still operating in a COVID-19 restricted environment.

CSI Activities

The table below summarizes the CSI program activities over the last four months.

Inspection Data

Jan-21

Feb-21

Mar-21

Apr-21

Authorization Inspections

11

17

16

13

Compliance Inspections

69

97

93

128

Compliance Assistance

205

152

114

68

Compliance Audit

5

18

10

6

The total activities for last month continue to show a downward trend from the COVID-19 activities high in January and remain below the COVID-19 average. This is mainly due to the decline in the number of Compliance Assistance visits. This was certainly due to the large increase in the number of facilities with approved site security plans in March (see the table below); fewer facilities were needing help with developing their SSPs.

Facility Status

The table below shows the regulatory status of facilities in the CFATS program. The total number of facilities in the program has remained relatively stable over the last three months.

Facility Status

Jan-21

Feb-21

Mar-21

Apr-21

Tiered

103

100

86

103

Authorized

152

153

139

145

Approved

3037

3027

3057

3034

Total

3292

3280

3282

3282

This month we saw a sharp decline in the number of facilities with approved site security plans; the largest in 12 months. This could only happen if at least that number of facilities left the program. Facilities can leave the program by reducing the inventory of the DHS chemicals of interest below the screening quantity threshold by modifying their processes or product mix, or closing the plant. Even closing the plant would specifically require the removal of the COI from the facility for it to be able to leave the CFATS program.

The total number of facilities in the program at the end of the month remained the same as in March, so there must have been a large influx of new facilities. Given the post-January decline in the COVID infection rates across most of the country, I suspect that many of these new facilities were facilities that were previously in the program but had to close due to the pandemic. Those facilities will almost certainly have an easier time moving through the SSP approval process. I doubt that all of the new facilities were re-openings, so it would seem that the OCS outreach program continues to identify new facilities.

Monday, May 3, 2021

HR 1607 Introduced – HACT Act

Back in early March Rep Allred (D,TX) introduced HR 1607, the Homeland And Cyber Threat (HACT) Act. The bill would remove foreign state immunity from lawsuits brought for injuries incurred from computer intrusions by a foreign state.

NOTE: GPO finally published the language for this bill last Friday, almost two months after it was introduced. COVID has had an impact on the operations of the GPO, that is understood. I think this, however, is more than just work from home issues. We saw many government organizations loose workers during the Trump Administration. I am beginning to think that may be part of the issue here.

The Language

The bill would amend 28 USC Chapter 27, Jurisdictional Immunities of Foreign States, by adding a new §1605C. Subsection 1605C(a) would allow law suits to proceed for any of the following activities, whether occurring in the United States or a foreign state:

• Unauthorized access to or access exceeding authorization to a computer located in the United States.

• Unauthorized access to confidential, electronic stored information located in the United States.

• The transmission of a program, information, code, or command to a computer located in the United States, which, as a result of such conduct, causes damage without authorization.

• The use, dissemination, or disclosure, without consent, of any information obtained by means of any activity described in paragraph (1), (2), or (3).

• The provision of material support or resources for any activity described above, including by an official, employee, or agent of such foreign state.

Subsection 1605C(b) would limit the application of this removal of immunity “to any action pending on or filed on or after the date of the enactment of this Act.”

Moving Forward

Allred is not a member of the House Judiciary Committee, the Committee to which this bill was assigned for consideration, but five of his 26 cosponsors {Rep Correa, J. Luis (D,CA), Rep Neguse, Joe (D,CO), Rep Demings, Val Butler (D,FL), Rep Garcia, Sylvia R. (D,TX), and Rep Chabot, Steve (R,OH)} are. This means that there may be enough influence to have this bill considered in Committee.

There will be bipartisan support for this measure, but I suspect that there will also be bipartisan opposition. That opposition will be from those who would be reluctant to advance any additional changes to the Foreign Sovereign Immunities Act of 1976 which forms the basis of Chapter 27. Sovereign immunity is a staple of international law and Congress has been very careful about authorizing exceptions to that concept. How much that will affect support for this bill remains to be seen.

Commentary

The crafters of this bill have avoided most of the technical terms that have drawn my ire over the years. So, we do not have the normal concerns about terms like ‘information system’ or ‘cybersecurity risk’ or ‘control system’. They have been able to do this by focusing more on the outcome of a cyber attack than the means of the attack.

While the bill continues to use some IT focused language related to unauthorized access, there is the one paragraph that could be considered to specifically address attacks related to industrial control systems:

“The transmission of a program, information, code, or command to a computer located in the United States, which, as a result of such conduct, causes damage without authorization.”

A strict interpretation of ‘to a computer’ would, however, not seem to apply to an attack on the component levels of industrial control systems. Thus, for instance, a Stuxnet type attack on centrifuges would not technically be covered under this language. The fix would be relatively simple; change ‘command to a computer’ to read ‘command to or thru a computer’. This would tend to leave devices that could be contacted directly through a wireless communications system connection, but there would probably still be a ‘computer’ connection somewhere in the data network that would allow the definition to be used by a talented lawyer.

Arguably, the most important part of the bill is found in the new §1605C(a)(5), the ‘material support or resources’ provision. This is due to the difficulty in proving that a foreign State was the perpetrator of an attack. This allows the petitioner to make the somewhat easier proof that the State provided ‘material support’ to the organization perpetrating the attack rather than having to prove that the State directed the attack.

This bill makes no attempt to address the issue of attribution for attacks. Instead, it allows the courts unfettered authority to establish the acceptable standards for attribution. Since the bill limits the sovereign immunity exemption to civil suits, courts would be using the ‘reasonable man’ standard rather than the ‘beyond reasonable doubt’ standard used in criminal cases. Thus, we could expect to see many more civil actions than the government could be bringing in criminal cases.

No one should expect that this legislation, if passed, would have any great impact on the support in foreign capitals for cyber attacks on the United States. Some adversaries, North Korea comes immediately to mind, have little or no assets in the US that would be attachable in favorable judgements. Other countries like Iran (and probably Russia) would see such judgements as an acceptable cost of pursuing these types of attacks (as they have done with their support of terrorist organizations). But it would allow injured parties to seek and obtain some level of redress to their losses in these attacks.

Sunday, May 2, 2021

CFATS Post-Pandemic

We are getting close to the end of the COVID-19 Pandemic and all of the changes that it has wrought on the world in general and the Chemical Facility Anti-Terrorism Standards (CFATS) program in particular. What will that brave new world look like?

The End of the Pandemic

It is unlikely that the pandemic will just stop being. We are likely to see a continuing loosening of restrictions as more people get completely vaccinated. We already see a gradual decline in the vaccination rate, and it is becoming clear that we will have a relatively large segment of the population that will not accept a free vaccination for a variety of reasons.

At this point it is not clear if that anti-vax sentiment will prevent the country from reaching ‘herd immunity’. That is the point where the rapid spread of COVID-19 would no longer be possible because the likelihood of an unprotected person coming in contact with an infected person is low enough that most cases will not result in another person becoming infected.

Scientists still do not know enough about the COVID virus to be able to give us (and more importantly the government) a firm figure about how many people have to be protected (either by vaccine or previous infection) to be able to declare the pandemic over. And making the problem even more difficult the ongoing mutation of the virus is going to continue to produce new strains that will inevitably have an effect on the transmissibility of the bug. The more transmissible, the larger number of people that will have to be protected before herd immunity could be declared.

The End and CFATS

The managers for the CFATS program did not really put an awful lot of changes in place because of the pandemic. They did modify their compliance inspection regime somewhat, including adding a remove audit process. Other than that, there were not any other real programmatic changes to the CFATS process. I expect that at some point we will see the Office for Chemical Security (OCS) announce that those inspection regime changes would be terminated.

Unofficially, OCS let the covered chemical facilities know that they understood that there were going to be process modifications made by facilities to cope with the staffing issues associated with the running of their facilities. In some cases, those changes were coordinated with chemical security inspectors (CSI) and in others not. In any case OCS accepted the reality of the situation and essentially turned a blind eye when those changes had minor impacts on the site security plans (SSPs) that facilities had negotiated with DHS.

I doubt that we will see any centralized notifications that those facility led changes are no longer acceptable. Rather, I think that contact will be made by CSI and they will work with facilities to transition back to where their SSPs were before the pandemic struck.

The COVID Reality

One thing is becoming increasingly evident, COVID-19 will be with us for quite some time, if it is ever in fact eliminated. We are seeing people previously infected with the virus becoming re-infected. The rate is relatively low at this point, but how much of that is because the potential rate is low and how much is related to the protection provided by social distancing and mask wearing has yet to be determined.

Additionally, we are seeing a small number of people who were successfully vaccinated becoming infected. This is not unusual in any vaccination program. There is just too much variability in people’s immune systems to achieve 100% success rate.

As I mentioned before, we are continuing to see mutations within the virus producing different strains. So far, there has not been a strain publicly identified that is significantly changed to be able to infect large numbers of vaccinated people. It would seem inevitable, especially with the huge number of new infections that we are seeing in India and South American, that such mutations will arise. The more infections that occur, the more the virus will mutate.

All of this is going to mean that facility management is going to have to plan for local outbreaks of COVID-19, especially in areas of the country with higher non-vaccination rates. Since management has a pretty good idea of the potential effects of such outbreaks based upon their COVID experiences, they should be able to come up with a reasonable plan to respond to such outbreaks.

I would not be surprised to see OCS mandate that facilities develop a pandemic/epidemic response plan under Risk-Based Performance Standard 14, Specific Threats, Vulnerabilities, or Risks. Taking a hard look at what worked and did not work in the last year, facilities should not have too much of a problem developing such a response plan. The approved plan should be able to be implemented by the facility with notice to OCS or when directed by OCS.

Such a response plan would be developed and approved in much the same way that any revision to the facility’s SSP is done. Facilities would come up with their proposed plan and negotiate an approve through OCS. It would then become an inspectable part of their SSP during compliance inspections.

Saturday, May 1, 2021

Public ICS Disclosures – Week of 4-24-21

This week we three vendor NAME:WRECK disclosures from Boston Scientific, Braun, and Rockwell. We also have 14 vendor disclosures from Beckhoff, Bosch (2), B&R Industrial Automation, MB connect, CODESYS (5), Moxa, ODA, and Texas Instruments (2). We have five researcher reports for products from Advantech (4) and Siemens. Finally, we have exploits for products from OpenPLC and VMWare.

NAME:WRECK Advisories

Boston Scientific published an advisory discussing the NAME:WRECK vulnerabilities, announcing that they are investigating to see if any of their products are affected.

Braun published an advisory discussing the NAME:WRECK vulnerabilities, announcing that none of their ‘connected devices’ are affected.

Rockwell published an advisory discussing the NAME:WRECK vulnerabilities, providing a list of affected products and fixed versions.

Beckhoff Advisory

Beckhoff published an advisory describing an improper input validation vulnerability in their TwinCAT OPC UA Server and IPC Diagnostics UA Server. The vulnerability was reported by Industrial Control Security Laboratory of QI-ANXIN Technology Group. Beckhoff has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Bosch Advisories

Bosch published an advisory describing seven vulnerabilities in their ctrlX CORE - IDE App. These are third-party (OpenSSL and Python) vulnerabilities. The next version of the product will mitigate the vulnerabilities.

The seven reported vulnerabilities are:

• Improper encoding or escaping of output - CVE-2020-26116 (exploit),

• Inadequate information (NIST ?) - CVE-2020-27619,

• HTTP request smuggling - CVE-2021-23336 (exploit),

• Integer overflow or wraparound - CVE-2021-23840, CVE-2021-23841,

• Classic buffer overflow - CVE-2021-3177 (exploit), and

• NULL pointer dereference - CVE-2021-3449

Bosch published an advisory describing an FTP backdoor in their Rexroth Fieldbus Couplers. Bosch provides generic workarounds.

B&R Advisory

B&R published an advisory describing an uncontrolled resource consumption vulnerability in their  I/O system and HMI components. This is a third-party (Siemens) vulnerability. B&R provides generic workarounds.

MB Advisory

CERT-VDE published an advisory discussing the DNSpooq vulnerabilities in the MB connect mbNET products. MB connect has new versions that mitigate the vulnerabilities.

CODESYS Advisories

CODESYS published an advisory [.PDF download link] describing a cross-site request forgery vulnerability in their CODESYS Automation Server. The vulnerability was reported by Uri Katz of Claroty. CODESYS has a new version that mitigates this vulnerability. There is no indication that Katz has been provided an opportunity to verify the efficacy of the fix.

CODESYS published an advisory [.PDF download link] describing a NULL pointer dereference vulnerability in their CODESYS V3 products containing the CmpGateway. The vulnerability was reported by Uri Katz of Claroty. CODESYS has a new version that mitigates this vulnerability. There is no indication that Katz has been provided an opportunity to verify the efficacy of the fix.

CODESYS published an advisory [.PDF download link] describing an insufficient verification of data authenticity vulnerability in their Development System V3. The vulnerability was reported by an OEM customer. CODESYS has a new version that mitigates the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

CODESYS published an advisory [.PDF download link] describing describing an insufficient verification of data authenticity vulnerability in their Development System V3. The vulnerability was reported by Uri Katz of Claroty. CODESYS has a new version that mitigates this vulnerability. There is no indication that Katz has been provided an opportunity to verify the efficacy of the fix.

CODESYS published an advisory [.PDF download link] describing an improper input validation vulnerability in their V3 products and Control V3 Runtime System Toolkit. The vulnerability was reported by Alexander Nochvay from Kaspersky Lab ICS CERT. CODESYS has a new version that mitigates the vulnerability. There is no indication that Nochvay has been provided an opportunity to verify the efficacy of the fix.

Moxa Advisory

Moxa published an advisory describing four vulnerabilities in their NPort IA5000A Series Serial Device Servers. The vulnerability was reported by Alexander Nochvay from Kaspersky Lab ICS CERT. Moxa has a new version to mitigate one of the vulnerabilities and workarounds for the others. There is no indication that Nochvay has been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities:

• Improper access control - CVE-2020-27149,

• Unprotected storage of credentials - CVE-2020-27150,

• Cleartext transmission of sensitive information (2) - CVE-2020-27184 and CVE-2020-27185

ODA Advisory

ODA published an advisory describing an out-of-bounds write vulnerability in their Open Design Alliance Drawings SDK. ODA has a new version that mitigates the vulnerability.

NOTE: This is a very minimalist advisory.

TI Advisories

TI published an advisory discussing the BadAlloc vulnerabilities in their SimpleLink™ CC13XX, CC26XX, CC32XX and MSP432E4 products. TI provides generic work arounds for these vulnerabilities.

TI published an advisory describing an integer overflow vulnerability in their Networks Developers Kit. The vulnerability was reported by Omri Ben Bassat and David Atch of Microsoft. The product is no longer supported.

Advantech Report

The Zero Day Initiative published four reports for vulnerabilities in the Advantech WebAccess/HMI Designer products. The vulnerabilities were reported by kimiya and have been coordinated with NCCIC-ICS and an advisory from them is pending.

The four reported vulnerabilities are:

• Heap-based buffer overflow - ZDI-21-490 and ZDI-21-487,

• File parsing memory corruption- ZDI-21-489, and

• Out-of-bounds write - ZDI-21-488,

Siemens Report

ZDI published a report describing an information validation vulnerability in the Siemens JT2Go product. The vulnerability was reported by Michael DePlante. ZDI has been coordinating with NCCIC-ICS since last September.

OpenPLC Exploit

Fellipe Oliveira published an exploit for a remote code execution vulnerability in the OpenPLC product. There is no CVE provided and no indications of coordination with the vendor. This may be a 0-day vulnerability.

VMware Exploit

Egor Dimitrenko published a Metasploit module for two vulnerabilities in the VMware vRealize Operations Manager. The vulnerabilities were reported by VMware on March 31st, 2021.

The two exploited vulnerabilities are:

• Server-side request forgery - CVE-2021-21975, and

• Arbitrary file write - CVE-2021-21983


Bills Introduced – 4-30-21

Yesterday, with the House meeting in pro forma session and the Senate out of town until May 10th, there were 56 bills introduced. Two of those bills will receive additional coverage in this blog:

HR 2928 To require the Secretary of Energy to establish a voluntary Cyber Sense program to test the cybersecurity of products and technologies intended for use in the bulk-power system, and for other purposes. Rep. Latta, Robert E. [R-OH-5] 

HR 2931 To provide for certain programs and developments in the Department of Energy concerning the cybersecurity and vulnerabilities of, and physical threats to, the electric grid, and for other purposes. Rep. McNerney, Jerry [D-CA-9]

 
/* Use this with templates/template-twocol.html */