Wednesday, May 12, 2021

Bills Introduced – 5-11-21

Yesterday, with both the House and Senate in session, there were 92 bills introduced. One of those bills will receive additional coverage in this blog:

HR 3078 To require the Secretary of Energy to carry out a program relating to physical security and cybersecurity for pipelines and liquefied natural gas facilities. Rep. Upton, Fred [R-MI-6]

Looks like Upton has been thinking about this for a while, either that or his staff is really good at throwing legislation together quickly. One bad thing about relying on DOE for pipeline security oversight is that they would only have a mandate on crude and fuel pipelines, leaving the hazardous chemical pipelines in the same lax oversight (from a security perspective) regime that got Colonial Pipeline into trouble.

I would like to mention in passing a resolution that was also introduced yesterday. I know that there will be some interested readers, so I will probably mention process highlights for this legislation, but I will not be reviewing it in any depth.

H Res 383 Recognizing the 50th anniversary of the National Association of Chemical Distributors. Rep. Moolenaar, John R. [R-MI-4]

Tuesday, May 11, 2021

15 Advisories Published – 5-11-21

Today CISA’s NCCIC-ICS published fifteen control system security advisories for products from Siemens (13), Mitsubishi, and Omron. NCCIC-ICS also published six updates today, I will cover them in a separate blog post tomorrow.

SIMATIC Advisory #1

This advisory describes two vulnerabilities in the Siemens SIMATIC S7-1500 CPU 1518F-4. These are third-party (Intel) vulnerabilities. Siemens provides generic work arounds to mitigate the vulnerabilities.

The two reported vulnerabilities are:

• Improper initialization - CVE-2020-8744, and

• Improper restriction of operation within the bound of a memory buffer - CVE-2020-0591

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to allow unauthorized privilege escalation.

SCALANCE Advisory #1

This advisory describes 19 vulnerabilities in the Siemens SCALANCE W1750D. These are third-party vulnerabilities (Aruba Instant Access Points). Siemens has a new version that mitigates the vulnerabilities.

The 19 vulnerabilities are:

• Improper authentication (2) - CVE-2019-5317 and CVE-2021-25143,

• Classic buffer overflow (3) - CVE-2019-5319, CVE-2021-25144, and CVE-2021-25149,

• Command injection (5) - CVE-2020-24635, CVE-2020-24636, CVE-2021-25146, CVE-2021-25150, and CVE-2021-25162,

• Improper input validation (7) - CVE-2021-25145, CVE-2021-25148, CVE-2021-25155, CVE-2021-25156, CVE-2021-25157, CVE-2021-25159, and CVE-2021-25160,

• Race condition - CVE-2021-25158, and

• Cross-site scripting - CVE-2021-25161

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to execute arbitrary code as a privileged user on the underlying operating system, fully compromise the underlying operating system, overwrite sensitive system files, create a denial-of-service condition, execute arbitrary script code in a victim’s browser, read arbitrary files off the underlying file system, create an attacker named directory, corrupt backup files, or obtain sensitive information.

NOTE: I briefly discussed the Aruba vulnerabilities back in March.

SINAMICS Advisory #1

This advisory describes a missing authentication for critical function in the Siemens SINAMICS Medium Voltage Products. This vulnerability is self-reported. Siemens has new versions that mitigate the vulnerablity.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow an attacker to gain full remote access to the HMI.

NOTE: This same Telnet service vulnerability was reported in the Siemens SIMATIC HMI Comfort Panels back in February.

SIMATIC Advisory #2

This advisory describes seven vulnerabilities in the Siemens SIMATIC HMIs/WinCC products. These are third-party (SmartVNC) vulnerabilities. Siemens has updates that mitigate the vulnerabilities. Siemens has updates that mitigate the vulnerabilities.

The seven reported vulnerabilities are:

• Access of memory location after end of buffer (3) - CVE-2021-25660, CVE-2021-25661, and CVE-2021-27384,

• Improper handling of exceptional conditions - CVE-2021-25662,

• Improper restriction of operations within the bounds of a memory buffer (2) - CVE-2021-27383 and CVE-2021-27386,

• Uncontrolled resource consumption - CVE-2021-27385,

NCCIC-ICS reported that an uncharacterized attacker could remotely exploit the vulnerabilities to allow remote code execution, information disclosure and denial of service attacks under certain conditions.

SIMATIC Advisory #3

This advisory describes ten vulnerabilities in the Siemens SIMATIC HMIs/WinCC Products. These are third party (UltraVNC) vulnerabilities. Siemens has updates that mitigate the vulnerabilities.

The ten reported vulnerabilities are:

• Improper initialization (2) - CVE-2019-8259 and CVE-2019-8277,

• Out-of-bounds read (2) - CVE-2019-8260 and CVE-2019-8261,

• Heap-based buffer overflow - CVE-2019-8262,  

• Stack-based buffer overflow - CVE-2019-8263,

• Access memory location after buffer (3) - CVE-2019-8264, CVE-2019-8265, and CVE-2019-8280,

• Improper null termination - CVE-2019-8275,

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow remote code execution, information disclosure, and denial-of-service attacks under certain conditions.

NOTE: These vulnerabilities were reported in the Siemens SINUMERIK products back in June of 2020. That advisory included 22 vulnerabilities.

SCALANCE Advisory #2

This advisory describes an incorrect calculation vulnerability in the Siemens SCALANCE XM-400, XR-500 products. The vulnerability is self-reported. Siemens has updates available that mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an unauthenticated remote attacker to create a permanent denial-of-service condition.

Mendix Advisory #1

This advisory describes a generation of error message containing sensitive information in the Siemens Mendix Excel Importer. The vulnerability is self-reported. Mendix has an update that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to  expose information to unauthorized parties.

Tecnomatix Advisory

This advisory describes three vulnerabilities in the Siemens Tecnomatix Plant Simulation. The vulnerabilities were reported by Francis Provencher via the Zero Day Initiative. Siemens has a new version that mitigates the vulnerabilities.

The three reported vulnerabilities are:

•Stack-based buffer overflow - CVE-2021-27396 and CVE-2021-27398, and

• Improper restriction of operations within the bounds of a memory buffer - CVE-2021-27397

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to lead to arbitrary code execution.

SIMATIC Advisory #4

This advisory describes an uncontrolled resource consumption vulnerability in the Siemens SIMATIC CP343-1 devices. The vulnerability is self-reported. Siemens has provided a generic workaround to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a denial-of-service condition.

SNMP Implementation Advisory

This advisory describes an out-of-bounds write vulnerability in the Siemens SNMP Implementation of WinCC Runtime. The vulnerability was reported by Younes Dragoni and Alessandro Di Pinto of Nozomi Networks. Siemens has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to crash the SNMP service and require a manual restart of the device to resume operation of the service.

NOTE: Someone has been holding onto this vulnerability (CVE-2019-19276) for a while because there is no listing for it in either the NIST or Mitre databases.

Mendix Advisory #2

This advisory describes a generation of error message containing sensitive information vulnerability in the Siemens Mendix Database Replication Module. The vulnerability is self-reported. Mendix has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to  gain access to sensitive information.

SINAMCS Advisory #2

This advisory describes a missing authentication for critical function vulnerability in the Siemens SINAMICS Medium Voltage Products. The vulnerability is self-reported. Siemens has a new version that mitigates the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit this vulnerability to gain full remote access to the HMI.

NOTE: The Siemens advisory (SSA-752103) mentioned in this advisory does not correspond to the CVE reported by NCCIC-ICS. In fact, the Siemens advisory CVE corresponds to ICSA-21-131-13 reported in SINAMICS Advisory #1 above which also references SSA-752103. None of the other Siemens’ advisories published today report CVE-2021-31337 that is being reported by NCCIC-ICS in this advisory, and that CVE appears to be well out of the current NCCIC-ICS CVE sequence. I am not sure what is going on here.

Siemens Linux Advisory  

This advisory describes a use of insufficiently random variables vulnerability in the Siemens Linux based products. This is the Sad DNS vulnerability and proof-of-concept code is available on the report site. Siemens has updates available to mitigate the vulnerability in some of the affected products.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit this vulnerability to compromise confidentiality and integrity.

NOTE: Siemens has previously added CVE for this vulnerability to their generic GNU/Linux subsystem advisory.

Mitsubishi Advisory

This advisory describes a buffer access with incorrect length vulnerability in the Mitsubishi GOT and Tension Controller. The vulnerability was reported by Parul Sindhwad and Dr. Faruk Kazi of COE-CNDS Lab, VJTI, Mumbai, India. Mitsubishi has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to to stop the communication function of the products, requiring a reset to regain functionality.

Omron Advisory

This advisory describes a stack-based buffer overflow in the Omron CX-One automation software suite. The vulnerability was reported by rgod via ZDI. Omron has an updated version that mitigates the vulnerability. There is no indication that rgod has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to may allow arbitrary code execution.

Other Advisories

Siemens published one other advisory today that was not reported by NCCIC-ICS. If it is not covered Thursday by NCCIC-ICS then I will discuss it this weekend.

Monday, May 10, 2021

S 1350 Introduced - National Risk Management Act

Last month Sen Hassan (D,NH) introduced S 1350, the National Risk Management Act of 2021. The bill would require CISA to “establish a process by which to identify, assess, and prioritize risks to critical infrastructure, considering both cyber and physical threats, vulnerabilities, and consequences” {new §2218(b)(1)(A). The bill adds a new §2218, National Risk Management Cycle, to the Homeland Security Act of 2002.

NOTE: This review is based upon a submission draft of the bill from Hassan’s web site. An official GPO version of the bill is not yet available. See my blog post about that publication delay problem.

Definitions

Section 2218(a) provides the key definition for the Section. Two terms are defined:

• Critical infrastructure, and

• National critical functions

The first is defined by reference to 42 USC 5195c(e). The term ‘national critical functions’ is similarly defined as {new §2218(a)(2)}:

The functions of government and the private sector so vital to the United States that their disruption, corruption, or dysfunction would have a debilitating effect on security, national economic security, national public health or safety, or any combination thereof.

National Risk Management Cycle

Subsection (b)(1) requires CISA to establish “a process by which to identify, assess, and prioritize risks to critical infrastructure, considering both cyber and physical threats, vulnerabilities, and consequences”. The process will include CISA consultation with “Sector Risk Management Agencies, critical infrastructure owners and operators, and the National Cyber Director” {new §2218(b)(1)(B)}. The process will be publicly reported in the Federal Register within 180 days of the enactment of this bill.

National Critical Infrastructure Resilience Strategy

Subsection (b)(2) requires the President to submit to Congress a national critical infrastructure resilience strategy designed to address the risks identified above. In the submitted strategy, the President will {new §2218(b)(2)(B):

• Identify, assess, and prioritize areas of risk to critical infrastructure that would compromise, disrupt, or impede their ability to support the national critical functions of national security, economic security, or public health and safety,

• Assess the implementation of the previous national critical infrastructure resilience strategy, as applicable,

• Identify and outline current and proposed national-level actions, programs, and efforts to be taken to address the risks identified,

• Identify the Federal departments or agencies responsible for leading each national-level action, program, or effort and the relevant critical infrastructure sectors for each,

• Outline the budget plan required to provide sufficient resources to successfully execute the full range of activities proposed or described by the strategy, and

• Request any additional authorities or resources necessary to successfully execute the strategy.

Moving Forward

As I mentioned earlier today, S 1350 will be considered by the Senate Homeland Security and Governmental Affairs Committee during a business meeting on Wednesday. This almost certainly means that there will be significant bipartisan support for the bill in Committee.

The problem will be moving the bill to the floor of the Senate. Last year I would have said that this would not be an important enough bill to be considered on the floor under regular order. The extended debate, amendment and cloture process takes up a lot of the Senate’s limited floor time. This is especially true early in an Administration when so much of the Senate efforts are expended in providing advice and consent on political appointees. Typically, I would have said that this bill would have to run the risks of the unanimous consent process; the risk being that a single Senator could stop consideration of the bill.

This year with the ghosts of the SolarWind and Microsoft Server attacks and the ongoing problems with the ransomware attack on Colonial Pipeline, there might be some serious pressure to bring this bill to the floor. It could end up being the vessel for containing the increasing political pressures to do something about the national cybersecurity problem. The problem then would be for the fractured Senate leadership to keep some modicum of control over the amendment process.

Commentary

This bill is very broadly written and that was certainly the intent. The crafters wanted to give CISA and the President the greatest leeway to define a frequently changing problem and provide congress with specific proposals to Congress for future lawmaking efforts to support solving the problem. In general, I support this process.

Having said that, there is a glaring disconnect between the risk identification process and the national response process. The first cause of this is the failure to limit the risk identification process to just those areas where the national government can have a direct impact on risk mitigation. The Federal government cannot afford the people, time or money to address all of the risks faced by the critical infrastructure in the United States. Fortunately, the second definition in §2218(a) provides a reasonable means for limiting that risk assessment process. I would make the following revisions to §2218(b)(1)(A):

‘‘(A) IN GENERAL.—The Secretary, acting through the Director, shall establish a process by which to identify, assess, and prioritize risks to critical infrastructure, considering both cyber and physical threats, vulnerabilities, and consequences.:

“(i) establish a process by which to identify, assess, and prioritize risks to critical infrastructure that would be expected to impact national critical functions, and

“(ii) consider both cyber and physical threats, vulnerabilities, and consequences.”

The second part of the problem is the failure to identify those mitigation and resiliency measures that ought to be the sole responsibility of the critical infrastructure owner/operators (including in some instances State, local and Tribal governments). To that end, I would add an additional subparagraph to (A) above:

“(iii) identify the necessary minimum self-protection measures and reporting requirements that a critical infrastructure facility should be expected to implement to help reduce the risks identified in this Section.”

Update for Senate HSGA Markup – 5-12-21

The Senate.gov website now lists the bills that will be marked up by the Senate Homeland Security and Governmental Affairs Committee on Wednesday. The thirteen bills scheduled include four cybersecurity related measures:

S 1097, to establish a Federal rotational cyber workforce program for the Federal cyber workforce {Sen. Peters, (D,MI)}

S 1316, to amend the Homeland Security Act of 2002 to authorize the Secretary of Homeland Security to make a declaration of a significant incident {Sen. Peters, (D,MI)},

S 1324, to establish a Civilian Cyber Security Reserve as a pilot project to address the cyber security needs for the United States with respect to national security {Sen Rosen (D,NV)}, and

S 1350, to require the Secretary of Homeland Security to establish a national risk management cycle {Sen Hassan (D,NH)},

The GPO has not yet published official versions of any of these bills, nor can I find them posted to the HSGA web site. Hassan’s web site does have a submission draft copy posted for S 1350, the ‘National Risk Management Act of 2021. I will have a detailed review of that bill, based upon that draft available later this evening. We may see S 1097 published this evening, but I doubt the GPO will get to S 1316 or S 1324 before Wednesday morning.

Committee Hearings – Week of 5-9-21

This week with both the House and Senate back in Washington, there is a full slate of congressional hearings scheduled. There is one markup hearing that may be of interest, and there are two cybersecurity hearings planned, neither deal with ransomware or the Colonial Pipeline hack. These things take some time to set up, so that is not unexpected. There is an outside chance of a hearing on those topics being added later this week.

Markup Hearing

The Senate Homeland Security and Governmental Affairs Committee will be holding a business meeting on Wednesday. There is no agenda available at this time, but I will be keeping an eye on this time slot.

Cybersecurity Hearings

Tomorrow the Senate Homeland Security and Governmental Affairs Committee will be holding a hearing on “Prevention, Response, and Recovery: Improving Federal Cybersecurity Post-SolarWinds”. The witness list includes:

• Brandon Wales, CISA,

• Ryan A. Higgins, DOC,

• Janet Vogel, HHS

On Friday the Subcommittee on Cyber, Innovative Technologies, and Information Systems of the House Armed Services Committee will be holding a hearing on “Operations in Cyberspace and Building Cyber Capabilities Across the Department of Defense”. The short witness list includes:

• Mieke Eoyang, DOD, and

• General Paul Nakasone, Cyber Command

For both hearings there may be questions about ransomware, Colonial Pipeline, and support for critical infrastructure, but at this point it would be political point making questions. I would not expect any responses of substance, it is too early in the game.

Sunday, May 9, 2021

Pipeline Cybersecurity – The Colonial Ransomware Attack

While it is still early in the investigation, the ransomware attack on the Colonial Pipeline IT systems has had a definite impact on the operation of their East Coast pipeline. Apparently, the control systems involved in the control of the pipeline were not directly affected, but the company shutdown those systems to prevent the attackers from pivoting into the industrial control system networks. An excellent article (to be expected, certainly) from Kim Zetter points out the reasons that the two networks (IT and OT) are connected.

IT-OT Connection Risk Assessment

Pipeline managers have to make the risk assessment about how much interconnection there should be between their IT and OT networks. This attack may (probably not) make some managers change their risk assessments and disconnect the two networks.

Pivoting from the corporate IT networks to the operational networks needs to be difficult. Colonial apparently had controls in place to help prevent that move. They also realized that the longer the attacker was present in their IT networks, the more likely it would be that a route bypassing the security measures in place would be found. Shutting down the control systems until the IT attack could be remediated was a prudent act.

But, as this ransomware epidemic (yes, I used ‘that’ word) is showing the world, corporate IT networks are increasingly vulnerable to this attack methodology. And we are increasingly seeing that the IT/OT nexus has allowed control system networks to become targetable for ransomware attack.

Old Fashioned Air-Gap Security

If the system had been designed to allow for physical network segregation while continuing operation, the effect of the ransomware attack would not be as drastic as the East Coast may be facing in the coming days. Completely air gapping a pipeline control system is probably not possible. Sensors, valves, pumps and other equipment along the length of the pipeline all needs central oversight and control. This means that communications between all of the components of the pipeline control system must exist. And those communications nodes must be adequately protected.

Companies need to be able to physically isolate their control systems from the IT network. This would allow them to continue manufacturing and/or transportation activities while it was working to remediate the ransomware problems on the IT networks. Thus companies could continue money making operations while they worked on their other problems.

Cybersecurity Regulations

I have said before (see here for example) that the federal government has to be careful about what operations they try to regulate for the purpose of protecting control systems from outsider attack. There is simply not enough money or qualified workers available to regulate every control system in the United States. The government does have an interest, however, in overseeing the safety and security of critical infrastructure like fuel pipelines and that should probably include regulating cybersecurity of those facilities so that the populous can rely on the timely delivery of that fuel.

TSA is the agency that is responsible for overseeing the security (including cybersecurity) of pipelines. It is easy to fault TSA for lax oversight, but in truth Congress has been very slow to provide TSA with any specific regulatory authority over cybersecurity of these pipelines. That means that any specific cybersecurity requirements are going to have to go through the legislative process before TSA can start crafting any real regulations.

I would like to suggest that Congress consider (probably as part of their annual pipeline oversight authorization bill) requiring that TSA prepare a regulation for pipeline control systems requiring that they are able to be physically isolated from corporate IT networks when there are indications of a cyber attack (probably should specifically include ransomware attacks) on the IT networks.

Saturday, May 8, 2021

OMB Approves Limited Recreational UAS Operations ANPRM

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a ‘Notice’ (presumably an advanced notice of proposed rulemaking?) on the FAA’s  “Exception for Limited Recreational Operations of Unmanned Aircraft”. This rulemaking was not listed in the Fall 2020 Unified Agenda. The notice was sent to OIRA in November of last year.

 
/* Use this with templates/template-twocol.html */