Tuesday, January 13, 2015

ICS-CERT Publishes 5 Advisories and 1 Update

It was a busy day for ICS-CERT today with four new advisories, an almost three month old advisory being publicly published and one update of an advisory that was published yesterday. Did anyone mention that S4x15 started today?

GE DNP3 Advisory

Let’s get the old advisory out of the way first. This advisory was originally published back on October 14th on the US-CERT Secure Portal. It describes a Crain-Sistrunk improper input validation vulnerability in the DNP3 implementation used by GE iFix and Cimplicity products. The implementation was produced by Catapult Software who developed a patch that mitigates the vulnerability and GE has verified the efficacy of the patch. It does not appear that Crain-Sistrunk have verified the efficacy.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to effect a DOS attack.

According to the Project Robus web site it now looks like 29 of the 30 DNP3 vulnerabilities reported by Crain-Sistrunk have now been publicly disclosed by ICS-CERT.

NOTE: There is no reason given for the unusually long delay between the US-CERT publication and the ICS-CERT public notification.

GE Multilink Advisory

This advisory describes two vulnerabilities that effect the GE Multilink line of switches. The vulnerabilities were found by Eireann Leverett of IOActive in one of the Multilink switch lines and GE notified ICS-CERT that other lines were affected as well. A firmware upgrade is available.

The two reported vulnerabilities are:

● Resource consumption vulnerability - CVE-2014-5418; and
● Hard-coded key - CVE-2014-5419

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to conduct a DOS attack or decrypt traffic. ICS-CERT reports that there is no public exploits for these specific vulnerabilities while GE restricts that claim specifically only to the ML800 switches.

Phoenix Contact Software Advisory

This advisory describes an authentication vulnerability in applications developed by Phoenix Contact Software. These applications are used by undisclosed vendors to run process control and manage IEC 61131 logic. The vulnerabilities were originally reported by Reid Wightman of Digital Bond. Phoenix Contact Software is considering developing a fix for these vulnerabilities.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to inject arbitrary commands into the protocol.

The end use product may or may not contain mitigation measures to protect against this vulnerability.

GOOD LUCK. Caveat emptor.

Clorius Controls Advisory

This advisory describes an insecure Java client web authentication vulnerability in the Clorius Controls A/S ISC SCADA server. The vulnerability was originally reported by  Aditya Sood  who has validated the efficacy of the update that has been made available.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to gain complete access to the server.

Siemens Advisory

I noted the Siemens release of their advisory about this vulnerability this morning on Twitter and am now happy to report the ICS-CERT prompt release of their advisory. It describes three separate authentication vulnerabilities in the WinCC Sm@rtClient iOS Application. The vulnerabilities were originally reported by Kim Schlyter, Seyton Bradford, and Richard Warren from FortConsult. Siemens has produced an update to mitigate the vulnerability, but there is no report that the researchers have validated its efficacy.

The vulnerabilities include:

● Insufficiently protected credentials - CVE-2014-5231 and CVE-2014-5233; and
● Improper authentication - CVE-2014-5232

ICS-CERT reports that a relatively low skilled attacker with local access to the mobile device could exploit these vulnerabilities to gain access to the application and then presumably (my guess, not mentioned in the advisory) remotely access the control system with the full rights of the mobile device owner.

CodeWrights Advisory Update

Yesterday’s advisory was updated today to clarify that while ABB is a customer of CodeWrights HART DTM  library that they have not yet verified that any of their systems are affected by the identified vulnerability. The update provides a link to the ABB security advisory page where ABB will make the notification if any systems are found to be vulnerable.

I think that it is probably safe to assume that ICS-CERT has not yet verified that any other of the potentially affected vendors listed actually have products with the vulnerabilities. They apparently made the somewhat reasonable assumption that if these vendors (including ABB) had bought the rights to use the vulnerable libraries that there products using those libraries would be affected.


I guess we will just have to wait and see. I know which way I would bet.

Pool Chemical Spills

I tend to avoid writing about pool chemical incidents. First they are so common place because the chemicals are so ubiquitous; so I would be spending an inordinate amount of time writing about these incidents. And secondly the news reporting on the incidents is almost uniformly poor that there is little to be gained by trying to analyze the incidents for lessons learned for the greater chemical handling and transportation industries.

But occasionally, the incident is bad enough and the reporting poor enough that I just can’t help myself. An incident Monday near Orlando, FL is just such a case. The local TV station reports that “a tanker was delivering chlorine to a pool supply facility when the driver accidentally pumped the chemical into a sulfuric acid tank, making ‘mustard gas’. Where to begin…

Sodium Hypochlorite

First off, while chlorine gas is used in some large swimming pools or water parks, most pool supply houses use sodium hypochlorite, essentially household bleach, just slightly more concentrated (if in liquid form). This is the favored form of chlorinating pools because it is much less dangerous than chlorine gas and does not require sophisticated handling equipment. Most home pool users are more likely to use the powdered from as it is even easier to handle safely than the liquid.

Sodium hypochlorite in either form is very reactive and has a tendency to give off chlorine gas when it does react. The most common accidents involve using it in conjunction with acids (also used in the pool treating business to adjust pH). If the acid and ‘bleach’ are added to the pool too closely together they react very quickly and the chlorine gas production is so fast that a large bubble is formed and it looks like the pool water is ‘exploding’.

The chlorine gas cloud (unless released in a confined space) is seldom really dangerous as the concentration if fairly low. It will certainly irritate the moist membranes of the eyes, nose and throat. The larger the cloud or the closer an individual is to the cloud the more severe this irritation will be. If the cloud is large enough, concentrated enough, or in a small enclosed area the chlorine gas can be lethal, but that is seldom the case.

Sulphuric Acid and Bleach

Sulfuric acid is a special case. The reaction between any acid and sodium hypochlorite is exothermic. With sulfuric acid, especially concentrated sulfuric acid the temperature rise can result in sulfuric acid fumes which are potentially more dangerous than the chlorine gas produced in the reaction. This is because the sulfuric acid is very corrosive and can cause chemical burns as well as severely irritate the lining of the eyes, nose and throat.

‘Mustard Gas’ is not produced. In fact, there is no such thing as ‘mustard gas’. Mustard agent is an oily liquid that produces blisters when it contacts the skin or other body surfaces. People that inhale mustard agent are actually inhaling droplets not a gas. Sulphur mustard is not produced from hypochlorite and sulfuric acid. It is produced by the reaction of hydrochloric acid and a chemical weapon precursor called thiodiglycol or thio-bis-ethanol.

What Probably Happened

Remember, I wasn’t there and only have the news reports and my experience as a chemist in an industrial environment to guide me, but here is what probably happened. A truck driver shows up to make a delivery of liquid sodium hypochlorite to a pool supply house. It’s raining and the driver is in a hurry and is probably not familiar with the establishment. He hooks up his hose to the sulfuric acid tank which was inadequately marked.

The hypochlorite reacts immediately with the sulfuric acid produces heat, steam, chlorine gas and sulfuric acid fumes. Fortunately the tank is adequately vented so that it does not catastrophically collapse due to over pressure. The cloud comes out of the top of the tank and immediately engulfs the driver. The cloud spreads off site and injures some passers-by. Fortunately the rain knocks down the worst of the cloud and no one, beyond perhaps the driver, is seriously injured.

Unnoticed in the story is the off-site acid contamination. If the local storm drains go to a sewage treatment plants (more and more common) then the plant has a temporary upset in its treatment process as the acid water kills off many of the bugs used to treat the sewage. If the drains lead directly to a local water way then there might have been a small fish kill associated with the incident, depending on the amount of rain that was falling. The greater the rainfall the smaller the fish kill (the old ‘dilution is the solution to pollution’ saying really is based in part on observable fact).

What Should Have Happened

A delivery driver should never be allowed to unload into a storage tank without at least someone from the facility pointing him at the proper tank. Tanks and off-loading lines should be clearly and unequivocally marked with the contents of the tank. When tanks of incompatible materials exist at the same facility they should be physically separated enough to make it extremely difficult for the reactive materials to put into the wrong tank.

A best practice is for the off-loading lines to be double locked. Two different people should provide the keys to unlock the lines before unloading can begin. Both people should independently verify the contents of the material to be off-loaded before the keys to the tanks are provided. It goes without saying that the same keys should not be able to unlock tanks of different materials.


The mixing of incompatible materials in the unloading process can be a very serious problem and is more common than chemical professionals would like to admit. In my opinion it would be the easiest form of attack on a chemical facility, especially since most delivery content checks are paperwork checks only. If the paperwork gets attached to the wrong trailer through deliberate action then the trailer will almost certainly get unloaded into the wrong tank.

NTSB Meeting on Pipeline Safety

The National Transportation Safety Board (NTSB) published a meeting notice in today’s Federal Register (80 FR 1671-1672) for a meeting in Washington, DC on January 27th, 2015. The public meeting will address the results of a recent safety study on the topic of Integrity Management of Gas Transmission Pipelines in High Consequence Areas.


The meeting will also be web cast; access will be available via the NTSB web site.

Monday, January 12, 2015

HR 240 Details

Today the House Rules Committee published the Explanatory Statement for HR 240 provided by the House Appropriations Committee. This document is the legislative equivalent of the Conference Committee Report. It provides details on the FY 2015 DHS spending bill that are not typically found in the actual bill. It is also the document that the Congress uses to provide additional direction on how the Executive Branch is expected to spend the money that Congress allocates.

CFATS Spending

The CFATS program is too small to be directly mentioned in the DHS spending bill. It is politically sensitive enough, however, to be mentioned in the Explanatory Statement. There it rates two paragraphs on page 46. The first describes the various reports that Congress expects to receive about the progress made in this program. Interestingly, these reports are not consistent with those required under the provisions of HR 4007 (which are much more detailed). It seems as if the House Appropriations Committee Staff ignored the effects of HR 4007 when they crafted this portion of their report.

The second paragraph discusses the actual funding for the CFATS program. It explains:

“As described in the House [HR 4093; link added] and Senate [S 2534; link added] reports, NPPD's excessive use of administratively uncontrollable overtime (AUO) was inappropriate. As a result, the President's budget request for Infrastructure Security Compliance has been reduced [from $86,976,000 to $85,027]. NPPD shall brief the Committees on implementation of its new overtime policies and on overtime year-to-date and anticipated expenditures, not later than May I, 2015.”

Interestingly the original version of HR 4007 introduced in the House called for a CFATS authorization of $87,436,000 {§2110} but the authorization section was removed in Senate version.

Cybersecurity

Cybersecurity spending is spelled out in more detail in the Explanatory Statement. The table below shows the expenditures authorized on page 45 for the cybersecurity spending details for Infrastructure Protection and Information Security portion of the NPPD spending. With a single exception, this bill would reduce cybersecurity spending.

NPPD Cybersecurity Programs
Budget Request
Spending
Cybersecurity Coordination
$4,330,000
$4,311,000
US CERT Operations
$98,794,000
$98,573,000
Federal Network Security
$171,500,000
$171,000,000
Network Security Deployment
$377,690,000
$377,000,000
Global Cybersecurity Management
$17,613,000
$25,873,000
Critical Infrastructure Cyber Protection and Awareness
$70,963,000
$70,919,000
Business Operations
$5,554,000
$5,524,000
Total
$746,444,000
$753,200,000

The ‘Global Cybersecurity Management’ category is a workforce development program. The majority of the money in this category ($15,810,000) is going into spending for cybersecurity education; presumably for DHS personnel.

Office of Health Affairs


One of the other areas of DHS spending that I kind of keep an eye on is the Office of Health Affairs. This office keeps track of two interesting security related activities; BioWatch and the Chemical Defense Program. In keeping with the Congressional almost irrational fear of bio-attacks the spending on BioWatch is more than 100 times as much as is spent on the Chemical Defense Program ($86,891,000 vs $824,000). This is a truly ludicrous mismatching of funds to potential threats as it takes very little technical expertise to effect an attack on industrial chemical storage or transportation.

ICS-CERT Extends Emerson Advisory

Today the DHS ICS-CERT published a new advisory for the vulnerability they reported in the Emerson HART DTM last week. The difference is that instead of just limiting the advisory to Emerson HART DTM they are extending it to all versions of the DTM that use the same DTM libraries produced by CodeWrights. Specifically they include HART systems from:

● ABB,
● Berthold Technologies,
● Emerson,
● Endress+Hauser,
● Magnetrol, and
● Pepperl+Fuchs.

As with the revised advisory published on Friday, ICS-CERT claims that there are no publicly available exploits of these vulnerabilities. CodeWrights has developed a new version of the library and Emerson has tested the library to validate its efficacy. No one has apparently asked the original researcher, Alexander Bolshev, to validate the new library efficacy.


At this point it seems that only Emerson has fixed the vulnerability in their use of the libraries. ICS-CERT states that it will update this advisory when additional reports of fixes have been provided. They also note that CodeWrights is only providing the updated libraries to ‘customers with current support agreements’. This would seem to suggest that other vendors with HART applications may be using the same affected libraries.

HR 54 Introduced – Chemical Facility Security

As I mentioned in an earlier post, Rep. Jackson-Lee (D,TX) introduced HR 54, the Frank Lautenberg Memorial Secure Chemical Facilities Act. This bill is comprehensive chemical facility security bill that is almost a direct copy of S 68 introduced by the late Sen. Lautenberg in the 113th Congress.

I’m not sure why Ms Jackson-Lee introduced this bill. It does not take into account that HR 4007 was introduced last year. It certainly has no chance of being considered in committee in a Republican controlled House, much less of being brought to the floor.


I am rather surprised that this bill was not re-written as a revision of the Title XXI that was put into place by HR 4007 last year. There are a number of provisions in this bill that have been and will remain priorities of many Democrats and some of their most important constituents.

HR 48 Introduced – TSDB Review

As I mentioned earlier Rep. Jackson-Lee (D,TX) introduced HR 48, the No Fly for Foreign Fighters Act. This is a simple requirement for Attorney General to review the Terrorist Screening Database (TSDB) to ensure that anyone “who is known or suspected of being a member of a foreign terrorist organization” {§2(a)} is listed on the TSDB. There is, of course, a requirement to report to Congress on the results of the review.


This bill would certainly have a high probability of passing if it made its way to the floor of the House. It will be interesting to see how well Rep. Jackson-Lee is able work with Republican leadership to move this forward. It might be a good measurement of how well bipartisanship will work in this Congress on non-controversial bills.
 
/* Use this with templates/template-twocol.html */