Saturday, December 10, 2016

Senate Sends FY 2017 Continuing Resolution to President

Last night the Senate in a modestly bipartisan vote approved the House amendment to HR 2028, the Further Continuing and Security Assistance Appropriations Act, 2017. The final vote was 63 to 36. Thirteen Republicans voted against the bill.

This extends the current spending authority until April 28th, 2017. The Trump administration and the 115th Congress will have to work out the spending plan for the remainder of the fiscal year.


It is interesting that a coalition of moderates in both houses of congress passed this bill. If the Republican leadership can withstand challenges from their less moderate wing, this may prove to be the model for getting things done in the 115th Congress. Otherwise, the Republicans lack of a filibuster proof majority in the Senate will allow the Democrats to block most legislation.

Friday, December 9, 2016

OMB Approves PHMSA Interim Final Rule on Underground Natural Gas Storage

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved an interim final rule proposed by DOT’s Pipeline and Hazardous Material Safety Administration (PHMSA) concerning the regulation of underground storage facilities for natural gas. This new rulemaking (first published in the Spring 2016 Unified Agenda) was initiated in response to the Aliso Canyon fiasco.

PHMSA is going directly to an interim final rule on this rulemaking so we have no real sense of the specifics that will be included. According to the Fall 2016 Unified Agenda PHMSA is going to require owners to implement two voluntary standards from the American Petroleum Institute (API RP 1170 and API RP 1171) unless “they provide justification” for deviations from those standards. Key provisions to look for will be the time frame for required implementation and the standards to be used to evaluate the justifications for deviations.


With the late addition of this to the rulemaking process and the move to proceed directly to an interim final rule (which can last practically forever) this rulemaking will almost certainly be suggested for Congressional recision action by the 115th Congress in January.

Bills Introduced – 12-08-16

Both the House and Senate were in town yesterday as the 114th Congress edges towards a close (the House is scheduled to meet again on Monday). There were a surprising 73 bills introduced yesterday; nearly all of which will never see any sort of action in Congress. There was one bill that may, however, be of potential interest to readers of this blog:

HR 6480 To authorize appropriations for fiscal year 2017 for intelligence and intelligence-related activities of the United States Government, the Intelligence Community Management Account, and the Central Intelligence Agency Retirement and Disability System, and for other purposes. Rep. Nunes, Devin [R-CA-22]

This is the third attempt by Nunes to get an intelligence authorization bill to the President. The previous two (HR 5077 and HR 6393) have passed the House but did not make it to the Senate floor for consideration. It took the House less than a minute to consider and approve this bill yesterday. It will be interesting to see if it is taken up in the Senate today.


The language of the bill is not yet available, but I suspect that the port security intelligence report provision is still in the bill.

Thursday, December 8, 2016

House Passes HR 2028, FY 2017 Continuing Resolution

This afternoon the House approved an amendment to the Senate amendment to HR 2028. This new amendment is the vehicle for extending the current federal government spending rate until April 28th, 2017. The Further Continuing and Security Assistance Appropriations Act, 2017 passed by a bipartisan vote of 326 – 96. Even the no votes were relatively bipartisan with 33 Republicans voting no.


The Senate should take up this bill tomorrow in plenty of time to meet the midnight deadline for the end of the current continuing resolution.

ICS-CERT Publishes Four Advisories

Today the DHS ICS-CERT published four control system security advisories for products from INTERSCHALT, Adcon, Sauter and Moxa.

INTERSCHALT Advisory


This advisory describes a path traversal vulnerability the INTERSCHALT Maritime Systems (INTERSCHALT) VDR G4e application. The vulnerability was reported by Maxim Rupp. INTERSCHALT has produced a patch to mitigate this vulnerability. ICS-CERT reports that Maxim has verified the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to read/download arbitrary files from the target host.

Adcon Advisory


This advisory describes a cross-site scripting vulnerability in the Adcon Telemetry A850 Telemetry Gateway Base Station. The vulnerability was reported by the Aditya K. Sood. Adcon has produced a new firmware version to mitigate the vulnerability. There is no indication that Sood has been provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to allow the injection of arbitrary JavaScript that may affect the integrity of the system.

Sauter Advisory


This advisory describes an authentication bypass vulnerability in the Sauter NovaWeb web HMI application. The vulnerability was reported by Maxim Rupp. The HMI application is no longer supported so there will be no fix for the vulnerability.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to gain authorized access to the application.

Moxa Advisory


This advisory describes two vulnerabilities in the Moxa MiiNePort. The vulnerabilities were reported by Aditya Sood. Moxa has produced new firmware versions to mitigate the vulnerabilities. There is no indication that Sood was provided an opportunity to verify the efficacy of the fix.

The reported vulnerabilities are:

• Permissions, privileges, and access controls - CVE-2016-9344; and

• Cleartext storage of sensitive information - CVE-2016-9346

Tuesday, December 6, 2016

ICS-CERT Publishes Two Advisories

Today the DHS ICS-CERT published two control system security advisories for products from Locus Energy and Tesla Motors.

Locus Energy Advisory


This advisory describes a command injection vulnerability in the Locus Energy LGate application. The vulnerability was reported by Daniel Reich. Locus Energy has produced a firmware update to mitigate the vulnerability. The update will be remotely installed by Locus Energy upon request. There is no indication that Reich has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to take control of LGate that has its web server port publicly exposed.

This advisory was originally posted to the US-CERT secure Portal library on September 29, 2016.

Tesla Motors Advisory


This advisory describes a gateway ECU advisory for the Tesla Motors (Tesla) Model S automobile. The vulnerability was reported by Tencent’s Keen Security Lab. Tesla has produced an over-the-air firmware update to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix. ICS-CERT reports that the updated has been available since September 18th.

ICS-CERT reports that it would be difficult to craft an exploit for this vulnerability as it would require a complex chain of exploits, “including a web browser compromise, local privilege escalation, and custom-built firmware”. A successful exploit would allow an attacker to remotely control the vehicle’s software and driving functions.

Monday, December 5, 2016

Committee Hearings – Week of 12-04-16

The House and the Senate are both in Washington for what could be the last week of the 114th Congress. As you would suspect, the hearing schedule is light, but there is one hearing on transportation security that might be of interest to readers of this blog.

Transportation Security


The Surface Transportation and Merchant Marine Infrastructure, Safety, and Security Subcommittee of the Senate Commerce, Science and Transportation Committee will be holding a hearing on Wednesday on “Assessing the Security of Our Critical Transportation Infrastructure”. This hearing will focus on surface transportation. The witness list includes:

• John Roth, Inspector General, DHS;
• Chief Neil Trugman, Interim Chief of Police, Amtrak
• Mr. Chris Spear, President and CEO, American Trucking Association
• Mr. Tony Straquadine, Manager of Commercial and Government Affairs, Alliance Pipeline;
• Mr. Tom Belfiore, Chief Security Officer, Port Authority of New York and New Jersey

Obviously, nothing will come of this hearing this session, but the information will carry over to help shape how the staff deals with transportation security issues in the next session. As is usual, watching the questions is more important than listening to the testimony.

On the Floor


The only thing currently of specific interest to readers of this blog to be scheduled to be voted on in the House and Senate this week is the Continuing Resolution to continue funding the government past the current FY 2017 funding that expires on December 9th. The current ‘plan’ is to pass a short-term measure to carry the current funding rate some time past the Trump inauguration to allow the new President to have input on the final FY 2017 spending bill.


The House Majority Leader does note that the current schedule of items to be considered under suspension of the rules may not be complete. We will have to watch for changes on a daily basis. I half expect HR 6381, the DHS ‘improvement’ bill, to be added to the list.
 
/* Use this with templates/template-twocol.html */