Saturday, June 17, 2017

Bills Introduced – 06-16-17

With both the House and Senate gone for the weekend there were 8 bills introduced in a proforma session in the House. Of those one may be of specific interest to readers of this blog:

HR 2930 To develop a civil unmanned aircraft policy framework, a pilot program, and for other purposes. Rep. Lewis, Jason [R-MN-2]


I will be watching this bill to see if it addresses issues related to UAS and critical infrastructure security.

Public ICS Disclosure – Week of 6-10-17

This week Richard Young described a privilege escalation vulnerability on the APC UPS Daemon. The Seclist – Full Disclosure report notes that Young has attempted a coordinated disclosure, but received an inadequate response from the vendor. He reports that:

“The default installation of APCUPSD allows a local unprivileged user to run arbitrary code with elevated privileges by replacing the service executable apcupsd.exe with a malicious executable, which will run with SYSTEM privileges at startup.”


The APCUPSD web site reports that the program supports Modbus (via both serial and USB connections) making this UPS support program vulnerability potentially a control system security issue.

Friday, June 16, 2017

Bills Introduced – 06-15-17

Yesterday with both the House and Senate in session there were 54 bills introduced. Of those, one may be of specific interest to readers of this blog:

HR 2922 To reform and improve the Federal Emergency Management Agency, the Office of Emergency Communications, and the Office of Health Affairs of the Department of Homeland Security, and for other purposes. Rep. Donovan, Daniel M., Jr. [R-NY-11]


The Office of Health Affairs currently has two chemical safety/security programs that have received mention in this blog: the medical countermeasures program for DHS employees, and the chemical defense program. I will be watching to see if HR 2922 addresses either program.

Thursday, June 15, 2017

ICS-CERT Publishes Advisory and Updates 5 Siemens Advisories

Today the DHS ICS-CERT published one new control system security advisory for a product from Cambium Networks and updated five previously published advisories for products from Siemens.

Cambium Advisory


This advisory describes two vulnerabilities in the Cambium ePMP Network Access Control products. The vulnerabilities were reported by Karn Ganeshen. According to Cambium, newer versions of the firmware are not affected. There is no indication that Ganeshen was provided an opportunity to verify that.

The two reported vulnerabilities are:

• Improper access control - CVE-2017-7918; and
• Improper privilege management - CVE-2017-7922

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to access device configuration as well as make unauthorized changes to the product’s configuration.

ICS-CERT also notes that Cambium also recommends that users edit default SNMP configuration.

PROFINET Update 1


This update provides additional information on the advisory that was originally published on May 9th, 2017. The update provides new information on the affected version of and links to the updates for:

• SIMATIC STEP 7 V5.X: All versions prior to V5.6;
• SIMATIC WinCC: All versions prior to V7.4 SP1 Upd1; and
• Security Configuration Tool (SCT): All versions prior to V5.0

PROFINET Update 2


This update provides additional information on the advisory that was originally published on May 9th, 2017. The update provides new information on the affected version of and links to the updates for:

• SCALANCE X300, X408: All versions prior to V4.1.0;
• X414 (not previously listed): All versions prior to V3.10.2;
• SITOP PSU8600 PROFINET: All versions prior to V1.2.0,
• SITOP UPS1600 PROFINET (not previously listed): All versions prior to V2.2;
• SIMATIC S7-400 including F and H: All versions prior to V8.2;

SIMATIC Update


This update provides additional information on the advisory that was originally published on February 14th, 2017. The update provides new information on the affected version:

• SIMATIC WinCC: All versions prior to V7.4 SP1; and
• SIMATIC WinCC Runtime Professional: All versions prior to V14 SP1,
The previously published mitigation measure (SIMATIC Logon V1.5 SP3 Update 2) will work on these products as well.

SICAM PAS Update

This update provides additional information on the advisory that was originally published on December 1st, 2016. The update provides updated version information and the announcement that the newest version of the software fixes all of the reported vulnerabilities. There is no indication that the researchers have verified the efficacy of the fix.

DROWN Update


This update provides additional information on the advisory that was originally published on April 12th, 2016 and subsequently updated on February 28th, 2017. The new update provides updated affected version information for:

• SCALANCE X300 family: All versions prior to V4.1.0,
• SCALANCE X414: All versions prior to V3.10.2,
• SCALANCE X200 RNA family: All versions prior to V3.2.5, and
• ROX I: All versions not using the mitigations listed in SSA-327980 (Siemens link).

Additionally, the update also provides new mitigation information for:

• SCALANCE X300 family;
• SCALANCE X414; and
• ROX I

Missing Siemens Advisories and Updates



The updates published today address five of the six ‘missing updates’ that I discussed on Tuesday. The still missing update is for the Siemens SPIROTEC products; SSA-732541, originally ICSA-15-202-01. I still have not seen the Siemens WannaCry updates that I mentioned on Monday being reported by ICS-CERT. Of course, ICS-CERT could have been waiting for the two new WannaCry updates Siemens announced today (here and here).

Wednesday, June 14, 2017

EPA Submits TSCA Submission Guidance to OMB

Yesterday the OMB announced that the EPA had submitted a new guidance document supporting requirements to submit submitting draft risk evaluations to the EPA as part of the new TSCA requirements under the Frank R. Lautenberg Chemical Safety for the 21st Century Act (PL 114-182). This document was not included in the Obama Administration’s last Unified Agenda and the Trump Administration has not yet published a Unified Agenda.


This is the third OMB submission from the Trump Administration supporting the new TSCA requirements (see here and here).

Tuesday, June 13, 2017

ICS-CERT Publishes 3 Advisories

Today the DHS ICS-CERT published three control system security advisories for products from Trihedral and OSIsoft. ICS-CERT continues to have problems with Siemens security advisories and updates.

PI Web API Advisory


This advisory describes cross-site request forgery vulnerability in the OSIsoft Web API. The vulnerability is self-reported. OSIsoft has produced an upgraded version and provides additional mitigation measures.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to access the PI System with the privileges of a legitimate client user (write data).

PI Server Advisory


This advisory describes two improper authentication vulnerabilities in the OSIsoft PI Server. The vulnerability is self-reported. A new version (not currently available) has been developed that mitigates the vulnerability.

ICS-CERT reports that an (uncharacterized skill level) attacker could remotely exploit the vulnerability to spoof a PI Server or cause undefined behavior within the PI Network Manager.

Trihedral Advisory


This advisory describes three vulnerabilities in the Trihedral VTScada product. Karn Ganeshen reported the vulnerability. Trihedral has developed a patch to mitigate the vulnerability. ICS-CERT reports that Ganeshen has verified the efficacy of the fix.

The three reported vulnerabilities are:

• Uncontrolled resource consumption - CVE-2017-6043;
• Cross-site scripting - CVE-2017-6053; and
• Information exposure - CVE-2017-6045

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to result in uncontrolled resource consumption, arbitrary code execution, or information exposure.

NOTE: the VTScada upgrade notes report that “VTScada logo images are now protected by a checksum. VTScada will not start if these files have been removed or modified. If you wish to create a custom-branded application, contact Trihedral Engineering for licensing.” So it is possible that a facility is using a vulnerable system and not know it.

Missing Siemens Advisories and Updates


In addition to the five Siemens’ WannaCry updates I mentioned yesterday, there are six recently reported Siemens’ advisories and updates published that have not been reported by ICS-CERT. They are:

SSA-275839: Denial-of-Service Vulnerability in Industrial Products", June 7th;
SSA-946325: Vulnerabilities in SICAM PAS, June 9th;
SSA-732541: Denial-of-Service Vulnerability in SIPROTEC 4, June 12th;
SSA-293562: Vulnerabilities in Industrial Products, June 13th;
SSA-623229: DROWN Vulnerability in Industrial Products, June 13th; and
SSA-931064: Authentication Bypass in SIMATIC Logon, June 13th

To be fair it is probably too soon to be concerned about the last four, but the other 7 missing Siemens reportings are definite of concern.


As always thanks to the Siemens @ProductCERT for their tweets about security updates on their products.

CFATS Civil Penalties

Yesterday DHS published a new web page outlining the policy and processes for assessing civil penalties and cease operations orders for the Chemical Facility Anti-Terrorism Standards (CFATS) program. The short web page provides links to two documents; the policy document and a fact sheet. The Infrastructure Security Compliance Division (ISCD) has had (and periodically has used) the authority to issue administrative orders and assess civil penalties. This is the first time that a policy document has been provided outlining the process to be used.

The ten-page policy document should be read carefully by all CFATS covered (and potentially covered) facilities. It outlines the shortcomings that can draw an administrative order, civil penalty assessement, and/or cease and desist order (in accordance with 6 CFR 27.300), the method by which ISCD assesses the amount of the penalty and subsequent negotiations to reduce assessed penalties.

The policy addresses three separate types of situations where the policy may apply:

• Failure to file violations (Top Screen and SVA/SSP);
• SSP/ASP deficiencies and infractions;
• Chemical-Terrorism Vulnerability (CVI) infractions.

Unlike other some regulatory agencies of the Federal government (ie: EPA and OSHA) ISCD has not, does not, and apparently does not plan to publish individual notices of penalty assessments and/or orders issued. This is understandable as it would provide public notice of individual high-risk chemical facilities with less than adequate security measures; surely that would be any serious terrorists top wish list.


BTW: There is not currently any mention of this new web site on the CFATS landing page. I expect that we will see that in the next couple of days.
 
/* Use this with templates/template-twocol.html */