Thursday, March 14, 2019

3 Advisories Published – 03-14-19


Today the DHS NCCIC-ICS published three control system security advisories for products from PEPPERL+FUCHS, Gemalto and Leão Consultoria e Desenvolvimento de Sistemas Ltda (LCDS).

PEPPERL+FUCHS Advisory


This advisory describes a path traversal vulnerability in the PEPPERL+FUCHS WirelessHART-Gateways. The vulnerability was publicly reported (with exploit) by Hamit CİBO. PEPPERL+FUCHS has firmware upgrades to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could use publicly available code to remotely exploit this vulnerability to allow access to files and restricted directories stored on the device through the manipulation of file parameters.

NOTE: I briefly reported on this vulnerability last Saturday.

Gemalto Advisory


This advisory describes an uncontrolled search path element in the Gemalto Sentinel UltraPro. The vulnerability was reported by ADLab of Venustech. Gemalto has a software update to mitigate the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to load and execute a malicious file from the ux32w.dll in Sentinel UltraPro.

NOTE: Gemalto issued an early warning to upgrade the UltraPro software back on January 19th, 2019 with a restricted link to their advisory on this product. I do not know what information was included in that advisory.

LCDS Advisory


This advisory describes an out-of-bounds write vulnerability in the LCDS LAquis SCADA. The vulnerability was reported by Mat Powel via the Zero Day Infitiative. LCDS has a new version that mitigates the vulnerability. There is no indication that Powel was provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow remote code execution.

Bills Introduced – 03-13-19


Yesterday with both the House and Senate in session there were 87 bills introduced. Two of these were cybersecurity related bills that may receive additional coverage in this blog:

HR 1731 To amend the Securities Exchange Act of 1934 to promote transparency in the oversight of cybersecurity risks at publicly traded companies. Rep. Himes, James A. [D-CT-4]

S 771 A bill to amend section 21 of the Small Business Act to require cyber certification for small business development center counselors, and for other purposes. Sen. Rubio, Marco [R-FL]

I will be watching these bills for specific language and or definitions related to industrial control system security.

Wednesday, March 13, 2019

HR 1589 Marked Up in House


Today the House Homeland Security Committee held a markup hearing to consider seven bills, including HR 1589, the CBRN Intelligence and Information Sharing Act of 2019. That bill was amended twice and adopted by the Committee by unanimous consent as part of a block of bills.

Both of the amendments to HR 1589 were relatively minor wording additions.

The first amendment from Rep. Clarke (D,NY) changed §210H(a)(1) to read:

“(1) support homeland security-focused intelligence analysis of terrorist actors, their claims, and their plans to conduct attacks involving chemical, biological, radiological, or nuclear materials against the United States, including critical infrastructure [added];”

The second amendment from Rep. Jackson-Lee (D,TX) changed §210H(a)(4) to read:

“(4) leverage existing and emerging homeland security intelligence capabilities and structures to enhance early detection, [added] prevention, protection, response, and recovery efforts with respect to a chemical, biological, radiological, or nuclear attack;”

As I mentioned in my earlier blog post today, this bill will make its way to the floor of the House where it will be considered under the suspension of the rules process. That process does not provide for any additional amendments to be made from the floor. The bill will almost certainly pass with a significant bipartisan vote.

HR 1589 Introduced – CBRN Intelligence


Last week Rep. Walker (R,NC) introduced HR 1589, the CBRN Intelligence and Information Sharing Act of 2019. The bill would establish DHS responsibilities for collecting and disseminating intelligence information involving terrorist threats “involving chemical, biological, radiological, or nuclear materials against the United States” {new §210H(a)(1)}. The bill is very similar to HR 677 from the last session which passed in the House without amendment.

There are a number of relatively small changes made in the current bill. The largest is the addition of the words “the Countering Weapons of Mass Destruction Office and” in paragraph (b). This office was created since HR 677 was introduced in 2017 and it would be added to the list of offices with which the DHS Office of Intelligence and Analysis would coordinate in developing CBRN information.

Moving Forward


As I mentioned earlier this week, HR 1589 will be considered by the House Homeland Security Committee in a markup hearing today. It is expected to pass by a voice vote without amendment. The bill is likely to come to the House floor in the not too distant future under the suspension of the rules process where there will be limited debate and no floor amendments will be authorized. The bill would be expected to pass there with substantial bipartisan support.

As in the last two sessions of Congress it is likely that this bill will not receive consideration in the Senate.

Commentary


While the word ‘chemical’ in the ‘CBRN’ of the title of this bill and in a couple of places within the language itself, there appears to be little intent to involve DHS intelligence in trying to track terrorist threats to chemical manufacturing or transportation. This bill remains at heart a bill addressing the potential threat of bioterror attacks.

While bioterrorism certainly presents a theatrical level threat, that type of attack is much harder to successfully pull off than a conventional or even a cyber attack on chemical storage or transportation systems. In my opinion paragraph (a)(5) of this bill should be modified to reflect this by making it read:

“(5) share information and provide tailored analytical support on such threats to:

(A) State, local, Tribal, and territorial authorities, and other Federal agencies;

(B) Relevant national biosecurity and biodefense stakeholders, as appropriate;

(C) Owners and operators of chemical facilities operating under the Chemical Facility Anti-Terrorism Standards and the Maritime Transportation Security Act; and

(D) Freight rail owners operating under conditions specified in 49 CFR 1580 Subpart B.”

An interesting side note here; HR 677 was introduced by then Rep. McSally (R,AZ). She has since moved on to the Senate and has not yet introduced a version of this bill in the Senate. McSally was the chair of the Intelligence and Counterterrorism Subcommittee of the Homeland Security Committee when she introduced HR 677. Walker is not the Ranking Member of that Committee. This would seem to indicate that this bill is a priority for the Republican leadership of the Homeland Security Committee.

Tuesday, March 12, 2019

1 Advisory and 6 Updates Published – 03-12-19


Today the DHS NCCIC-ICS published on control system security advisory for products from WIBU Systems and six updates for previously published advisories for products from Siemens.

WIBU Advisory 


This advisory describes three vulnerabilities in the WibuKey Digital Rights Management tool. NCCIC-ICS reports that the vulnerabilities were reported to it by Siemens, but the vulnerabilities were originally reported by Talos (here, here and here) with exploits. Wibu has an updated software version that mitigates the vulnerability. There is no indication that Talos has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Information exposure - CVE-2018-3989;
• Out-of-bounds write - CVE-2018-3990; and
Heap-based buffer overflow - CVE-2018-3991

NCCIC-ICS reports that a relatively low-skilled attacker could use a publicly available exploit to remotely exploit the vulnerabilities to allow information disclosure, privilege escalation, or remote code execution.

NOTE: This advisory originally published on February 12th, 2019 by NCCIC-ICS and updated on February 14th, 2019 as a third-party software problem only affecting the Siemens SICAM 230. This advisory was renamed today as a Wibu Systems problem affecting Siemens (2 product lines, the second reported here on March 2nd, 2019) and three other vendors; COPA-DATA, SPRECHER Automation, and Phoenix Contact (reported here last Saturday). As with other third-party software issues, there may be other vendors added to this revised advisory in the future.

Industrial Products Update


This update provides additional information on an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th, November 28th, February 27th, 2018, May 3rd, 2018 May 15th, 2018, September 11th, 2018, October 9th, 2018, November 13th, 2018, December 11th, 2018, February 5th, 2019 and most recently on February 12th, 2019. The update provides additional affected version information and links for mitigation measures for SINUMERIK 840D sl.

Desigo PXC Update


This update provides additional information on an advisory that was originally published on January 25th, 2018, February 6th, and updated on March 22nd, 2018. Added links to mitigation measures for products before v 6.00.

SIPROTEC 4 Update


This update provides additional information on an advisory that was originally published on March 8th, 2018, April 19th, 2018, and updated on May 17th, 2018. The update provides additional affected version information and links for mitigation measures for:

• 7SJ61;
• 7SJ62;
• 7SJ64; and
• Contacts for mitigation measures for products without solution.

SIMATIC PCS 7 Update


This update provides additional information on an advisory that was originally published on March 29th, 2018 and updated on April 24th, 2018, June 12th, 2018, and again on November 13th, 2018. The update corrected the data for fixed version for the WinCC 7.4.

NOTE: This should be “Update E” not “Update G”.

SIMATIC S7 Update


This update provides additional information on an advisory that was originally published on November 13th, 2018. The update provides additional affected version information and links for mitigation measures for SIMATIC S7-1200.

SINUMERIK Update


This update provides additional information on an advisory that was originally published on December 11th, 2018. The update provides additional affected version information and links for mitigation measures for SINUMERIK 808D.

Siemens Advisory Day


The six Siemens updates published today by NCCIC-ICS were all published by Siemens today on their monthly release of vulnerabilities and updates. There was also one new advisory published today by Siemens and three other updates.

CFATS Subcommittee Hearing – 03-12-19


Today the Cybersecurity, Infrastructure Protection, and Innovation Subcommittee of the House Homeland Security Committee held a hearing on “Securing Our Nation's Chemical Facilities: Stakeholders Perspectives on Improving the CFATS Program” (video here). The Subcommittee heard from a panel of labor and safety advocates as well as a representative of the American Chemistry Council (ACC).

Witnesses


Today’s witnesses included (link to prepared testimony):

Mr. John Morawetz, International Chemical Workers Union Council;
Dr. Mike Wilson, Ph.D, MPH, BlueGreen Alliance;
Pamela Nixon, People Concerned About Chemical Safety; and
Kirsten Meskill, BASF

As I mentioned in an earlier blog post, there was a fifth witness originally scheduled to be on the panel. There was no indication today why Randy E. Manner, Manner Analytics, was not present at the hearing.

Expected Coverage


As expected, based upon previous hearings and the change in leadership in the House, much of the questioning today addressed four topics:

• Voluntary ‘best practices’;
• Information sharing;
• Employee involvement; and
• Whistleblower protections

The ‘new’ term ‘best practices’ has apparently replaced the more controversial ‘inherently safer technology (IST)’ that was used extensively in the chemical safety and security discussions in the earlier Democratic lead House. All of the questioners and panel members (even to an extent Meskill) generally agreed that the sharing of ‘best practices’ related to actions that facility could take to reduce their chemical risk was a good idea. There were no concrete ideas (or even suggestions) how those ‘best practices’ could be implemented at other facilities. There was a general agreement that DHS Infrastructure Security Compliance Division (never named in the hearing) should share what information that it did have.

The ‘information sharing’ bit was mainly about how and what CFATS facilities should share with local first responders, emergency planners and local communities to help respond to the release of chemicals or chemical incidents resulting from terrorist attacks, weather emergencies or accidents. Again, there was a general agreement that that information sharing was important and should be expanded. Ranking Member Katko (R,NY) made the point that other regulatory programs had more expansive information sharing requirements where concerns should more probably be addressed. Katko made a vague point about the CVI requirements for first responders.

Employee involvement in safety and security planning has long been a priority for Democrats. The point was made many times by Committee members and panelists that line employees would have valuable insights that should be included in identifying security vulnerabilities and planning for site security plans. Meskill made the point that they included employees at all stages of the security (and safety) planning and implementation process but agreed that she could not speak for all CFATS facilities.

The Democrats again have long had concerns about the whistleblowing protections provided to employees. Member concerns about protecting employees from retaliation due to their reporting security (and safety) problems at facilities. Interesting, none of the panel members could provide any information on the problem when questioned. Katko pointed out (in the only second round of questioning in the hearing) that the CFATS Tip Line provided a way that employees could anonymously report problems at covered facilities (including the lack of initial notification to ISCD).

Cybersecurity


The one new (and unexpected to me) topic that came up a number of different times was cybersecurity. Langevin (D,RI), Rice (D,NY) and Jackson-Lee (D,TX) all had questions about cybersecurity issues. Langevin questioned cybersecurity training (particularly in control rooms); Rice asked about cybersecurity standards in CFATS and Jackson-Lee announced that she would be introducing the Frank Lautenberg Chemical Facility Cybersecurity. No detailed responses were available from any of the panel members.

Commentary


In an earlier set of blog posts I identified those items that I though should be addressed in any legislation reauthorizing the CFATS program. Two of those posts are appropriate (in my opinion) responses to some of the questions raised today. Those include:

Best practices (IST); and

There are a couple of things that still need to be addressed here. First is Katko’s comments about the applicability of Chemical-Terrorism Vulnerability Information (CVI) requirements to first responders. ISCD has long maintained that first responders entering a facility in response to an actual emergency situation are not required to be CVI qualified; actual emergency response does not rely on access to CVI controlled information. Emergency planning is something else entirely. There are requirements (§7.02) outlined in the CVI Guidance manual for providing access to CVI information to State and local officials, including emergency response planners. That guidance ends by explaining:

“State, local, and tribal officials, including first responders, must have access to any information that is necessary to plan for and respond to an emergency event at a chemical facility [emphasis added]. It is equally important that this information is available in a form that is readily accessible and easily disseminated. Accordingly, to the extent possible, facilities should provide information to State, local and tribal entities in non-CVI form. In many cases, a facility can provide a product that contains all of the necessary operational and facility-specific information and excludes CVI.”

Katko also made a point that should be remembered by everyone involved in the CFATS reauthorization process; the CFATS regulations are not the only federal rules that require chemical companies to coordinate emergency response planning information with local authorities. Facilities could easily find the necessary information for emergency response planners in their already required information provided to local fire departments and Local Emergency Planning Committees (LEPCs).

There are some exceptions to the EPA reporting requirements that apply to CFATS facilities. Most chemicals on the DHS list of chemicals of interest (COI) that triggers CFATS reporting requirements that are not on the EPA’s Risk Management Program list of covered chemicals are covered by CFATS because they can be used for preparing improvised explosives or improvised chemical weapons. While these chemicals are not generally as much of an off-site hazard as the RMP covered chemicals, the emergency response planning is more of a law enforcement issue than fire department response planning. This would make for some interesting information sharing requirements that are not specifically outlined in any existing regulations.

The other interesting thing that came out of this hearing was the new Committee interest in cybersecurity issues. Richmond’s Subcommittee should probably hold another hearing (maybe two) specifically about cybersecurity issues. This is going to be a complex set of issues and a wide variety of experts and stakeholders are going to have to be involved in the efforts to address it.

One thing that the Committee crafters are going to have to deal with in writing cybersecurity requirements is that the CFATS program is a risk-based program that prohibits DHS from requiring specific security measures. This is due to the recognition that each of the very wide variety of covered facilities (from a number of different chemical and non-chemical manufacturing facilities) require differing security measures to protect against terrorist attacks. This remains true for the varying information and control system technologies that will be found in these facilities.

Bills Introduced – 03-12-19


Yesterday with both the House and Senate in session there were 33 bills introduced. Two of these will receive future mention in this blog:

HR 1668 To leverage Federal Government procurement power to encourage increased cybersecurity for Internet of Things devices, and for other purposes. Rep. Kelly, Robin L. [D-IL-2]

S 734 A bill to leverage Federal Government procurement power to encourage increased cybersecurity for Internet of Things devices, and for other purposes. Sen. Warner, Mark R. [D-VA]

These bills are probably companion bills according to an article published yesterday on TheHill.com. Similar sounding bills (see here for example) have been introduced in the last two sessions of Congress and they have all suffered from an overly broad definition of ‘internet connected device’ that left them essentially useless. It will be interesting to see if anything has changed.

 
/* Use this with templates/template-twocol.html */