Thursday, February 13, 2020

2 Advisories Published – 2-13-20


Today the CISA NCCIC-ICS published two control system security advisories for products from Schneider Electric.

Magelis HMI Panel Advisory


This advisory describes an improper check for unusual or exceptional conditions vulnerability in the Schneider Magelis HMI Panel. The vulnerability was reported by VAPT Team, C3i Center. Schneider has provided generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a denial-of-service condition.

NOTE: I briefly discussed this vulnerability last August.

Modicon Ethernet Serial RTU Advisory


This advisory describes three vulnerabilities in the Schneider Modicon BMXNOR0200H Ethernet/Serial RTU module. The vulnerability was reported by VAPT Team, C3i Center. Schneider has provided generic workarounds to mitigate the vulnerability.

The three reported vulnerabilities are:

• Improper check for unusual or exception conditions (2) - CVE-2019-6813 and CVE-2019-6831; and
• Improper access control - CVE-2019-6810

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow remote code execution or cause a denial-of-service condition.

NOTE: I briefly discussed this vulnerability last August.

Other Schneider Advisories


While NCCIC-ICS was covering these two 5-month old vulnerability reports, Schneider was publishing three new advisories this week. I will cover them this weekend.

HR 5823 Introduced – Cybersecurity Grants


Earlier this week Rep Richmond (D,LA) introduced HR 5823, the State and Local Cybersecurity Improvement Act. The bill would establish a DHS grant program to help State and local governments establish cybersecurity programs. The bill would add a new §2215 to the Homeland Security Act of 2002 (presumably 6 USC 665).

Definitions


Section 2215(p) provides the definitions to be used in the new section. Most of the critical definitions are taken from other sections of the US Code. Key definitions include:

• ‘Cyber threat indicator’ – from 6 USC 1501;
• ‘Cybersecurity risk’ – from 6 USC 659;
• ‘Incident’ – from §659;
• ‘Information system’ – from §1501;

There are two definitions provided in §2215(p) that reference ‘section 2’. There are no free standing definitions in §2; §2(a) adds the new §2215 and §2(b) amends the table of contents of the Homeland Security Act of 2002 to reflect the new §2215. The two undefined terms are:

• ‘Critical infrastructure’; and
• ‘Key resources’

Grant Program


Section 2215(a) establishes the ‘State and Local Cybersecurity Grant Program’ “to make grants to States to address cybersecurity risks and cybersecurity threats to information systems of State, local, Tribal, or territorial governments”. The new grant program would be administered under the same program office that administers the Urban Area Security Initiative (6 USC 604) and the State Homeland Security Grant Program (6 USC 605).

Each State applying for a grant would be required to submit to DHS a ‘Cybersecurity Plan’ for approval. The Plan would describe how the State would {new §2215(d)(1)(B)}:

• Enhance the preparation, response, and resiliency of information systems owned or operated by such State against cybersecurity risks and cybersecurity threats;
• Implement a process of continuous cybersecurity vulnerability assessments and threat mitigation practices prioritized by degree of risk to address cybersecurity risks and cybersecurity threats;
• Ensure that State, local, Tribal, and territorial governments adopt best practices and methodologies to enhance cybersecurity;
• Mitigate any identified gaps in the State, local, Tribal, or territorial government cybersecurity workforces, enhance recruitment and retention efforts for such workforces, and bolster the knowledge, skills, and abilities of government personnel to address cybersecurity risks and cybersecurity threats;
• Ensure continuity of communications and data networks in the event of an incident;
• Assess and mitigate cybersecurity risks and cybersecurity threats related to critical infrastructure and key resources, the degradation of which may impact the performance of information systems;
• Enhance capability to share cyber threat indicators and related information between such State and local, Tribal, and territorial governments; and
• Develop and coordinate strategies to address cybersecurity risks with local, Tribal, and territorial governments within the State.

The plan would also include an inventory of the information technology deployed on the covered information systems including; “legacy information technology that is no longer supported by the manufacturer” {new §2215(d)(1)(C)}.

Section 2215(h) sets limitations on how the grant monies could be spent. Grant funds could not be spent {new 2215(h)(2)}:

• To supplant State, local, Tribal, or territorial funds;
• For any recipient cost-sharing contribution;
• To pay a demand for ransom in an attempt to regain access to information or an information;
• For recreational or social purposes; or
• For any purpose that does not directly address cybersecurity risks or cybersecurity threats on information systems of such State.

Section 2215(o) would authorize $400 million for the grant program per year for 2021 through 2025.

Advisory Committee


Section 2215(m) would require the DHS Cybersecurity and Infrastructure Security Agency (CISA) to establish a State and Local Cybersecurity Resiliency Committee to “to provide State, local, Tribal, and territorial stakeholder expertise, situational awareness, and recommendations” {new §2215(m)(1)} to CISA. The advice would provide CISA information on how to:

• Address cybersecurity risks and cybersecurity threats to information systems of State, local, Tribal, or territorial governments; and
• Improve the ability of such governments to prevent, protect against, respond, mitigate, and recover from cybersecurity risks and cybersecurity threats.

Members of the Committee would include individuals recommended by {new §2215(m)(3)}:

• The Director by the National Governors Association (2);
• The Director by the National Association of State Chief Information Officers (2);
• The Director by the National Guard Bureau;
• The Director by the National Association of Counties (2);
• The Director by the National League of Cities (2);
• The Director by the United States Conference of Mayors; and
• The Director by the Multi-State Information Sharing and Analysis Center.

Strategy to Improve Cybersecurity


Section 3 of the bill would amend 6 USC 660, adding a new §660(e), Homeland Security Strategy to Improve the Cybersecurity of State, Local, Tribal, and Territorial Governments. It would give CISA 270 days to publish the Strategy to {new §660(e)(2)}:

• Identify capability gaps in the ability of State, local, Tribal, and territorial governments to identify, prepare for, detect, protect against, respond to, and recover from cybersecurity risks, cybersecurity threats, and incidents;
• Identify Federal resources and capabilities to help such governments identify, prepare for, detect, protect against, respond to, and recover from cybersecurity risks, cybersecurity threats, and incidents;
• Identify and assess the limitations of Federal resources and capabilities available to help governments identify, prepare for, detect, protect against, respond to, and recover from cybersecurity risks, cybersecurity threats, and incidents, and make recommendations to address such limitations;
• Identify opportunities to improve the Agency’s coordination to improve incident exercises, information sharing and incident notification procedures;
• Recommend new initiatives the Federal Government should undertake to help such governments identify, prepare for, detect, protect against, respond to, and recover from cybersecurity risks, cybersecurity threats, and incidents;
• Set short-term and long-term goals that will improve the ability of such governments to identify, prepare for, detect, protect against, respond to, and recover from cybersecurity risks, cybersecurity threats, and incidents; and
• Set dates, including interim benchmarks, as appropriate for State, local, Tribal, territorial governments to establish baseline capabilities to identify, prepare for, detect, protect against, respond to, and recover from cybersecurity risks, cybersecurity threats, and incidents.

Amended in Committee


This bill was taken up yesterday by the House Homeland Security Committee in a markup hearing. The bill was amended four times with amendments submitted by:

• Rep Katko (R,NY);
• Rep Langevin (D,RI);
• Richmond; and
• Rep Slotkin (D,MS)

Most of the changes made by the four amendments were relatively minor word changes. The most significant amendment was the addition of another section (§2216) included in the Slotkin amendment. That section would require CISA to “develop a resource guide for use by State, local, Tribal, and territorial government officials, including law enforcement officers, to help such officials identify, prepare for, detect, protect against, respond to, and recover from cybersecurity risks, cybersecurity threats, and incidents”.

All four amendments were adopted by unanimous consent as was the amended bill.

Moving Forward


One the Committee Report is prepared the bill will be ready to move to the floor of the House. This appears to be a high-priority bill so there is little doubt that it will make it to the floor for consideration. It will be considered under the House suspension of the rules process. This means there will be limited debate, no floor amendments and the bill will require a super majority to pass. The bill will almost certainly pass with substantial bipartisan support.

Commentary


Normally I would expect a bill with a $400 million authorization to face some opposition. That does not appear to be the case with this bill. That is almost certainly due to the large number of high-profile ransomware attacks against various city governments and local agencies. There is some significant pressure for Congress to ‘do something’ about the problem.

I am not sure that a mere $400 million spread across 50-states is going to do an awful lot to prevent future attacks. It will certainly provide a large number of congresscritter TV news spots when they get a chance to be on hand when the grant money is handed over.

Wednesday, February 12, 2020

ISCD Publishes CFATS Quarterly – 2-12-20


Today the CISA Infrastructure Security Compliance Division (ISCD) published a link to the January 2020 issue of the Chemical Security Quarterly. If you had previously signed up for Chemical Facility Anti-Terrorism Standards (CFATS) notifications from CISA you would have received an email version of this publication back on January 27th like I did.

Veteran readers of this blog know how much I hate corporate report type publications from government agencies. When I first opened my email, it looked like this Quarterly was going to be one since it started with a month-by-month year-in-review for 2019; you know, ‘hey look at what great things I done’. Actually, I must admit some of the tidbits were things that I missed or had forgotten about.

The Quarterly then went on to review the ‘heightened geopolitical tensions’ issues surrounding the potential conflict with Iran. It is a nice recap if you missed the January 17th notice on the CFATS Knowledge Center or either of my two blog posts (here and here) on the topic.

Probably the most valuable part of this issue is the ‘Compliance Closeup’ feature dealing with CSAT 2.0. There is a good chance that many CFATS facilities may be seeing the new SVA/SSP portion of CSAT 2.0 for the first time as they implement the Tier 3 and 4 Personnel Surety Program (PSP) requirements. ISCD has done a nice job of briefly going over some of the changes with which facilities will have to deal. And there is a companion discussion about some of the resources available for implementing the PSP.

All in all, I have to continue to give ISCD points for publishing a worthwhile document than everyone associated with the CFATS program should read.

13 Advisories and 5 Updates Published – 2-11-20

Today the CISA NCCIC-ICS published 13 control system security advisories for products from Synergy Systems and Solutions, Digi International and Siemens (11). They also updated five control system security advisories for products from Siemens.

Synergy Systems Advisory


This advisory describes two vulnerabilities in the SSS HUSKY RTU. The vulnerabilities were reported by VAPT Team, C3i Center. SSS has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper authentication - CVE-2019-20046; and
• Improper input validation - CVE-2019-20045

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to read sensitive information, execute arbitrary code, or cause a denial-of-service condition.

Digi Advisory


This advisory describes two vulnerabilities in the Digi ConnectPort LTS 32 MEI. The vulnerabilities were reported by Murat Aydemir and Fatih Kayran of Biznet Bilisim. Digi has a new release that mitigates the vulnerabilities. There is no indication that the researchers have been provided with an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Unrestricted upload of file with dangerous type - CVE-2020-6975; and
• Cross-site scripting - CVE-2020-6973

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to limit system availability.

SIPROTEC Advisory


This advisory describes an improper input validation vulnerability in the Siemens SIPROTEC 4 and SIPROTEC Compact. The vulnerability was reported by Tal Keren from Claroty. Siemens has provided generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to conduct a denial-of-service attack over the network.

SIMATIC S7-1500 Advisory


This advisory describes a resource exhaustion vulnerability in the Siemens SIMATIC S7-1500 CPU family. The vulnerability is self-reported. Siemens has provided generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to conduct denial-of-service attacks.

SCALANCE S-600 Advisory


This advisory describes three vulnerabilities in the Siemens SCALANCE S-600 Firewall. One of the vulnerabilities was reported by Melih Berk Ekşioğlu. Siemens has provided generic workarounds to mitigate the vulnerability.

The three reported vulnerabilities are:

• Cross-site scripting - CVE-2019-6585; and
• Uncontrolled resource consumption (2) - CVE-2019-13925 and CVE-2019-13926

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to conduct denial-of-service or cross-site scripting attacks. User interaction is required for a successful exploitation of the cross-site-scripting attack.

OZW Web Server Advisory


This advisory describes and information disclosure vulnerability in the Siemens OZW web server. The vulnerability was reported by Maxim Rupp. Siemens has a new version that mitigates the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow unauthenticated users to access project files.

SIPORT Advisory


This advisory describes an insufficient logging vulnerability in the Siemens SIPORT MP. The vulnerability is self-reported. Siemens has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow the attacker to create special accounts with administrative privileges.

SCALANCE Advisory


This advisory describes a protection mechanism failure vulnerability in the Siemens SCALANCE X switches. The vulnerability is self-reported. Siemens has updates that mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to perform administrative actions.

SIMATIC PCS 7 Advisory


This advisory describes an incorrect calculation of buffer size vulnerability in the Siemens SIMATIC PCS 7, SIMATIC WinCC, SIMATIC NET PC products. The vulnerability was reported by Nicholas Miles from Tenable. Siemens has new versions that mitigate the vulnerability. There is no indication that Miles has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker with network access to cause a denial-of-service condition.

SIMATIC S7 Advisory


This advisory describes a resource exhaustion vulnerability in the Siemens SIMATIC S7 devices. The vulnerability was reported by China Industrial Control Systems Cyber Emergency Response Team. Siemens has a new version that mitigates the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow remote attackers to perform a denial-of-service attack by sending a specially crafted HTTP request to the web server of an affected device.

PROFINET Advisory


This advisory describes a resource exhaustion vulnerability in the Siemens PROFINET-IO Stack. The vulnerability was reported by Yuval Ardon and Matan Dobrushin of OTORIO. Siemens has updates that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to lead to a denial-of-service condition.

NOTE: OTORIO reports that this same vulnerability is found in multiple vendor products including the Moxa EDS Ethernet Switches.

SIMATIC CP Advisory


This advisory describes two vulnerabilities in the Siemens SIMATIC CP 1543-1. The vulnerabilities are self-reported. Siemens has a new version that mitigates the vulnerabilities.

The two reported vulnerabilities are:

• Improper access control - CVE-2019-12815; and
• Loop with unreachable exit condition - CVE-2019-18217

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow for remote code execution and information disclosure without authentication, or unauthenticated denial of service.

Industrial Products Advisory


This advisory describes two vulnerabilities in the Siemens SCALANCE, SIMATIC, SIPLUS products. The vulnerabilities were reported by Artem Zinenko of Kaspersky Lab. Siemens has new versions that mitigate the vulnerabilities. There is no indication that Zinenko has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Data processing errors - CVE-2015-5621; and
• Null pointer dereference - CVE-2018-18065

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow remote attackers to conduct a denial-of-service attack by sending specially crafted packets to Port 161/UDP (SNMP).

SIMOCODE Update


This update provides additional information on an advisory that was originally published on March 9th, 2019 and most recently updated on January 14th, 2020. The new information includes the addition of two affected products:

• SITOP PSU8600; and
• TIM 1531 IRC

Industrial Products w/OPC UA Update


This update provides additional information on an advisory that was originally published on April 9th, 2019 and most recently updated on January 14th, 2020. The new information includes updated affected version data and mitigation links for SIMATIC NET PC Software.

PROFINET Update


This update provides additional information on an advisory that was originally published on October 10th, 2019 and most recently updated on January 14th, 2020. The new information includes updated affected version data and mitigation links for SINAMICS DCP.

Industrial Real Time Devices Update


This update provides additional information on an advisory that was originally published on October 10th, 2019 and most recently updated on January 14th, 2020. The new information includes updated affected version data and mitigation links for SINAMICS DCP.

SIMATIC Update


This update provides additional information on an advisory that was originally published on December 10th, 2019. The new information includes updated affected version data and mitigation links for:

• TIM 1531 IRC;
• SIMATIC NET PC Software

Other Siemens Advisories and Updates


Siemens also published two additional advisories and 3 updates yesterday that have not yet been addressed by NCCIC-ICS.

Additionally, on Monday Siemens published updates of 58 previously published advisories. All of these updates were adding references to the SIPLUS device variants as affected products. Siemens has been adding references to this as they have been updating advisories for the last couple of months, so it looks like they are just doing the final house cleaning on the issue. I do not expect NCCIC-ICS to update all of their applicable advisories.

Tuesday, February 11, 2020

HR 4432 Passed in House – UAS Threat Assessment


Yesterday the House passed HR 4432, the Protecting Critical Infrastructure Against Drones and Emerging Threats Act by a voice vote. There was only about six minutes of ‘debate’ on the bill with no voices heard in opposition.

The language that disappeared between the Committee Hearing and the publication of the Report stayed gone. The reported language was the version that the House adopted.

If this bill is taken up in the Senate it will be considered under the Senate’s unanimous consent process. The major draw back to that process is that a single Senator could block consideration of the bill for reasons totally unrelated to the provisions being considered.

HR 5780 Introduced – Safe Communities Act


Last week Rep Underwood (D,IL) introduced HR 5780, the Safe Communities Act of 2020. The bill is very nearly identical to HR 5667 that was introduced by Underwood last month.

Difference


There is only one difference that I can find between the two bills. In the earlier bill §3(a) reads:

“(a) STRATEGY.—Not later than 180 days after the date of the enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security shall issue a strategy to improve stakeholder outreach and operational engagement that includes the Agency’s strategic and operational goals and priorities for carrying out the stakeholder engagement activities described in paragraphs (6) and (11) of section 2202(c) of the Homeland Security Act of 2002 (6 U.S.C. 652(c)), as added and redesignated, respectively, by section 2 of this Act.”

In HR 5780 §3(a) reads the same except everything from the words ‘described in paragraphs’ to the end of the sentence has been removed.

Moving Forward


As I noted yesterday, the House Homeland Security Committee will markup this bill tomorrow. The bill is likely to receive widespread bipartisan support.

Bills Introduced – 2-10-20


Yesterday with both the House and Senate in session there were 27 bills introduce. One of those bills will receive additional attention in this blog:

HR 5823 To establish a program to make grants to States to address cybersecurity risks and cybersecurity threats to information systems of State, local, Tribal, or territorial governments, and for other purposes. Rep. Richmond, Cedric L. [D-LA-2]

This is the second bill I mentioned yesterday that will be marked up by the House Homeland Security Committee tomorrow. A copy of the bill has been published by the GPO so I may be able to review this bill before tomorrow’s hearing.

 
/* Use this with templates/template-twocol.html */