Wednesday, December 9, 2020

House Agrees to HR 6395 Conference Report – FY 2021 NDAA

Yesterday the House voted to agree to the Conference Report on HR 6395, the FY 2021 National Defense Authorization Act. The Report was agreed to by a strongly bipartisan vote of 335 to 78. The 78 negative votes were nearly equally divided between Republicans (40) and Democrats (37). This would tend to indicate that the crafters of the Report constructed a fairly middle-of-the-road compromise on the legislation.

The Senate will take up the bill later this week. It appears that the Senate will also agree to the Report with a bipartisan majority.

There has been no word of Trump backing down from his threat to veto the bill. The vote in the House could mean that there were enough votes there to override a veto. That is not certain, since there is a good chance that there would be some level of Republican defections if it comes down to a veto override vote.

OMB Approves NISPOM Interim Final Rule

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved the DOD’s National Industrial Security Program Operating Manual (NISPOM) interim final rule. This rulemaking was submitted to ORIA back in August.

According to the Spring 2020 Unified Agenda entry for this rulemaking:

“This rule will codify the National Industrial Security Program Operating Manual (NISPOM) which prescribes specific requirements, restrictions, and other safeguards that are necessary to preclude unauthorized disclosure and control authorized disclosure of Federal Government classified information to contractors, licensees, or grantees. The NISPOM applies to the release of classified information during all phases of the contracting process, including bidding, negotiation, award, performance, and termination of contractors, the licensing process or the grant process, with or under the control of departments or agencies.”

Again, I am not intending to delve deeply into the DOD’s Industrial Security Program. I am highlighting this rulemaking because this manual is going to be a good guide to information security requirements for anyone that wants to gain routine access to classified information, for example government cyber-threat intel.

House to Take Up Short Term CR

Yesterday Rep. Lowey (D,NY) introduced HR 8900 (this is not an ‘official’ copy of the bill), the Further Continuing Appropriations Act, 2021. The bill is a ‘clean’, short-term extension of the current spending authority for FY 2021. It would extend that authority thru December 18th, 2020. The House is scheduled to take up the bill this afternoon under the suspension of the rules process. This means limited debate, no floor amendments and it would require a super-majority to pass the bill.

The bill does include extensions of a number of Medicare, Medicaid, and public health programs for the same period.

The House is expected to pass this bill with significant bipartisan support and the Senate will take it up later this week. No word yet on the President’s intentions with respect to this bill.

The current spending authority expires at midnight on Friday.

13 Updates Published – 12-8-20

Yesterday the CISA NCCIC-ICS updated thirteen control system security advisories for products from Siemens.

LOGO! Update #1

This update provides additional information on an advisory that was originally published on August 31st, 2017 (not August 13th as reported in the advisory, a simple case of typing dyslexia I suppose). The new information includes adding mitigation solution for CVE-2017-12735.

SCALANCE Update

This update provides additional information on an advisory that was originally published on June 14th, 2018 and most recently updated on June 11th, 2019. The new information includes adding data about successor products for SIMATIC RF182C and RFID 181EIP

LOGO! Update #2

This update provides additional information on an advisory that was originally published on May 14th, 2019. The new information includes adding a mitigation solution for LOGO! 8 BM

LOGO! Update #3

This update provides additional information on an advisory that was originally published on May 14th, 2019. The new information includes adding mitigation measures.

Industrial Products Update #1

This update provides additional information on an advisory that was originally published on September 10th, 2019 and most recently updated on October 13th, 2020. The new information includes adding solution for SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP.

PROFINET Update

This update provides additional information on an advisory that was originally published on February 11th, 2020 and most recently updated on August 11th, 2020. The new information includes:

• Adding SIMOTION products to the affected products list;

• Updating information regarding successor products for SIMATIC RF180C and RF182C

SIMATIC Update #1

This update provides additional information on an advisory that was originally published on July 9th, 2020 and most recently updated on July 14th, 2020. The new information includes correcting affected version and patch link for SINAMICS STARTER.

SIMATIC Update #2

This update provides additional information on an advisory that was originally published on July 9th, 2020 and most recently updated on September 8th, 2020. The new information includes adding solution for:

• SIMATIC S7-1500 Software Controller, and

• SINAMICS STARTER

LOGO! Update #4

This update provides additional information on an advisory that was originally published on June 9th, 2020. The new information includes adding mitigation for LOGO! V8.3.

UMC Stack Update

This update provides additional information on an advisory that was originally published on July 14th, 2020 and most recently updated on November 11th, 2020. The new information includes adding solution for Soft Starter ES.

SIMATIC Update #3

This update provides additional information on an advisory that was originally published on August 11th, 2020. The new information includes adding solution for SIMOTICS CONNECT 400.

Industrial Products Update #2

This update provides additional information on an advisory that was originally published on September 8th, 2020 and most recently updated on October 13th, 2020. The new information includes adding solutions for:

• for SIMATIC IPC427E,

• SIMATIC IPC477E, and

• SIMATIC IPC477E PRO

SIMATIC Update #4

This update provides additional information on an advisory that was originally published on September 8th, 2020 and most recently updated on November 10th, 2020. The new information includes adding the following researchers in the acknowledgements section:

• Jongwon Choi from NSR (National Security Research Institute), and

• Taeshik Shon from Ajou University

Other Siemens Updates

Siemens also published updates for five other advisories yesterday. I will report on these this weekend.

Tuesday, December 8, 2020

11 Advisories Published – 12-8-20

Today the CISA NCCIC-ICS published 10 control system security advisories for products from Siemens (6), Schneider (2), Mitsubishi, and multiple vendors. They also published a medical device security advisory for products from GE Healthcare.

NOTE: NCCIC-ICS also published 13 updates (according to an email I received from CISA) for previously published advisories. Interestingly the ICS Archive Information Products web page only currently lists 5 updates. In any case, I will address these updates tomorrow.

LOGO! Advisory

This advisory describes eight vulnerabilities in the Siemens LOGO! 8 BM products. The vulnerabilities were reported by Thomas Meesters from cirosec GmbH, as well as Tobias Gebhardt, and Max Bäumler. Siemens has new versions that mitigate the vulnerability. There is no  indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The eight reported vulnerabilities are:

• Missing authentication for critical function - CVE-2020-25228,

• Use of hard-coded cryptographic key (4) - CVE-2020-25229, CVE-2020-25231, CVE-2020-25233, and CVE-2020-25234,

• Use of a broken or risky cryptographic algorithm (2) - CVE-2020-25230, and CVE-2020-25232, and

• Insufficiently protected credentials - CVE-2020-25235

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker the ability to make configuration and password changes, capture device keys, access confidential information, and gain full control of the device.

SIMATIC Advisory

This advisory describes an uncaught exception vulnerability in the Siemens SIMATIC Controller Web Servers. The vulnerability is self-reported. Siemens has updates that mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to cause a denial-of-service condition.

TightVNC Advisory

This advisory describes four vulnerabilities in the Siemens SIMATIC products using TightVNC (v1.X), a remote-control software package. TightVNC is an open-source third-party product. The vulnerability was reported by Kaspersky Labs. Siemens has updates for some of the affected products. There is no indication that the researchers have been provided with an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Heap-based buffer overflow (2) - CVE-2019-15678, and CVE-2019-15679,

• Null pointer dereference - CVE-2019-15680, and

• Classic buffer overflow - CVE-2019-8287

NOTE: The Kaspersky report identifies vulnerabilities in three other implementations of the VNC protocol; LibVNC, TurboVNC and UltraVNC. Other products (other vendors) with remote access capabilities are going to be affected by these issues. This is going to be a fun one.

SICAM Advisory

This advisory describes a protection mechanism failure vulnerability in the Siemens SICAM A8000 Remote Terminal Unit Series. The vulnerability was reported by Sam Hamra from KTH Royal Institute of Technology. Siemens has a version that mitigates the vulnerability. There is no indication that Hamra has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to gain unauthorized read or write access to network traffic to or from the device.

XHQ Advisory

This advisory describes seven vulnerabilities in the Siemens XHQ Operations Intelligence. The vulnerabilities are self-reported. Siemens has a new version that mitigates the vulnerabilities.

The seven reported vulnerabilities are:

• Exposure of sensitive information to an unauthorized actor - CVE-2019-19283,

• Cross-site scripting - CVE-2019-19284, and CVE-2019-19288,

• Basic XSS - CVE-2019-19285,

• SQL injection - CVE-2019-19286,

• Relative path traversal - CVE-2019-19287, and

• Cross-site request forgery - CVE-2019-19289

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to read sensitive information, modify web content, and perform cross-site scripting and cross-site request forgery on unsuspecting users.

Embedded TCP/IP Stack Advisory

This advisory describes an integer overflow vulnerability in the Siemens SENTRON PAC3200, SENTRON PAC4200, SIRIUS 3RW5 products. This is the third-party Amensia33 vulnerability. The vulnerability was reported by Daniel dos Santos, Stanislav Dashevskyi, Jos Wetzels, and Amine Amri of Forescout Research Labs. Siemens has upgrades available for some of the affected products.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to ause a denial-of-service condition.

Modicon Advisory

This advisory describes five vulnerabilities in the Schneider Modicon M221 Programmable Logic Controller. The vulnerabilities were reported by Yehuda Anikster and Rei Henigman of Claroty, and Seok Min Lim and Bryon Kaan of Trustwave. Schneider has provided generic workarounds to mitigate the vulnerabilities.

The five reported vulnerabilities are:

• Inadequate encryption strength - CVE-2020-7565,

• Small space of random values - CVE-2020-7566,

• Missing encryption of sensitive data - CVE-2020-7567,

• Exposure of sensitive information - CVE-2020-7568, and

• Use of a one-way hash with a predictable salt - CVE-2020-28214

NCCIC-ICS reports that an uncharacterized attacker on an adjacent network could exploit the vulnerabilities to allow an attacker to take control over the PLC and gain unauthorized access, which could result in exposure of sensitive information.

NOTE 1: I briefly reported on the original Schneider advisory back in November. This NCCIC-ICS advisory is based upon an updated version of that advisory published today that adds the last vulnerability reported above.

NOTE 2: The Trustwave report includes proof-of concept exploit code.

Easergy Advisory

This advisory describes five vulnerabilities in the Schneider Easergy T300. The vulnerabilities were reported by Evgeniy Druzhinin and IIya Karpov of Rostelecom-Solar. Schneider has a new version that mitigates the vulnerabilities. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Missing authentication for critical function - CVE-2020-7561,

• Missing authorization - CVE-2020-28215,

• Missing encryption of sensitive data (2) - CVE-2020-28216, and CVE-2020-28217, and

• Improper restriction of rendered UI layers or frames - CVE-2020-28218

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerabilities to obtain unauthorized access to the internal product LAN, which could result in exposure of sensitive information, denial of service, and remote code execution when access to a resource from an attacker is not restricted or incorrectly restricted.

NOTE: I briefly reported on the original Schneider advisory back in November. This NCCIC-ICS advisory is based upon an updated version of that advisory published today that adds the last four vulnerabilities reported above.

NOTE: Schneider also published nine new advisories and three additional updates today. I suspect that I will be addressing these this weekend.

Mitsubishi Advisory

This advisory describes an out-of-bounds read vulnerability in the Mitsubishi GOT and Tension Controller. The vulnerability is self-reported. Mitsubishi is providing generic mitigation measures while it continues to work on a fixed version of the products.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause deterioration of communication performance or cause a denial-of-service condition of the TCP communication functions of the products.

NOTE: I briefly reported on this vulnerability last weekend.

Embedded TCP/IP Stacks Advisory

This advisory discusses the Amnesia33 vulnerabilities that were briefly addressed in the Siemens TCP/IP advisory above. This separate advisory lists 33 distinct vulnerabilities (thus the ‘33’ in the title of the Forescout report) found in the different TCP/IP stack implementations. It also provides a list of vendor advisories for products affected by these vulnerabilities:

Devolo

EMU Electronic AG

FEIG

Genetec

Harting

Hensoldt

Microchip

Nanotec

NT-Ware

Tagmaster

Siemens

Uniflow

Yanzi Networks

It is interesting that NCCIC-ICS published a separate advisory for the Siemens version of the vulnerability.

GE Advisory

This advisory describes two vulnerabilities in the GE Imaging and Ultrasound Products. The vulnerabilities were reported by Lior Bar Yosef and Elad Luz of CyberMDX. GE has publicly provided generic workarounds to mitigate the vulnerabilities.

The two reported vulnerabilities are:

• Unprotected transport of credentials - CVE-2020-25175, and

• Exposure of sensitive system information to an unauthorized control sphere - CVE-2020-25179

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to gain access to affected devices in a way that is comparable with GE (remote) service user privileges. A successful exploitation could expose sensitive data such as a limited set of patient health information (PHI) or could allow the attacker to run arbitrary code, which might impact the availability of the system and allow manipulation of PHI.


Monday, December 7, 2020

ISCD Publishes CFATS November Update – 12-7-20

Today the CISA Infrastructure Security Compliance Division (ISCD) updated their Chemical Facility Anti-Terrorism Standards (CFATS) Monthly Statistics page to provide information for Chemical Security Inspector activities and facility status for the month of November.

CSI Activities

The table below shows the activities conducted by the CSI in November.

Inspection Data

Aug-20

Sep-20

Oct-20

Nov-20

Authorization Inspections

24

31

21

14

Compliance Inspections

107

131

90

68

Compliance Assistance

115

140

100

102

Compliance Audit

9

23

5

0

The web page does not explain the month-to-month variations in the CSI activities. The numbers this month continue the decline in activities that we saw last month. The November numbers dropped to the lowest levels since the Federal Funding Fiasco in December 2018. Since the largest component of that drop is the number of Compliance Inspections conducted, it is possible that this is due to a drop in the number of facilities that are due for their periodic re-inspections; it is just not yet time for the CSI to come back and check facility site security plan compliance again.

Facility Status

The table below shows the status of facilities covered under the CFATS program.

Facility Status

Aug-20

Sep-20

Oct-20

Nov-20

Tiered

124

108

90

85

Authorized

147

159

161

146

Approved

3056

3053

3048

3050

Total

3327

3320

3299

3281

We are continuing to see a rather sharp drop in the number of facilities covered under the CFATS program. This has been a general trend since the program began. There is, of course, a financial incentive for companies to try to reduce their level of risk of a terrorist attack by reducing or eliminating the inventory of DHS chemicals of interest at the facility. Unfortunately, with the ongoing COVID-19 pandemic, it is also possible that the sharp decrease seen in covered facilities over the last two months may be partially attributable to facility closures or declining manufacturing rates.

Conference Report for HR 6395 – FY 2021 NDAA

On Thursday the conferees for HR 6395, the FY 2021 National Defense Authorization Act (NDAA), published their 4500 page ‘Conference Report’ working out the differences between the two versions of the bill. The official GPO version is not yet available, but the House Armed Services Committee posted a copy on their web site. The House is slated to take up the revised language from the report on Tuesday, followed by the Senate later in the week. There is an open threat of a presidential veto, but we will have to wait and see how that turns out.

Provisions of Interest

There are a huge number of ‘cyber’ related provisions in this bill. The following list shows those that I think are most interesting from a control system security point of view.

§1715. Establishment in Department of Homeland Security of joint cyber planning office. (pg 1810) (revised pg 4170)
§1716. Subpoena authority. (pg 1815)
§1717. Cybersecurity State Coordinator. (pg 1827) (revised pg 4170)
§1718. Cybersecurity Advisory Committee. (pg 1836) (revised pg 4170)

§1725. Pilot program on remote provision by National Guard to National Guards of other States of cybersecurity technical assistance in training, preparation, and response to cyber incidents. (pg 1865) (revised pg 4174)

§1729. Cyber capabilities and interoperability of the National Guard. (pg 1880) (revised pg 4175)

§1736. Defense industrial base cybersecurity sensor architecture plan. (pg 1901) (revised pg 4178)

§1737. Assessment on defense industrial base participation in a threat information sharing program. (pg 1903) (revised pg 4179)

§1738. Assistance for small manufacturers in the defense industrial supply chain on matters relating to cybersecurity. (pg 1909)

§1739. Assessment on defense industrial base cybersecurity threat hunting program. (pg 1912) (revised pg 4180)

§1742. Department of Defense cyber hygiene and Cybersecurity Maturity Model Certification framework. (pg 1922) (revised pg 4182)

§1745. Cybersecurity and Infrastructure Security Agency review. (pg 1933)

§1752. National Cyber Director. (pg 1950) (revised pg 4186)

§9005. GAO study of cybersecurity insurance. (pg 3407)

The ‘(pg XXXX)’ listing refers to the language of the actual provision in the bill. The ‘(revised pg 4XXX)’ listing refers to the brief discussion of changes made to the provision in the conference.

Interesting Finds

There is no way that I ‘read’ all 4517 pages of the report. Most of what I did do was put the term ‘cyber’ in the search tool of my .PDF reader and click through the report. In doing so, I discovered a couple of interesting items.

I found the first item on page 680 in §589F. This section introduces a new term that I have never heard before; ‘cyberexploitation’. It is defined as using digital means and online platforms to [§589F(d)(1)]:

• “knowingly access, or conspire to access, without authorization, an individual’s personal information to be employed (or to be used) with malicious intent; or

• “to deceive an individual with misinformation with malicious intent.”

In this section of the NDAA it is used to describe actions taken against family member of armed forces personnel. The bullet in the definition above could apply to all sorts of cyber activities that we have been seeing in recent history. I think that this term (I would hyphenate it ‘cyber-exploitation’) should be more widely used.

I found the second item on page 2247 during the discussion of §2826, Improved electrical metering of Department of Defense infrastructure supporting critical missions. The final subsection shows the increasing cybersecurity sophistication of congressional staffers. It reads:

“(c) CYBERSECURITY.—The Secretary of Defense and the Secretaries of the military departments shall consult with the Chief Information Officer of the Department of Defense to ensure that the electrical energy metering options considered under subsection (b) do not compromise the cybersecurity of Department of Defense networks.”

Intelligence Authorization Act

As I noted in my blog post about the Senate passing HR 3695, the Senate include the FY 2021 Intelligence Authorization Act as a division in the bill. That language did not survive conference. The House has not yet acted on their version of this (HR 7856) ‘must pass’ legislation. The Senate has not acted on their standalone version (S 3905). There is still a chance that some version of this bill could find it into the omnibus spending bill.

 
/* Use this with templates/template-twocol.html */