2 Advisories and 1 Update Published - 7-8-21
Today CISA’s NCCIC-ICS published two control system security advisories for products from MDT Software and Rockwell Automation. They also published an update for an advisory for products from VISAM Automation.
MDT Advisory
This advisory describes seven vulnerabilities in the MDT AutoSave product. The vulnerability was reported by Amir Preminger of Claroty Research. MDT has updated versions that mitigate the vulnerabilities. There is no indication that Preminger has been provided an opportunity to verify the efficacy of the fix.
The seven reported vulnerabilities are:
Inadequate encryption strength - CVE-2021-32945,
SQL injection - CVE-2021-32953,
Relative path traversal - CVE-2021-32949,
Command injection - CVE-2021-32933,
Uncontrolled search path element - CVE-2021-32957,
Generation of error message containing sensitive information - CVE-2021-32937, and
Unrestricted upload of file with dangerous type - CVE-2021-32961
NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to lead to full remote execution on the Remote MDT Server without an existing user or password.
NOTE: NCCIC-ICS prefaces their risk evaluation with the interesting phrase “by an attacker with detailed understanding of the product architecture and database structure” after saying that there is a ‘low attack complexity’ (that I continue to describe as ‘relatively low-skilled attacker’, using the old-style NCCIC-ICS language). The attack is relatively simple but requires detailed system knowledge. This is probably a good description of the problem with attacking industrial control systems. Of course, the longer an attacker has access to a system, the easier it is to gain ‘detailed system knowledge’.
Rockwell Advisory
This advisory describes an improper input validation vulnerability in the Rockwell MicroLogix 1100. The vulnerability was reported by Beau Taub of Bayshore Networks. Rockwell has provided generic mitigation measures.
NOTE: This is one of those vulnerabilities that can be ‘fixed’ by turning the switch from ‘Program’ to ‘Run’.
NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to create a denial-of-service condition.
NOTE: The Rockwell advisory is not currently listed on their advisory web page (registration required).
VISAM Update
This update provides additional information for an advisory that was originally published on 3-24-20. The new information is mitigation measure (new version).
NOTE: The new language replaces the following statement in the original advisory:
“VISAM has not yet responded to provide mitigations for these vulnerabilities.”