Today CISA’s NCCIC-ICS published three control system security advisories for products from xArrow, Advantech, and ThroughTek. They also updated an advisory for products for multiple RTOS.
xArrow Advisory
This advisory describes three vulnerabilities in the xArrow SCADA/HMI. The vulnerabilities were reported by Sharon Brizinov from Claroty, and Michael Heinzl. xArrow has not responded to NCCIC-ICS about these vulnerabilities.
The three reported vulnerabilities are:
Cross-site scripting (2) - CVE-2021-33021 and CVE-2021-33001, and
Improper input validation - CVE-2021-33025
NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to result in remote code execution.
NOTE: It is not often that you see editorial comments in an NCCIC-ICS advisory, but, because of the lack of response they note: “Users of these affected products who would like to see more responsible security are invited to contact xArrow customer support.” An email link (support@xarrow.net) may have been more appropriate.
Advantech Advisory
This advisory describes an improper authentication vulnerability in the Advantech WebAccess network management system (NMS). The vulnerability was reported by Selim Enes Karaduman via the Zero Day Initiative. Advantech has a new version that mitigates the vulnerability. There is no indication that the Karaduman has been provided an opportunity to verify the efficacy of the fix.
NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to lead to the exposure of resources or functionality and could result in sensitive information disclosure.
ThroughTek Advisory
This advisory describes an improper access control vulnerability in their Kalay P2P software development kit (SDK). The vulnerability was reported by Jake Valletta, Erik Barzdukas, and Dillon Franke from Mandiant. ThroughTek provides mitigation measures for the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.
NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to permit remote code execution and unauthorized access to sensitive information, such as to camera audio/video feeds.
NOTE 1: This is the first time that I have published a ‘reported by’ link to a YouTube® video. Mandiant provides a demonstration of proof-of-concept code for the vulnerability.
NOTE 2: NCCIC-ICS notes: “ThroughTek supplies multiple original equipment manufacturers of IP cameras with P2P connections as part of its cloud platform.” So this vulnerability could end up being a third-party vulnerability for a number of vendors.
Multiple RTOS Update
This update provides additional information for an advisory that was originally published on April 29th, 2021 and most recently updated on May 20th, 2021. The new information includes:
Adding three BlackBerry QNX products to the list of affected products,
Adding a new vulnerability (another integer overflow or wraparound vulnerability - CVE-2021-22156) that is apparently unique to the affected BlackBerry products, and
Adding updates for the affected BlackBerry products
NOTE 1: NCCIC-ICS got the date of the ‘B’ update wrong; it was May 20th, not May 24th. They had a similar problem with the earlier update.
NOTE 2: CISA’s National Cyber Awareness System (NCAS) published a separate advisory for the BlackBerry BadAlloc vulnerabilities covered in this update.