Today, CISA’s NCCIC-ICS published three control system security advisories for products from WIN-911 and GE (2).
WIN-911 Advisory
This advisory describes two incorrect default permissions vulnerabilities in the WIN-911 2021 alarm notification platform. The vulnerabilities were reported by Noam Moshe of Claroty. WIN-911 has a hot fix that mitigates the vulnerability. There is no indication that Moshe has been provided an opportunity to verify the efficacy of the fix.
NCCIC-ICCS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to leverage the misconfigured privileges to the installed directory and achieve code execution in the application’s context and permissions.
NOTE: The WIN-911 advisory provides a good explanation of the how these two vulnerabilities work.
GE Advisory #1
This advisory describes a clear-text transmission of sensitive information vulnerability in the GE Proficy CIMPLICITY HMI and SCADA platform. The vulnerability was reported by Yuval Ardon and Roman Dvorkin of OTORIO. GE provides generic mitigation measures.
NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to capture a connection session, resulting in disclosure of sensitive information.
GE Advisory #2
This advisory describes an improper privilege management vulnerability in the GE Proficy CIMPLICITY HMI and SCADA platform. The vulnerability was reported by Yuval Ardon and Roman Dvorkin of OTORIO. GE has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.
NCCIC-ICS reports that an uncharacterized actor with uncharacterized access could exploit the vulnerability to allow an attacker to achieve both code execution and local privilege escalation.