4 Advisories Published – 2-24-22
Today, CISA’s NCCIC-ICS published four control system security advisories for product from Baker Hughes, Schneider Electric, Mitsubishi Electric and FATEK Automation.
Baker Hughes Advisory
This advisory describes a use of password hash with insufficient computational effort vulnerability in the Baker Hughes Bently Nevada 3500 machinery protection system. The vulnerability was reported by Ron Brash and Nicolas Harsey from Verve Industrial. Baker Hughes has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.
NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker access to system credentials.
NOTE: This advisory was originally published to the HSIN ICS library on August 19th, 2021. This allows CISA to share the information with critical infrastructure organizations prior to making the vulnerability public. To request access to the HSIN ICS library email HSIN.HelpDesk@hq.dhs.gov.
Schneider Advisory
This advisory describes three vulnerabilities on the Schneider Easergy P5 and P3 medium voltage protection relays. The vulnerabilities were reported (possibly here?) by Timothée Chauvin, Paul Noalhyt, and Yuanzhe Wu at Red Balloon Security. Schneider has new firmware that mitigates the vulnerabilities. There is no indication that the researcher have been provided an opportunity to verify the efficacy of the fix.
The three reported vulnerabilities are:
Use of hard-coded credentials - CVE-2022-22722, and
Classic buffer overflow (2) - CVE-2022-22723 and CVE-2022-22725
NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to disclose device credentials, cause a denial-of-service condition, device reboot, or allow an attacker to gain full control of the relay. This could result in loss of protection to your electrical network.
NOTE: I briefly discussed the two Schneider advisories for these vulnerabilities on January 16th, 2022.
Mitsubishi Advisor
This advisory describes nine vulnerabilities in the Mitsubishi EcoWebServerIII. These vulnerabilities were self-reported. Mitsubishi has new versions that mitigate the vulnerabilities.
The nine reported vulnerabilities are:
Cross-site scripting (7) - CVE-2016-10735 (exploit), CVE-2018-14040 (exploit), CVE-2018-14042 (exploit), CVE-2018-20676, CVE-2019-8331 (exploit), CVE-2020-11022 (exploit), and CVE-2020-11023 (exploit)
Uncontrolled resource consumption - CVE-2017-18214, and
Improperly controlled modification of dynamically-determined object attributes - CVE-2020-7746 (exploit)
NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow information to be disclosed, tampered with, or result in a denial-of-service condition.
NOTE: I briefly discussed these vulnerabilities last Saturday.
FATEK Advisory
This advisory describes three vulnerabilities in the FATECK FvDesigner software tool. The vulnerabilities were reported by xina1i via the Zero Day Initiaive and Khangkito of VinCSS. FATEK has not responded to NCCIC-ICS about these vulnerabilities.
The three reported vulnerabilities are:
Stack-based buffer overflow - CVE-2022-25170,
Out-of-bounds write - CVE-2022-23985, and
Out-of-bounds read - CVE-2022-21209
NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to allow an attacker to execute arbitrary code.