Public ICS Disclosures – Week of 2-5-22 - Part 2
For Part 2 we have 14 vendor disclosures from strongSwan, Wireshark (5), Yokogawa, Siemens (2), and Schneider (6). There are six vendor updates from GE Gas Power, Siemens Healthineers, and Schneider (4). Finally, we have an exploit for products from Siemens.
NOTE: Part 3 will address the remaining 30+ updates published by Siemens on Tuesday.
strongSwan Advisory
StrongSwan published a blog post describing an improper authentication vulnerability in their EAP client implementation. The vulnerability was reported by Zhuowei Zhang. StrongSwan has a new version that mitigates the vulnerability. There is no indication that Zhuowei has been provided an opportunity to verify the efficacy of the fix.
NOTE: This blog post contains an interesting discussion about the EAP authentication process in VPNs.
Wireshark Advisories
Wireshark published an advisory describing a CMS dissector crash vulnerability. Wireshark has new versions that mitigates the vulnerability.
Wireshark published an advisory describing a CSN.1 dissector vulnerability. The vulnerability was reported by Sharon Brizinov of Claroty. Wireshark has new versions that mitigate the vulnerability. There is no indication that Sharon was provided an opportunity to verify the efficacy of the fix.
Wireshark published an advisory describing a PVFS dissector crash vulnerability. The vulnerability was reported by Sharon Brizinov of Claroty. Wireshark has new versions that mitigate the vulnerability. There is no indication that Sharon was provided an opportunity to verify the efficacy of the fix.
Wireshark published an advisory describing ten large loop vulnerabilities in multiple dissectors. The vulnerabilities were reported by Sharon Brizinov of Claroty. Wireshark has new versions that mitigate the vulnerabilities. There is no indication that Sharon was provided an opportunity to verify the efficacy of the fix.
Wireshark published an advisory describing a RTMPT dissector infinite loop vulnerability. The vulnerability was reported by Sharon Brizinov of Claroty. Wireshark has new versions that mitigate the vulnerability. There is no indication that Sharon was provided an opportunity to verify the efficacy of the fix.
Yokogawa Advisory
Yokogawa published an advisory discussing the Log4Shell vulnerabilities in their CENTUM VP Unified Gateway Station. Yokogawa has a new version that mitigates the vulnerabilities.
Siemens Advisory
Siemens published an advisory discussing a out-of-bounds read vulnerability in their Industrial Products. This is a third-party (OpenSSL) vulnerability. Siemens has new versions for a relatively small number of the affected products that mitigate the vulnerability.
Siemens published an advisory discussing two vulnerabilities in their SIMATIC NET CP, SINEMA and SCALANCE Products. These are third-party (strongSwan) vulnerabilities. Siemens has new versions for a relatively small number of the affected products that mitigate the vulnerability.
The two reported Integer overflow or wraparound vulnerabilities are:
CVE-2021-41990, and
CVE-2021-41991 (contains proof-of-concept code)
Schneider Advisories
Schneider published an advisory describing eight vulnerabilities in their Interactive Graphical SCADA System (IGSS). The vulnerabilities were reported by Tenable (this report contains proof-of-concept code for two of the vulnerabilities), and Vyacheslav Moskvin via the Zero Day Initiative. Schneider has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.
The eight reported vulnerabilities are:
Integer overflow or wrap around - CVE-2022-24310,
Improper limitation of pathname to a restricted directory - CVE-2022-24311, CVE-2022-24312,
Buffer copy without checking size of input - CVE-2022-24313,
Out-of-bounds read - CVE-2022-24314, CVE-2022-24315,
Improper initialization - CVE-2022-24316, and
Missing authorization - CVE-2022-24317
Schneider published an advisory describing two vulnerabilities in their EcoStruxure EV Charging Expert. The vulnerabilities were reported by Tony Marcel Nasr. Schneider has a new version that mitigates the vulnerabilities. There is no indication that Nasr has been provided an opportunity to verify the efficacy of the fix.
The two reported vulnerabilities are:
Permissive cross-domain policy with untrusted domains - CVE-2022-22808, and
Improper restrictions of rendered UI layers or frames - CVE-2022-22807
Schneider published an advisory describing a use of hard-coded credentials vulnerability in their Easergy P40 protection relay. Schneider also reports that the product uses an older version of OpenSSL with known vulnerabilities. Schneider recommends “disabling ‘Courier Tunnel’ in settings when not in use” as a mitigation measure.
Schneider published an advisory describing four vulnerabilities in their spaceLYnk, Wiser For KNX, fellerLYnk products. The vulnerabilities were reported by Tony Marcel Nasr. Schneider has new versions that mitigates the vulnerabilities. There is no indication that Nasr has been provided an opportunity to verify the efficacy of the fix.
The four reported vulnerabilities are:
Missing authentication for critical function - CVE-2022-22809,
Improper restriction of excessive authentication attempts - CVE-2022-22810,
Cross-site request forgery - CVE-2022-22811, and
Cross-site scripting - CVE-2022-22812
Schneider published an advisory describing four vulnerabilities in their EcoStruxure Geo SCADA Expert (ClearSCADA). The vulnerabilities were reported by Frank Lycops of Asvalis, and Cameron Stokes Mandiant. Schneider has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.
The four reported vulnerabilities are:
Inadequate encryption strength - CVE-2022-24318,
Improper certificate validation (2) - CVE-2022-24319 and CVE-2022-24320, and
Improper check for unusual or exceptional conditions - CVE-2022-24321
Schneider published an advisory describing an incorrect default permissions vulnerability in their Harmony/Magelis iPC Series HMI, Vijeo Designer and Vijeo Designer Basic products. The vulnerability was reported by Sharon Brizinov of Claroty. Schneider has new versions that mitigate the vulnerability. There is no indication that Sharon has been provided an opportunity to verify the efficacy of the fix.
GE Gas Power Update
GE Gas Power published an update for their ToolBoxST advisory that was originally published on January 25th, 2022. The new information includes updating the affected version number.
Siemens Healthineers Update
Siemens Healthineers published an update for their Log4Shell advisory. The new information includes:
Removing Atellica Hema Track from the ‘Not Affected’ list,
Adding patch/update information to the ‘Affected’ list.
Schneider Updates
Schneider published an update for their CODESYS V3 Runtime advisory that was originally published on January 11th, 2022. The new information includes:
Adding mitigation for M241/M251, and
Adding Easy Harmony ET6 (HMIET Series) and Easy Harmony GXU (HMIGXU Series) to the list of affected products.
Schneider published an update for their BadAlloc advisory that was originally published on November 9th, 2021 and most recently updated on January 13th, 2022. The new information includes:
Adding remediations for Easy Harmony ET6 (HMIET Series), Easy Harmony GXU (HMIGXU Series), Harmony/ Magelis (HMIGTU Series, HMIGTUX Series, HMIGK Series), Modicon M262 Logic Controllers, and Modicon M241/M251 Logic Controllers, and
Adding Easergy MiCOM P30 and Easergy MiCOM P40 to the list of affected products.
Schneider published an update for their INFRA:HALT advisory that was originally published on August 5th, 2021. The new information includes adding the following to the list of affected products:
Altivar Profinet Communication Module (VW3A3627),
Lexium Ethernet TCP/IP Communication Module (VW3A3616), and
Altivar Profinet - Communication Card (VW3A3327)
Schneider published an update for their Harmony (Magelis) HMI panels that was originally published on August 13th, 2019. The new information includes adding mitigation measures for:
Harmony/Magelis HMIGTO series,
Harmony/Magelis, HMIGTU series,
Harmony/Magelis HMIGTUX series,
Harmony/Magelis HMIGK series
Siemens Exploit
A. Ovsyannikova published an exploit for an open redirect vulnerability in the Siemens SINEMA Remote Connect Server. Siemens disclosed this vulnerability earlier this week.