Showing posts with label DoS. Show all posts
Showing posts with label DoS. Show all posts

Saturday, November 28, 2020

Not enough attention paid to industrial automated systems

 

Nearly all the products we purchase are processed by automated systems. If these were to stop working, or workflow maliciously adjusted, there would be a clear issue immediately as the products were assembled incorrectly or broken during the “adjusted” process. While this potential to wreck our way of life if implemented on a large scale, there has not been a sufficient amount of attention paid to it. Recently, a new vulnerability was uncovered with the equipment. This vulnerability, which is critical, is in the real-time automation’s (RTA) 499E5 EtherNet/IP (ENIP) stack. The stack is widely used and is the standard for factory floor I/O applications in North American plants. If the attacker is able to exploit this, the equipment could experience a DoS-type attack, and allow for remote code execution. This vulnerability, CVE-2020-25159, has the opportunity to not only shut down a line and part of a plant but also be instructed to do whatever the unauthorized third party directs it to. Based on the pertinence to society these automated processed play and the costs associated with these lines not being productive, more of a focus needs to be applied to this. There is even a tool available used to scour the internet seeking the robots used in these processes which are not properly secured. Without cybersecurity, in place, there is the potential for individual attacks and much worse with a concerted attack.


Please contact us when we may be of assistance with embedded systems cybersecurity architecture, validation, and penetration testing. We have a full lab ready to perform.

Charles Parker, II; Principal Scientist; MBA/MSA/JD/LLM/PhD/DCS (IP)

charlesparkerii@gmail.com

810-701-5511


Friday, November 1, 2019

Mitsubishi PLC targeted


Mitsubishi Electric (ME) manufactures various products through their lines. One of these is the programmable logic controller (PLC). PLCs are not singularly used in one industry or another. These have many uses across many industries. The units are used across the world, in Mitsubishi Electric’s case, in manufacturing facilities.
PLC Targeted
ME has several different PLC models manufactured and actively used. Of the many PLCs manufactured, the subject model is MELSEC-Q series QJ71E71-100 Ethernet Interface modules with serial numbers 20121 and prior were subject to the vulnerability. While this is only one model, these are placed in service in a myriad of locations.
Vulnerability
The vulnerability has been noted with ICSA-19-141-02 and CVE-2019-10977. This has a high severity with a CVSS score of 7.5. This indicates the organizations employing this hardware should have paid strict attention to this. This issue being left open would create the potential for a significant problem. The issue involves the denial of service (DoS) attack vector. The vulnerability may be exploited remotely. This makes the vulnerability especially interesting for the organizations using this. The attack is done through sending malicious TCP packets. These are sent to the target’s FTP service. This ends up, when exploited, in placing the PLC into fault mode, which ceases its operations. The only option to correct this is to restart the PLC. While not as detrimental as other successful attacks, this shuts down the PLC and any other services or functions dependent on it.
Attack
The attacker could exploit the issue, from anywhere with a good internet connection. One saving grace with this is the PLCs are not detectable using Shodan or a like tool.
Remediation
Fortunately, ME resolved the vulnerability issue with firmware update version 20122. With this downloaded and into each PLC, there could have been rather significant issues causing many headaches.
Resources

CISA. (2019, May 21). ICA advisory (ICSA-19-141-02). Retrieved from https://www.us-cert-gov/ics/advisories/ICSA-19-141-02

Kovacs, E. (2019, May 22). Flaw exposes Mitsubishi PLCs to remote DoS attacks. Retrieved from https://www.securityweek.com/flaw-exposes-mitsubishi-plcs-remote-dos-attacks

SecuriTeam. (2019, July 15). Mitsubishi electric MELSEC-Q series Ethernet module ZJ71E71-100 serial number 20121 remote code execution vulnerability. Retrieved from https://securiteam.com/securitynews/mitsubishi-electric-melser-q-series-ethernet-module-qq71e71-100-serial-number-20121-remote-code-execution-vulnerability/


Sunday, October 27, 2019

Mitsubishi Electric Issues

Due to several significant factors, there are a limited number of automobile manufacturers. The
infrastructure expenses alone are massive and limit the scape of potential persons and organizations
financially able to be involved. 


Mitsubishi is Japan-based, is one of these manufacturers. As with most of the organizations, there are
separate organizations under the general corporate envelope. For Mitsubishi, one of these is
Mitsubishi Electric. 


FR Configurator 2 Inverter Engineering Software
The subject issue is with the FR Configurator 2 inverter software. This affects version 1.165 and 1.10L
and prior to SW1DND-FRCZ-E or -J. This works to permit the user to set-up, program, configure,
and monitor the drives. This software runs on all versions of MS Windows. This is used throughout
the world. 


Vulnerabilities
With this software tool, there are three significant vulnerabilities. The first is a high severity issue
with a CVSSv3 score of 8.8. This is associated with the XML external entity (XXE) processing.
This works by exploiting the DTD parameter. When this vulnerability is exploited, the attacker is
able to read and exfiltrate files located on the targeted system. To execute this, the user has to
only open a malicious files. As a bonus, this may in certain instances allow the attacker to execute
their malicious code on the target system. This has been labeled as ICSA-10-204-01 and
CVE-2019-10976. 


The second vulnerability permits the attacker to force the software from responding. This operates
much like a DoS attack, aka CPU exhaustion. The only way to resolve this is to do a hard restart.
This vulnerability is labeled as ICSA-19-204-01 and CVE-2019-10972. This vulnerability has been
rated as the medium severity issue with a CVSSv3 score of 5.5. This is exploited also by having the
user open a malicious file. The first and second vulnerabilities both require social engineering and a
phishing attempt. The end goal is to have the user open the email and attachment. 


The third and last vulnerability rated as high severity, under the CVSSv3 score of 8.2. With this issue,
the problem is with the binary’s read, write, and execute rights. This allows for privilege escalation.
When exploited, this allows an account with lower-level privileges, such as a guest account, to
increase their rights, and may execute malicious files. 


Remediated 
These vulnerabilities were relatively significant. These could allow successful attackers to effectively
shut down a system, exfiltrate data, and elevate privileges. Mitsubishi Electric advised the users not
to open files from sources unknown or untrusted to the user. When the user receives an email that
is unsolicited, the user should not click on links or attachments. 

Resources 
Cyware. (2019, July 24). Vulnerabilities found in mitsubishi inverter engineering software. Retrieved
from
https://cyware.com/news/vulnerabilities-found-in-mitsubishi-inverter-engineering-software-fe6610d7 


ISS Source. (2019, July 23). Mitsubishi fixes FR configurator 2 holes. Retrieved from
https://isssource.com/mitsubishi-fixes-fr-configurator-2-holes/ 


Kovacs, E. (2019, July 24). Vulnerabilities found in mitsubishi inverter engineering software. Retrieved
from https://www.securityweek.com/vulnerabilities-found-mitsubishi-invertr-engineering-software 


Mitsubishi Electronic. (2019, July 23). XML vulnerability in FR configurator 2. Retrieved from
https://www.mitsubishielectric.com/fa/download/software/drv/inv/vulnerability-protection/2019-001.pdf 


Mitsubishi Electric. (2019, July 24). AUSCERT external security bulletin redistribution. 


US-Cert. (2019, July 23). ICS advisory (ICSA-19-204-01). Retrieved from
https://www.us-cert.gov/ics/advisories/icsa-19-204-01 


Westenberg, T. (2019, July 24). AR 2019011: Mitsubishi electric FR configurator 2 multiple
vulnerabilities. 

Zurkus, K. (2019, May 22). Firmware vulnerability in mitsubishi electric. Retrieved from
https://www.infosecurity-magazine.com/news/firmware-vulnerability-in-1/