Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Tenable 部落格

訂閱

OT:ICEFALL Research from Forescout Explores Insecure-by-Design State of Operational Technology

OT:ICEFALL Research from Forescout Explores Insecure-by-Design State of Operational Technology

The latest research from Forescout’s Vedere Labs explores the state of risk management in operational technology through the lens of 56 insecure-by-design vulnerabilities.

背景說明

On June 20, Forescout’s Vedere Labs published their latest research findings into operational technology (OT) vulnerabilities titled OT:ICEFALL. This group has been examining vulnerabilities affecting OT security for a few years now and has produced notable findings including: NUCLEUS:13, NAME:WRECK, NUMBER:JACK and AMNESIA:33.

OT:ICEFALL sought to analyze and understand the prevalence and impact of insecure-by-design vulnerabilities in OT products. The researchers took a systemic look at OT risk management. The research notes that many factors complicate OT risk management including the certification of vulnerable products, lack of CVE assignment and supply chains propagating vulnerabilities. In the course of this research, Forescout also disclosed 56 vulnerabilities across nine vendor’s products. A tenth vendor is also affected by four vulnerabilities, but they are still going through the disclosure process.

分析

The 56 vulnerabilities are all tied to “insecure-by-design” flaws common in the OT space within the following products:

Vendor Impacted Products
Bently Nevada

3700

TDI equipment

Emerson

DeltaV

Ovation

OpenBSI

ControlWave

BB 33xx

ROC

Fanuc

PACsystems

Honeywell

Trend IQ

Safety Manager FSC

Experion LX

ControlEdge

Saia Burgess PCD

JTEKT Toyopuc
Motorola

MOSCAD

ACE IP gateway

MDLC

ACE1000

MOSCAD Toolbox STS

Omron

SYSMAC Cx series

Nx series

Phoenix Contact ProConOS
西門子 WinCC OA
Yokogawa STARDOM

These vulnerabilities can be grouped into four categories:

  • Insecure engineering protocols
  • Weak cryptography or broken authentication schemes
  • Insecure firmware updates
  • Remote code execution via native functionality

In a worst case scenario, an attacker with network access to a vulnerable device could exploit some of these flaws to “remotely execute code, change the logic, files or firmware of OT devices, bypass authentication, compromise credentials, cause denials of service or have a variety of operational impacts.” According to Forescout, 35% of the 56 vulnerabilities disclosed could allow for firmware manipulation or remote code execution.

This research harkens back to past industrial attacks, like Industroyer and TRITON, that relied on similar insecure-by-design flaws in their targeted OT environments. It also traces its history to Project Basecamp, an effort by Digital Bonds in 2017 to “highlight and demonstrate the fragility and insecurity of most [supervisory control and data acquisition] SCADA and [distributed control system] DCS field devices.”

概念驗證

There are no proofs-of-concept available for any of the 56 vulnerabilities disclosed. Because “many of [these vulnerabilities] will remain unpatched in production environments for a significant amount of time,” Forescout did not release any technical details of the individual vulnerabilities discovered through the course of its research.

Vendor response

Forescout does not provide specific details on whether or when any of the vendors will be patching these vulnerabilities. Organizations should monitor for vendor advisories from all of their OT providers.

The Cybersecurity and Information Security Agency has also published an advisory for OT:ICEFALL, along with five Industrial Controls Systems Advisories for some of the affected products. Yokogawa has also issued an advisory for the vulnerabilities in its STARDOM product.

解決方法

The best defense for these vulnerabilities at this time is to ensure OT best practices are being followed.

  • Assess systems for vulnerable devices
  • Segment vulnerable devices, particularly from the internet
  • Use secure methods for remote access when that access is necessary to operations
  • Keep up to date on patches from vendors and establish remediation practices
  • Develop network monitoring rules to block or alert for anomalous traffic

找出受影響的系統

Tenable Research has developed plugins to identify devices that may be vulnerable to the OT:ICEFALL related flaws:

  • 500655 - Saia Burgess OT:ICEFALL Multiple Potential Vulnerabilities
  • 500656 - Honeywell OT:ICEFALL Multiple Potential Vulnerabilities
  • 500657 - Omron OT:ICEFALL Multiple Potential Vulnerabilities
  • 500658 - Emerson OT:ICEFALL Multiple Potential Vulnerabilities

取得更多資訊

加入 Tenable Community 的 Tenable 安全回應團隊

深入瞭解 Tenable,這是用於全面管理新型攻擊破綻的首創 Cyber Exposure 平台。

Get a free 30-day trial of Tenable.io Vulnerability Management.

相關文章

您可以利用的網路安全最新消息

輸入您的電子郵件,就不會錯過來自 Tenable 專家提供的及時警示與安全指引。

Tenable Vulnerability Management

享受現代、雲端型的弱點管理平台,能夠以無與倫比的準確性查看和追蹤所有資產。

您的 Tenable Vulnerability Management 試用版軟體也包含 Tenable Lumin 和 Tenable Web App Scanning。

Tenable Vulnerability Management

享受現代、雲端型的弱點管理平台,使您能夠以無與倫比的準確性查看和追蹤所有資產。 立即訂閱一年。

100 項資產

選取您的訂閱選項:

立即購買

Tenable Vulnerability Management

享受現代、雲端型的弱點管理平台,能夠以無與倫比的準確性查看和追蹤所有資產。

您的 Tenable Vulnerability Management 試用版軟體也包含 Tenable Lumin 和 Tenable Web App Scanning。

Tenable Vulnerability Management

享受現代、雲端型的弱點管理平台,使您能夠以無與倫比的準確性查看和追蹤所有資產。 立即訂閱一年。

100 項資產

選取您的訂閱選項:

立即購買

Tenable Vulnerability Management

享受現代、雲端型的弱點管理平台,能夠以無與倫比的準確性查看和追蹤所有資產。

您的 Tenable Vulnerability Management 試用版軟體也包含 Tenable Lumin 和 Tenable Web App Scanning。

Tenable Vulnerability Management

享受現代、雲端型的弱點管理平台,使您能夠以無與倫比的準確性查看和追蹤所有資產。 立即訂閱一年。

100 項資產

選取您的訂閱選項:

立即購買

試用 Tenable Web App Scanning

享受完整存取我們專為新型應用程式所設計、屬於 Tenable One 曝險管理平台一部分的最新 Web 應用程式掃描產品。不需耗費大量人力或中斷重要 Web 應用程式,即可高度準確且安全地掃描您整個線上產品系列中是否含有任何弱點。 立即註冊。

您的 Tenable Web App Scanning 試用版軟體也包含 Tenable Vulnerability Management 和 Tenable Lumin。

購買 Tenable Web App Scanning

享受現代、雲端型的弱點管理平台,使您能夠以無與倫比的準確性查看和追蹤所有資產。 立即訂閱一年。

5 個 FQDN

$3,578

立即購買

試用 Tenable Lumin

利用 Tenable Lumin 視覺化並探索您的曝險管理、追蹤經過一段時間後風險降低的情形以及與同業進行指標分析。

您的 Tenable Lumin 試用版軟體也包含 Tenable Vulnerability Management 和 Tenable Web App Scanning。

購買 Tenable Lumin

聯絡業務代表,瞭解 Tenable Lumin 如何協助您取得您整個環境的深入解析和管理網路風險。

免費試用 Tenable Nessus Professional

免費試用 7 天

Tenable Nessus 是目前市場上最全方位的弱點掃描器。

最新 - Tenable Nessus Expert
現已上市

Nessus Expert 新增了更多功能,包括外部攻擊破綻掃描和新增網域及掃描雲端基礎架構的能力。按這裡試用 Nessus Expert。

請填妥以下表單以繼續 Nessus Pro 試用。

購買 Tenable Nessus Professional

Tenable Nessus 是目前市場上最全方位的弱點掃描器。Tenable Nessus Professional 可協助將弱點掃描流程自動化,節省您執行合規工作的時間並讓您與 IT 團隊合作。

購買多年期授權,節省更多。新增 365 天全年無休 24 小時全天候可使用電話、社群及對談的進階支援。

選擇您的授權

購買多年期授權,節省更多。

增加支援與訓練

免費試用 Tenable Nessus Expert

免費試用 7 天

Nessus Expert 是專為現代攻擊破綻所打造,它能讓您從 IT 到雲端洞察更多資訊,並保護貴公司免於弱點危害。

您已經有 Tenable Nessus Professional 了嗎?
升級至 Nessus Expert,免費試用 7 天。

購買 Tenable Nessus Expert

Nessus Expert 是專為現代攻擊破綻所打造,它能讓您從 IT 到雲端洞察更多資訊,並保護貴公司免於弱點危害。

選擇您的授權

購買多年期授權省更多!

增加支援與訓練