{"id":6126,"date":"2019-08-01T12:51:19","date_gmt":"2019-08-01T11:51:19","guid":{"rendered":"http:\/\/s313789864.websitehome.co.uk\/?p=6126"},"modified":"2020-12-15T15:28:28","modified_gmt":"2020-12-15T15:28:28","slug":"major-industrial-control-vulnerability-identified","status":"publish","type":"post","link":"http:\/\/s313789864.websitehome.co.uk\/?p=6126","title":{"rendered":"Major Industrial Control Vulnerability Identified"},"content":{"rendered":"<p>11 zero-day vulnerabilities have been discovered in one of the world\u2019s most widely used IoT operating systems. VxWorks is so common that it is used in over 2 billion devices around the world, including by most major Industrial control brands.<\/p>\n<p>The security researchers <a href=\"http:\/\/www.armis.com\" target=\"_blank\" rel=\"noopener noreferrer\">Armis<\/a>, who discovered and disclosed the vulnerability have estimated that over 200 million devices may be exposed and at risk of a potential attack. Six of the eleven identified vulnerabilities have been classified as critical, enabling Remote Code Execution (RCE) through network connectivity to target the core underlying OS; described by Armis as \u201cthe holy grail for attackers\u201d.<\/p>\n<p>Due to the high likelihood of exposure to the VxWorks vulnerabilities TES are recommending that our clients undertake the following steps.<\/p>\n<ol>\n<li>Identify and Patch vulnerable devices:<br \/>\nYou need to urgently identify all devices that use VxWorks and reach out to the device manufacturers for information about patching the software on each device. Most of the major industrial control brands use VxWorks and may be vulnerable. TES are able to conduct onsite scanning to detect affected devices on ICS networks. Please <a href=\"https:\/\/tesgroup.com\/contact\/\" target=\"_blank\" rel=\"noopener noreferrer\">contact us<\/a> to discuss this further or to arrange an appointment.<\/li>\n<\/ol>\n<ol start=\"2\">\n<li>Shield all vulnerable devices via network controls:<br \/>\nTemporarily segment your network to ensure that any vulnerable device is isolated within a small subnet until you can patch or replace vulnerable devices.<\/li>\n<\/ol>\n<ol start=\"3\">\n<li>Monitor vulnerable devices for evidence of compromise:<br \/>\nMonitor all devices that are running vulnerable versions of VxWorks for indication of compromise at network level.<\/li>\n<\/ol>\n<p><strong>We are aware that many ICS environments are running older (vulnerable) versions of VxWorks, have no patch management strategy for ICS and heavily rely on air gaps which cannot be effectively monitored. Should this be the case for you we recommend that you contact ICS Cyber Security experts such as TES Cybersafe for advice and assistance.<\/strong><\/p>\n<h4>A list of CVE\u2019s for each vulnerability is included below;<\/h4>\n<h6>Critical Vulnerabilities allowing remote-code-execution:<\/h6>\n<ul>\n<li>Stack overflow in the parsing of IPv4 options\n<ul>\n<li><em>CVE-2019-12256 affecting VxWorks v6.9.4 or above<\/em><\/li>\n<\/ul>\n<\/li>\n<li>Four memory corruption vulnerabilities stemming from erroneous handling of TCP\u2019s Urgent Pointer field\n<ul>\n<li><em>CVE-2019-12255 affecting VxWorks v6.5 to 6.9.3<\/em><\/li>\n<li><em>CVE-2019-12260 affecting VxWorks v6.94 and above<\/em><\/li>\n<li><em>CVE-2019-12261 affecting VxWorks v6.7 and above<\/em><\/li>\n<li><em>CVE-2019-12263 affecting VxWorks v6.6 and above<\/em><\/li>\n<\/ul>\n<\/li>\n<li>Heap overflow in DHCP Offer\/ACK parsing in ipdhcpc\n<ul>\n<li><em>CVE-2019-12257 affecting VxWorks v6.5 to 6.9.3<\/em><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h6>Vulnerabilities leading to denial of service, information leak or certain logical flaws:<\/h6>\n<ul>\n<li>TCP connection DoS via malformed TCP options\n<ul>\n<li><em>CVE-2019-12258 affecting VxWorks v6.5 and above<\/em><\/li>\n<\/ul>\n<\/li>\n<li>Handling of unsolicited Reverse ARP replies (Logical Flaw)\n<ul>\n<li><em>CVE-2019-12262 affecting VxWorks v6.5 and above<\/em><\/li>\n<\/ul>\n<\/li>\n<li>Logical flaw in IPv4 assignment by the ipdhcpc DHCP client\n<ul>\n<li><em>CVE-2019-12264 affecting VxWorks v6.5 and above<\/em><\/li>\n<\/ul>\n<\/li>\n<li>DoS via NULL deference in IGMP parsing\n<ul>\n<li><em>CVE-2019-12259 affecting VxWorks v6.5 and above<\/em><\/li>\n<\/ul>\n<\/li>\n<li>IGMP Information leak via IGMPv3 specific membership report\n<ul>\n<li><em>CVE-2019-12265 affecting VxWorks v6.9.3 and above<\/em><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>For further information about the 11 zero-day vulnerability please visit the <a href=\"https:\/\/armis.com\/urgent11\/\" target=\"_blank\" rel=\"noopener noreferrer\">Armis website<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>11 zero-day vulnerabilities have been discovered in one of the world\u2019s most widely used IoT operating systems. VxWorks is so common that it is used in over 2 billion devices around the world, including by most major Industrial control brands&#8230;.<\/p>\n","protected":false},"author":1,"featured_media":6127,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[31],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v17.8 (Yoast SEO v20.9) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Major Industrial Control Vulnerability Identified - TES Group<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"http:\/\/s313789864.websitehome.co.uk\/?p=6126\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Major Industrial Control Vulnerability Identified\" \/>\n<meta property=\"og:description\" content=\"11 zero-day vulnerabilities have been discovered in one of the world\u2019s most widely used IoT operating systems. VxWorks is so common that it is used in over 2 billion devices around the world, including by most major Industrial control brands....\" \/>\n<meta property=\"og:url\" content=\"http:\/\/s313789864.websitehome.co.uk\/?p=6126\" \/>\n<meta property=\"og:site_name\" content=\"TES Group\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/TES.Group.Online\/\" \/>\n<meta property=\"article:published_time\" content=\"2019-08-01T11:51:19+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-12-15T15:28:28+00:00\" \/>\n<meta property=\"og:image\" content=\"http:\/\/s313789864.websitehome.co.uk\/wp-content\/uploads\/2020\/12\/TES_NIS_reg.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"662\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Gary McLorn\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@TESGroupLtd\" \/>\n<meta name=\"twitter:site\" content=\"@TESGroupLtd\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Gary McLorn\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"http:\/\/s313789864.websitehome.co.uk\/?p=6126#article\",\"isPartOf\":{\"@id\":\"http:\/\/s313789864.websitehome.co.uk\/?p=6126\"},\"author\":{\"name\":\"Gary McLorn\",\"@id\":\"http:\/\/s313789864.websitehome.co.uk\/#\/schema\/person\/69c3b561ee07c4260c39da321fe1cb8b\"},\"headline\":\"Major Industrial Control Vulnerability Identified\",\"datePublished\":\"2019-08-01T11:51:19+00:00\",\"dateModified\":\"2020-12-15T15:28:28+00:00\",\"mainEntityOfPage\":{\"@id\":\"http:\/\/s313789864.websitehome.co.uk\/?p=6126\"},\"wordCount\":491,\"publisher\":{\"@id\":\"http:\/\/s313789864.websitehome.co.uk\/#organization\"},\"articleSection\":[\"Cybersafe\"],\"inLanguage\":\"en-GB\"},{\"@type\":\"WebPage\",\"@id\":\"http:\/\/s313789864.websitehome.co.uk\/?p=6126\",\"url\":\"http:\/\/s313789864.websitehome.co.uk\/?p=6126\",\"name\":\"Major Industrial Control Vulnerability Identified - TES Group\",\"isPartOf\":{\"@id\":\"http:\/\/s313789864.websitehome.co.uk\/#website\"},\"datePublished\":\"2019-08-01T11:51:19+00:00\",\"dateModified\":\"2020-12-15T15:28:28+00:00\",\"breadcrumb\":{\"@id\":\"http:\/\/s313789864.websitehome.co.uk\/?p=6126#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\/\/s313789864.websitehome.co.uk\/?p=6126\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\/\/s313789864.websitehome.co.uk\/?p=6126#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"http:\/\/s313789864.websitehome.co.uk\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Major Industrial Control Vulnerability Identified\"}]},{\"@type\":\"WebSite\",\"@id\":\"http:\/\/s313789864.websitehome.co.uk\/#website\",\"url\":\"http:\/\/s313789864.websitehome.co.uk\/\",\"name\":\"TES Group\",\"description\":\"Critical Infrastructure Experts\",\"publisher\":{\"@id\":\"http:\/\/s313789864.websitehome.co.uk\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"http:\/\/s313789864.websitehome.co.uk\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"http:\/\/s313789864.websitehome.co.uk\/#organization\",\"name\":\"TES Group\",\"url\":\"http:\/\/s313789864.websitehome.co.uk\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"http:\/\/s313789864.websitehome.co.uk\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.tesgroup.com\/wp-content\/uploads\/2019\/04\/site_logo.png\",\"contentUrl\":\"https:\/\/www.tesgroup.com\/wp-content\/uploads\/2019\/04\/site_logo.png\",\"width\":336,\"height\":336,\"caption\":\"TES Group\"},\"image\":{\"@id\":\"http:\/\/s313789864.websitehome.co.uk\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/TES.Group.Online\/\",\"https:\/\/twitter.com\/TESGroupLtd\",\"https:\/\/www.instagram.com\/tesgroup_hq\/\",\"https:\/\/www.linkedin.com\/company\/tesgroup\/\",\"https:\/\/www.youtube.com\/c\/Tes-ni\/videos\"]},{\"@type\":\"Person\",\"@id\":\"http:\/\/s313789864.websitehome.co.uk\/#\/schema\/person\/69c3b561ee07c4260c39da321fe1cb8b\",\"name\":\"Gary McLorn\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"http:\/\/s313789864.websitehome.co.uk\/#\/schema\/person\/image\/\",\"url\":\"http:\/\/2.gravatar.com\/avatar\/e6018905504ad5a61a4ca8cd69ddeadf?s=96&d=mm&r=g\",\"contentUrl\":\"http:\/\/2.gravatar.com\/avatar\/e6018905504ad5a61a4ca8cd69ddeadf?s=96&d=mm&r=g\",\"caption\":\"Gary McLorn\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Major Industrial Control Vulnerability Identified - TES Group","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/s313789864.websitehome.co.uk\/?p=6126","og_locale":"en_GB","og_type":"article","og_title":"Major Industrial Control Vulnerability Identified","og_description":"11 zero-day vulnerabilities have been discovered in one of the world\u2019s most widely used IoT operating systems. VxWorks is so common that it is used in over 2 billion devices around the world, including by most major Industrial control brands....","og_url":"http:\/\/s313789864.websitehome.co.uk\/?p=6126","og_site_name":"TES Group","article_publisher":"https:\/\/www.facebook.com\/TES.Group.Online\/","article_published_time":"2019-08-01T11:51:19+00:00","article_modified_time":"2020-12-15T15:28:28+00:00","og_image":[{"width":1024,"height":662,"url":"http:\/\/s313789864.websitehome.co.uk\/wp-content\/uploads\/2020\/12\/TES_NIS_reg.jpg","type":"image\/jpeg"}],"author":"Gary McLorn","twitter_card":"summary_large_image","twitter_creator":"@TESGroupLtd","twitter_site":"@TESGroupLtd","twitter_misc":{"Written by":"Gary McLorn","Estimated reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"http:\/\/s313789864.websitehome.co.uk\/?p=6126#article","isPartOf":{"@id":"http:\/\/s313789864.websitehome.co.uk\/?p=6126"},"author":{"name":"Gary McLorn","@id":"http:\/\/s313789864.websitehome.co.uk\/#\/schema\/person\/69c3b561ee07c4260c39da321fe1cb8b"},"headline":"Major Industrial Control Vulnerability Identified","datePublished":"2019-08-01T11:51:19+00:00","dateModified":"2020-12-15T15:28:28+00:00","mainEntityOfPage":{"@id":"http:\/\/s313789864.websitehome.co.uk\/?p=6126"},"wordCount":491,"publisher":{"@id":"http:\/\/s313789864.websitehome.co.uk\/#organization"},"articleSection":["Cybersafe"],"inLanguage":"en-GB"},{"@type":"WebPage","@id":"http:\/\/s313789864.websitehome.co.uk\/?p=6126","url":"http:\/\/s313789864.websitehome.co.uk\/?p=6126","name":"Major Industrial Control Vulnerability Identified - TES Group","isPartOf":{"@id":"http:\/\/s313789864.websitehome.co.uk\/#website"},"datePublished":"2019-08-01T11:51:19+00:00","dateModified":"2020-12-15T15:28:28+00:00","breadcrumb":{"@id":"http:\/\/s313789864.websitehome.co.uk\/?p=6126#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["http:\/\/s313789864.websitehome.co.uk\/?p=6126"]}]},{"@type":"BreadcrumbList","@id":"http:\/\/s313789864.websitehome.co.uk\/?p=6126#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"http:\/\/s313789864.websitehome.co.uk\/"},{"@type":"ListItem","position":2,"name":"Major Industrial Control Vulnerability Identified"}]},{"@type":"WebSite","@id":"http:\/\/s313789864.websitehome.co.uk\/#website","url":"http:\/\/s313789864.websitehome.co.uk\/","name":"TES Group","description":"Critical Infrastructure Experts","publisher":{"@id":"http:\/\/s313789864.websitehome.co.uk\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"http:\/\/s313789864.websitehome.co.uk\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"http:\/\/s313789864.websitehome.co.uk\/#organization","name":"TES Group","url":"http:\/\/s313789864.websitehome.co.uk\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"http:\/\/s313789864.websitehome.co.uk\/#\/schema\/logo\/image\/","url":"https:\/\/www.tesgroup.com\/wp-content\/uploads\/2019\/04\/site_logo.png","contentUrl":"https:\/\/www.tesgroup.com\/wp-content\/uploads\/2019\/04\/site_logo.png","width":336,"height":336,"caption":"TES Group"},"image":{"@id":"http:\/\/s313789864.websitehome.co.uk\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/TES.Group.Online\/","https:\/\/twitter.com\/TESGroupLtd","https:\/\/www.instagram.com\/tesgroup_hq\/","https:\/\/www.linkedin.com\/company\/tesgroup\/","https:\/\/www.youtube.com\/c\/Tes-ni\/videos"]},{"@type":"Person","@id":"http:\/\/s313789864.websitehome.co.uk\/#\/schema\/person\/69c3b561ee07c4260c39da321fe1cb8b","name":"Gary McLorn","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"http:\/\/s313789864.websitehome.co.uk\/#\/schema\/person\/image\/","url":"http:\/\/2.gravatar.com\/avatar\/e6018905504ad5a61a4ca8cd69ddeadf?s=96&d=mm&r=g","contentUrl":"http:\/\/2.gravatar.com\/avatar\/e6018905504ad5a61a4ca8cd69ddeadf?s=96&d=mm&r=g","caption":"Gary McLorn"}}]}},"_links":{"self":[{"href":"http:\/\/s313789864.websitehome.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/6126"}],"collection":[{"href":"http:\/\/s313789864.websitehome.co.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/s313789864.websitehome.co.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/s313789864.websitehome.co.uk\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/s313789864.websitehome.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6126"}],"version-history":[{"count":1,"href":"http:\/\/s313789864.websitehome.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/6126\/revisions"}],"predecessor-version":[{"id":6128,"href":"http:\/\/s313789864.websitehome.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/6126\/revisions\/6128"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/s313789864.websitehome.co.uk\/index.php?rest_route=\/wp\/v2\/media\/6127"}],"wp:attachment":[{"href":"http:\/\/s313789864.websitehome.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6126"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/s313789864.websitehome.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6126"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/s313789864.websitehome.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6126"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}