ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Siemens CT scanners open to remote compromise via publicly available exploits

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2015-1635
Unauthenticated Remote Code Execution in Microsoft HTTP.sys (MS15-034)

CVE-2015-1635 is a remote code execution flaw in HTTP.sys, the kernel-mode HTTP protocol stack component of Microsoft Windows that handles HTTP(S) traffic for IIS and other web-facing Windows roles. A remote, unauthenticated attacker can trigger it by sending specially crafted HTTP requests to a system listening via HTTP.sys, most commonly an internet-facing IIS web server. Successful exploitation yields arbitrary code execution with kernel/system-level privileges on the target server, giving the attacker full control of the host. Any Windows deployment where HTTP.sys is reachable is affected - typically IIS web servers and web-facing roles such as Exchange or WSUS - although the source data does not specify exact version ranges. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-10) with a ~100% EPSS probability of exploitation within 30 days, indicating active exploitation; public proof-of-concept code is not noted in the data and ransomware use is unknown.

Do: Apply Microsoft updates per vendor instructions (this CVE is addressed by the April 2015 MS15-034 bulletin) on every Windows system where HTTP.sys is reachable, prioritizing internet-facing IIS, Exchange, and WSUS hosts. Inventory your environment for systems running web-facing Windows roles and, if patching must be delayed, restrict inbound HTTP/80 and HTTPS/443 from untrusted sources or filter malformed HTTP requests at a front-end proxy/WAF. As a CISA KEV entry, this is a required patch for federal agencies; treat it as urgent everywhere else.

100% KEV
  • Microsoft HTTP.sys (Windows HTTP protocol stack)
masshundreds of thousands of internet-exposed Windows/IIS servers
Full article266 words · extracted from helpnetsecurity.com · click to collapse

Siemens has finally provided patches for a number of Microsoft Windows SMBv1 vulnerabilities that affect some of the medical devices sold under the Siemens Healthineers brand.

Siemens CT scanners compromise

Some fixes are available

After WannaCry hit systems around the world in May, the company acknowledged that some of its customers may be facing impacts from the cyber-attack, as some of Siemens Healthineers’ products “may be affected by the Microsoft vulnerability being exploited by the WannaCry ransomware.”

Fixes have now been provided for a variety of laboratory diagnostics products, as well as radiography, mobile X-ray and mammography systems.

Siemens is still working on a few updates

But the company is yet to release patches for four easily and remotely exploitable flaws affecting select Siemens Healthineers molecular imaging products (PET, SPECT and CT scanners), exploits for which are, according to ICS CERT, publicly available.

The vulnerabilities are:

  • A code injection flaw affecting the Microsoft web server of affected devices (CVE-2015-1635)
  • A code injection, a buffer overflow, and a privilege escalation flaw affecting the HP Client automation service of affected devices (CVE-2015-1497, CVE-2015-7860, and CVE-2015-7861, respectively).

All of these vulnerabilities could be exploited by unauthenticated attackers to achieve remote code execution on vulnerable devices. And, as one can see from the CVE numbers assigned to them, they all date back to 2015.

Siemens has published an advisory last week acknowledging the vulnerabilities, and has said that they are working on updates for affected products.

Until those updates are ready and made available, Siemens is advising administrators of those devices to disconnect the product from the network and use in standalone mode.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2017/08/07/siemens-ct-scanners-compromise/