Two months after a security firm disclosed 11 vulnerabilities (called URGENT/11) found in specific versions of VxWorks (Real Time Operating System) by Wind River, the U.S. Food and Drug Administration (FDA) released its safety communications to the healthcare industries. The FDA warned that the exposure to vulnerabilities in a 3rd party software stack (IPnet) extends beyond VxWorks, but also several other RTOS’s. Organizations are now scrambling to assess their exposure by identifying any vulnerable assets in their inventory, and then respond by either patching or implementing compensating controls to protect at-risk devices.
ORDR Systems Control Engine (SCE) can identify vulnerable assets, detect URGENT/11 cyberattacks, proactively protect devices from current and future vulnerabilities, as well as take swift action when bad things do happen.
Identifying Devices Vulnerable to URGENT/11
ORDR exercises a combination of manufacturer advisories and proactive probing to track devices that are vulnerable to URGENT/11. This information is compared to any matching inventory in ORDR SCE customer environments automatically through a new URGENT/11 feed service. This ensures organizations will be continually apprised for vulnerabilities as soon as the information is available. A major challenge to reliance on manufacturer disclosure is the presence of countless variants of the IPnet implementation from numerous manufacturers that have licensed the IPnet TCP/IP stack over the years. What’s even more challenging is the length and breadth of the impact affecting not just bio-med devices but also facility, security, industrial control devices, and more. This makes full and reliable disclosure elusive, distant or in some cases non-existent.
To help guarantee organizations can accurately identify any system vulnerable to URGENT/11, whether it has been published or not, ORDR has built an URGENT/11 active scanner. The scanner dynamically identifies, or verifies, at risk devices. The scanner is “light and tight” minimal operational impact, and it can be tuned to only scan specific device types or areas of the network.
Below is an example of how customer can initiate vulnerability scan, looking for URGENT/11 impacted endpoints.
When devices are discovered that are vulnerable to URGENT/11, either due to the feed service or the active scanner, they are called-out on the ORDR Security Dashboard.
Here is an example of a vulnerable device, and more detailed information about the CVE detected.
Reports can be generated for auditing or reporting purposes from ORDR SCE.
Please note that ORDR SCE integrates with external vulnerability assessment tools such as Tenable and Rapid7. Organizations using those tools to detect devices vulnerable to URGENT/11 can integrate them into the ORDR SCE inventory and security dashboard.
Detect Active Exploitation of URGENT/11
ORDR SCE has a built-in Network Intrusion Detection System (NIDS) engine which monitors traffic traveling throughout the network. The NIDS rules are updated to detect the URGENT/11 vulnerability behavior. This is a distinct advantage over reliance on traditional firewalls that typically monitor traffic coming through north-south choke point such as the Internet Edge. In order to exploit most of the URGENT/11 vulnerabilities, attackers need to be on the same segment or in the same VLAN rendering traditional firewall-based solutions ineffective. ORDR SCE monitors every device communication passively and checks against its NIDS rules. This generates instant alarms against devices that are being exploited, along with the attack vectors, such as devices that initiated attack, complete visibility of the attacking device, and retrospective record of communications during attack.
There are many NIDS CVEs that correspond to active URGENT/11 attacks, as shown in the following table, and they are all included in the ORDR NIDS engine.
CVEs | CVSS | Details |
CVE-2019-12256 | 9.8 | Stack overflow in parsing of IPv4 packets’ IP options |
CVE-2019-12255 | 9.8 | TCP Urgent Pointer = 0 leads to integer underflow VxWorks versions 6.5 to 6.9.3 |
CVE-2019-12260 | 9.8 | TCP Urgent Pointer state confusion caused by malformed TCP AO option VxWorks versions 6.9.4 and above |
CVE-2019-12261 | 8.8 | TCP Urgent Pointer state confusion during connect() to a remote VxWorks versions 6.6 and above |
CVE-2019-12263 | 8.1 | TCP Urgent Pointer state confusion due to a race condition VxWorks versions 6.7 and above |
CVE-2019-12257 | 8.8 | Heap overflow in DHCP Offer/Ack parsing inside ipdhcpc |
CVE-2019-12258 | 7.5 | DoS (Denial of Service) of TCP connection via malformed TCP options |
CVE-2019-12262 | 7.1 | Handling of unsolicited Reverse ARP replies (logic flaw) |
CVE-2019-12264 | 7.1 | Logic flaw in IPv4 assignment by ipdhcpc DHCP client |
CVE-2019-12259 | 6.3 | DoS via NULL dereference in IGMP parsing |
CVE-2019-12265 | 5.3 | IGMP Information leak via IGMPv3 specific membership report |
When an exploit attempt is detected, the security dashboard is updated as shown below, and details of the issue are called out, including aggressor and target of the attack.
Optionally, security incidents can be shared with Security Information and Event Management (SIEM) tools like Splunk, ServiceNow and Nuvolo so they can tie into existing response and remediation processes.
Protect Vulnerable Devices
Organizations should contact their device manufacturer to obtain patches to URGENT/11. If you have devices that cannot be patched in a timely fashion, ORDR SCE can implement microsegment as a compensating control to limit the surface area of attack while ensuring the device’s continued operation.
The safeguard can be achieved by provisioning whitelist security policies with Access Control List (ACL) based on device behaviors observed by ORDR SCE. The policy enforcement can enabled directly from ORDR SCE and enforced directly in the network on switches and wireless controllers, sent to NAC solutions such as Cisco Identity Services Engine (ISE) or HPE Aruba ClearPass, or protected with zone-based security at firewalls including Palo Alto Networks, Check Point, Fortinet, and Cisco.
In case of URGENT/11, for instance, ORDR SCE automatically generates appropriate ACL denying specific TCP flags used in URGENT/11 vulnerabilities. This process is typically the most time-consuming part of the protection as it takes multiple efforts to combine device visibility and device behavior to build right security policies.
Take Swift Action
In cases where ORDR SCE sees suspicion activities from compromised endpoints, operator can immediately initiate the remediation process by sending appropriate policy change to the network or firewall to isolate and quarantine offending devices. Sample remediations may include the use of quarantine Virtual LANs (VLANs) or denying network access to the endpoint completely through blacklisting and/or shutting down the endpoint’s network port. This can be performed directly from ORDR SCE or automated through NAC tools like Cisco ISE and HPE Aruba ClearPass.
Conclusion
URGENT/11 vulnerabilities reinforce the challenges organizations face with connected IoT and OT devices. These threats also validate the need for proactive protection based on rich visibility of connected devices and their behavior to combat vulnerabilities like URGENT/11 and for other vulnerabilities that are right around the corner.
Please contact the ORDR team for a demo and discussion on how to protect your assets from the never ending vulnerability advisories.