News: 1646828972

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Millions of APC Smart-UPS devices vulnerable to TLStorm

(2022/03/09)


If you're managing a smart model from ubiquitous uninterrupted power supply (UPS) device brand APC, you need to apply updates now – a set of three critical zero-day vulnerabilities are making Smart-UPS devices a possible entry point for network infiltration.

The vulnerabilities, dubbed "TLStorm" were found in Schneider Electric's APC Smart-UPS products by security firm Armis, which made the info [1]public on Tuesday.

The name stems from the Transport Layer Security (TLS) implementation where two out of the three vulnerabilities were found.

[2]

The affected UPSes – ranging across 10 product lines listed [3]here [PDF] – cater to small to medium businesses, providing backup power in emergency situations.

[4]

[5]

A full list of models affected by the TLStorm vulnerabilities is available in Schneider Electric's own security advisory [6]here [PDF]. We have asked Schneider how many of the affected Smart-UPS models have been sold and for details on any models that were not affected.

[7]Schneider Electric says on its product page that it has sold over 20 million units of its Smart-UPS brand, calling it an "ideal UPS for servers, point-of-sale, routers, switches, hubs and other network devices."

Potential weaponized power outages

According to Armis, a complete remote takeover via the internet is possible as the devices are controlled through a cloud connection, potentially without even any signs of an attack through remote code execution. An exploitation could result in weaponized power outages or surges of battery function affecting both the power supply and other connected systems, as well as breaches of company data or installed malware.

Such attacks have happened before. Notably, and topically, threat actors attacked the [8]Ukrainian power grid in 2015. Alongside other actions, [9]according to US federal agents at the Cybersecurity and Infrastructure Security Agency at the time, the attackers scheduled disconnects for server UPS through its remote management interface, leading to a wide-scale power outage.

[10]IT blamed after HR forgets to install sockets in new office

[11]Russia mulls making software piracy legal and patent licensing compulsory

[12]Deere & Co won't give out software and data needed for repairs, watchdog told

[13]UK govt signs IT contracts 'without understanding' the needs

[14]Enterprise IT finds itself in a war zone – with no script

The first two of the three TLS vulnerabilities found by Armis come about due to an improper connection between the UPS and APC parent company Schneider Electric's cloud via its SmartConnect feature.

SmartConnect automatically establishes a TLS connection upon startup or whenever cloud connections are temporarily lost. Both vulns require no human interaction and can be exploited as a zero-click attack.

[15]

The restart could enable the TLS handshake to bypass authentication potentially resulting in an unauthorized firmware upgrade, or a buffer overflow memory corruption bug in packet reassembly could lead to a remote code execution.

The authentication bypass is tracked as [16]CVE-2022-22806 , and the buffer overflow as [17]CVE-2022-22805 . Both are rated at 9 out of 10 on the CVSS bug-severity scale.

The third vulnerability is a design flaw, rated ever-so-minutely better than the two TLS vulnerabilities with an 8.9 bug severity and tracked as [18]CVE-2022-0715 . In this flaw, the firmware updates are not cryptographically signed securely, allowing a potential attacker to install malware through the internet, LAN or a USB thumb drive, asserted Armis.

[19]

"Schneider Electric is aware of the vulnerabilities associated with APC Smart-UPS uninterruptible power supply devices which, if compromised, may allow for potential unauthorized access and control of the device," said Schneider Electric, adding that it was working to develop remediations and mitigations, as well as disclose to customers and end-users.

Schneider Electric has issued patches while the researchers advised changing default network management card passwords where applicable and installing publicly-signed SSL certificates. Access control lists are also said to help.

Armis said there's currently no indication the flaws are being exploited in the wild. ®

Get our [20]Tech Resources



[1] https://www.prnewswire.com/news-releases/armis-finds-three-critical-zero-day-vulnerabilities-in-apc-smart-ups-devices-dubbed-tlstorm-exposing-more-than-20-million-enterprise-devices-301497137.html

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YijdOZUyvmZVifhhaZyMDgAAAQI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://regmedia.co.uk/2022/03/09/schnieder_advisory.pdf

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YijdOZUyvmZVifhhaZyMDgAAAQI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YijdOZUyvmZVifhhaZyMDgAAAQI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://regmedia.co.uk/2022/03/09/schnieder_advisory.pdf

[7] https://www.se.com/ww/en/product-range/61915-smartups/

[8] https://www.theregister.com/2015/12/29/kiev_power_outages_blamed_on_russian_hackers/

[9] https://www.cisa.gov/uscert/ics/alerts/IR-ALERT-H-16-056-01

[10] https://www.theregister.com/2022/03/07/who_me/

[11] https://www.theregister.com/2022/03/08/russia_software_piracy/

[12] https://www.theregister.com/2022/03/07/deere_repair_ftc/

[13] https://www.theregister.com/2022/03/08/uk_government_it_contracts/

[14] https://www.theregister.com/2022/03/07/column_ukraine_enterprise/

[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YijdOZUyvmZVifhhaZyMDgAAAQI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[16] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22806

[17] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22805

[18] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0715

[19] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YijdOZUyvmZVifhhaZyMDgAAAQI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[20] https://whitepapers.theregister.com/



Yet another pointless insistence on "cloud"

Down not across

Why on earth would my UPS need to connect to "cloud" or anything external?

All my UPS and RPC kit are on their own VLAN and definitely without any access to internet. Only access is internal monitoring, logging and control.

Re: Yet another pointless insistence on "cloud"

Anonymous Coward

Indeed. Another good reason why "IoT" devices should never have free unfettered access to external environments. SNMP, email, http, etc - all of which can be monitored and controlled internally, but automatic connection to cloud services. No chance.

I have just this week purchased two of these UPS's, which I note support this "cloud management" as an integral feature. I have not yet opened them up to see if this can be disabled. Out of precaution I also bought the optional plug-in management cards, so that I can run internal management services without needing to connect the cloud port to anything.

There is absolutely no reason why i would ever want devices on my internal network to "phone home" with their data and for APC to give me access to their portal to view my own devices.

Re: Yet another pointless insistence on "cloud"

cawfee

Let's connect a giant flammable device to the internet, I don't see anything that could go wrong

Re: Yet another pointless insistence on "cloud"

ThatOne

> Why on earth would my UPS need to connect to "cloud"

Automatic status updates to Facebook & Twitter?

(You don't really live if other people can' read about it.)

Re: Yet another pointless insistence on "cloud"

Anonymous Coward

We had to add a UPS to some installations of some other equipment for our main customer (part of the US Army). Yes, it's probably on this list.

But I specified NO network connection lest we had to go down that rabbit hole of tracking even more software/firmware versions, testing, etc. Customer prefers to just leave it alone until it beeps that it needs a new battery, or maybe they already have a UPS maintenance schedule.

That's what they get for insisting on the COTS product due to schedule and cost. I'm (mainly) the cable guy and just had to make sure the power levels worked out.

Re: Yet another pointless insistence on "cloud"

Dwarf

I came here to say the same, so have an upvote instead.

There is absolutely no need for core infrastructure to have a connection to the cloud. Anything used for management of any IT component should be on a management network - one in-band (to the OS) and one out of band to the OS. There need to be enough of these management networks so that there is no way to move horizontally across systems and bypass other controls.

Its dead simple to configure with a bunch of VLAN's and a management firewall, then with the support teams connecting via management (jump host) workstations.

Any platforms that just stick everything on the same network is just asking for trouble, be that local LAN segment, or the public Internet.

Re: Yet another pointless insistence on "cloud"

Graham Cobb

I completely agree in the case where this is a personal/home deployment or a data-centre deployment.

However, I am sure there are many, many millions of these devices (probably a majority) which are just a tiny part of a managed service doing something else. For example, I am sure the (independent) petrol station across the road doesn't own their own cash register/credit card payment machine. They are in the car business, not the IT business - a lot of money passes through their tills, with a lot of regulations about tax, etc - and I am sure they contract that out.

The managed service almost certainly provides the tills, the card readers, the network devices and the UPS for them all. This UPS will be connected to a cloud-based service for remote monitoring and management, scheduling of battery replacement, etc. The service provider probably accepts APC's assurances regarding the security of the setup (and may even subcontract the connectivity to the APC cloud service). Those are the cases that will be screwed by this vulnerability.

Re: Yet another pointless insistence on "cloud"

AMBxx

But that just makes it even harder to update. Why the insistence on cloud, when a secure VPN connection would be sufficient.

Re: Yet another pointless insistence on "cloud"

Graham Cobb

Because this is the reality of the business world.

The garage owner (tiny business) contracts with a PoS supplier. The PoS supplier is a managed service: they contract with someone who designs the particular solution for this garage from standard building blocks and shows them how to use the web interface to monitor the UPS batteries and error reports. The solution builder uses the boxes recommended by the manufacturers and connects them together following the designs and specs from the manufacturers. The UPS manufacturer recommends the cloud service: after all, they have spent a lot of time and money designing and provisioning it to make life easier for their customers than their competitors do. And, in most cases, it is adequately secure (the biggest security concerns in PoS are about the money flow, after all!).

The fault lies with APC - not with their customers for using their deployment instructions.

I am sure that in your enterprise projects you have the luxury of a Solution Architect who can look across the end-to-end solution and see the weaknesses. But the real world of the bulk of systems implementations, particularly in tiny companies and in retail, do not have that luxury. Profit margins are so tiny they can't pay for the architect, and even if they did, they wouldn't be able to afford a solution that was not straight off-the-peg.

Re: Yet another pointless insistence on "cloud"

Dwarf

@Graham.

Do you think that APC used an architect to design their solution, or did someone in marketing just make a fuss about having the word cloud in their product description and some developer lashed something up to meet the minimum cost and minimum time that would have been defined in the same meeting ?

I agree that end customers should be able to consume a system in a secure and reliable manner.

But it doesn't need cloud in the first place, a simple buzzer and an LED on the front that says "Fault" would do the same, having it send an email or alert to someone is also easy to do, as is providing a local app on the PC / server to see the UPS state and report it to the OS. There are many reference patterns on how to do this without requiring a cloud connection.

On the flip side though, any PoS provider or other such company should have appropriately skilled people to do an install right and once installed, have the appropriate ongoing management of a system through its lift. After all, if the PoS system is down, then so is the company, hence they should want to protect their systems.

Re: Yet another pointless insistence on "cloud"

badflorist

"...not with their customers for using their deployment instructions."

You're missing the point about UPS by using PoS as a contrast, while under the context of a "cloud" based UPS. At what point does your batteries need to virtually transfer to a home base for calculation?

In fact, isn't it irresponsible to add any latency between communicating you may or may not have power or worse, a fire has started? How does the fire department feel about this? If "... this is the reality of the business world.", you may want to start and question your reality, you might save some money and/or lives.

For the PoS angle, yeh, that's sticky. With automobiles though, I thought there is no lemon law on 2nd hand vehicles and "new" vehicles are supplied with all retail information by law (although dealership/franchise integration would be sticky, unless you take the McDonald's approach :-/).

Re: Yet another pointless insistence on "cloud"

badflorist

"...a cloud-based service for remote monitoring and management, scheduling of battery replacement, etc."

Nope, no cloud needed or even "smart" anything. I've personally assembled a 1200 array lug-to-lug UPS and the only software used was in the Fluke meters. Test a sample and rotate them out after X months regardless, then test the old/replaced batteries. You'll know immediately when the voltage drop occurs at the control, all this without anything smart. At home, you can do this with a USB charging adapter plugged in with a ATTiny attached to a buzzer. I don't go that far, but if you want smart you can achieve this many ways without a cloud or vendor supplied anything, just build it up as needed.

Another field being sold the "smarter is better" crap is in the main control, so just because the UPS is fine, that doesn't mean your control thinks so. IMO all of this should be completely analog and while I'm no longer part of any of this, I've been hearing scary stories about fire systems. Apparently there's a few fire marshals out there doing too much work thanks to things being so "smart" (you're lucky if the fire marshal doesn't shut you down after 2 times, 3 times and you're on forced vacation).

FWIW, with the smart/nic controllers on UPS's you can have access to things like N.U.T., but personally while I've read the readings, I never really have done anything with those readings as I simply replace a home UPS battery ever 18-24 months. So it's a neat feature, just not that amazing.

Re: Yet another pointless insistence on "cloud"

TeeCee

Because anything that isn't in "the cloud" is old, busted, obsolete and only purchased by companies that are out of touch with the world.

Look, it says so in the tech pages of the FT.

Use case

Anonymous Coward

I actually own one of these UPS's that's used at a cabin a few miles south of the Canadian border that's remote enough that the only low latency internet connection possible (until Starlink ever delivers after 16 months on their waiting list) is 1.5Mbps DLS over a land line. (And the phone company has run out of lines in the area, so I can't even upgrade to bonded 3Mbps service.) The remote access via the cloud isn't very useful but it seems that's required to get the thing to email alerts when the power at the cabin goes out or comes back on, which I want to know about.

Otherwise, while I see the advantages of remote access via a LAN (which allows remote accessibility via a VPN) is useful, it's clear that Schneider has architected this cloud scheme for subscription revenue. You get 3 years "standard" service when you buy the unit. but after that you'll have to pay. And they have several levels of varying uselessness service at various gouging price levels.

I guess the crappy security comes for free.

"the firmware updates are not cryptographically signed securely"

Mike 137

Why on Earth not? This is so basic. One wonders who they got to develop the software.

Oh, I keep forgetting - we no longer programme, we code (and when stuck we copy and paste blindly from Stack Overflow).

James Simmons wrote:
> Crap can work. Given enough thrust pigs will fly, but it's not necessary a
> good idea. [ Alexander Viro on linux-kernel ]

Watch the attributions.

With sufficient thrust, pigs fly just fine.
However, this is not necessarily a good idea.
It is hard to be sure where they are going to land,
and it could be dangerous sitting under them as they fly overhead.
From RFC1925, R Callon, 1996.

- Al Viro on linux-kernel