{ "Event": { "analysis": "0", "date": "2023-12-05", "extends_uuid": "", "info": "AA23-335A: IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including U.S. Water and Wastewater Systems Facilities", "publish_timestamp": "1702630157", "published": true, "threat_level_id": "3", "timestamp": "1702630147", "uuid": "c578cb44-e440-486d-80a4-8cf6256c1d53", "Orgc": { "name": "CIRCL", "uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f" }, "Tag": [ { "colour": "#2e2c61", "local": false, "name": "misp-galaxy:stix-2.1-attack-pattern=\"9a280255-c770-4d42-ae50-aff1896ebded\"", "relationship_type": "" }, { "colour": "#004646", "local": false, "name": "type:OSINT", "relationship_type": "" }, { "colour": "#0071c3", "local": false, "name": "osint:lifetime=\"perpetual\"", "relationship_type": "" }, { "colour": "#ffffff", "local": false, "name": "tlp:white", "relationship_type": "" }, { "colour": "#ffffff", "local": false, "name": "tlp:clear", "relationship_type": "" } ], "Attribute": [ { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "first_seen": "2023-09-13T00:00:00+00:00", "timestamp": "1701722284", "to_ids": true, "type": "sha256", "uuid": "b4097d04-408a-4279-aac4-40ae3dd0710f", "value": "440b5385d3838e3f6bc21220caa83b65cd5f3618daea676f271c3671650ce9a3" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "first_seen": "2023-09-13T00:00:00+00:00", "timestamp": "1701722284", "to_ids": true, "type": "sha1", "uuid": "95a83932-6e7a-4024-b3f5-d878d78fd1d0", "value": "66ae21571faee1e258549078144325dc9dd60303" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "first_seen": "2023-09-13T00:00:00+00:00", "timestamp": "1701722284", "to_ids": true, "type": "ip-dst", "uuid": "eb825787-5cf3-423a-aec9-42d611cc61e1", "value": "178.162.227.180" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "first_seen": "2023-09-13T00:00:00+00:00", "timestamp": "1701722284", "to_ids": true, "type": "md5", "uuid": "695afe84-7eb6-4004-a7e1-2ad80bfa5131", "value": "ba284a4b508a7abd8070a427386e93e0" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "first_seen": "2018-05-14T00:00:00+00:00", "timestamp": "1701722284", "to_ids": true, "type": "ip-dst", "uuid": "b74311f5-0fc4-4fda-a6c3-3a13cf1d3069", "value": "185.162.235.206" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1702630128", "to_ids": false, "type": "vulnerability", "uuid": "8f057a13-41e4-4e2f-ade8-19802a62f278", "value": "CVE-2023-6448" } ], "Object": [ { "comment": "", "deleted": false, "description": "Object describing the original file used to import data in MISP.", "meta-category": "file", "name": "original-imported-file", "template_uuid": "4cd560e9-2cfe-40a1-9964-7b2e797ecac5", "template_version": "2", "timestamp": "1701762533", "uuid": "0025bc8f-1af0-48a6-9534-e82af80ee21c", "Attribute": [ { "category": "External analysis", "comment": "", "data": "{
    "type": "bundle",
    "id": "bundle--9405aaae-cf00-4030-a326-70b96ea6bbb5",
    "objects": [
        {
            "id": "location--e2c889aa-b0b1-4f05-b90c-a0a1a155dc62",
            "spec_version": "2.1",
            "type": "location",
            "country": "US",
            "administrative_area": "US-DC",
            "created": "2023-12-04T20:38:04.000Z",
            "modified": "2023-12-04T20:38:04.000Z",
            "created_by_ref": "identity--b3bca3c2-1f3d-4b54-b44f-dac42c3a8f01",
            "object_marking_refs": [
                "marking-definition--479081c8-3a60-4eb8-b410-96a30f395def",
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "marking-definition",
            "spec_version": "2.1",
            "id": "marking-definition--479081c8-3a60-4eb8-b410-96a30f395def",
            "created": "2023-03-02T16:48:57.959Z",
            "extensions": {
                "extension-definition--3a65884d-005a-4290-8335-cb2d778a83ce": {
                    "extension_type": "property-extension",
                    "identifier": "isa:guide.19001.ACS3-9e0cd50e-6efc-45b3-8a3d-b6376541c9c5",
                    "create_date_time": "2023-03-02T16:48:57.959Z",
                    "responsible_entity_custodian": "USA.DHS.NCCIC",
                    "responsible_entity_originator": "USA.DHS.NCCIC",
                    "policy_reference": "urn:isa:policy:acs:ns:v3.0?privdefault=deny&sharedefault=permit",
                    "control_set": {
                        "classification": "U",
                        "formal_determination": [
                            "INFORMATION-DIRECTLY-RELATED-TO-CYBERSECURITY-THREAT",
                            "PUBREL"
                        ]
                    },
                    "authority_reference": [
                        "urn:isa:authority:ais"
                    ],
                    "access_privilege": [
                        {
                            "privilege_action": "CISAUSES",
                            "rule_effect": "permit",
                            "privilege_scope": {
                                "entity": [
                                    "ALL"
                                ],
                                "permitted_nationalities": [
                                    "ALL"
                                ],
                                "permitted_organizations": [
                                    "ALL"
                                ],
                                "shareability": [
                                    "ALL"
                                ]
                            }
                        }
                    ]
                }
            }
        },
        {
            "id": "attack-pattern--9a280255-c770-4d42-ae50-aff1896ebded",
            "type": "attack-pattern",
            "created": "2023-12-04T20:38:04.000Z",
            "modified": "2023-12-04T20:38:04.000Z",
            "spec_version": "2.1",
            "created_by_ref": "identity--b3bca3c2-1f3d-4b54-b44f-dac42c3a8f01",
            "name": "Credential Access - Brute Force [T1110]",
            "object_marking_refs": [
                "marking-definition--479081c8-3a60-4eb8-b410-96a30f395def",
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "id": "indicator--b4097d04-408a-4279-aac4-40ae3dd0710f",
            "type": "indicator",
            "spec_version": "2.1",
            "pattern_type": "stix",
            "created": "2023-12-04T20:38:04.000Z",
            "modified": "2023-12-04T20:38:04.000Z",
            "object_marking_refs": [
                "marking-definition--479081c8-3a60-4eb8-b410-96a30f395def",
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "name": "File Indicator",
            "indicator_types": [
                "malicious-activity"
            ],
            "valid_from": "2023-09-13T00:00:00Z",
            "pattern": "[file:hashes.'SHA-256' = '440B5385D3838E3F6BC21220CAA83B65CD5F3618DAEA676F271C3671650CE9A3']",
            "created_by_ref": "identity--b3bca3c2-1f3d-4b54-b44f-dac42c3a8f01"
        },
        {
            "id": "indicator--95a83932-6e7a-4024-b3f5-d878d78fd1d0",
            "type": "indicator",
            "spec_version": "2.1",
            "pattern_type": "stix",
            "created": "2023-12-04T20:38:04.000Z",
            "modified": "2023-12-04T20:38:04.000Z",
            "object_marking_refs": [
                "marking-definition--479081c8-3a60-4eb8-b410-96a30f395def",
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "name": "File Indicator",
            "indicator_types": [
                "malicious-activity"
            ],
            "valid_from": "2023-09-13T00:00:00Z",
            "pattern": "[file:hashes.'SHA-1' = '66AE21571FAEE1E258549078144325DC9DD60303']",
            "created_by_ref": "identity--b3bca3c2-1f3d-4b54-b44f-dac42c3a8f01"
        },
        {
            "id": "indicator--eb825787-5cf3-423a-aec9-42d611cc61e1",
            "type": "indicator",
            "spec_version": "2.1",
            "pattern_type": "stix",
            "created": "2023-12-04T20:38:04.000Z",
            "modified": "2023-12-04T20:38:04.000Z",
            "object_marking_refs": [
                "marking-definition--479081c8-3a60-4eb8-b410-96a30f395def",
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "name": "IPv4 Indicator",
            "indicator_types": [
                "malicious-activity"
            ],
            "valid_from": "2023-09-13T00:00:00Z",
            "pattern": "[ipv4-addr:value = '178.162.227.180']",
            "created_by_ref": "identity--b3bca3c2-1f3d-4b54-b44f-dac42c3a8f01"
        },
        {
            "id": "indicator--695afe84-7eb6-4004-a7e1-2ad80bfa5131",
            "type": "indicator",
            "spec_version": "2.1",
            "pattern_type": "stix",
            "created": "2023-12-04T20:38:04.000Z",
            "modified": "2023-12-04T20:38:04.000Z",
            "object_marking_refs": [
                "marking-definition--479081c8-3a60-4eb8-b410-96a30f395def",
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "name": "File Indicator",
            "indicator_types": [
                "malicious-activity"
            ],
            "valid_from": "2023-09-13T00:00:00Z",
            "pattern": "[file:hashes.MD5 = 'BA284A4B508A7ABD8070A427386E93E0']",
            "created_by_ref": "identity--b3bca3c2-1f3d-4b54-b44f-dac42c3a8f01"
        },
        {
            "id": "indicator--b74311f5-0fc4-4fda-a6c3-3a13cf1d3069",
            "type": "indicator",
            "spec_version": "2.1",
            "pattern_type": "stix",
            "created": "2023-12-04T20:38:04.000Z",
            "modified": "2023-12-04T20:38:04.000Z",
            "object_marking_refs": [
                "marking-definition--479081c8-3a60-4eb8-b410-96a30f395def",
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ],
            "name": "IPv4 Indicator",
            "indicator_types": [
                "malicious-activity"
            ],
            "valid_from": "2018-05-14T00:00:00Z",
            "pattern": "[ipv4-addr:value = '185.162.235.206']",
            "created_by_ref": "identity--b3bca3c2-1f3d-4b54-b44f-dac42c3a8f01"
        },
        {
            "type": "relationship",
            "spec_version": "2.1",
            "id": "relationship--3d8bb40f-01ef-46f9-a5c0-004a12e40155",
            "created_by_ref": "identity--b3bca3c2-1f3d-4b54-b44f-dac42c3a8f01",
            "created": "2023-12-04T20:38:04.000Z",
            "modified": "2023-12-04T20:38:04.000Z",
            "source_ref": "identity--b3bca3c2-1f3d-4b54-b44f-dac42c3a8f01",
            "relationship_type": "located-at",
            "target_ref": "location--e2c889aa-b0b1-4f05-b90c-a0a1a155dc62",
            "object_marking_refs": [
                "marking-definition--479081c8-3a60-4eb8-b410-96a30f395def",
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "id": "report--c578cb44-e440-486d-80a4-8cf6256c1d53",
            "type": "report",
            "spec_version": "2.1",
            "created": "2023-12-04T20:38:04.000Z",
            "modified": "2023-12-04T20:38:04.000Z",
            "name": "AA23-335A: IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including U.S. Water and Wastewater Systems Facilities",
            "description": "The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Environmental Protection Agency (EPA), and the Israel National Cyber Directorate (INCD)\\u2014hereafter referred  to  as \"the authoring agencies\" - are disseminating this joint Cybersecurity Advisory (CSA) to highlight continued malicious cyber activity against operational technology devices by Iranian Government Islamic Revolutionary Guard Corps IRGC)-affiliated Advanced Persistent Threat (APT) cyber actors. \r\n\r\nThe IRGC is an Iranian military organization that the United States designated as a foreign terrorist organization in 2019. IRGC-affiliated cyber actors using the persona \\u201cCyberAv3ngers\\u201d are actively targeting and compromising Israeli-made Unitronics Vision Series programmable logic controllers  (PLCs). These PLCs are commonly used in the Water and Wastewater Systems (WWS) Sector and are additionally used in other industries including, but not limited to, energy, food and beverage manufacturing, and healthcare. The PLCs may be rebranded and appear as different manufacturers and companies. In addition to the recent CISA Alert, the authoring agencies are releasing this joint CSA to share indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) associated with IRGC cyber operations.\r\n",
            "published": "2023-12-02T00:00:00Z",
            "created_by_ref": "identity--b3bca3c2-1f3d-4b54-b44f-dac42c3a8f01",
            "object_refs": [
                "marking-definition--479081c8-3a60-4eb8-b410-96a30f395def",
                "attack-pattern--9a280255-c770-4d42-ae50-aff1896ebded",
                "indicator--b4097d04-408a-4279-aac4-40ae3dd0710f",
                "indicator--95a83932-6e7a-4024-b3f5-d878d78fd1d0",
                "indicator--eb825787-5cf3-423a-aec9-42d611cc61e1",
                "indicator--695afe84-7eb6-4004-a7e1-2ad80bfa5131",
                "indicator--b74311f5-0fc4-4fda-a6c3-3a13cf1d3069",
                "relationship--3d8bb40f-01ef-46f9-a5c0-004a12e40155"
            ],
            "object_marking_refs": [
                "marking-definition--479081c8-3a60-4eb8-b410-96a30f395def",
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        }
    ]
}", "deleted": false, "disable_correlation": true, "object_relation": "imported-sample", "timestamp": "1701762533", "to_ids": false, "type": "attachment", "uuid": "63b59f7b-462d-4bdb-9861-b2de803a358c", "value": "AA23-335A-IRGC-Affiliated-Cyber-Actors-Exploit-PLCs-in-Multiple-Sectors-Including-US-Water-and-Wastewater-Systems-Facilities.stix_.json" }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": true, "object_relation": "format", "timestamp": "1701762533", "to_ids": false, "type": "text", "uuid": "a8bc59ca-67e3-4e50-acd3-c1867a2acc3c", "value": "STIX 2.1" } ] }, { "comment": "\"AA23-335A: IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including U.S. Water and Wastewater Systems Facilities", "deleted": false, "description": "Metadata used to generate an executive level report", "meta-category": "misc", "name": "report", "template_uuid": "70a68471-df22-4e3f-aa1a-5a3be19f82df", "template_version": "7", "timestamp": "1701762854", "uuid": "157412c1-046a-4e74-99f8-84a148792839", "Attribute": [ { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "link", "timestamp": "1701762854", "to_ids": false, "type": "link", "uuid": "c6fbcbef-c300-445b-85d0-025c748f5545", "value": "https://www.cisa.gov/sites/default/files/2023-12/AA23-335A-IRGC-Affiliated-Cyber-Actors-Exploit-PLCs-in-Multiple-Sectors-Including-US-Water-and-Wastewater-Systems-Facilities.stix_.json" }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "summary", "timestamp": "1701762854", "to_ids": false, "type": "text", "uuid": "548e3b68-36bd-4297-b825-3cadd87fc1c7", "value": "The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Environmental Protection Agency (EPA), and the Israel National Cyber Directorate (INCD)\\\\u2014hereafter referred to as \"the authoring agencies\" - are disseminating this joint Cybersecurity Advisory (CSA) to highlight continued malicious cyber activity against operational technology devices by Iranian Government Islamic Revolutionary Guard Corps IRGC)-affiliated Advanced Persistent Threat (APT) cyber actors. \\r\\n\\r\\nThe IRGC is an Iranian military organization that the United States designated as a foreign terrorist organization in 2019. IRGC-affiliated cyber actors using the persona \\\\u201cCyberAv3ngers\\\\u201d are actively targeting and compromising Israeli-made Unitronics Vision Series programmable logic controllers (PLCs). These PLCs are commonly used in the Water and Wastewater Systems (WWS) Sector and are additionally used in other industries including, but not limited to, energy, food and beverage manufacturing, and healthcare. The PLCs may be rebranded and appear as different manufacturers and companies. In addition to the recent CISA Alert, the authoring agencies are releasing this joint CSA to share indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) associated with IRGC cyber operations.\\r\\n" } ] }, { "comment": "CVE-2023-6448: Enriched via the cve_advanced module", "deleted": false, "description": "Vulnerability object describing a common vulnerability enumeration which can describe published, unpublished, under review or embargo vulnerability for software, equipments or hardware.", "meta-category": "vulnerability", "name": "vulnerability", "template_uuid": "81650945-f186-437b-8945-9f31715d32da", "template_version": "8", "timestamp": "1702630147", "uuid": "a2a355a0-75b3-42c8-93f7-401b8566ed00", "ObjectReference": [ { "comment": "", "object_uuid": "a2a355a0-75b3-42c8-93f7-401b8566ed00", "referenced_uuid": "8f057a13-41e4-4e2f-ade8-19802a62f278", "relationship_type": "related-to", "timestamp": "1702630147", "uuid": "b9fa53fe-cc5b-40c5-bf71-222546c09c71" }, { "comment": "", "object_uuid": "a2a355a0-75b3-42c8-93f7-401b8566ed00", "referenced_uuid": "25eafc23-5529-4c84-9cb9-13df3517f784", "relationship_type": "weakened-by", "timestamp": "1702630147", "uuid": "93917a54-e4f9-452b-819a-05a54c8ceead" }, { "comment": "", "object_uuid": "a2a355a0-75b3-42c8-93f7-401b8566ed00", "referenced_uuid": "ea5919da-346f-4b22-89c3-6dfeef61dba8", "relationship_type": "targeted-by", "timestamp": "1702630147", "uuid": "33ac05f3-ff79-4d4b-863e-754940d7cc4a" }, { "comment": "", "object_uuid": "a2a355a0-75b3-42c8-93f7-401b8566ed00", "referenced_uuid": "5d27dada-7e8c-45bf-8237-e2acf772667b", "relationship_type": "targeted-by", "timestamp": "1702630147", "uuid": "8f5e2a5a-525d-49a1-88d1-973227c6dbef" } ], "Attribute": [ { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "id", "timestamp": "1702630147", "to_ids": false, "type": "vulnerability", "uuid": "3ac90077-fcd5-4b25-bc21-bbd0f38420cf", "value": "CVE-2023-6448" }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "summary", "timestamp": "1702630147", "to_ids": false, "type": "text", "uuid": "51eb50ad-01bf-4301-b9ee-835af2b6878d", "value": "Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system." }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": true, "object_relation": "modified", "timestamp": "1702630147", "to_ids": false, "type": "datetime", "uuid": "ca2068ba-3a84-4e2f-b345-f6762677b757", "value": "2023-12-13T17:15:00+00:00" }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": true, "object_relation": "cvss-score", "timestamp": "1702630147", "to_ids": false, "type": "float", "uuid": "3b31aa3f-dd18-430f-8e0c-f6115d389227", "value": "9.8" }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": true, "object_relation": "cvss-string", "timestamp": "1702630147", "to_ids": false, "type": "text", "uuid": "5d63f96f-a574-4d43-a89b-c2b4c4e1f5ba", "value": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": true, "object_relation": "published", "timestamp": "1702630147", "to_ids": false, "type": "datetime", "uuid": "47e48f66-f643-47bc-a655-c2bdc2362b9a", "value": "2023-12-05T18:15:00+00:00" }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": true, "object_relation": "state", "timestamp": "1702630147", "to_ids": false, "type": "text", "uuid": "b7d06d9f-3fad-43e5-9bb1-ff1285bcb1f5", "value": "Published" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "44787f90-5e02-450b-9e8a-7d3fa46ed481", "value": "cpe:2.3:o:unitronics:vision1210_firmware:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "cd5b1cfd-d31d-4ff0-83f4-a26c169f8561", "value": "cpe:2.3:h:unitronics:vision1210:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "b9bc55c2-e3b8-419f-86c7-e6c2dc4c64b3", "value": "cpe:2.3:o:unitronics:vision1040_firmware:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "d9550d55-58ff-476c-8d6a-d3368393801c", "value": "cpe:2.3:h:unitronics:vision1040:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "3b507916-1a00-401a-ab8e-f3fb661f3e04", "value": "cpe:2.3:o:unitronics:vision700_firmware:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "6c3cd7c1-6946-4520-b7fc-3df20d18b365", "value": "cpe:2.3:h:unitronics:vision700:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "f6de9036-a91c-4459-8de3-6c346f7014d2", "value": "cpe:2.3:o:unitronics:vision570_firmware:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "303aaaa5-50a4-4382-a30e-a02d2b5706e9", "value": "cpe:2.3:h:unitronics:vision570:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "7374b6ad-8d8f-4d66-8b84-e312dac73368", "value": "cpe:2.3:o:unitronics:vision560_firmware:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "9db2c4d5-105c-4a44-8c7b-dee570f0e40b", "value": "cpe:2.3:h:unitronics:vision560:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "9dc37e71-6f86-4aa4-bd6e-a8c87f163157", "value": "cpe:2.3:o:unitronics:vision430_firmware:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "152e54ec-96a5-4fb7-b9e3-aa82145476c6", "value": "cpe:2.3:h:unitronics:vision430:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "aeb07593-6695-476d-8898-437abfaec588", "value": "cpe:2.3:o:unitronics:vision350_firmware:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "5d3e5d1a-b8fc-4647-8d59-8174c85b30b9", "value": "cpe:2.3:h:unitronics:vision350:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "052c7b91-dc64-4823-9744-2d68611d272e", "value": "cpe:2.3:o:unitronics:vision130_firmware:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "b758a772-a9f2-4854-86df-c47b9f9a5878", "value": "cpe:2.3:h:unitronics:vision130:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "b37f66b0-82d8-421a-88d2-a048eca80221", "value": "cpe:2.3:o:unitronics:vision230_firmware:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "90ed2868-e325-4a2e-952b-2af058fc6d4f", "value": "cpe:2.3:h:unitronics:vision230:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "6f07a9dc-71d4-4029-a55e-584910b5bd42", "value": "cpe:2.3:o:unitronics:vision280_firmware:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "632ebe1b-0161-4faa-89c5-288755b3cc93", "value": "cpe:2.3:h:unitronics:vision280:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "2088e8b2-7bc2-4aac-a858-36ad6cd97981", "value": "cpe:2.3:o:unitronics:vision290_firmware:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "d51695b8-a20d-484b-ab9d-98d2dabeca8f", "value": "cpe:2.3:h:unitronics:vision290:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "7c0e0c2f-a8c9-4fd0-800d-224e96b96c4c", "value": "cpe:2.3:o:unitronics:vision530_firmware:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "fad3c59a-c149-45e4-b6c9-e71281d03bcf", "value": "cpe:2.3:h:unitronics:vision530:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "b278d0eb-788a-4a63-96b8-c2358d92f8d9", "value": "cpe:2.3:o:unitronics:vision120_firmware:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "vulnerable-configuration", "timestamp": "1702630147", "to_ids": false, "type": "cpe", "uuid": "ae51bb6a-b492-4508-8bc0-4af0d03a91ac", "value": "cpe:2.3:h:unitronics:vision120:-:*:*:*:*:*:*:*" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "references", "timestamp": "1702630147", "to_ids": false, "type": "link", "uuid": "a9c34fac-d808-4a12-a9a5-6f2ec8523d6a", "value": "https://www.cisa.gov/news-events/alerts/2023/11/28/exploitation-unitronics-plcs-used-water-and-wastewater-systems" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "references", "timestamp": "1702630147", "to_ids": false, "type": "link", "uuid": "b31fc487-8e7a-4090-a6cb-c64b05e20862", "value": "https://www.unitronicsplc.com/cyber_security_vision-samba/" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "references", "timestamp": "1702630147", "to_ids": false, "type": "link", "uuid": "ca9a4c44-a24c-44c9-802d-871175d0871a", "value": "https://downloads.unitronicsplc.com/Sites/plc/Visilogic/Version_Changes-Bug_Reports/VisiLogic%209.9.00%20Version%20changes.pdf" } ] }, { "comment": "CVE-2023-6448: Enriched via the cve_advanced module", "deleted": false, "description": "Weakness object describing a common weakness enumeration which can describe usable, incomplete, draft or deprecated weakness for software, equipment of hardware.", "meta-category": "vulnerability", "name": "weakness", "template_uuid": "b8713fc0-d7a2-4b27-a182-38ed47966802", "template_version": "1", "timestamp": "1702630147", "uuid": "25eafc23-5529-4c84-9cb9-13df3517f784", "Attribute": [ { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "id", "timestamp": "1702630147", "to_ids": false, "type": "weakness", "uuid": "b29a1b99-ff49-4ab7-80da-3267910b36ac", "value": "CWE-798" }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "name", "timestamp": "1702630147", "to_ids": false, "type": "text", "uuid": "7ab12f43-9356-45b0-b368-91f2b682750d", "value": "Use of Hard-coded Credentials" }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": true, "object_relation": "status", "timestamp": "1702630147", "to_ids": false, "type": "text", "uuid": "d64d1466-dc39-45ee-b281-0f7332c5564d", "value": "Draft" }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": true, "object_relation": "weakness-abs", "timestamp": "1702630147", "to_ids": false, "type": "text", "uuid": "a4cb95b3-7531-4f14-bce9-df6c266964df", "value": "Base" } ] }, { "comment": "CVE-2023-6448: Enriched via the cve_advanced module", "deleted": false, "description": "Attack pattern describing a common attack pattern enumeration and classification.", "meta-category": "vulnerability", "name": "attack-pattern", "template_uuid": "35928348-56be-4d7f-9752-a80927936351", "template_version": "1", "timestamp": "1702630147", "uuid": "ea5919da-346f-4b22-89c3-6dfeef61dba8", "Attribute": [ { "category": "Other", "comment": "", "deleted": false, "disable_correlation": true, "object_relation": "id", "timestamp": "1702630147", "to_ids": false, "type": "text", "uuid": "a7b82da7-33cb-4c8c-a4fc-b9d2dd6006a0", "value": "70" }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "name", "timestamp": "1702630147", "to_ids": false, "type": "text", "uuid": "78ebaaf4-762a-4241-b8b0-0fc0b4afecfe", "value": "Try Common or Default Usernames and Passwords" }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "summary", "timestamp": "1702630147", "to_ids": false, "type": "text", "uuid": "75a110eb-df9f-477e-85b5-e6a7946bcf18", "value": "An adversary may try certain common or default usernames and passwords to gain access into the system and perform unauthorized actions. An adversary may try an intelligent brute force using empty passwords, known vendor default credentials, as well as a dictionary of common usernames and passwords. Many vendor products come preconfigured with default (and thus well-known) usernames and passwords that should be deleted prior to usage in a production environment. It is a common mistake to forget to remove these default login credentials. Another problem is that users would pick very simple (common) passwords (e.g. \"secret\" or \"password\") that make it easier for the attacker to gain access to the system compared to using a brute force attack or even a dictionary attack using a full dictionary." }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "prerequisites", "timestamp": "1702630147", "to_ids": false, "type": "text", "uuid": "e4c3238a-2e05-4a16-8d2f-9feaf942ae23", "value": "The system uses one factor password based authentication.The adversary has the means to interact with the system." }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "solutions", "timestamp": "1702630147", "to_ids": false, "type": "text", "uuid": "b49b98fd-9f2c-4552-9957-3f140e18b089", "value": "Delete all default account credentials that may be put in by the product vendor. Implement a password throttling mechanism. This mechanism should take into account both the IP address and the log in name of the user. Put together a strong password policy and make sure that all user created passwords comply with it. Alternatively automatically generate strong passwords for users. Passwords need to be recycled to prevent aging, that is every once in a while a new password must be chosen." }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "related-weakness", "timestamp": "1702630147", "to_ids": false, "type": "weakness", "uuid": "cf909c1a-b189-4219-81f8-643cf8422091", "value": "CWE-262" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "related-weakness", "timestamp": "1702630147", "to_ids": false, "type": "weakness", "uuid": "6b1b8809-3041-4797-990b-7bcee84d8ce4", "value": "CWE-263" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "related-weakness", "timestamp": "1702630147", "to_ids": false, "type": "weakness", "uuid": "d1dfdc82-d337-413b-9ea0-7933ba301d79", "value": "CWE-308" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "related-weakness", "timestamp": "1702630147", "to_ids": false, "type": "weakness", "uuid": "ff3b2610-2a3a-4863-a0f0-e46f70fbde3c", "value": "CWE-309" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "related-weakness", "timestamp": "1702630147", "to_ids": false, "type": "weakness", "uuid": "8125de66-cefc-4297-bb6d-2bec73ad8f13", "value": "CWE-521" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "related-weakness", "timestamp": "1702630147", "to_ids": false, "type": "weakness", "uuid": "1a6432f6-90df-4a97-8d0f-68499a9d4eef", "value": "CWE-654" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "related-weakness", "timestamp": "1702630147", "to_ids": false, "type": "weakness", "uuid": "771be904-10ef-4132-9459-c0bd5ac2cecd", "value": "CWE-798" } ] }, { "comment": "CVE-2023-6448: Enriched via the cve_advanced module", "deleted": false, "description": "Attack pattern describing a common attack pattern enumeration and classification.", "meta-category": "vulnerability", "name": "attack-pattern", "template_uuid": "35928348-56be-4d7f-9752-a80927936351", "template_version": "1", "timestamp": "1702630147", "uuid": "5d27dada-7e8c-45bf-8237-e2acf772667b", "Attribute": [ { "category": "Other", "comment": "", "deleted": false, "disable_correlation": true, "object_relation": "id", "timestamp": "1702630147", "to_ids": false, "type": "text", "uuid": "3ceb3eee-0de8-4942-ba7e-932f585f175e", "value": "191" }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "name", "timestamp": "1702630147", "to_ids": false, "type": "text", "uuid": "d193113d-e947-49e7-8afc-a500650847d8", "value": "Read Sensitive Constants Within an Executable" }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "summary", "timestamp": "1702630147", "to_ids": false, "type": "text", "uuid": "6f16a779-f8c8-4811-bb77-8c2e7413c4e5", "value": "An adversary engages in activities to discover any sensitive constants present within the compiled code of an executable.\n These constants may include literal ASCII strings within the file itself, or possibly strings hard-coded into particular routines that can be revealed by code refactoring methods including static and dynamic analysis. One specific example of a sensitive string is a hard-coded password. Typical examples of software with hard-coded passwords include server-side executables which may check for a hard-coded password or key during a user's authentication with the server. Hard-coded passwords can also be present in client-side executables which utilize the password or key when connecting to either a remote component, such as a database server, licensing server, or otherwise, or a processes on the same host that expects a key or password. When analyzing an executable the adversary may search for the presence of such strings by analyzing the byte-code of the file itself. Example utilities for revealing strings within a file include 'strings,' 'grep,' or other variants of these programs depending upon the type of operating system used. These programs can be used to dump any ASCII or UNICODE strings contained within a program. Strings can also be searched for using a hex editors by loading the binary or object code file and utilizing native search functions such as regular expressions.\n Additionally, sensitive numeric values can occur within an executable. This can be used to discover the location of cryptographic constants." }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "prerequisites", "timestamp": "1702630147", "to_ids": false, "type": "text", "uuid": "dfa9bc66-7199-42c8-80b5-dcf5b65d14c6", "value": "Access to a binary or executable such that it can be analyzed by various utilities." }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "related-weakness", "timestamp": "1702630147", "to_ids": false, "type": "weakness", "uuid": "ed1b9615-ddd8-4340-8ed7-1da4a08ffc19", "value": "CWE-798" } ] } ] } }