Vulnerabilities / Threats

3/27/2019
12:50 PM
50%
50%

GAO Finds Deficiencies in Systems for Handling National Debt

IT systems at the Bureau of the Fiscal Service and the Federal Reserve Bank show vulnerabilities that could lead them open to exploitation and breach.

Two related reports from the General Accounting Office (GAO) point out significant issues with the IT systems involved in managing and servicing more than $22 trillion in federal debt. The reports — one a GAO financial audit of the Bureau of the Fiscal Service, and the other a management report on the Federal Reserve — each conclude that there are problems with the configuration and control systems within IT. And while those problems have not yet resulted in system breaches, according to the reports, they're worthy of immediate attention and remediation.

In the financial audit of the Bureau of the Fiscal Service, auditors include a section in which they underscore the importance of a significant deficiency in information system controls. "These general control deficiencies increase the risk of unauthorized access to, modification of, or disclosure of sensitive data and programs and disruption of critical operations," they say. In particular, the audit mentions the lack of least privilege access as a security concern for systems.

The audit also lists broad suggestions for remediation, though it doesn't express any great optimism for the implementation of those steps. "We continued to identify instances in which known information system vulnerabilities were not being remediated on a timely basis. We also continued to identify instances in which implemented configuration settings were not effectively monitored against baseline security requirements," they say.

Federal Reserve Banks are charged with implementing many of the practical steps of dealing with the national debt. Although the GAO didn't audit the banks, it did conduct a management review looking at issues similar to those raised in the Bureau of the Fiscal Service audit. The GAO issued a pair of reports, one limited to staff and the board of governors, and the other a high-level public report.

The public management report points out deficiencies in configuration management. "These new and continuing control deficiencies increase the risk of unauthorized access to, modification of, or disclosure of sensitive data and programs," it says.

Though the deficiencies have not resulted in breaches, the response has not come through improvements to the technology and its use. Rather, the GAO found the deficiencies were "mitigated primarily by Fiscal Service's compensating management and reconciliation controls to detect potential misstatements of the Schedule of Federal Debt."

Each report points out that some of the issues identified in previous audits and reports have been mitigated, while others remain to be dealt with.

Read more here and here.

 

 

Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industry's most knowledgeable IT security experts. Check out the Interop agenda here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
ThomasMaloney
50%
50%
ThomasMaloney,
User Rank: Apprentice
4/16/2019 | 3:00:36 AM
Need intervention
It is really not surprising at all that there are actually deficiencies in the systems regardless of whether or not they belong to the state. Vulnerabilities are bound to be present anywhere at all as long as there are security lapses that are still pending intervention.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
3/30/2019 | 1:57:30 PM
deficiencies
"These new and continuing control deficiencies increase the risk of unauthorized access to, modification of, or disclosure of sensitive data and programs," Obviously there is good amount of work to be done. Unauthorized access can easily be mitigated.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
3/30/2019 | 1:55:45 PM
Re: End Game
I would posit that debt isn't an asset so is it something worth targeting. Interesting to point out. Anything that can be hacked my be considered target.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
3/30/2019 | 1:54:14 PM
Re: End Game
What is the actual risk if these systems were to be compromised? Good question. Level of risk getting bigger in each step they do not have any mitigation.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
3/30/2019 | 1:52:54 PM
Breaches
Though the deficiencies have not resulted in breaches, the response has not come through improvements to the technology and its use. I wonder how they wiiid know that. Most breaches go unheard.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
3/30/2019 | 1:51:51 PM
least privilege access
the audit mentions the lack of least privilege access as a security concern for systems. This may be important, they may need to address this first I would say.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
3/28/2019 | 9:14:43 AM
End Game
What is the actual risk if these systems were to be compromised? Do they only touch data around National Debt?

I would posit that debt isn't an asset so is it something worth targeting. Is it IP in those systems that is the main worry?
Russia Hacked Clinton's Computers Five Hours After Trump's Call
Robert Lemos, Technology Journalist/Data Researcher,  4/19/2019
Tips for the Aftermath of a Cyberattack
Kelly Sheridan, Staff Editor, Dark Reading,  4/17/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-11378
PUBLISHED: 2019-04-20
An issue was discovered in ProjectSend r1053. upload-process-form.php allows finished_files[]=../ directory traversal. It is possible for users to read arbitrary files and (potentially) access the supporting database, delete arbitrary files, access user passwords, or run arbitrary code.
CVE-2019-11372
PUBLISHED: 2019-04-20
An out-of-bounds read in MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.
CVE-2019-11373
PUBLISHED: 2019-04-20
An out-of-bounds read in File__Analyze::Get_L8 in File__Analyze_Buffer.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.
CVE-2019-11374
PUBLISHED: 2019-04-20
74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.
CVE-2019-11375
PUBLISHED: 2019-04-20
Msvod v10 has a CSRF vulnerability to change user information via the admin/member/edit.html URI.