Headlines

Severe RCE Bugs Pose Major Threat to Industrial IoT Devices

Severe RCE Bugs Pose Major Threat to Industrial IoT DevicesindustrialIoT,RCE,cybersecurity,vulnerability,threat
Eleven vulnerabilities found in cloud-management platforms of three industrial cellular router vendors have exposed operational technology (OT) networks to the risk of remote code execution, even if the platform is not actively configured for cloud management. According to researchers from cybersecurity firm Otorio, the flaws could impact thousands of industrial IoT (IIoT) devices and networks in a variety of sectors, especially those that use traditional wired internet connections that may not be available or reliable. The vulnerabilities can be exploited via various attack vectors, such as gaining root access through a reverse-shell, and could impact the safety of those working in the environment, warn the researchers. The vendors affected by the vulnerability are Sierra Wireless AirLink, Teltonika Networks RUT and InHand Networks InRouter.

The increasing sophistication of ransomware groups and other cyber attackers has prompted Otorio’s researchers to recommend that OT network administrators prioritize security protocols. They should disable any unused cloud feature if they’re not actively using the router for cloud management to prevent device takeovers and reduce the attack surface. They also should register devices under their own accounts in the cloud platform before connecting them to the internet, and limit direct access to the routers from IIoT devices since built-in security features like VPN tunnels and firewalls are ineffective once compromised. Vendors, in addition to avoiding the use of weak identifiers should enforce initial credential setup so network operators avoid using default credentials and thus exposing the network to immediate security risks.

The security requirements of the IIoT are unique and should be considered separately to the IoT footprint, the researchers warned, adding that companies need to reduce “high-risk” features upon demand and add extra layers of authentication, encryption, access control, and monitor. For businesses that rely on IIoT devices, the report underscores the importance of taking a proactive approach to cybersecurity initiatives, particularly as hackers continue to create even more sophisticated threats.

Industrial IoT Devices-industrialIoT,RCE,cybersecurity,vulnerability,threat


Severe RCE Bugs Pose Major Threat to Industrial IoT Devices
<< photo by samer daboul >>

You might want to read !