Artwork

Daily Security Review에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 Daily Security Review 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.
Player FM -팟 캐스트 앱
Player FM 앱으로 오프라인으로 전환하세요!

Novakon Ignored Security Reports on ICS Weaknesses, Leaving 40,000+ Devices Exposed

22:35
 
공유
 

Manage episode 507480649 series 3645080
Daily Security Review에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 Daily Security Review 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.

A new security report has revealed serious, unpatched vulnerabilities in industrial control system (ICS) products manufactured by Novakon, a Taiwan-based subsidiary of iBASE Technology. Security researchers at CyberDanube identified five categories of flaws affecting Novakon’s Human-Machine Interfaces (HMIs), including an unauthenticated buffer overflow that allows remote code execution with root privileges. Other weaknesses include directory traversal, weak authentication, excessive process privileges, and insufficient system protections.

What makes this situation particularly alarming is that these flaws can be exploited remotely and without authentication—meaning attackers don’t need credentials or physical access to compromise the devices. Once exploited, adversaries could disrupt production, manipulate industrial processes, disable safety systems, or use the devices as stepping stones for further attacks inside critical environments.

The risks are compounded by Novakon’s lack of response. Despite repeated disclosure attempts, the company has ignored most communications from CyberDanube and has released no security patches. This leaves organizations operating these devices with no vendor-supported mitigation, effectively shifting the full burden of protection to asset owners.

With an estimated 40,000 Novakon HMIs deployed globally in data centers and critical infrastructure, the potential impact is severe. Researchers stress that asset owners must immediately assess their exposure, ensure Novakon devices are not internet-facing, implement compensating network controls, and develop incident response playbooks.

This episode examines the vulnerabilities in detail, the risks they pose to industrial environments, and what organizations can do in the absence of vendor support.

#Novakon #ICS #CriticalInfrastructure #CyberSecurity #Vulnerabilities #HMI #iBASE #OTSecurity #CyberDanube #RemoteCodeExecution #DataCenters

  continue reading

368 에피소드

Artwork
icon공유
 
Manage episode 507480649 series 3645080
Daily Security Review에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 Daily Security Review 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.

A new security report has revealed serious, unpatched vulnerabilities in industrial control system (ICS) products manufactured by Novakon, a Taiwan-based subsidiary of iBASE Technology. Security researchers at CyberDanube identified five categories of flaws affecting Novakon’s Human-Machine Interfaces (HMIs), including an unauthenticated buffer overflow that allows remote code execution with root privileges. Other weaknesses include directory traversal, weak authentication, excessive process privileges, and insufficient system protections.

What makes this situation particularly alarming is that these flaws can be exploited remotely and without authentication—meaning attackers don’t need credentials or physical access to compromise the devices. Once exploited, adversaries could disrupt production, manipulate industrial processes, disable safety systems, or use the devices as stepping stones for further attacks inside critical environments.

The risks are compounded by Novakon’s lack of response. Despite repeated disclosure attempts, the company has ignored most communications from CyberDanube and has released no security patches. This leaves organizations operating these devices with no vendor-supported mitigation, effectively shifting the full burden of protection to asset owners.

With an estimated 40,000 Novakon HMIs deployed globally in data centers and critical infrastructure, the potential impact is severe. Researchers stress that asset owners must immediately assess their exposure, ensure Novakon devices are not internet-facing, implement compensating network controls, and develop incident response playbooks.

This episode examines the vulnerabilities in detail, the risks they pose to industrial environments, and what organizations can do in the absence of vendor support.

#Novakon #ICS #CriticalInfrastructure #CyberSecurity #Vulnerabilities #HMI #iBASE #OTSecurity #CyberDanube #RemoteCodeExecution #DataCenters

  continue reading

368 에피소드

모든 에피소드

×
 
Loading …

플레이어 FM에 오신것을 환영합니다!

플레이어 FM은 웹에서 고품질 팟캐스트를 검색하여 지금 바로 즐길 수 있도록 합니다. 최고의 팟캐스트 앱이며 Android, iPhone 및 웹에서도 작동합니다. 장치 간 구독 동기화를 위해 가입하세요.

 

빠른 참조 가이드

탐색하는 동안 이 프로그램을 들어보세요.
재생