• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
high severity flaw reported in critical system used in oil and

High-Severity Flaw Reported in Critical System Used in Oil and Gas Companies

You are here: Home / General Cyber Security News / High-Severity Flaw Reported in Critical System Used in Oil and Gas Companies
November 10, 2022

Cybersecurity researchers have disclosed information of a new vulnerability in a method applied throughout oil and fuel organizations that could be exploited by an attacker to inject and execute arbitrary code.

The vulnerability, tracked as CVE-2022-0902 (CVSS score: 8.1), is a route-traversal vulnerability in ABB Totalflow flow personal computers and distant controllers.

“Attackers can exploit this flaw to get root accessibility on an ABB stream laptop or computer, read and generate files, and remotely execute code,” industrial security enterprise Claroty claimed in a report shared with The Hacker News.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


ABB, a Swedish-Swiss industrial automation business, has since released firmware updates as of July 14, 2022, pursuing liable disclosure.

Move pcs are specific-reason electronic devices used by petrochemical producers to interpret facts from movement meters and compute and file the volume of substances these kinds of as all-natural gasoline, crude oils, and other hydrocarbon fluids at a precise place in time.

These gasoline measurements are critical not only when it will come to process protection, but are also applied as inputs when bulk liquid or gas products and solutions adjust hands concerning parties, creating it imperative that the stream measurements are properly captured.

In a nutshell, the vulnerability determined by Claroty is a route traversal flaw that exists in ABB’s implementation of its proprietary Totalflow TCP protocol, which is used to remotely configure the pcs.

CyberSecurity

The issue, specifically, concerns a aspect that lets for importing and exporting the configuration documents, enabling an attacker to just take edge of an authentication bypass issue to get earlier the security passcode barrier and upload arbitrary data files.

By having edge of the shortcoming, a distant malicious actor could seize handle of the products and hamper their means to thoroughly file oil and gas move costs.

“A thriving exploit of this issue could impede a company’s potential to monthly bill prospects, forcing a disruption of solutions, related to the effects suffered by Colonial Pipeline next its 2021 ransomware attack,” Claroty researcher Vera Mens mentioned.

Found this posting attention-grabbing? Abide by THN on Fb, Twitter  and LinkedIn to examine extra special articles we submit.


Some pieces of this posting are sourced from:
thehackernews.com

Previous Post: «re focusing cyber insurance with security validation Re-Focusing Cyber Insurance with Security Validation
Next Post: GitHub launches private vulnerability reporting to secure the software supply chain github launches private vulnerability reporting to secure the software supply»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.