• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
high severity flaw reported in critical system used in oil and

High-Severity Flaw Reported in Critical System Used in Oil and Gas Companies

You are here: Home / General Cyber Security News / High-Severity Flaw Reported in Critical System Used in Oil and Gas Companies
November 10, 2022

Cybersecurity researchers have disclosed information of a new vulnerability in a method applied throughout oil and fuel organizations that could be exploited by an attacker to inject and execute arbitrary code.

The vulnerability, tracked as CVE-2022-0902 (CVSS score: 8.1), is a route-traversal vulnerability in ABB Totalflow flow personal computers and distant controllers.

“Attackers can exploit this flaw to get root accessibility on an ABB stream laptop or computer, read and generate files, and remotely execute code,” industrial security enterprise Claroty claimed in a report shared with The Hacker News.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


ABB, a Swedish-Swiss industrial automation business, has since released firmware updates as of July 14, 2022, pursuing liable disclosure.

Move pcs are specific-reason electronic devices used by petrochemical producers to interpret facts from movement meters and compute and file the volume of substances these kinds of as all-natural gasoline, crude oils, and other hydrocarbon fluids at a precise place in time.

These gasoline measurements are critical not only when it will come to process protection, but are also applied as inputs when bulk liquid or gas products and solutions adjust hands concerning parties, creating it imperative that the stream measurements are properly captured.

In a nutshell, the vulnerability determined by Claroty is a route traversal flaw that exists in ABB’s implementation of its proprietary Totalflow TCP protocol, which is used to remotely configure the pcs.

CyberSecurity

The issue, specifically, concerns a aspect that lets for importing and exporting the configuration documents, enabling an attacker to just take edge of an authentication bypass issue to get earlier the security passcode barrier and upload arbitrary data files.

By having edge of the shortcoming, a distant malicious actor could seize handle of the products and hamper their means to thoroughly file oil and gas move costs.

“A thriving exploit of this issue could impede a company’s potential to monthly bill prospects, forcing a disruption of solutions, related to the effects suffered by Colonial Pipeline next its 2021 ransomware attack,” Claroty researcher Vera Mens mentioned.

Found this posting attention-grabbing? Abide by THN on Fb, Twitter  and LinkedIn to examine extra special articles we submit.


Some pieces of this posting are sourced from:
thehackernews.com

Previous Post: «re focusing cyber insurance with security validation Re-Focusing Cyber Insurance with Security Validation
Next Post: GitHub launches private vulnerability reporting to secure the software supply chain github launches private vulnerability reporting to secure the software supply»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • New FjordPhantom Android Malware Targets Banking Apps in Southeast Asia
  • Qakbot Takedown Aftermath: Mitigations and Protecting Against Future Threats
  • Chinese Hackers Using SugarGh0st RAT to Target South Korea and Uzbekistan
  • Discover How Gcore Thwarted Powerful 1.1Tbps and 1.6Tbps DDoS Attacks
  • WhatsApp’s New Secret Code Feature Lets Users Protect Private Chats with Password
  • U.S. Treasury Sanctions North Korean Kimsuky Hackers and 8 Foreign Agents
  • Zyxel Releases Patches to Fix 15 Flaws in NAS, Firewall, and AP Devices
  • Zero-Day Alert: Apple Rolls Out iOS, macOS, and Safari Patches for 2 Actively Exploited Flaws
  • Google Unveils RETVec – Gmail’s New Defense Against Spam and Malicious Emails
  • North Korea’s Lazarus Group Rakes in $3 Billion from Cryptocurrency Hacks

Copyright © TheCyberSecurity.News, All Rights Reserved.