• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
researchers disclose critical flaws in industrial access control system from

Researchers Disclose Critical Flaws in Industrial Access Control System from Carrier

You are here: Home / General Cyber Security News / Researchers Disclose Critical Flaws in Industrial Access Control System from Carrier
June 10, 2022

As many as 8 zero-working day vulnerabilities have been disclosed in Carrier’s LenelS2 HID Mercury entry manage technique that’s employed widely in health care, education and learning, transportation, and government facilities.

“The vulnerabilities uncovered permitted us to show the capacity to remotely unlock and lock doors, subvert alarms and undermine logging and notification devices,” Trellix security researchers Steve Povolny and Sam Quinn reported in a report shared with The Hacker News.

The issues, in a nutshell, could be weaponized by a malicious actor to obtain entire technique regulate, which include the potential to manipulate doorway locks. One particular of the bugs (CVE-2022-31481) contains an unauthenticated distant execution flaw that’s rated 10 out of 10 for severity on the CVSS scoring method.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


CyberSecurity

Other shortcomings could guide to command injection (CVE-2022-31479, CVE-2022-31486), denial-of-services (CVE-2022-31480, CVE-2022-31482), person modification (CVE-2022-31484), and info spoofing (CVE-2022-31485) as effectively as attain arbitrary file write (CVE-2022-31483).

LenelS2 is used in environments to grant bodily accessibility to privileged facilities and combine with additional complicated making automation deployments. The subsequent HID Mercury obtain panels offered by LenelS2 are impacted –

  • LNL-X2210
  • LNL-X2220
  • LNL-X3300
  • LNL-X4420
  • LNL-4420
  • S2-LP-1501
  • S2-LP-1502
  • S2-LP-2500, and
  • S2-LP-4502

CyberSecurity

Trellix mentioned that by chaining two of the aforementioned weaknesses, it was capable to obtain root-degree privileges on the system remotely and unlock and management the doorways, effectively subverting the method monitoring protections.

Coinciding with the community disclosure is an industrial regulate devices (ICS) advisory from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), urging people to update the accessibility panels to the latest firmware model (CARR-PSA-006-0622).

“Effective exploitation of these vulnerabilities could let an attacker obtain to the gadget, allowing for checking of all communications sent to and from the product, modification of onboard relays, switching of configuration information, device instability, and a denial-of-provider situation,” the company mentioned in an alert.

Observed this write-up intriguing? Observe THN on Fb, Twitter  and LinkedIn to go through additional exclusive content material we write-up.


Some areas of this posting are sourced from:
thehackernews.com

Previous Post: «Cyber Security News #RSAC: Plain Language Threat Modeling for DevSecOps
Next Post: Researchers Detail How Cyber Criminals Targeting Cryptocurrency Users researchers detail how cyber criminals targeting cryptocurrency users»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.