• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Researchers Reveal 56 OT Bugs in “Icefall” Report

You are here: Home / General Cyber Security News / Researchers Reveal 56 OT Bugs in “Icefall” Report
June 21, 2022

Security scientists have disclosed 56 new vulnerabilities in 10 operational technology (OT) vendors’ items that they say show significant “insecure-by-design” procedures.

Forescout issued the OT:Icefall report right now, revealing the impacted producers as Bently Nevada, Emerson, Honeywell, JTEKT, Motorola, Omron, Phoenix Make contact with, Siemens and Yokogawa.

It stated the vulnerabilities them selves broadly in shape into four classes:

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


  • Insecure engineering protocols
  • Weak cryptography or damaged authentication techniques
  • Insecure firmware updates
  • Remote code execution (RCE) by means of indigenous operation

The most frequent vulnerability kind permits attackers to compromise credentials (38%). Next comes firmware manipulation (21%), RCE (14%) and configuration manipulation (8%). A compact variety of DoS, authentication bypass, file manipulation and logic manipulation bugs are also outlined.

“With OT:ICEFALL, we needed to disclose and supply a quantitative overview of OT insecure-by-layout vulnerabilities fairly than depend on the periodic bursts of CVEs for a one products or a smaller set of general public serious-entire world incidents that are generally brushed off as a specific seller or asset operator staying at fault,” Forescout stated in a blog put up.

“These issues array from persistent insecure-by-design and style tactics in security-licensed products to subpar makes an attempt to go absent from them. The objective is to illustrate how the opaque and proprietary mother nature of these systems, the suboptimal vulnerability management encompassing them, and the often-bogus sense of security supplied by certifications considerably complicate OT risk management endeavours.”

Forescout unveiled that 74% of the product households affected by OT:Icefall have some kind of security certification and argued that most of the issues it unveiled should really have been found comparatively quickly and conveniently if companies had executed in-depth vulnerability discovery.

The security seller added that opacity in the market is harming efforts to strengthen the security of OT merchandise. Lots of insecure-by-style and design challenges are not assigned CVEs, so they typically continue to be “less obvious and actionable,” it argued.

“The speedy growth of the danger landscape is well documented at this stage. By connecting OT to IoT and IT devices, vulnerabilities that when were being witnessed as insignificant because of to their lack of connectivity are now significant targets for poor actors,” warned Daniel dos Santos, head of security analysis at Forescout Vedere Labs.


Some areas of this posting are sourced from:
www.infosecurity-magazine.com

Previous Post: «Cyber Security News US Bank Data Breach Impacts Over 1.5 Million Customers
Next Post: Former Amazon Employee Found Guilty in 2019 Capital One Data Breach former amazon employee found guilty in 2019 capital one data»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.