Thursday, August 8, 2019

Crucial Vulnerabilities Exist in the VxWorks IPnet Stack

According to Security Week (reported the other day):

"In late July, IoT security firm Armis disclosed eleven vulnerabilities found by its researchers in the VxWorks real time operating system (RTOS). The flaws, six of which have been described as critical, can allow a remote attacker to take control of impacted systems.
Armis said the vulnerabilities exist in the VxWorks IPnet stack and they expose over 200 million mission-critical devices from around the world to attacks, including in the healthcare, manufacturing, cybersecurity, tech, and industrial automation sectors. ..."

Devices from several vendors might be impacted ...

Click HERE for the full report. There you find links to the vendor's recommendations ... You know what that could mean? One vendor notes: "Applying the update causes the device / module to go through a single restart cycle."


No comments: