CERT Warns Wind Turbines Open to Compromise
ID: 231b4430-aa38-55f9-8635-f6b30b6e7851
STIX ID: report--231b4430-aa38-55f9-8635-f6b30b6e7851
Feed Name: Security Ledger
Threat Score
ICS-CERT warned that XZERES 442SR wind turbines have a critical web-interface vulnerability (CVE-2015-0985, CVSS 9.8) enabling unauthenticated attackers to hijack administrator sessions (via XSS/CSRF patterns) and take control of devices; fixes exist but require manual installation and some turbines remain exposed on the Internet according to Shodan, increasing the risk to residential and off-grid deployments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
