logo

Security Holes in Power Analyzers More Bad News for Industry

ID: 7e87eb65-5b24-538a-9c4d-ac4ed23f8445

STIX ID: report--7e87eb65-5b24-538a-9c4d-ac4ed23f8445

Feed Name: Security Ledger

Threat Score
70/100

Date Published: 2015-10-27

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

Applied Risk and DHS/ICS-CERT disclosed critical vulnerabilities in Janitza UMG/UMB power analyzers that allow trivial remote compromise—issues include a 4-digit PIN with no brute-force protections, unchangeable default FTP credentials, predictable session tokens, and persistent XSS. Exploitation could enable attackers to take full control of devices, manipulate measurement values or device behavior, and disrupt energy and industrial operations; Janitza released firmware updates and DHS recommended network mitigations (blocking specific ports, segmentation, firewalls/IDS).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.