Security Holes in Power Analyzers More Bad News for Industry
ID: 7e87eb65-5b24-538a-9c4d-ac4ed23f8445
STIX ID: report--7e87eb65-5b24-538a-9c4d-ac4ed23f8445
Feed Name: Security Ledger
Applied Risk and DHS/ICS-CERT disclosed critical vulnerabilities in Janitza UMG/UMB power analyzers that allow trivial remote compromise—issues include a 4-digit PIN with no brute-force protections, unchangeable default FTP credentials, predictable session tokens, and persistent XSS. Exploitation could enable attackers to take full control of devices, manipulate measurement values or device behavior, and disrupt energy and industrial operations; Janitza released firmware updates and DHS recommended network mitigations (blocking specific ports, segmentation, firewalls/IDS).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
