Many Fuel Tank Monitoring Systems Vulnerable to Disruption
ID: f2dc96dd-b174-5016-b07c-676f0fe4825c
STIX ID: report--f2dc96dd-b174-5016-b07c-676f0fe4825c
Feed Name: Dark Reading
RSAC 2025 coverage highlights that Internet-connected automated tank gauges (ATGs) used by gas stations and fuel facilities contain multiple high-severity vulnerabilities and are widely exposed online, enabling attackers to disable pumps/alarms, falsify tank data, trigger false refills, or even cause physical damage (relay burnout). Bitsight's 2024 research and prior studies found thousands of ATGs reachable via port 10001, several CVEs (including CVE-2024-45066 and CVE-2024-43693 with CVSS up to 10), and easy discovery via Shodan and default credentials, posing cascading operational risks to fuel retail and critical infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
