Targeting an industrial protocol gateway
ID: a7cf1ba8-f1d1-5b43-8c1a-96a20164d2d6
STIX ID: report--a7cf1ba8-f1d1-5b43-8c1a-96a20164d2d6
Feed Name: SensePost Blog
This research analyzes the Anybus X-Gateway AB7832-F OT protocol gateway and discloses three vulnerabilities that allow trivial remote denial-of-service and unauthenticated configuration changes: a packet-induced crash via UDP/TCP port 7412 (CVE-2024-23765), an exposed unauthenticated web reboot endpoint (CVE-2024-23766), and an insecure HICP configuration protocol that sends cleartext passwords and can be abused or locked by attackers (CVE-2024-23767). The report includes PoCs, network discovery details, and remediation notes—HMS recommends replacement or network controls for affected legacy devices since some flaws cannot be patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
