/* ---- Google Analytics Code Below */
Showing posts with label VxWorks. Show all posts
Showing posts with label VxWorks. Show all posts

Saturday, August 03, 2019

Details of VxWorks Vulnerability Found by Armis

More on the topic mentioned recently about extensive vulnerability of common embedded OS.

200 Million Devices—Some Mission-Critical—Vulnerable to Remote Takeover 
in Ars Technica
by Dan Goodin

Researchers at California-based security firm Armis have identified 11 vulnerabilities in various versions of VxWorks, an operating system (OS) that runs on more than 2 billion devices worldwide. The researchers found about 200 million Internet-connected devices (some of which may be controlling elevators, medical equipment, and other mission-critical systems) are vulnerable to attacks that give bad actors complete control of those systems. The vulnerabilities, collectively known as Urgent 11, include six remote code flaws and five less-severe issues that allow a range of security issues including information leaks and denial-of-service attacks. None of the vulnerabilities affect the most recent version of VxWorks, or any certified versions of the OS, including VXWorks 653 or VxWorks Cert Edition. "Such vulnerabilities do not require any adaptations for the various devices using the network stack, making them exceptionally easy to spread," according to the Armis researchers .... "

Friday, August 02, 2019

Most Everything is now Vulnerable

As part of a project,  I am looking at hacking vulnerabilities, and have been following some of the security press.   Another remarkable discovery.  That the vulnerabilities in the VxWorks embedded  OS exists in hundred of millions of devices.  Some have existed without discovery since 1987.    In particular IOT devices, but also most anything that connects to the net.  An sample excerpt of specific vulnerabilities were posted here:  https://www.grc.com/sn/SN-725-Notes.pdf   Page 10-    This will be covered in the Vegas Black Hat conference next week on August 8-  So expect more details then.  Given all the healthcare, mobility and IOT systems involved, this is very serious.

See also coverage in Wired:   https://www.wired.com/story/vxworks-vulnerabilities-urgent11/

(VxWorks has been corrected for this problem, but you must update your systems now)