Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 4 sources · 14 days · First seen · Last updated
Data center cyber-physical system vulnerabilities
Overview
Security research has highlighted significant vulnerabilities within the cyber-physical systems (CPS) that support global data center infrastructure. Initial findings identified specific critical weaknesses in Vertiv uninterruptible power supplies (UPS) that could lead to total power loss, as well as exploitable bugs in Trane Tracer SC+ HVAC controllers allowing remote code execution. Additionally, researchers uncovered 15 unknown vulnerabilities in TP-Link Omada’s Zero-Touch Provisioning system, which could allow attackers to gain control over network controllers and cloud services.
Subsequent analysis by Claroty, titled ‘State of CPS Security: Data Center Exposures’, expanded on these risks by examining over 750,000 CPS components. The report found that one in five systems, including HVAC and UPS, possess serious flaws. The study noted that 41% of power distribution units and 32% of HVAC/cooling systems are either directly internet-exposed or nearly so. Furthermore, 88% of building management systems are exposed via insecure protocols, and a significant portion of operational technology (OT) and IoT systems rely on obsolete protocols such as BACnet and MODBUS.
Entities
Claroty · TP‑Link · Trane · Vertiv · Forescout Research
Timeline
-
24 days ago
[TECHNOLOGY] 4 sourcesClaroty report finds critical security flaws in data center systemsA Claroty report reveals that one in five cyber-physical systems in data centers has serious security flaws, leaving critical infrastructure like power and cooling systems vulnerable to cyberattacks.
-
about 1 month ago
[TECHNOLOGY] 3 sourcesCritical Vulnerabilities Uncovered in Data Center Power Systems and TP‑Link Network ProvisioningResearchers found critical UPS and HVAC controller flaws that could shut down data centers, and 15 new TP‑Link Omada ZTP vulnerabilities that enable wide‑scale network compromise.
Sources
it-business.de · mit-blog.de · presse-board.de · pressnetwork.de