< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 4 sources · 14 days · First seen · Last updated

Data center cyber-physical system vulnerabilities

Overview

Security research has highlighted significant vulnerabilities within the cyber-physical systems (CPS) that support global data center infrastructure. Initial findings identified specific critical weaknesses in Vertiv uninterruptible power supplies (UPS) that could lead to total power loss, as well as exploitable bugs in Trane Tracer SC+ HVAC controllers allowing remote code execution. Additionally, researchers uncovered 15 unknown vulnerabilities in TP-Link Omada’s Zero-Touch Provisioning system, which could allow attackers to gain control over network controllers and cloud services.

Subsequent analysis by Claroty, titled ‘State of CPS Security: Data Center Exposures’, expanded on these risks by examining over 750,000 CPS components. The report found that one in five systems, including HVAC and UPS, possess serious flaws. The study noted that 41% of power distribution units and 32% of HVAC/cooling systems are either directly internet-exposed or nearly so. Furthermore, 88% of building management systems are exposed via insecure protocols, and a significant portion of operational technology (OT) and IoT systems rely on obsolete protocols such as BACnet and MODBUS.

Entities

Claroty · TP‑Link · Trane · Vertiv · Forescout Research

Timeline

  1. 24 days ago

    [TECHNOLOGY] 4 sources
    Claroty report finds critical security flaws in data center systems

    A Claroty report reveals that one in five cyber-physical systems in data centers has serious security flaws, leaving critical infrastructure like power and cooling systems vulnerable to cyberattacks.

  2. about 1 month ago

    [TECHNOLOGY] 3 sources
    Critical Vulnerabilities Uncovered in Data Center Power Systems and TP‑Link Network Provisioning

    Researchers found critical UPS and HVAC controller flaws that could shut down data centers, and 15 new TP‑Link Omada ZTP vulnerabilities that enable wide‑scale network compromise.

Sources

it-business.de · mit-blog.de · presse-board.de · pressnetwork.de