Critical HVAC and UPS Vulnerabilities Could Let Hackers Disrupt Data Centers

https://www.securityweek.com/wp-content/uploads/2024/09/Data-center-Cybersecurity-1.jpg

Researchers at cyber-physical systems security firm Claroty have uncovered multiple vulnerabilities in two widely deployed HVAC and UPS products used in data centers, demonstrating how attackers could exploit them to launch disruptive remote attacks.

The researchers targeted network cards designed to provide a network interface for uninterruptible power supply devices made by Vertiv.

“UPSs are heavily used in data centers to maintain operations in the event of a power outage; they also protect systems from power spikes and drops, and enable safe shutdowns,” Claroty noted.

The security firm’s researchers found that the Vertiv network cards, which provide a default web interface for UPS devices, are affected by two vulnerabilities: an authentication bypass flaw and a remote code execution vulnerability.

Chaining the two security holes can allow an attacker to remotely access the targeted UPS and execute arbitrary code, potentially causing significant operational disruptions.

“What makes [the vulnerabilities] especially concerning is...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more