{"id":9177,"date":"2019-07-29T15:41:17","date_gmt":"2019-07-29T19:41:17","guid":{"rendered":"http:\/\/pappp.net\/?guid=e47ef9dd2c4f71acd0e6d2ef0e760b3b"},"modified":"2019-07-29T15:41:17","modified_gmt":"2019-07-29T19:41:17","slug":"200-million-devices-some-mission-critical-vulnerable-to-remote-takeover","status":"publish","type":"post","link":"https:\/\/pappp.net\/?p=9177","title":{"rendered":"200 million devices&mdash;some mission-critical&mdash;vulnerable to remote takeover"},"content":{"rendered":"<p class=\"syndicated-attribution\">Source: <a href=\"https:\/\/arstechnica.com\/?p=1542997\">Ars Technica<\/a><\/p>\n<div style=\"background-color : #fff7d5;\n\t\t\tborder-width : 1px; padding : 5px; border-style : dashed; border-color : #e7d796;margin-bottom : 1em; color : #9a8c59;\">Article note: VXWorks is one of those invisibly-everywhere things, from electrical appliances to Mars rovers.  It's generally pretty trustworthy, but this is ...low hanging. \r\n\r\nIt would likely be difficult to get something generally-wormable because of platform diversity due to customization, but it would be easy to do a lot of damage by worming something prolific and connected (like the many modems that run it) or attacking something life-critical (think medical devices).<\/div><div>\n<figure><img src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2017\/11\/LisaBrewster_Flickr_HackerDefcon15-800x536.jpg\" alt=\"A repairman with \" hacker his shirt patch referrerpolicy=\"no-referrer\"\/><p><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2017\/11\/LisaBrewster_Flickr_HackerDefcon15.jpg\" rel=\"noopener noreferrer\" >Enlarge<\/a> (credit: <a rel=\"noopener noreferrer\" href=\"https:\/\/www.flickr.com\/photos\/sophistechate\/2669139341\/in\/photolist-54S38P-9P7G9h-63aP8G-75dUX2-89nCB3-nKjDpV-8pKKaQ-9Lbq9x-9z6NPi-axAie9-8Zce1K-3W29yL-7fELfh-33WQKK-7azeRh-aBWQVx-c4xxKd-q5LZoo-aBZwoj-2B8mB-85ZXFR-85ZXE4-dz6Ur4-dQEYKA-5pqTTa-75dU9K-75hLDh-9AkFeW-75hLNq-oUzmyP-icqdnP-ouQhTq-icpxdP-7avC62-jpsSp-4vi7es-pc4zGP-5U2KfY-8648uC-foNUqo-9cwaEm-9Jdaus-7avqEa-jUiRoz-6x4n6h-Qp9eN-aBWRj6-6DE3GQ-5Em9FN-6Z5prw\" >Lisa Brewster \/ Flickr<\/a>)<\/p>  <\/figure><div><a name=\"page-1\"><\/a><\/div>\n<p>About 200 million Internet-connected devices&mdash;some that may be controlling elevators, medical equipment, and other mission-critical systems&mdash;are vulnerable to attacks that give attackers complete control, researchers warned on Monday.<\/p>\n<p>In all, researchers with security firm Armis identified 11 vulnerabilities in various versions of VxWorks, a slimmed-down operating system that runs on more than 2 billion devices worldwide (<a href=\"https:\/\/en.wikipedia.org\/wiki\/VxWorks#Notable_uses\" rel=\"noopener noreferrer\" >this section<\/a> of Wikipedia's article on the OS lists some of its more notable uses). Billed collectively as Urgent 11, the vulnerabilities consist of six remote code flaws and five less-severe issues that allow things like information leaks and denial-of-service attacks. None of the vulnerabilities affects the most recent version of VxWorks&mdash;which was released last week&mdash;or any of the certified versions of the OS, including VxWorks 653 or VxWorks Cert Edition.<\/p>\n<h2>High stakes<\/h2>\n<p>For the 200 million devices Armis estimated are running a version that&rsquo;s susceptible to a serious attack, however, the stakes may be high. Because many of the vulnerabilities reside in the networking stack known as IPnet, they can often be exploited by little more than boobytrapped packets sent from the Internet. Depending on the vulnerability, exploits may also be able to penetrate firewalls and other types of network defenses. The most dire scenarios are attacks that chain together multiple exploits that trigger the remote takeover of multiple devices.<\/p>\n<\/div><p><a href=\"https:\/\/arstechnica.com\/?p=1542997#p3\" rel=\"noopener noreferrer\" >Read 6 remaining paragraphs<\/a> | <a href=\"https:\/\/arstechnica.com\/?p=1542997&amp;comments=1\" rel=\"noopener noreferrer\" >Comments<\/a><\/p><div>\n<a href=\"http:\/\/feeds.arstechnica.com\/~ff\/arstechnica\/index?a=Fng80UstqFY:hjZK0C2SsLk:V_sGLiPBpWU\" rel=\"noopener noreferrer\" ><img src=\"http:\/\/feeds.feedburner.com\/~ff\/arstechnica\/index?i=Fng80UstqFY:hjZK0C2SsLk:V_sGLiPBpWU\" border=\"0\" referrerpolicy=\"no-referrer\"\/><\/a> <a href=\"http:\/\/feeds.arstechnica.com\/~ff\/arstechnica\/index?a=Fng80UstqFY:hjZK0C2SsLk:F7zBnMyn0Lo\" rel=\"noopener noreferrer\" ><img src=\"http:\/\/feeds.feedburner.com\/~ff\/arstechnica\/index?i=Fng80UstqFY:hjZK0C2SsLk:F7zBnMyn0Lo\" border=\"0\" referrerpolicy=\"no-referrer\"\/><\/a> <a href=\"http:\/\/feeds.arstechnica.com\/~ff\/arstechnica\/index?a=Fng80UstqFY:hjZK0C2SsLk:qj6IDK7rITs\" rel=\"noopener noreferrer\" ><img src=\"http:\/\/feeds.feedburner.com\/~ff\/arstechnica\/index?d=qj6IDK7rITs\" border=\"0\" referrerpolicy=\"no-referrer\"\/><\/a> <a href=\"http:\/\/feeds.arstechnica.com\/~ff\/arstechnica\/index?a=Fng80UstqFY:hjZK0C2SsLk:yIl2AUoC8zA\" rel=\"noopener noreferrer\" ><img src=\"http:\/\/feeds.feedburner.com\/~ff\/arstechnica\/index?d=yIl2AUoC8zA\" border=\"0\" referrerpolicy=\"no-referrer\"\/><\/a>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Enlarge (credit: Lisa Brewster \/ Flickr)<br \/>\nAbout 200 million Internet-connected devices&mdash;some&#8230;<\/p>\n<p> <a href=\"https:\/\/pappp.net\/?p=9177\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[226],"tags":[],"class_list":["post-9177","post","type-post","status-publish","format-standard","hentry","category-news-2"],"_links":{"self":[{"href":"https:\/\/pappp.net\/index.php?rest_route=\/wp\/v2\/posts\/9177","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pappp.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pappp.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pappp.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pappp.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9177"}],"version-history":[{"count":0,"href":"https:\/\/pappp.net\/index.php?rest_route=\/wp\/v2\/posts\/9177\/revisions"}],"wp:attachment":[{"href":"https:\/\/pappp.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9177"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pappp.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9177"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pappp.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9177"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}