Hacking ABB Cylon building management: 20 root RCEs, ~800 other issues, and some insights ๐ข๐๐แแ||แ๐จ๐ปโ๐ป
Security researcher Gjoko Krstic, in his presentation last year, shared his research on ABB Cylon BMSs (building-management systems): from controllers to software supplied for diagnostics and management. These systems manage our infrastructure as you read this.
The authors report finding around 20 root RCEs (2 unauthenticated) and around 800 other vulnerabilities in different parts of the system itself, including the controllers. And most of the vulnerabilities are... easy to spot. :)
Here we touch on a cornerstone of OT cybersecurity: ABB warns on every docs page not to expose the controllers to the internet. Customers, on the other hand, rarely read the docs. Now, who is responsible for securing those ~1,000 systems the author found connected today?
The bottom line is - we have critical infrastructure with multiple serious vulnerabilities connected to the internet right now. And more will follow.
Good research and presentation, and a distress call to vendors and clients to address the issue. For security researchers and future OT experts - this is a great opportunity to learn! Enjoy.
More details:
Project Brainfog: Beyond The Facade-Exposing Smart Giants [Youtube]: https://lnkd.in/deQ9_2Hg


