Heads up on hacker risks for HVAC

Cyber-physical systems (CPS) protection company, Claroty, has issued a warning about vulnerabilities for data centre HVAC systems.

A report released by Claroty at the end of July this year presented research showing that 32% of HVAC/cooling systems in data centres are either directly exposed or “one hop away from a risky connection to the public internet” according to the company’s news announcement.

The report from Claroty’s Team82, State of CPS Security: Data Center Exposures analyses more than 750,000 cyber-physical security (CPS) assets across global large-scale and hyper-scale data centres, finding that nearly one in five of these assets are “one hop” away from systems making outbound connections that could provide attackers a pathway to exposed data centre assets.

In addition to HVAC system vulnerabilities, researchers identified that:

  • 41% of power distribution units have assets that are either directly exposed or one hop away from a risky connection to the public internet
  • 88% of BMS are exposed via communication over insecure protocols, and 40% contain outdated firmware
  • More than 80% of operational technology (OT) control systems, power monitoring, and IoT systems communicate over legacy, insecure protocols such as BACnet and MODBUS
  • 23% of IoT devices in data centers contain known exploited vulnerabilities (KEVs). 

CPS assets include building management systems (BMS), building automation systems (BAS), power distribution, monitoring and control systems, uninterruptible power supplies (UPS), generators, cooling infrastructure, environmental monitoring platforms, and data centre infrastructure management (DCIM) solutions.

“Data centres have evolved into critical infrastructure globally, and much like electric utilities or transportation, threat actors will see the high value in disrupting their operations,” says Amir Preminger, Chief technology Officer and head of Team82 at Claroty.

“As data centre protection is vitally important on a societal scale in terms of the AI boom and economic and national security, building operational resilience is the best path forward for operators safeguarding these complex CPS ecosystems.”

OEMs issue fixes

Trane, Danfoss and Copeland have recently issued recommendations for software updates to address vulnerabilities identified by Claroty’s Team82.

An article at Refindustry reports that the vulnerabilities affect the Danfoss AK-SM 800A, Copeland XWEB Pro and Trane Tracer platforms and include authentication bypass, command injection, denial-of-service and information disclosure issues. 

Team82 tested possible consequences of a security breach, for example, malicious actors gaining capability to manipulate temperature displays or disable cooling fans.

The manufacturers have issued fixes: Danfoss firmware R4.3.1 for the AK-SM 800A, Copeland firmware 1.13 for XWEB Pro, and Trane version v6.3 or later for Tracer SC+.

Trane and Danfoss also gave further advice around isolating equipment controller management and other systems from public internet to reduce the risks.

Read the full story and the advice from Team82 and the HVAC OEMs here.

Image from Pixabay


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *