Security News > 2020 > June > Critical Vulnerability Could Have Allowed Hackers to Disrupt Traffic Lights

Critical Vulnerability Could Have Allowed Hackers to Disrupt Traffic Lights
2020-06-05 12:33

A critical vulnerability affecting traffic light controllers made by SWARCO could have been exploited by hackers to disrupt a city's traffic lights.

Peter Fröhlich, managing director at ProtectEM, told SecurityWeek that the vulnerability was discovered during a security audit conducted for a city in Germany that hired his company to analyze networked traffic systems.

The affected SWARCO controller runs BlackBerry's QNX real-time operating system and it's designed to control traffic lights in one intersection.

"In the unpatched system, an attacker gets unlimited root access to any traffic light controller without requiring any credentials through a well documented and known feature of the underlying operating system. The access is meant for debugging, so it is not a bug or software defect that can be exploited. Rather the system was deployed in a configuration not meant for a production system with no security in place for this access port. As documented for the operating system, for a production system this debug option needs to be turned off," Fröhlich explained.

"As we move to smart cities the industry faces new challenges with respect to hardening their system against intentional and untargeted security threats. Embedded controllers not only run traffic lights but also lighting systems, heating and cooling, elevators, doors and many other automated systems which affect a large number of people. Manipulation of the the behavior of such systems or mere denial of service can create significant impact," Fröhlich concluded.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/Eku9iYp7YVE/critical-vulnerability-could-have-allowed-hackers-disrupt-traffic-lights