Security News > 2020 > December > Vulnerability in NI Controller Can Allow Hackers to Remotely Disrupt Production

Vulnerability in NI Controller Can Allow Hackers to Remotely Disrupt Production
2020-12-11 18:14

A potentially serious vulnerability affecting CompactRIO controllers made by NI could allow hackers to remotely disrupt production processes in an organization, according to researchers.

The U.S. Cybersecurity and Infrastructure Security Agency last week published an ICS-CERT advisory to inform organizations about a high-severity vulnerability affecting NI's CompactRIO product, a rugged, real-time controller used in industrial environments in sectors such as heavy equipment, industrial manufacturing, transportation, power generation, and oil and gas.

"We are not aware of any incidents where this potential vulnerability has been exploited but have provided recommended steps for mitigation as part of the disclosure filed with CISA. Maintaining the safety and security of all NI products remains our top priority."

Borja Lanseros, CEO of Titanium Industrial Security, told SecurityWeek that the vulnerability was reported to the vendor in May 2019, but it was only patched in September 2020.

The security hole can be exploited remotely from the internet and Titanium Industrial Security said it had identified nearly 150 internet-exposed devices using the Shodan search engine.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/NNNAtEcenbQ/vulnerability-ni-controller-can-allow-hackers-remotely-disrupt-production

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
NI 18 0 10 8 7 25