The CISA issued an alert concerning attacks against industrial systems known as automatic tank gauges (ATG). These systems are utilized by the Energy, Chemical, Food and Agriculture and even Transportation systems throughout the United States. It wouldn’t surprise me but that they are found in places many of us would just not suspect! But, since they are present and since they are vital in many ways for many organizations to operate, they have become a target of hackers.
The CISA has observed malicious cyber attacks which are compromising these systems and modifying them through command execution. These ATG systems are vital to the proper functioning of critical operating systems and organizations throughout the United States. If they are under attack, it would behoove us to pay attention and do everything we can to protect them.
Cyber threat actors may exploit flaws in ATG systems through multiple attack vectors:
- Authentication Bypass and Hardcoded Credentials: Threat actors gain unauthorized access to device management interfaces.
- OS Command Execution and Structured Query Language (SQL) Injection: Threat actors execute arbitrary code and manipulate underlying databases.
- Privilege Escalation: Threat actors achieve full administrator privileges over the device application and operating system.
As stated above, these attack vectors are being seen in the ongoing attacks and each administrator who handles these systems needs to pay attention to the mitigations for each attack. They are fairly typical, but oftentimes these systems are ignored when it comes to cyber security and now need to be focused upon.
CISA also provides some mitigation advice in their bulletin:
- Eliminate public internet exposure: Do not expose the ATG serial port (default TCP Port 8001, 9001 or 10001) or other web interfaces directly to the Internet.
- Enforce credential security: Any default passwords should be changed immediately, daand strong password policies should be enacted and enforced.
- Apply any patches to these systems as soon as possible.
- Monitor these systems for any intrusion attempts whether successful or not and report these attempts to the proper authorities.
- Ensure logging, auditing and monitoring of logs are enabled.
Do not wait to become a victim, take action today if these systems are in your environment.
Carpe Diem!
Leave a Reply