Cyber-physical system vulnerabilities disclosed in the second half (2H) of 2022 declined by 14 percent from the previous year, but while that is good news, the manufacturing sector still faces tough sledding with a record number of vulnerabilities found in the second half, new research found.

In addition, vulnerabilities found by internal research and product security teams have increased by 80 percent from the second half of 2021 to 2022, according to the State of XIoT Security Report: 2H 2022 by Claroty, the cyber-physical systems protection provider.

The findings show researchers are having an impact on strengthening the security of the Extended Internet of Things (XIoT), a vast network of cyber-physical systems across industrial, healthcare, and commercial environments, and XIoT vendors are dedicating more resources to examining the security and safety of their products than ever before.

The sixth biannual State of XIoT Security Report, compiled by Team82, Claroty’s research team, is a deep examination and analysis of vulnerabilities impacting the XIoT, including operational technology and industrial control systems (OT/ICS), Internet of Medical Things (IoMT), building management systems, and enterprise IoT.

The data set comprises vulnerabilities publicly disclosed in 2H 2022 by Team82 and from trusted open sources including the National Vulnerability Database (NVD), the Industrial Control Systems Cyber Emergency Response Team (ICS-CERT), CERT@VDE, MITRE, and industrial automation vendors Schneider Electric and Siemens.

Schneider Bold

“Cyber-physical systems power our way of life. The water we drink, the energy that heats our homes, the medical care we receive – all of these rely on computer code and have a direct link to real-world outcomes,” said Amir Preminger, vice president of research at Claroty. “The purpose of Team82’s research and compiling this report is to give decision makers in these critical sectors the information they need to properly assess, prioritize, and address risks to their connected environments, so it is very heartening that we are beginning to see the fruits of vendors’ and researchers’ labor in the steadily growing number of disclosures sourced by internal teams.”

  • Key findings from the study include:
  • 62 percent of published OT vulnerabilities affect devices at Level 3 of the Purdue Model for ICS. These devices manage production workflows and can be key crossover points between IT and OT networks, thus very attractive to threat actors aiming to disrupt industrial operations.
  • In the second half of 2022, there were a record number of 485 published OT vulnerabilities which jumped from 435 in the first half of the year.Source: State of XIoT Security Report: 2H 2022

  • 71 percent of vulnerabilities were assessed a CVSS v3 score of “critical” (9.0-10) or “high” (7.0-8.9), reflecting security researchers’ tendency to focus on identifying vulnerabilities with the greatest potential impact in order to maximize harm reduction. Additionally, four of the top five Common Weakness Enumerations (CWEs) in the dataset are also in the top five of MITRE’s 2022 CWE Top 25 Most Dangerous Software Weaknesses, which can be relatively simple to exploit and enable adversaries to disrupt system availability and service delivery.
  • 63 percent of vulnerabilities are remotely exploitable over the network, meaning a threat actor does not require local, adjacent, or physical access to the affected device in order to exploit the vulnerability.
  • The leading potential impact is unauthorized remote code or command execution (prevalent in 54 percent of vulnerabilities), followed by denial-of-service conditions (crash, exit, or restart) at 43 percent.
  • The top mitigation step is network segmentation (recommended in 29 percent of vulnerability disclosures), followed by secure remote access (26 percent) and ransomware, phishing, and spam protection (22 percent).

Click here for more on the report.

ISSSource

Pin It on Pinterest

Share This