Back to all lessons
Awareness Lessons
6 months ago

Critical Vulnerabilities Expose Industrial Network Devices to Remote Takeover

Forescout discovered 22 critical vulnerabilities in widely-deployed serial-to-IP converters from Lantronix and Silex that could allow attackers to remotely execute code, bypass authentication, and take control of devices. These converters bridge legacy industrial equipment with modern networks, making them critical attack vectors into operational technology environments. With tens of thousands of these devices exposed online, the findings highlight how poor visibility and security practices around industrial networking equipment create significant attack surfaces that could impact utilities, manufacturing, and healthcare operations.

Tactical Insight

Immediate actions

  • Patch affected Lantronix and Silex devices to latest firmware versions
  • Remove unnecessary internet exposure of industrial networking devices
  • Change default credentials on all serial-to-IP converters

Long-term improvements

  • Implement network segmentation to isolate OT devices from corporate networks
  • Establish regular vulnerability scanning for all industrial networking equipment
  • Maintain comprehensive asset inventory of all network bridge devices

Detection measures

  • Deploy network monitoring to detect unauthorized access to industrial devices
  • Enable logging on all serial-to-IP converters where supported