Awareness Lessons
6 months ago
Critical Vulnerabilities Expose Industrial Network Devices to Remote Takeover
Forescout discovered 22 critical vulnerabilities in widely-deployed serial-to-IP converters from Lantronix and Silex that could allow attackers to remotely execute code, bypass authentication, and take control of devices. These converters bridge legacy industrial equipment with modern networks, making them critical attack vectors into operational technology environments. With tens of thousands of these devices exposed online, the findings highlight how poor visibility and security practices around industrial networking equipment create significant attack surfaces that could impact utilities, manufacturing, and healthcare operations.
Tactical Insight
Immediate actions
- Patch affected Lantronix and Silex devices to latest firmware versions
- Remove unnecessary internet exposure of industrial networking devices
- Change default credentials on all serial-to-IP converters
Long-term improvements
- Implement network segmentation to isolate OT devices from corporate networks
- Establish regular vulnerability scanning for all industrial networking equipment
- Maintain comprehensive asset inventory of all network bridge devices
Detection measures
- Deploy network monitoring to detect unauthorized access to industrial devices
- Enable logging on all serial-to-IP converters where supported