[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fwnhqIDs_-IYhu6vLUgATKcKnhC6s6GbT8kDYnIpW1RM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"d7e74382-1368-4adf-872f-93d7c29be82b","hard-coded-cryptographic-keys-expose-wrtsil-marine-software-to-remote-code-execution","0434bdb5-6d09-40b8-bdde-faa5ba5c752c","Hard-Coded Cryptographic Keys Expose Wärtsilä Marine Software to Remote Code Execution","The core failure in Wärtsilä's FOS-Onboard software stems from the use of hard-coded cryptographic keys — a well-known and avoidable anti-pattern in secure software development. Hard-coded keys are inherently dangerous because any attacker who discovers them (through reverse engineering or a leak) gains a permanent, shared secret that cannot be rotated without a full software update. In this case, the consequences are severe: unauthorized firmware updates, arbitrary code execution, and credential theft on maritime operational technology (OT) systems. This matters enormously in marine environments where software integrity directly affects vessel safety and operational continuity. The incident underscores that cryptographic secrets must never be embedded in code and that OT vendors must apply secure-by-design principles from the earliest stages of development.","**Immediate actions:**\n- Apply Wärtsilä's official patch immediately by contacting the vendor, and verify installation integrity before returning systems to operation.\n- Audit all deployed instances of FOS-Onboard version 5.07.0923.01 to confirm exposure scope and prioritize patching based on network accessibility.\n- Isolate affected systems from untrusted networks or external update channels until the patch is confirmed installed.\n\n**Long-term improvements:**\n- Enforce a secure development lifecycle (SDL) policy that explicitly prohibits hard-coded credentials, keys, or secrets in any software or firmware.\n- Implement a centralized secrets management solution (e.g., HashiCorp Vault) to manage cryptographic keys dynamically and support key rotation without software releases.\n- Maintain a comprehensive OT\u002FICS asset inventory with version tracking to enable rapid identification and response to future vulnerability disclosures.\n\n**Detection measures:**\n- Deploy integrity monitoring on OT software update pipelines to detect unauthorized or tampered update packages before installation.\n- Establish network monitoring and anomaly detection around maritime OT systems to identify unusual authentication attempts or unexpected code execution behavior.\n- Subscribe to ICS-CERT and vendor security advisories to receive timely alerts on vulnerabilities affecting operational technology systems.",[12,13,14,15,16,17,18,19,20],"CIS Control 2 – Inventory and Control of Software Assets","CIS Control 7 – Continuous Vulnerability Management","CIS Control 16 – Application Software Security","NIST SP 800-82 – Guide to ICS Security","NIST CSF PR.IP-2 – System Development Life Cycle for Security","NIST SP 800-57 – Recommendation for Key Management","IEC 62443-4-2 – Security for Industrial Automation and Control Systems (Component Requirements)","ITIL Change Management – Controlled patching and change authorization processes","GDPR Article 32 – Security of processing (where personal data may be at risk via credential theft)","published","2026-09-15T17:21:26.97682+00:00","2026-09-15T17:21:26.741+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fics-advisories\u002Ficsa-26-258-02","wartsila-fos-onboard-2f5bf3","Wärtsilä FOS-Onboard",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":42,"name":43,"slug":44,"description":45,"color":46},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]