[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fFMn7hNubn32YpjnyYH_1BUKft29ed05RR8Lb-m3iaKI":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"5ffca850-eaee-4642-bf53-1079f6ea70b1","missing-authentication-in-critical-gas-infrastructure-controllers","3b84f272-ec70-43aa-a104-d29bd714f3d5","Missing Authentication in Critical Gas Infrastructure Controllers","GPL Odorizers gas odorant injection controllers contain a high-severity vulnerability (CVE-2026-4436) that allows remote attackers to manipulate critical gas infrastructure without authentication. Attackers can send malicious Modbus packets to alter odorant levels in gas lines, potentially creating serious safety hazards for communities relying on natural gas detection. This incident highlights the dangerous combination of missing authentication controls and direct network exposure of industrial control systems. The vulnerability affects multiple controller models deployed globally, demonstrating how a single security flaw can impact widespread critical infrastructure.","**Immediate actions:**\n- Apply firmware and software updates provided by GPL Odorizers and Horner Automation immediately\n- Implement network access controls to restrict Modbus protocol communications to authorized systems only\n- Deploy network segmentation to isolate industrial control systems from general corporate networks\n\n**Long-term improvements:**\n- Establish mandatory authentication requirements for all industrial control system communications\n- Implement continuous monitoring of Modbus traffic for unauthorized command attempts\n- Create incident response procedures specific to industrial control system compromises\n\n**Detection measures:**\n- Deploy industrial protocol monitoring tools to detect suspicious Modbus register modifications\n- Set up alerts for unexpected changes in odorant injection levels or system configurations",[12,13,14,15,16,17],"CIS Control 4","CIS Control 12","NIST AC-2","NIST AC-3","IEC 62443-3-3","NERC CIP-005","published","2026-04-09T19:09:30.157684+00:00","2026-04-09T19:09:29.857+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fics-advisories\u002Ficsa-26-099-02","gpl-odorizers-gpl750-9b5fc9","GPL Odorizers GPL750",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":33,"name":34,"slug":35,"description":36,"color":37},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[]]