APC Smart-UPS vulnerabilities expose millions of businesses to hacking

Discussion in 'other security issues & news' started by hawki, Mar 8, 2022.

  1. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,130
    Location:
    DC Metro Area
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    I don't get it, why would you connect UPS devices to the internet?
     
  3. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,920
    APC warns of critical unauthenticated RCE flaws in UPS software - April 24, 2023
    https://www.bleepingcomputer.com/ne...al-unauthenticated-rce-flaws-in-ups-software/

    Read there more!
     
  4. Tinstaafl

    Tinstaafl Registered Member

    Joined:
    Jul 30, 2015
    Posts:
    965
    Location:
    USA
    Is anyone actually connecting their UPS to the internet? o_O
     
  5. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,145
    Location:
    USA
    It's my understanding that these are the Enterprise class devices that are remotely managed, not consumer based devices that sit under your desk.
     
  6. Tinstaafl

    Tinstaafl Registered Member

    Joined:
    Jul 30, 2015
    Posts:
    965
    Location:
    USA
    I get that they are remote managed, but all connections to Enterprise devices should be done over one's private or corporate network. Who was allowed to connect them directly to the public internet where they are exposed to potential adversaries?

    In the article linked earlier, it was stated: "General security recommendations provided by the vendor include placing mission-critical internet-connected devices behind firewalls, utilizing VPNs for remote access, implementing strict physical access controls".

    Well, yeah...
     
  7. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,145
    Location:
    USA
    You'd be surprised how many people run a data center from home. I'm not defending it, just acknowledging it.
     
  8. Tinstaafl

    Tinstaafl Registered Member

    Joined:
    Jul 30, 2015
    Posts:
    965
    Location:
    USA
    Cool! I suppose if there is really that much low hanging fruit available, they are not going to come after me, LOL!
     
  9. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,145
    Location:
    USA
    That's probably more true than you think it is. As long as 123456 is one of the most common passwords in use, there is plenty of low hanging fruit. Plus, you just won the Nigerian lottery!!!
     
  10. Tinstaafl

    Tinstaafl Registered Member

    Joined:
    Jul 30, 2015
    Posts:
    965
    Location:
    USA
    Yay me!!! Now where do I send the money...? :argh:
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.