APC Smart-UPS vulnerabilities expose millions of businesses to hacking

Discussion in 'other security issues & news' started by hawki, Mar 8, 2022.

  1. hawki

    hawki Registered Member

  2. Rasheed187

    Rasheed187 Registered Member

    I don't get it, why would you connect UPS devices to the internet?
     
  3. FanJ

    FanJ Updates Team

    APC warns of critical unauthenticated RCE flaws in UPS software - April 24, 2023
    https://www.bleepingcomputer.com/ne...al-unauthenticated-rce-flaws-in-ups-software/

    Read there more!
     
  4. Tinstaafl

    Tinstaafl Registered Member

    Is anyone actually connecting their UPS to the internet? o_O
     
  5. xxJackxx

    xxJackxx Registered Member

    It's my understanding that these are the Enterprise class devices that are remotely managed, not consumer based devices that sit under your desk.
     
  6. Tinstaafl

    Tinstaafl Registered Member

    I get that they are remote managed, but all connections to Enterprise devices should be done over one's private or corporate network. Who was allowed to connect them directly to the public internet where they are exposed to potential adversaries?

    In the article linked earlier, it was stated: "General security recommendations provided by the vendor include placing mission-critical internet-connected devices behind firewalls, utilizing VPNs for remote access, implementing strict physical access controls".

    Well, yeah...
     
  7. xxJackxx

    xxJackxx Registered Member

    You'd be surprised how many people run a data center from home. I'm not defending it, just acknowledging it.
     
  8. Tinstaafl

    Tinstaafl Registered Member

    Cool! I suppose if there is really that much low hanging fruit available, they are not going to come after me, LOL!
     
  9. xxJackxx

    xxJackxx Registered Member

    That's probably more true than you think it is. As long as 123456 is one of the most common passwords in use, there is plenty of low hanging fruit. Plus, you just won the Nigerian lottery!!!
     
  10. Tinstaafl

    Tinstaafl Registered Member

    Yay me!!! Now where do I send the money...? :argh:
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice