Comments
Internet Of Things Contains Average Of 25 Vulnerabilities Per Device
Newest First  |  Oldest First  |  Threaded View
markoer
50%
50%
markoer,
User Rank: Apprentice
7/30/2014 | 6:06:36 AM
Re: Ok, but....
Thanks a lot, Kelly!
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
7/29/2014 | 2:43:42 PM
Re: Ok, but....
Here you go: http://fortifyprotect.com/HP_IoT_Research_Study.pdf

The link has now been added to the story, too. Thanks!
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
7/29/2014 | 2:41:22 PM
Re: Ok, but....
Here you go: http://fortifyprotect.com/HP_IoT_Research_Study.pdf

The link has now been added to the story, too. Thanks!
markoer
50%
50%
markoer,
User Rank: Apprentice
7/29/2014 | 12:08:28 PM
Ok, but....
...where is the link to the HP study?...
GonzSTL
50%
50%
GonzSTL,
User Rank: Ninja
7/29/2014 | 10:53:30 AM
Re: 25 vulns/device
I think we have come to accept that all things are vulnerable, so it really boils down to a risk vs benefit/utility analysis. If vulnerabilities can be mitigated without outweighing the benefit or utility, then it becomes an organizational decision. On a personal level, my smartphone is an essential need, but the need to control my home thermostat remotely just doesn't have the same level of utility as my phone, and is the last thing I need to worry about. I guess it all comes down to a matter of priorities.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
7/29/2014 | 9:44:33 AM
25 vulns/device
That seems pretty high to me, but how does that compare to, for instance, a typical smartphone or tablet? I'd also be curious to know if OWASP has info abut which are most vulnerabe IoT devices on the market.


Google Engineering Lead on Lessons Learned From Chrome's HTTPS Push
Kelly Sheridan, Staff Editor, Dark Reading,  8/8/2018
White Hat to Black Hat: What Motivates the Switch to Cybercrime
Kelly Sheridan, Staff Editor, Dark Reading,  8/8/2018
PGA of America Struck By Ransomware
Dark Reading Staff 8/9/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Now about that mortgage refinance offer from Wells Fargo .....
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-6970
PUBLISHED: 2018-08-13
VMware Horizon 6 (6.x.x before 6.2.7), Horizon 7 (7.x.x before 7.5.1), and Horizon Client (4.x.x and prior before 4.8.1) contain an out-of-bounds read vulnerability in the Message Framework library. Successfully exploiting this issue may allow a less-privileged user to leak information from a privil...
CVE-2018-14781
PUBLISHED: 2018-08-13
Medtronic MMT 508 MiniMed insulin pump, 522 / MMT - 722 Paradigm REAL-TIME, 523 / MMT - 723 Paradigm Revel, 523K / MMT - 723K Paradigm Revel, and 551 / MMT - 751 MiniMed 530G The models identified above, when paired with a remote controller and having the "easy bolus" and "remote bolu...
CVE-2018-15123
PUBLISHED: 2018-08-13
Insecure configuration storage in Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version -118 allows remote attacker perform new attack vectors and take under control device and smart home.
CVE-2018-15124
PUBLISHED: 2018-08-13
Weak hashing algorithm in Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version -118 allows unauthenticated attacker extract clear text passwords and get root access on the device.
CVE-2018-15125
PUBLISHED: 2018-08-13
Sensitive Information Disclosure in Zipato Zipabox Smart Home Controller allows remote attacker get sensitive information that expands attack surface.