How many more times are we going to go through this before companies realise that basic security considerations, like I don't know, not hard coding keys, should be sorted out long before they release the bloody hardware.
Got a GE industrial Ethernet switch? Get patching
GE is the latest industrial kit vendor to send users patching to protect against hard-coded credentials in Ethernet switches. IOActive disclosed the vulnerability to ICS-CERT, which issued this advisory (details here CVE-2014-5418 and here CVE-2014-5419). The vulnerability occurs in various GE Multilink managed Ethernet …
COMMENTS
-
-
This post has been deleted by its author