back to article Got a GE industrial Ethernet switch? Get patching

GE is the latest industrial kit vendor to send users patching to protect against hard-coded credentials in Ethernet switches. IOActive disclosed the vulnerability to ICS-CERT, which issued this advisory (details here CVE-2014-5418 and here CVE-2014-5419). The vulnerability occurs in various GE Multilink managed Ethernet …

  1. Terra Rasa

    How many more times are we going to go through this before companies realise that basic security considerations, like I don't know, not hard coding keys, should be sorted out long before they release the bloody hardware.

    1. petur

      because the developer(s) don't know and the PM/management (still) don't care....

  2. thames Silver badge

    Ah yes, "industrial" - the "special needs" version of security.

  3. This post has been deleted by its author

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like