Attackers could use vulnerabilities in Bosch Rexroth nutrunners to disrupt automotive production

Covertly tampering with tightening programs also carries potential health and safety risks: As the recent in-flight emergency involving a Boeing 737 Max 9 plane operated by Alaska Airlines has shown, inadequately tightened bolts can lead to extremely dangerous situations.
The Bosch Rexroth NXA015S-36V-B nutrunner is powered by NEXO-OS, a Linux-based operating system that allows users to generate and configure tightening programs and analyse and diagnose tightening cases via the management web application.
It has a built-in display and connects to wireless networks via an embedded Wi-Fi module.
The device supports a number of communication protocols that are used to integrate it with SCADA systems, PLCs, or other production devices.
The management web app is exposed on the internet by default, they say.
They also told us that most of the vulnerabilities are remotely exploitable - an attacker does not need to be on the same subnet to compromise vulnerable devices.
Bosch Rexroth nutrunners are widely used in automotive production lines.
Determined threat actors could leverage the vulnerabilities to stop the production or affect the quality of manufactured products, leading to delays, product recalls, reputational damage, accidents, etc.
There has been no mention of these vulnerabilities being exploited by threat actors, but once technical details and updated firmware are made available, there's a chance some enterprising, skilled attackers might find it profitable to do the same research and use what they discovered.
As confirmed by Bosch Rexroth, the vulnerabilities affect Nexo cordless nutrunners from the NXA, NXP and NXV series, as well as a number of other similar devices.
For now, Nozomi refrained from publishing technical details about the vulnerabilities.
Bosch Rexroth says that roughly half of the vulnerabilities will be fixed in the updated firmware version that will be released later this month, and has provided mitigation advice for CVE-2023-48257.
The researchers advise restricting the network reachability of the device as much as possible and reviewing all accounts that have login access to the devices and delete unnecessary ones.


This Cyber News was published on www.helpnetsecurity.com. Publication date: Tue, 09 Jan 2024 16:13:45 +0000


Cyber News related to Attackers could use vulnerabilities in Bosch Rexroth nutrunners to disrupt automotive production

Attackers could use vulnerabilities in Bosch Rexroth nutrunners to disrupt automotive production - Covertly tampering with tightening programs also carries potential health and safety risks: As the recent in-flight emergency involving a Boeing 737 Max 9 plane operated by Alaska Airlines has shown, inadequately tightened bolts can lead to extremely ...
1 year ago Helpnetsecurity.com
Bosch Nutrunner Vulnerabilities Could Aid Hacker Attacks Against Automotive Production Lines - Vulnerabilities found in Bosch Rexroth nutrunners used in the automotive industry could be exploited by hackers seeking direct financial gain or threat actors looking to cause disruption or reputational damage to the targeted organization, according ...
1 year ago Securityweek.com
Hackers can infect network-connected wrenches to install ransomware - Researchers have unearthed nearly two dozen vulnerabilities that could allow hackers to sabotage or disable a popular line of network-connected wrenches that factories around the world use to assemble sensitive instruments and devices. The ...
1 year ago Packetstormsecurity.com
Top Cyber Threats Automotive Dealerships Should Look Out For - Automotive dealerships are attractive targets for hackers. A combination of storing lots of sensitive customer data, handling large financial transactions, increased dependence on digital technologies and a perception of immature cybersecurity all ...
11 months ago Securityboulevard.com
VicOne Partners With 42Crunch to Deliver Comprehensive Security Across SDV and Connected-Vehicle Ecosystem - PRESS RELEASE. DALLAS and TOKYO, May 29, 2024- VicOne, an automotive cybersecurity solutions leader, today announced a partnership with 42Crunch to enhance the security of application programming interfaces for the software-defined vehicle and ...
8 months ago Darkreading.com
Network connected wrenches are now vulnerable to Ransomware attacks - Network-connected wrenches used globally are now at risk of exposure to ransomware hackers, who can manipulate their functionalities and gain unauthorized access to the connected networks, according to experts. Research conducted by Nozomi reveals ...
1 year ago Cybersecurity-insiders.com
OT Cybersecurity for Automotive Industry - OT systems are ubiquitous across all critical infrastructure industries, such as Oil and Gas, Automotive, Energy, Water Utilities, and Transportation. OT infrastructure is very vital to any nation's security to ensure the delivery of essential ...
1 year ago Feeds.dzone.com
Pwn2Own Automotive: $1.3M for 49 zero-days, Tesla hacked twice - The first edition of Pwn2Own Automotive has ended with competitors earning $1,323,750 for hacking Tesla twice and demoing 49 zero-day bugs in multiple electric car systems between January 24 and January 26. Throughout the contest organized by Trend ...
1 year ago Bleepingcomputer.com
CVE-2018-16994 - An issue was discovered on PHOENIX CONTACT AXL F BK PN <1.0.4, AXL F BK ETH < 1.12, and AXL F BK ETH XC < 1.11 devices and Bosch Rexroth S20-ETH-BK and Rexroth S20-PN-BK+ (the S20-PN-BK+/S20-ETH-BK fieldbus couplers sold by Bosch Rexroth ...
4 years ago
Vulnerability Puts Bosch Smart Thermostats at Risk of Compromise - A vulnerability has been discovered in a popular Bosch smart thermostat, allowing potential attackers to send commands to the device and replace its firmware, according to Bitdefender. The vulnerability impacts the Wi-Fi microcontroller that acts as ...
1 year ago Infosecurity-magazine.com
Automotive Industry Under Ransomware Attacks: Proactive Measures - Ransomware has become a highly profitable industry, with major players like Conti Ransomware and Evil Corp leading the way. Although these entities are not publicly traded and do not report earnings to regulatory bodies like the SEC, it is estimated ...
1 year ago Cysecurity.news
Achieving Automated TISAX Compliance - In its 2024 Automotive Cybersecurity Report, Upstream found that 50% of all automotive cyber incidents in 2023 had a high or massive impact. International institutions are taking steps to help automotive organizations defend themselves against black ...
8 months ago Tripwire.com
Qilin ransomware claims attack on automotive giant Yanfeng - The Qilin ransomware group has claimed responsibility for a cyber attack on Yanfeng Automotive Interiors, one of the world's largest automotive parts suppliers. Yanfeng is a Chinese automotive parts developer and manufacturer focused on interior ...
1 year ago Bleepingcomputer.com
Integrating cybersecurity into vehicle design and manufacturing - In this Help Net Security interview, Yaron Edan, CISO at REE Automotive, discusses the cybersecurity landscape of the automotive industry, mainly focusing on electric and connected vehicles. Edan highlights the challenges of technological ...
11 months ago Helpnetsecurity.com
49 unique zero-days Uncovered in Pwn2Own Automotive - On the final day of Pwn2Own Automotive 2024 - Day 3, researchers were granted $1,323,750 in rewards for identifying 49 distinct zero-days. Particularly, the infotainment system and modem of Tesla were attacked by the Synacktiv team, and each ...
1 year ago Cybersecuritynews.com
Cyberattack Disrupts Production at Varta Battery Factories - Germany-based battery manufacturer Varta revealed on February 13 that production at five of its plants had been disrupted as a result of a cyberattack. The attack was detected on February 12 and forced the company to shut down IT systems and ...
11 months ago Securityweek.com
Tesla hackers win big at first Pwn2Own automotive hack fest The Register - Infosec in brief Trend Micro's Zero Day Initiative held its first-ever automotive-focused Pwn2Own event in Tokyo last week, and awarded over $1.3 million to the discoverers of 49 vehicle-related zero day vulnerabilities. Researchers from French ...
1 year ago Go.theregister.com
Here's Why the World is Investing So Much in Semiconductors - Hannah Mullane, a BBC correspondent, recently visited Pragmatic Semiconductor, the UK's newest computer chip facility in Durham. The large site is being turned into a sophisticated computer chip production hub. Pragmatic Semiconductor has already ...
1 year ago Cysecurity.news
The reality of hacking threats in connected car systems - The automotive industry faces new cybersecurity challenges as vehicles become more connected. All parties in the manufacturing supply chain should follow key principles for vehicle cybersecurity, such as organizational security, risk assessment and ...
1 year ago Helpnetsecurity.com
Misconfiguration and vulnerabilities biggest risks in cloud security: Report - The two biggest cloud security risks continue to be misconfigurations and vulnerabilities, which are being introduced in greater numbers through software supply chains, according to a report by Sysdig. While zero trust is a top priority, data showed ...
2 years ago Csoonline.com
Eagers Automotive halts trading in response to cyberattack - Eagers Automotive has announced it suffered a cyberattack and was forced to halt trading on the stock exchange as it evaluates the impact of the incident. Eagers Automotive is the largest operator of car dealerships in Australia and New Zealand, with ...
1 year ago Bleepingcomputer.com
Operations, Trading of Eagers Automotive Disrupted by Cyberattack - Eagers Automotive, a vehicle dealer in Australia and New Zealand, announced this week that some of its operations have been disrupted as a result of a cyberattack that forced the company to halt trading on the Australian Securities Exchange. The ...
1 year ago Securityweek.com
Biden Admin To Award $162m To Microchip Tech - US Commerce Dept to provide $162 million to Microchip Technology to increase chip production in Colorado and Oregon. The Biden Administration has announced an award of millions of dollars to Arizona-based Microchip Technology, in order to help it ...
1 year ago Silicon.co.uk
CVE-2020-6768 - A path traversal vulnerability in the Bosch Video Management System (BVMS) NoTouch deployment allows an unauthenticated remote attacker to read arbitrary files from the Central Server. This affects Bosch BVMS versions 10.0 < 10.0.0.1225, 9.0 < ...
4 years ago
CVE-2020-6767 - A path traversal vulnerability in the Bosch Video Management System (BVMS) FileTransferService allows an authenticated remote attacker to read arbitrary files from the Central Server. This affects Bosch BVMS versions 10.0 < 10.0.0.1225, 9.0 < ...
4 years ago

Latest Cyber News


Cyber Trends (last 7 days)


Trending Cyber News (last 7 days)