Attackers could use vulnerabilities in Bosch Rexroth nutrunners to disrupt automotive production

Covertly tampering with tightening programs also carries potential health and safety risks: As the recent in-flight emergency involving a Boeing 737 Max 9 plane operated by Alaska Airlines has shown, inadequately tightened bolts can lead to extremely dangerous situations.
The Bosch Rexroth NXA015S-36V-B nutrunner is powered by NEXO-OS, a Linux-based operating system that allows users to generate and configure tightening programs and analyse and diagnose tightening cases via the management web application.
It has a built-in display and connects to wireless networks via an embedded Wi-Fi module.
The device supports a number of communication protocols that are used to integrate it with SCADA systems, PLCs, or other production devices.
The management web app is exposed on the internet by default, they say.
They also told us that most of the vulnerabilities are remotely exploitable - an attacker does not need to be on the same subnet to compromise vulnerable devices.
Bosch Rexroth nutrunners are widely used in automotive production lines.
Determined threat actors could leverage the vulnerabilities to stop the production or affect the quality of manufactured products, leading to delays, product recalls, reputational damage, accidents, etc.
There has been no mention of these vulnerabilities being exploited by threat actors, but once technical details and updated firmware are made available, there's a chance some enterprising, skilled attackers might find it profitable to do the same research and use what they discovered.
As confirmed by Bosch Rexroth, the vulnerabilities affect Nexo cordless nutrunners from the NXA, NXP and NXV series, as well as a number of other similar devices.
For now, Nozomi refrained from publishing technical details about the vulnerabilities.
Bosch Rexroth says that roughly half of the vulnerabilities will be fixed in the updated firmware version that will be released later this month, and has provided mitigation advice for CVE-2023-48257.
The researchers advise restricting the network reachability of the device as much as possible and reviewing all accounts that have login access to the devices and delete unnecessary ones.


This Cyber News was published on www.helpnetsecurity.com. Publication date: Tue, 09 Jan 2024 16:13:45 +0000


Cyber News related to Attackers could use vulnerabilities in Bosch Rexroth nutrunners to disrupt automotive production

Attackers could use vulnerabilities in Bosch Rexroth nutrunners to disrupt automotive production - Covertly tampering with tightening programs also carries potential health and safety risks: As the recent in-flight emergency involving a Boeing 737 Max 9 plane operated by Alaska Airlines has shown, inadequately tightened bolts can lead to extremely ...
2 years ago Helpnetsecurity.com CVE-2023-48257
Bosch Nutrunner Vulnerabilities Could Aid Hacker Attacks Against Automotive Production Lines - Vulnerabilities found in Bosch Rexroth nutrunners used in the automotive industry could be exploited by hackers seeking direct financial gain or threat actors looking to cause disruption or reputational damage to the targeted organization, according ...
2 years ago Securityweek.com
Hackers can infect network-connected wrenches to install ransomware - Researchers have unearthed nearly two dozen vulnerabilities that could allow hackers to sabotage or disable a popular line of network-connected wrenches that factories around the world use to assemble sensitive instruments and devices. The ...
2 years ago Packetstormsecurity.com
Network connected wrenches are now vulnerable to Ransomware attacks - Network-connected wrenches used globally are now at risk of exposure to ransomware hackers, who can manipulate their functionalities and gain unauthorized access to the connected networks, according to experts. Research conducted by Nozomi reveals ...
2 years ago Cybersecurity-insiders.com
Top Cyber Threats Automotive Dealerships Should Look Out For - Automotive dealerships are attractive targets for hackers. A combination of storing lots of sensitive customer data, handling large financial transactions, increased dependence on digital technologies and a perception of immature cybersecurity all ...
1 year ago Securityboulevard.com
VicOne Partners With 42Crunch to Deliver Comprehensive Security Across SDV and Connected-Vehicle Ecosystem - PRESS RELEASE. DALLAS and TOKYO, May 29, 2024- VicOne, an automotive cybersecurity solutions leader, today announced a partnership with 42Crunch to enhance the security of application programming interfaces for the software-defined vehicle and ...
1 year ago Darkreading.com
CVE-2018-16994 - An issue was discovered on PHOENIX CONTACT AXL F BK PN <1.0.4, AXL F BK ETH < 1.12, and AXL F BK ETH XC < 1.11 devices and Bosch Rexroth S20-ETH-BK and Rexroth S20-PN-BK+ (the S20-PN-BK+/S20-ETH-BK fieldbus couplers sold by Bosch Rexroth ...
5 years ago
OT Cybersecurity for Automotive Industry - OT systems are ubiquitous across all critical infrastructure industries, such as Oil and Gas, Automotive, Energy, Water Utilities, and Transportation. OT infrastructure is very vital to any nation's security to ensure the delivery of essential ...
2 years ago Feeds.dzone.com
Pwn2Own Automotive: $1.3M for 49 zero-days, Tesla hacked twice - The first edition of Pwn2Own Automotive has ended with competitors earning $1,323,750 for hacking Tesla twice and demoing 49 zero-day bugs in multiple electric car systems between January 24 and January 26. Throughout the contest organized by Trend ...
2 years ago Bleepingcomputer.com
Vulnerability Puts Bosch Smart Thermostats at Risk of Compromise - A vulnerability has been discovered in a popular Bosch smart thermostat, allowing potential attackers to send commands to the device and replace its firmware, according to Bitdefender. The vulnerability impacts the Wi-Fi microcontroller that acts as ...
2 years ago Infosecurity-magazine.com
Automotive Industry Under Ransomware Attacks: Proactive Measures - Ransomware has become a highly profitable industry, with major players like Conti Ransomware and Evil Corp leading the way. Although these entities are not publicly traded and do not report earnings to regulatory bodies like the SEC, it is estimated ...
2 years ago Cysecurity.news
Production Line Cameras Vulnerabilities Let Attackers Stop The Recordings - IB-MCT001 camera system known as “CHOCO TEI WATCHER mini,” enable attackers to bypass authentication mechanisms and gain unauthorized access to devices designed to record production line stoppages for analysis and troubleshooting. ...
10 months ago Cybersecuritynews.com CVE-2025-26689
Jaguar Land Rover says cyberattack severely disrupted production - Jaguar Land Rover, a leading automotive manufacturer, recently disclosed a significant cyberattack that severely disrupted its production operations. The attack impacted the company's manufacturing plants, causing delays and operational challenges. ...
5 months ago Bleepingcomputer.com
Achieving Automated TISAX Compliance - In its 2024 Automotive Cybersecurity Report, Upstream found that 50% of all automotive cyber incidents in 2023 had a high or massive impact. International institutions are taking steps to help automotive organizations defend themselves against black ...
1 year ago Tripwire.com
Qilin ransomware claims attack on automotive giant Yanfeng - The Qilin ransomware group has claimed responsibility for a cyber attack on Yanfeng Automotive Interiors, one of the world's largest automotive parts suppliers. Yanfeng is a Chinese automotive parts developer and manufacturer focused on interior ...
2 years ago Bleepingcomputer.com Qilin Black Basta
Britain's JLR hit by cyber incident that disrupts production, sales - Jaguar Land Rover (JLR), a leading British automotive manufacturer, recently suffered a significant cyber incident that disrupted its production and sales operations. This cyberattack has highlighted the increasing vulnerability of the automotive ...
5 months ago Reuters.com
Integrating cybersecurity into vehicle design and manufacturing - In this Help Net Security interview, Yaron Edan, CISO at REE Automotive, discusses the cybersecurity landscape of the automotive industry, mainly focusing on electric and connected vehicles. Edan highlights the challenges of technological ...
2 years ago Helpnetsecurity.com
49 unique zero-days Uncovered in Pwn2Own Automotive - On the final day of Pwn2Own Automotive 2024 - Day 3, researchers were granted $1,323,750 in rewards for identifying 49 distinct zero-days. Particularly, the infotainment system and modem of Tesla were attacked by the Synacktiv team, and each ...
2 years ago Cybersecuritynews.com
Cyber attack causes sales drop at Jaguar Land Rover - Jaguar Land Rover (JLR), the renowned British automotive manufacturer, recently experienced a significant disruption in its operations due to a cyber attack. This incident led to a notable drop in vehicle sales, highlighting the growing impact of ...
4 months ago Infosecurity-magazine.com
Cyberattack Disrupts Production at Varta Battery Factories - Germany-based battery manufacturer Varta revealed on February 13 that production at five of its plants had been disrupted as a result of a cyberattack. The attack was detected on February 12 and forced the company to shut down IT systems and ...
1 year ago Securityweek.com
Jaguar Land Rover faces another week of shutdown after cyberattack - Jaguar Land Rover (JLR), the renowned British automotive manufacturer, is grappling with the aftermath of a significant cyberattack that has forced the company to extend its production shutdown by another week. This incident highlights the growing ...
4 months ago Therecord.media
CVE-2020-6768 - A path traversal vulnerability in the Bosch Video Management System (BVMS) NoTouch deployment allows an unauthenticated remote attacker to read arbitrary files from the Central Server. This affects Bosch BVMS versions 10.0 < 10.0.0.1225, 9.0 < ...
6 years ago
CVE-2020-6767 - A path traversal vulnerability in the Bosch Video Management System (BVMS) FileTransferService allows an authenticated remote attacker to read arbitrary files from the Central Server. This affects Bosch BVMS versions 10.0 < 10.0.0.1225, 9.0 < ...
5 years ago
CVE-2020-6785 - Loading a DLL through an Uncontrolled Search Path Element in Bosch BVMS and BVMS Viewer in versions 10.1.0, 10.0.1, 10.0.0 and 9.0.0 and older potentially allows an attacker to execute arbitrary code on a victim's system. This affects both the ...
4 years ago