Thirty-eight vulnerabilities have been discovered in Wireless Industrial Internet of Things (IIoT) devices from four different manufacturers, creating a serious attack surface for attackers targeting operational technology (OT) systems.

“Attackers can use vulnerabilities in wireless IIoT devices to gain initial access to internal OT networks,” said Otorio, an Israeli company specializing in industrial cybersecurity. “They can be used to bypass security layers and infiltrate critical infrastructure, disrupting production.”

Essentially, these vulnerabilities provide remote entry points for attacks, allowing unauthorized attackers to gain a foothold in the network and expand their influence to other nodes. Security researcher Roni Gavrilov noted that some vulnerabilities can be combined to provide remote internet access to thousands of internal OT networks.

Among the critical issues are:

ETIC Telecom Remote Access Server (RAS): CVE-2022-3703, CVE-2022-41607, and CVE-2022-40981 — complete control over vulnerable devices;

InHand Networks InRouter 302 and InRouter 615: 5 vulnerabilities leading to remote code execution, data leakage, and command injection via the Device Manager cloud platform;

Sierra Wireless AirLink Router: CVE-2022-46649 and CVE-2022-46650 — data leakage and remote code execution.

Remaining vulnerabilities are disclosed responsibly. These findings show that IIoT devices can create a “single point of failure” accessible from the internet, bypassing all security measures. Local attackers can also attack cellular gateways and industrial Wi-Fi access points, creating adversary-in-the-middle (AitM) situations with potentially dangerous consequences.

Attacks can target combined chips in electrical devices or exploit weak encryption methods. Otorio recommends disabling insecure encryption protocols, hiding Wi-Fi network names, disabling unnecessary cloud management services, and restricting physical access to equipment.

“Low exploitation complexity combined with broad potential impact makes wireless IIoT devices and their cloud platforms an attractive target for attackers seeking to infiltrate industrial environments,” the company emphasized.

In addition, Otorio published information about two serious vulnerabilities in Siemens Automation License Manager (CVE-2022-43514 and CVE-2022-43513), which in combination could lead to privilege escalation and remote code execution. Siemens fixed these issues in January 2023.