8 zero-day vulnerabilities discovered in popular industrial control system from Carrier – The Record by Recorded Future
Eight zero-day vulnerabilities affecting a popular industrial control provided by Carrier have been identified and patched, according to security researchers from Trellix who discovered the issues.
The vulnerabilities affect the LenelS2 Mercury access control panel, which is used to grant physical access to facilities and integrate with more complex building automation deployments.
Carriers LenelS2 Mercury access control panels are widely used across hundreds of companies in the healthcare, education, and transportation industries as well as federal government agencies and organizations.
Trellix said they combined both known and novel techniques that allowed them to hack the system, achieve root access to the devices operating system and pull firmware for emulation and vulnerability discovery.
Carrier associate director of product security architecture Joshua Jessurun disputed the idea that these are zero-day vulnerabilities but told The Record that his team worked with Trellix on remediating the issues and released an advisory with detailed guidelines on what users need to do to address the vulnerabilities. Some of the issues need to be mitigated while most are addressed in firmware updates.
The Cybersecurity and Infrastructure Security Agency (CISA) released its own advisory on the issues which are tagged as CVE-2022-31479, CVE-2022-31480, CVE-2022-31481, CVE-2022-31482, CVE-2022-31483, CVE-2022-31484, CVE-2022-31485, CVE-2022-31486 with most carrying CVSS scores above 7.5.
CISA explained that exploitation of the bugs would give an attacker access to the device, allowing monitoring of all communications sent to and from the device, modification of onboard relays, changing of configuration files, device instability, and a denial-of-service condition.
Trellix security researchers Steve Povolny and Sam Quinn said they anticipated a strong potential for finding vulnerabilities, knowing that the access controller was running a Linux Operating System and root access to the board could be achieved by leveraging classic hardware hacking techniques.
While we believed flaws could be found, we did not expect to find common, legacy software vulnerabilities in a relatively recent technology. Furthermore, this product has been approved for U.S. Federal Government use following rigorous security vulnerability and interoperability testing, the two explained, noting that they took their findings to CISA after discovery.
Using the manufacturers built-in ports we were able to manipulate on-board components and interact with the device. Through reverse engineering and live debugging, we discovered six unauthenticated and two authenticated vulnerabilities exploitable remotely over the network.
They managed to bypass security measures by utilizing hardware hacking techniques to force the system into desired states.
The two explained that by chaining just two of the vulnerabilities together, they were able to exploit the access control board and gain root level privileges on the device remotely.
With this level of access, we created a program that would run alongside of the legitimate software and control the doors. This allowed us to unlock any door and subvert any system monitoring, they said.
Most significantly, the vulnerabilities uncovered allowed us to demonstrate the ability to remotely unlock and lock doors, subvert alarms and undermine logging and notification systems.
They added that customers using HID Global Mercury boards should contact their Mercury OEM partner for access to security patches prior to weaponization by malicious threat actors, which could lead to both digital or physical breaches of sensitive information and protected locations.
The two noted that the tools were added to the Government Service Administration (GSA) Approved Product List (APL) and were approved for federal government use, giving the impression that the product was highly vetted.
It is crucial to independently evaluate the certifications of any product prior to adding it into an IT or OT environment, Povolny and Quinn said.
Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
See the original post here:
8 zero-day vulnerabilities discovered in popular industrial control system from Carrier - The Record by Recorded Future
- Jimmy Kimmel and the MAGA strong-arming of American media - Media Matters for America - September 19th, 2025 [September 19th, 2025]
- Abbreviated Pundit Roundup: Controlling the media controls the message - Daily Kos - September 19th, 2025 [September 19th, 2025]
- The 31-day sprint: a timeline of the "media control law" - Maldives Independent - September 19th, 2025 [September 19th, 2025]
- Trump Admin Says Framework Reached for U.S. Owners to Take Control of TikTok - Gizmodo - September 17th, 2025 [September 17th, 2025]
- "We have a prime ministerial republic"/ Media: Changes to the Constitution, control of the Assembly and the opposition - cna.al - September 17th, 2025 [September 17th, 2025]
- Rupert Murdochs family reaches deal on who will control media empire after his death - Toronto Sun - September 15th, 2025 [September 15th, 2025]
- Erdogan tightens his control over the media - Atalayar - September 13th, 2025 [September 13th, 2025]
- Social Media May Be Fueling Negative Reactions To Birth Control Pills, Study Finds - indica News - September 13th, 2025 [September 13th, 2025]
- Usham backs Media Bill as a tool for lawful information dissemination - Edition.mv - September 13th, 2025 [September 13th, 2025]
- Big Data Leak in Pakistan: Where Is the Government Control? - The Media Line - September 13th, 2025 [September 13th, 2025]
- Tim Dillon Was Far From Funny in Joke About Jewish Control of the Media - Algemeiner.com - September 11th, 2025 [September 11th, 2025]
- Inside the Deal Ending the Murdoch Succession Fight - The New York Times - September 11th, 2025 [September 11th, 2025]
- ChamSys Acquires Arkaos MediaMaster, GrandVJ And KlingNet To Deliver Unified Lighting, Pixel Mapping And Media Control Solution - Live Design Online - September 11th, 2025 [September 11th, 2025]
- Lachlan finally has control of Murdoch empire but deal is a win for sibling rivals - The Guardian - September 11th, 2025 [September 11th, 2025]
- Lachlan Murdoch is now in control of News Corp and its Australian newspapers are safe for now - The Guardian - September 11th, 2025 [September 11th, 2025]
- Sri Lanka to expand scope of controversial 1970s media control law - EconomyNext - September 11th, 2025 [September 11th, 2025]
- Journalists stage protest near Majlis after being ousted from committee reviewing media control bill - raajje.mv - September 11th, 2025 [September 11th, 2025]
- Murdoch heirs settle dispute over control of the right-wing mogul's media empire - France 24 - September 9th, 2025 [September 9th, 2025]
- ChamSys acquires Arkaos MediaMaster to deliver unified lighting, pixel mapping and media control solution - Cinematography World - September 9th, 2025 [September 9th, 2025]
- Rupert Murdochs family reaches deal on who will control media empire after his death - AP News - September 9th, 2025 [September 9th, 2025]
- The Murdoch Succession Fight Is Over. So What Does Lachlan Control? - The New York Times - September 9th, 2025 [September 9th, 2025]
- Rupert Murdochs family reaches deal on who will control media empire after his death - Inquirer.com - September 9th, 2025 [September 9th, 2025]
- The real-life 'Succession' fight for control of the Murdoch media empire has come to an end - MSN - September 9th, 2025 [September 9th, 2025]
- Rupert Murdochs family reaches deal on who will control media empire after his death - WXXV News 25 - September 9th, 2025 [September 9th, 2025]
- The real-life 'Succession' fight for control of the Murdoch media empire has come to an end - Business Insider - September 9th, 2025 [September 9th, 2025]
- ChamSys Acquires Arkaos MediaMaster, GrandVJ and KlingNet to Deliver Unified Lighting, Pixel Mapping and Media Control Solution - etnow.com - September 9th, 2025 [September 9th, 2025]
- Rupert Murdochs family reach deal on who will control media empire after death - STV News - September 9th, 2025 [September 9th, 2025]
- Murdoch family resolves succession dispute with Lachlan remaining in control of media empire - 9News - September 9th, 2025 [September 9th, 2025]
- Outrage over 'ghost projects' for flood control lands on Filipino 'nepo babies' flaunting wealth on social media - Mothership - September 6th, 2025 [September 6th, 2025]
- Serbia: Media freedom groups warn against attempt to seize political control of last remaining independent TV stations N1 and Nova - ipi.media - September 5th, 2025 [September 5th, 2025]
- Sean Plunket now stands alone on his Platform - The Spinoff - September 5th, 2025 [September 5th, 2025]
- Maldives: Government faces increasing backlash on media control bill / FIP - International Federation of Journalists - IFJ - August 29th, 2025 [August 29th, 2025]
- Journalists sound alarm over bill to shackle free media - Raajje.mv - August 29th, 2025 [August 29th, 2025]
- Pres. denies media control: Not something I'm interested in, nor have I ever done - Raajje.mv - August 27th, 2025 [August 27th, 2025]
- Media control bill won't silence the people, even if passed: Mariya - Raajje.mv - August 27th, 2025 [August 27th, 2025]
- Media control bill placed on agenda for parliaments extraordinary sitting tomorrow - Edition.mv - August 27th, 2025 [August 27th, 2025]
- National Day, freedom bounds and media control - Maldives Independent - August 26th, 2025 [August 26th, 2025]
- How to manage social media notifications and regain control - Kurt the CyberGuy - August 22nd, 2025 [August 22nd, 2025]
- Orban and Fidesz: fifteen years of media control and an anti-Ukrainian strategy News from Fakti.bg - World - fakti.bg - August 22nd, 2025 [August 22nd, 2025]
- Taylor Swift Found a New Way to Control Her Narrative: Podcasts - The New York Times - August 16th, 2025 [August 16th, 2025]
- Influencers criticize birth control and push 'natural' methods. Here's what to know - NPR - August 12th, 2025 [August 12th, 2025]
- $250K Monster Month promotion withdrawn after dispute over social media control - Frequency News - August 7th, 2025 [August 7th, 2025]
- Analysis: Information is power, and Trump wants more control over it - CNN - August 7th, 2025 [August 7th, 2025]
- How to reassign keyboard keys in Windows 11 - theregister.com - July 24th, 2025 [July 24th, 2025]
- Google Maps media control feature missing on Android - VnExpress International - July 24th, 2025 [July 24th, 2025]
- Bitfocus Buttons Enterprise Edition Unveiled at IBC2025 with Advanced Features - Digital Studio India - July 10th, 2025 [July 10th, 2025]
- Assembly Launches 'Assembly Control' to Elevate Brand Safety, Suitability, and Campaign Performance in Programmatic Media - Yahoo Finance - July 10th, 2025 [July 10th, 2025]
- Bluesky Gives Users More Control Over their Notifications - Social Media Today - July 8th, 2025 [July 8th, 2025]
- Spin Control: Media struggles after Trump swears with cameras rolling - The Spokesman-Review - July 8th, 2025 [July 8th, 2025]
- Beyond banks and brokers: All about decentralized finance (DeFi) - Britannica - July 8th, 2025 [July 8th, 2025]
- The Future of Crypto Payroll Security: Bitchat and Decentralized Messaging - OneSafe - July 8th, 2025 [July 8th, 2025]
- Paradigm leads $11.5 million funding round in Kuru Labs, a decentralized exchange blending CLOBs and AMMs - The Block - July 8th, 2025 [July 8th, 2025]
- Decentralized Payroll: The Future of Work - OneSafe - July 8th, 2025 [July 8th, 2025]
- Jack Dorsey tests Bitchat decentralized messaging without internet - Cointelegraph - July 8th, 2025 [July 8th, 2025]
- CrossFis Haley Cromer on Bridging Traditional Finance and Web3 for a Decentralized Future - BlockTelegraph - July 8th, 2025 [July 8th, 2025]
- India's Crypto Tax: Navigating New Norms with Decentralized Solutions - OneSafe - July 8th, 2025 [July 8th, 2025]
- Turkey Tightens Its Grip on Crypto: What It Means for Decentralized Exchanges - OneSafe - July 8th, 2025 [July 8th, 2025]
- Spheron and AIxBlock Unite to Democratize Decentralized AI - CoinTrust - July 8th, 2025 [July 8th, 2025]
- The Role of Web3 in Shaping NFT Marketplace Opportunities - Vocal - July 8th, 2025 [July 8th, 2025]
- BNB Adds Centralized Features, But Lightchain AI Adds Decentralized Incentives That Drive New Demand - Modern Diplomacy - July 8th, 2025 [July 8th, 2025]
- Taiko and Nethermind Partner to Enhance Ethereum Rollup Infrastructure - Blockchain News - July 8th, 2025 [July 8th, 2025]
- The Rise of Decentralized Stablecoins: Can They Replace Centralized Counterparts in 2025? - Vocal - July 8th, 2025 [July 8th, 2025]
- On MSNBC's Deadline: White House, Angelo Carusone highlights how Trump is losing control of narrative dominance due to "fractures" in... - July 8th, 2025 [July 8th, 2025]
- Assembly Control Transforms Programmatic Advertising with Revolutionary Brand Safety Platform - Stock Titan - July 4th, 2025 [July 4th, 2025]
- Now, United States Border Control Scrutinizes Social Media: For The Travelers To The United States from France, Spain, and Beyond, Here Is All You... - July 4th, 2025 [July 4th, 2025]
- Assembly Launches 'Assembly Control' to Elevate Brand Safety, Suitability, and Campaign Performance in Programmatic Media - Macau Business - July 4th, 2025 [July 4th, 2025]
- Breaking the Studio Social Media Blackout: Caylee Cowan Takes Creative Control and Financial Freedom with Fanfix - Silicon UK - June 28th, 2025 [June 28th, 2025]
- Aleema's control over PTI social media makes her all-powerful within Imran-founded party - Geo News - June 26th, 2025 [June 26th, 2025]
- Tuenti social media co-founder takes control of Puerto Bans bullring with plans to demolish it - Sur in English - June 20th, 2025 [June 20th, 2025]
- InMobi Advertising Unveils Mobile-First Curation Platform Empowering All Media Buyers with Precision, Transparency, and Control - Passionate In... - June 20th, 2025 [June 20th, 2025]
- Trump takes control of media cycle with travel ban, Harvard visa restriction, Biden investigation policy spree - Washington Examiner - June 7th, 2025 [June 7th, 2025]
- Pushed Out and Unfiltered: Joy Reid, Misogynoir, Media Control,and the Fear of a Black Womans Voice - Daily Kos - June 7th, 2025 [June 7th, 2025]
- GitGuardian urges shift to machine identity control - SC Media - May 11th, 2025 [May 11th, 2025]
- Opinion: Its time to lose control - Main Street Media of Tennessee - May 8th, 2025 [May 8th, 2025]
- Opinion | How a Professional Bully Is Winning Control of the Media - Common Dreams - April 30th, 2025 [April 30th, 2025]
- Social Media, Social Control, and the Politics of Public Shaming - - Political Science Now - April 21st, 2025 [April 21st, 2025]
- Tariff saga creates a meme war on social media, making it difficult for brands to 'control the message' - Digiday - April 21st, 2025 [April 21st, 2025]
- Conservatives are limiting media access to Poilievre. Is it helping or hurting him? - CBC - April 12th, 2025 [April 12th, 2025]
- Robert W. McChesney, who warned of corporate media control, dies at 72 - Editor and Publisher - April 10th, 2025 [April 10th, 2025]
- FCC Commissioner Anna Gomez Sounds Alarm Over Trump Administrations Absolute Pattern of Censorship and Control - Variety - April 10th, 2025 [April 10th, 2025]