8 zero-day vulnerabilities discovered in popular industrial control system from Carrier – The Record by Recorded Future
Eight zero-day vulnerabilities affecting a popular industrial control provided by Carrier have been identified and patched, according to security researchers from Trellix who discovered the issues.
The vulnerabilities affect the LenelS2 Mercury access control panel, which is used to grant physical access to facilities and integrate with more complex building automation deployments.
Carriers LenelS2 Mercury access control panels are widely used across hundreds of companies in the healthcare, education, and transportation industries as well as federal government agencies and organizations.
Trellix said they combined both known and novel techniques that allowed them to hack the system, achieve root access to the devices operating system and pull firmware for emulation and vulnerability discovery.
Carrier associate director of product security architecture Joshua Jessurun disputed the idea that these are zero-day vulnerabilities but told The Record that his team worked with Trellix on remediating the issues and released an advisory with detailed guidelines on what users need to do to address the vulnerabilities. Some of the issues need to be mitigated while most are addressed in firmware updates.
The Cybersecurity and Infrastructure Security Agency (CISA) released its own advisory on the issues which are tagged as CVE-2022-31479, CVE-2022-31480, CVE-2022-31481, CVE-2022-31482, CVE-2022-31483, CVE-2022-31484, CVE-2022-31485, CVE-2022-31486 with most carrying CVSS scores above 7.5.
CISA explained that exploitation of the bugs would give an attacker access to the device, allowing monitoring of all communications sent to and from the device, modification of onboard relays, changing of configuration files, device instability, and a denial-of-service condition.
Trellix security researchers Steve Povolny and Sam Quinn said they anticipated a strong potential for finding vulnerabilities, knowing that the access controller was running a Linux Operating System and root access to the board could be achieved by leveraging classic hardware hacking techniques.
While we believed flaws could be found, we did not expect to find common, legacy software vulnerabilities in a relatively recent technology. Furthermore, this product has been approved for U.S. Federal Government use following rigorous security vulnerability and interoperability testing, the two explained, noting that they took their findings to CISA after discovery.
Using the manufacturers built-in ports we were able to manipulate on-board components and interact with the device. Through reverse engineering and live debugging, we discovered six unauthenticated and two authenticated vulnerabilities exploitable remotely over the network.
They managed to bypass security measures by utilizing hardware hacking techniques to force the system into desired states.
The two explained that by chaining just two of the vulnerabilities together, they were able to exploit the access control board and gain root level privileges on the device remotely.
With this level of access, we created a program that would run alongside of the legitimate software and control the doors. This allowed us to unlock any door and subvert any system monitoring, they said.
Most significantly, the vulnerabilities uncovered allowed us to demonstrate the ability to remotely unlock and lock doors, subvert alarms and undermine logging and notification systems.
They added that customers using HID Global Mercury boards should contact their Mercury OEM partner for access to security patches prior to weaponization by malicious threat actors, which could lead to both digital or physical breaches of sensitive information and protected locations.
The two noted that the tools were added to the Government Service Administration (GSA) Approved Product List (APL) and were approved for federal government use, giving the impression that the product was highly vetted.
It is crucial to independently evaluate the certifications of any product prior to adding it into an IT or OT environment, Povolny and Quinn said.
Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
See the original post here:
8 zero-day vulnerabilities discovered in popular industrial control system from Carrier - The Record by Recorded Future
- Opinion | Crypto and Trump Corrupted America - The New York Times - October 26th, 2025 [October 26th, 2025]
- After internal struggle, Colorados Libertarians look to pivot. It could impact Congress. - The Denver Post - October 26th, 2025 [October 26th, 2025]
- Argentina goes to polls amid economic crisis and Trump interference - The Guardian - October 26th, 2025 [October 26th, 2025]
- Five things to know about Argentina's pivotal midterm election - Purdue Exponent - October 26th, 2025 [October 26th, 2025]
- Milei promised to drain Argentinas swamp. Now hes sinki... - The Observer - October 26th, 2025 [October 26th, 2025]
- After Tunisian shipwreck kills 40, archbishop urges world to tackle migration crisis - Catholic News Agency - October 26th, 2025 [October 26th, 2025]
- Migrant prison farce proves the system is out of control - The Telegraph - October 26th, 2025 [October 26th, 2025]
- Labour blasted as 'too weak' to deport small boat migrants while pressure mounts on Keir Starmer to adopt Rwanda-style plan - GB News - October 26th, 2025 [October 26th, 2025]
- France backing away from pledge to intercept migrant boats, sources tell BBC - BBC - October 26th, 2025 [October 26th, 2025]
- Migrants abandon children on Spanish holidays so they can claim asylum - The Telegraph - October 26th, 2025 [October 26th, 2025]
- Ireland is making a dangerous mistake on immigration - The Telegraph - October 26th, 2025 [October 26th, 2025]
- Migrant sent back to France in one in, one out deal returns to UK - The Independent - October 26th, 2025 [October 26th, 2025]
- Syrian migrant with 'deep voice and receding grey hair' is ruled to be a child - GB News - October 26th, 2025 [October 26th, 2025]
- Stop lecturing migrant hotel protesters, Dublin is more proof of this total betrayal - Adam Brooks - GB News - October 26th, 2025 [October 26th, 2025]
- 'It's a FARCE!' Tom Harwood up in arms while Labour 'takes the mickey' with 'one in, one out' scheme - GB News - October 26th, 2025 [October 26th, 2025]
- Secret report reveals Home Office culture of defeatism on migration - The Telegraph - October 26th, 2025 [October 26th, 2025]
- Lammy: Catching migrant shows one in, one out is working - The Telegraph - October 26th, 2025 [October 26th, 2025]
- Migrant guilty of murdering woman with screwdriver - The Telegraph - October 26th, 2025 [October 26th, 2025]
- If UK controlled its own borders, killer illegal migrant would never have been here - Rakib Ehsan - GB News - October 26th, 2025 [October 26th, 2025]
- Mark White's Migration Monitor: The small boats farce continues - and the next act looks even darker - GB News - October 26th, 2025 [October 26th, 2025]
- Epping migrant STILL on the loose as David Lammy admits Ethiopian sex offender is 'at large in London' - GB News - October 26th, 2025 [October 26th, 2025]
- Cal State Invited Tech Companies to Remake Learning With A.I. - The New York Times - October 26th, 2025 [October 26th, 2025]
- Artificial intelligence (AI) - The Guardian - October 26th, 2025 [October 26th, 2025]
- Banking and Finance Symposium to Address AI, Technology Issues - University of Mississippi | Ole Miss - October 26th, 2025 [October 26th, 2025]
- AI Is Even Putting Animal Actors Out of Work - Futurism - October 26th, 2025 [October 26th, 2025]
- Impacts of artificial intelligence (AI) in teaching and learning of built environment students in a developing country - Taylor & Francis Online - October 26th, 2025 [October 26th, 2025]
- 3 Top Artificial Intelligence (AI) Stocks Ready for a Bull Run - The Motley Fool - October 26th, 2025 [October 26th, 2025]
- Israel playing catch-up in AI after two years of war - JNS.org - October 26th, 2025 [October 26th, 2025]
- Why Analysts See Alibabas Growth Story Changing With Cloud and AI Driving New Optimism - Yahoo Finance - October 26th, 2025 [October 26th, 2025]
- The AI Bubble Is Poised to Burst, Yet the Next One Is in the Works - 36Kr - October 26th, 2025 [October 26th, 2025]
- Beyond Chips: AI Infrastructure Spending Is Projected to Hit $490 Billion -- Who Benefits Most? - Yahoo Finance - October 26th, 2025 [October 26th, 2025]
- Jordan to lead MSUs AI efforts in new role, Willard named interim VP for research, economic development - Mississippi State University - October 26th, 2025 [October 26th, 2025]
- Artificial Intelligence and Medical Translation: An Editorial on the Ethical Considerations for Emerging Technologies in Dermatology - Cureus - October 26th, 2025 [October 26th, 2025]
- Scientists spent years teaching a robot to play sports. It's still terrible - BBC Science Focus Magazine - October 26th, 2025 [October 26th, 2025]
- There is no life: Kupiansks slow demise reflects the fate of cities on Ukraines frontline - The Guardian - October 26th, 2025 [October 26th, 2025]
- Ukraines Coalition of the Willing Has the Wind at Its Back - The New York Times - October 26th, 2025 [October 26th, 2025]
- Russia arrests Ukrainian biologist for backing curbs on Antarctic krill fishing - The Guardian - October 26th, 2025 [October 26th, 2025]
- Six metres below ground: inside the secret hospital treating Ukrainian soldiers injured by Russian drones - The Guardian - October 26th, 2025 [October 26th, 2025]
- Jet-powered bombs and planes-turned-missiles: Ukrainian and Russian militaries improvise and adapt in a battle of wits - CNN - October 26th, 2025 [October 26th, 2025]
- 3 Years Ago It Was a Casting Agency. Now It Has $1 Billion in Drone Contracts. - The New York Times - October 26th, 2025 [October 26th, 2025]
- Russia targets Kyiv with drones, killing 3 and wounding 29 - ABC News - Breaking News, Latest News and Videos - October 26th, 2025 [October 26th, 2025]
- More than Tomahawks: what Ukraines soldiers say they actually need - The Kyiv Independent - October 26th, 2025 [October 26th, 2025]
- Ukraines ingenuity alone will not be enough to win the war - The Independent - October 26th, 2025 [October 26th, 2025]
- After War Turned Their Fields Into Frontlines, Ukraines Farmers Return to Reclaim Them - UNITED24 Media - October 26th, 2025 [October 26th, 2025]
- Turkey urges US to act after accusing Israel of breaching Gaza ceasefire - Sky News - October 26th, 2025 [October 26th, 2025]
- President Erdoan visits Oman, his last stopover in the Gulf | Daily Sabah - Daily Sabah - October 26th, 2025 [October 26th, 2025]
- Erdoan to meet with DEM Party delegation on terror-free process | Daily Sabah - Daily Sabah - October 26th, 2025 [October 26th, 2025]
- Erdoan renews call for UN reform over Gaza in 80th anniversary message | Daily Sabah - Daily Sabah - October 26th, 2025 [October 26th, 2025]
- Foreign media: Russia reiterated its stance on full control of Donbas to the US last weekend - Bitget - October 23rd, 2025 [October 23rd, 2025]
- Health Ministry and PAHO Host Media Session on Upcoming National Tobacco Control Bill - Love FM Belize - October 19th, 2025 [October 19th, 2025]
- Ask Lucas: My teens social media obsession is out of control - Cleveland.com - October 17th, 2025 [October 17th, 2025]
- Molding the Message - China Media Project - October 17th, 2025 [October 17th, 2025]
- From clicks to curation: How publishers can reclaim control of the media ecosystem - Digiday - October 15th, 2025 [October 15th, 2025]
- Orbans Propaganda State in Hungary Is Starting to Show Cracks - The New York Times - October 15th, 2025 [October 15th, 2025]
- How Chioma Ikeh is helping small businesses take back control of their social media - Businessday NG - October 13th, 2025 [October 13th, 2025]
- Germany will not support 'Chat Control' message scanning in the EU - The Record from Recorded Future News - October 11th, 2025 [October 11th, 2025]
- Media: IDF will control 53% of Gaza in the first phase of the agreement - Baku.ws - October 11th, 2025 [October 11th, 2025]
- Rob Reiner Says U.S. Will Become an Autocracy if Trump Is Allowed to Control the Media and Commandeer the Election: We Have a Year to Stop Him -... - October 7th, 2025 [October 7th, 2025]
- Rob Reiner Warns Trump Wants "Control Of Media" To Steal 2026 Election - Deadline - October 7th, 2025 [October 7th, 2025]
- Move over Murdochs, the Ellisons are the new family dynasty shaking up US media - BBC - September 30th, 2025 [September 30th, 2025]
- How Trumps TikTok Deal Could Change the Future of US Media - TODAY.com - September 30th, 2025 [September 30th, 2025]
- Meghan Markles Media Battles: Control, Conflicts, and the Struggle for Credibility - vocal.media - September 28th, 2025 [September 28th, 2025]
- Trump announces deal to put TikTok under control of US investors - ABC News - Breaking News, Latest News and Videos - September 28th, 2025 [September 28th, 2025]
- President Tebbounes Media Exchange: Inflation Control, Electoral Reform, and a Drive Toward Modernization - - September 28th, 2025 [September 28th, 2025]
- Raptors GM Bobby Webster meets with the media ahead of first season with full team control - Toronto Star - September 28th, 2025 [September 28th, 2025]
- Murdochs TikTok? Trump offers allies another lever of media control - The Guardian - September 25th, 2025 [September 25th, 2025]
- Even legacy media admit left-wing violence is out of control - The Heartlander - September 25th, 2025 [September 25th, 2025]
- Capture the Media, Control the Culture? - The American Prospect - September 23rd, 2025 [September 23rd, 2025]
- Whats actually in the Media Control Act? - Maldives Independent - September 23rd, 2025 [September 23rd, 2025]
- Power Play: Murdochs, Ellison, and Dell Join Forces for TikTok Bid - International Business Times UK - September 23rd, 2025 [September 23rd, 2025]
- Jimmy Kimmel and the MAGA strong-arming of American media - Media Matters for America - September 19th, 2025 [September 19th, 2025]
- Abbreviated Pundit Roundup: Controlling the media controls the message - Daily Kos - September 19th, 2025 [September 19th, 2025]
- The 31-day sprint: a timeline of the "media control law" - Maldives Independent - September 19th, 2025 [September 19th, 2025]
- Trump Admin Says Framework Reached for U.S. Owners to Take Control of TikTok - Gizmodo - September 17th, 2025 [September 17th, 2025]
- "We have a prime ministerial republic"/ Media: Changes to the Constitution, control of the Assembly and the opposition - cna.al - September 17th, 2025 [September 17th, 2025]
- Rupert Murdochs family reaches deal on who will control media empire after his death - Toronto Sun - September 15th, 2025 [September 15th, 2025]
- Erdogan tightens his control over the media - Atalayar - September 13th, 2025 [September 13th, 2025]
- Social Media May Be Fueling Negative Reactions To Birth Control Pills, Study Finds - indica News - September 13th, 2025 [September 13th, 2025]
- Usham backs Media Bill as a tool for lawful information dissemination - Edition.mv - September 13th, 2025 [September 13th, 2025]
- Big Data Leak in Pakistan: Where Is the Government Control? - The Media Line - September 13th, 2025 [September 13th, 2025]