Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Martin Aman

Researcher fromProtectEM
#24594of 56,330
10Total CVSS
Vulnerabilities · 1
PT-2020-13141
10
2020-05-29
Swarco · Swarco Cpu Ls4000 Series · CVE-2020-12493
**Name of the Vulnerable Software and Affected Versions** SWARCO CPU LS4000 Series versions starting with G4 **Description** The issue concerns an open port used for debugging in the SWARCO CPU LS4000 Series, which grants root access to the device without access control via the network. A malicious user could exploit this to gain access to the device and disrupt operations with connected devices. Researchers from the German company ProtectEM discovered this vulnerability, which could allow an attacker to control or disable traffic lights, for example, by turning the green light on at an entire intersection simultaneously. Although there is no internet entry point, physical access to one device could provide access to the entire city's traffic light network. **Recommendations** For SWARCO CPU LS4000 Series versions starting with G4, consider disabling the debugging port as a temporary workaround until a patch is available. Restrict physical access to the devices to minimize the risk of exploitation.