FURUNO FA-50 Class B AIS Transponder

Summary

CISA has issued an alert regarding vulnerabilities in the FURUNO FA-50 Class B AIS Transponder. Successful exploitation of these flaws, including hard-coded credentials and missing authentication, could allow an attacker to alter device settings. While the product is End-of-Life, CISA recommends network isolation and physical security measures for deployed units.

IFF Assessment

FOE

The identified vulnerabilities, including hard-coded credentials and missing authentication, allow attackers to alter device settings, posing a significant risk to critical infrastructure.

Severity

9.1 Critical

Defender Context

This alert highlights the risks associated with legacy Operational Technology (OT) devices that are no longer supported with patches. Defenders should focus on network segmentation and access controls for similar systems, especially those in critical infrastructure, to mitigate the impact of unpatched vulnerabilities.

Read Full Story →