Wärtsilä FOS-Onboard

Summary

Wärtsilä FOS-Onboard versions 5.07.0923.01 are affected by vulnerabilities, including a hardcoded cryptographic server key. Successful exploitation could allow an attacker to deliver unauthorized updates, execute code, or extract credentials, leading to impersonation. Wärtsilä recommends obtaining and installing a security patch.

IFF Assessment

FOE

The vulnerabilities allow for unauthorized updates, code execution, and credential extraction, which directly enables attackers to compromise the system.

Severity

9.1 Critical

The CVSS score of 9.1 indicates a critical severity, stemming from the potential for remote exploitation and significant impact, including unauthorized code execution and credential theft.

Defender Context

This alert highlights critical vulnerabilities in Wärtsilä's FOS-Onboard system, used in transportation critical infrastructure. Defenders must ensure these systems are patched promptly to prevent unauthorized updates and credential compromise, which could lead to severe operational disruptions or sabotage.

Read Full Story →