Wärtsilä FOS-Onboard
Summary
Wärtsilä FOS-Onboard versions 5.07.0923.01 are affected by vulnerabilities, including a hardcoded cryptographic server key. Successful exploitation could allow an attacker to deliver unauthorized updates, execute code, or extract credentials, leading to impersonation. Wärtsilä recommends obtaining and installing a security patch.
IFF Assessment
The vulnerabilities allow for unauthorized updates, code execution, and credential extraction, which directly enables attackers to compromise the system.
Severity
The CVSS score of 9.1 indicates a critical severity, stemming from the potential for remote exploitation and significant impact, including unauthorized code execution and credential theft.
Defender Context
This alert highlights critical vulnerabilities in Wärtsilä's FOS-Onboard system, used in transportation critical infrastructure. Defenders must ensure these systems are patched promptly to prevent unauthorized updates and credential compromise, which could lead to severe operational disruptions or sabotage.