Tektronix TIF 2026
This page was machine-translated and may differ from the original. View original

Claroty, "IoT Vulnerability Up 56% Compared to Last Year"

Google 우선 소스Published2022.08.31 14:47



Release of XIoT Security Status Report for the First Half of 2022

It was analyzed that security vulnerabilities in IoT devices increased in the first half of this year compared to the same period last year, indicating an urgent need to strengthen the security of IoT-related devices.
On the 31st, Claroty's research team, Team82, released the XIoT Security Status Report for the first half of 2022, which contains in-depth investigations and analyses of vulnerabilities affecting Operational Technology (OT), Industrial Control Systems (ICS), IoMT, and XIoT.

According to this, vulnerability exposures affecting IoT devices increased by 56% compared to the second half of 2021, and vulnerabilities self-disclosed by vendors increased by 69% over the past year.

This is the first time that more disclosures from suppliers have been reported than those from independent investigative agencies.

It is notable that firmware vulnerabilities, whether wholly or partially fixed, also increased by 79%.

Given that resolving vulnerabilities in firmware patches is relatively more difficult than the initial software distribution, this can be seen as a notable improvement.

Looking at the key findings, 15% of IoT devices were found to have vulnerabilities, a significant increase from the 9% found in Team82's second-half 2021 report. In addition, the combined vulnerability of IoT and IoMT reached 18.2%, surpassing the 16.5% for total IT vulnerability for the first time.

▲ Vulnerability Survey Agency (Image courtesy of Claroty)
With vulnerabilities disclosed by vendors reaching 29%, they surpassed independent research organizations (19%) and became the second-largest reporter of vulnerabilities, following third-party security companies (45%).

214 were posted on CVE (Common Vulnerabilities and Exposures).

This figure is nearly double the 127 reported by Team82 in the second half of 2021.

This shows that more OT, IoT, and IoMT vendors are establishing vulnerability disclosure programs and investing more resources in inspecting the security and safety of their products.

The published firmware and software vulnerabilities showed nearly similar figures, at 46% and 48%, respectively. In the second half of 2021, firmware vulnerabilities (37%) were found to have increased significantly compared to software vulnerabilities (62%), which were nearly half the level of the software vulnerabilities.

In addition, XIoT vulnerabilities totaled 747 in the first half of 2022, and are being posted and resolved at a rate of 125 per month on average. The CVSS (Common Vulnerability Scoring System) scores were mostly at the critical (19%) or high severity (46%) level.

It has been confirmed that vulnerabilities reaching 71% are having a significant impact on system and device availability, and that these impact indicators are most pronounced in XIoT devices.

The greatest potential impact was unauthorized remote code execution or command execution (commonly occurring in 54% of vulnerabilities), followed by Denial-of-Service (DoS) situations (crashes, shutdowns, or restarts) at 43%.

The data in this report consists of vulnerabilities found by Team82 and trusted open sources including NVD (National Vulnerability Database), ICS-CERT (Industrial Control Systems Cyber Emergency Response Team), CERT@VDE, MITRE, Schneider Electric, and Siemens.

"As things become connected to the Internet, cyber-physical systems are having a direct impact on the real world, ranging from food and water to elevators and medical services," said Amir Preminger, Vice President of Research at Claroty. "We conducted this research to provide a blueprint of the XIoT vulnerability landscape, enabling the proper assessment, prioritization, and resolution of risks to critical systems that underpin public safety, patient health, smart grids, and utilities."
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
성유창 기자
성유창 기자