{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Daily Security Review","title":"Novakon Ignored Security Reports on ICS Weaknesses, Leaving 40,000+ Devices Exposed","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/2c1acac2\"></iframe>","width":"100%","height":180,"duration":1355,"description":"A new security report has revealed serious, unpatched vulnerabilities in industrial control system (ICS) products manufactured by Novakon, a Taiwan-based subsidiary of iBASE Technology. Security researchers at CyberDanube identified five categories of flaws affecting Novakon’s Human-Machine Interfaces (HMIs), including an unauthenticated buffer overflow that allows remote code execution with root privileges. Other weaknesses include directory traversal, weak authentication, excessive process privileges, and insufficient system protections.\nWhat makes this situation particularly alarming is that these flaws can be exploited remotely and without authentication—meaning attackers don’t need credentials or physical access to compromise the devices. Once exploited, adversaries could disrupt production, manipulate industrial processes, disable safety systems, or use the devices as stepping stones for further attacks inside critical environments.\nThe risks are compounded by Novakon’s lack of response. Despite repeated disclosure attempts, the company has ignored most communications from CyberDanube and has released no security patches. This leaves organizations operating these devices with no vendor-supported mitigation, effectively shifting the full burden of protection to asset owners.\nWith an estimated 40,000 Novakon HMIs deployed globally in data centers and critical infrastructure, the potential impact is severe. Researchers stress that asset owners must immediately assess their exposure, ensure Novakon devices are not internet-facing, implement compensating network controls, and develop incident response playbooks.\nThis episode examines the vulnerabilities in detail, the risks they pose to industrial environments, and what organizations can do in the absence of vendor support.\n#Novakon #ICS #CriticalInfrastructure #CyberSecurity #Vulnerabilities #HMI #iBASE #OTSecurity #CyberDanube #RemoteCodeExecution #DataCenters","thumbnail_url":"https://img.transistorcdn.com/pL79_MJFeJHamQ_ztImsGmDSMdl27VMk_30TAkieujE/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yNzg5/ZjlhNzM5Y2M4Njli/NjkxNzgyODA2Nzhi/MDI2ZC5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}