According to the Pentagon's inspector general, US Department of Defense (DoD) employees purchased products more than $32.8 million worth of. The problem is that these products contained vulnerabilities securitythat were known.
The purchases were made by Army and Air Force employees. The DOD Inspector General believes the vulnerable equipment could be used by U.S..
According to the report, the products with the vulnerabilities were: Lexmark printers, GoPro cameras , and Lenovo computers .
Purchases from LEXMARK
The army and the air force purchased over 8,000 Lexmark printers, worth 30 million dollars.
Buying printers from Lexmark was a big mistake, according to auditors, as a 2018 congressional report revealed vulnerabilities in Lexmark devices and alleged that the company was linked to the Chinese military and the country's nuclear and spy programs .
Additionally, Lexmark printers have been found to have more than 20 vulnerabilities in the past. The vulnerabilities affected the storage and transmission of information, and could allow an attacker to execute malicious code.
Additionally, the vulnerabilities could allow hackers to remotely use a connected Lexmark printer for espionage purposes or to carry out a denial of service attack on a Department of Defense network.
However, Brad Clay, Vice President and Chief Information Officer of Lexmark, expressed his disappointment and disagreement with what was said about Lexmark. He further said that the company has no relationship with the Chinese government.

Purchases from GOPRO
Additionally, the Army and Air Force purchased 117 GoPro action cameras , costing approximately $98,000
However, auditors reported that the cameras have vulnerabilities that could allow a remote attacker to gain access to stored credentials and live video streams.
“With the exploitation of these vulnerabilities, a malicious hacker could see the videos, record or take photos without the user's knowledge”.
Purchases from LENOVO
The biggest security issue has to do with Lenovo computers. The US government has warned about the problems with these devices.
For example, in 2006, the State Department banned the use of Lenovo computers on its networks, as there were reports that Lenovo computers were manufactured with hardware or software used for espionage.
In 2015, the Department of Homeland Security reported that Lenovo computers had pre-installed spyware, as well as several critical vulnerabilities.
In 2016, the Directorate of Secret Services of the General Staff also issued its own warning regarding Lenovo and the espionage risk from its devices.
However, despite the warnings, the army purchased 195 Lenovo products in 2018, worth $268,000, and the Air Force bought another 1,378 Lenovo products for $1.9 million.
The Ministry of Defense ignored the previous warnings
The Department of Defense ignored cybersecurity warnings and purchased products from these companies.
For example, Lexmark printers were still available for purchase by the Navy until February 2019, despite the US government warning not to purchase these products.
The Ministry of Defense has not taken care of cyber risk management.
The National Intelligence and Security Center (NCSC) attempted in April 2019 to “force” government agencies and the private sector to review their supply chains. Close attention should be paid to the equipment and software they purchase, especially from known US adversaries such as China.
With political tensions between China and the US, American government officials fear that an incident between the two countries could have devastating effects on the American IT infrastructure, which is filled with equipment from China.
