A security report has been published for a set of 56 vulnerabilities collectively called Icefall and affecting the operational technology (OT) equipment used in various critical infrastructure environments.

See also: BidenCash: New site sells credit card details for $0.15
The Icefall vulnerability collection was discovered by security researchers at Forescout's Vedere Labs and affects devices from ten vendors. The types of security flaws included allow remote code execution , compromised credentials, firmware and configuration changes , authentication bypass , and logic manipulation.
The affected vendors are Honeywell, Motorola, Omron, Siemens, Emerson, JTEKT, Bentley Nevada, Phoenix Contract, ProConOS and Yokogawa. They have been notified through an update coordinated by Phoenix Contact, CERT VDE and the U.S. Cybersecurity and Infrastructure Security Administration (CISA).
In recent years, the type of systems affected by Icefall have become more frequent targets of specialized malware Industroyer 2 and CaddyWiper, which were developed long ago by Russian hackers against Ukrainian power plants.
See also: Flagstar Bank: Data breach affects 1.5 million customers
Overview of Vulnerabilities
The flaws discovered by Vedere Labs mainly concern credential security, firmware manipulation, and remote code execution.

Forescout notes in its report that “many vulnerabilities are due to the insecure nature of OTs,” adding that “many authentication systems have been compromised ,” indicating inadequate security controls at the implementation stage .
As an example, the researchers point out that many devices used plaintext credentials, weak or broken cryptography , hardcoded keys , and client-side authentication
These authentication flaws open the way for threat actors to achieve remote code execution (RCE) and denial of service (DoS or install malicious firmware images. Direct operational manipulation by issuing commands to the target devices or those behind them is another risk that the researchers point out.
Potential consequences
Icefall affects a wide range of devices used in numerous industrial sectors, making them highly attractive, especially to state-sponsored hackers.
Some scenarios that Forescout says could arise from threat actors leveraging Icefall include generating false alarms, changing flow setpoints, disrupting SCADA operations, or disabling emergency and fire safety systems
See also: A Cloudflare outage hit many popular services
To demonstrate their findings and the potential risk, the researchers used a wind power generation and natural gas transmission system, showing where various flaws and how they could be chained together to achieve deeper levels of compromise.


The affected devices are scattered across the globe. Analysts used Shodan to scan the internet for exposed vulnerable systems and found the following top six:
- Honeywell Saia Burgess – 2924 devices in Italy, Germany, Switzerland, Sweden and France.
- Omron Controllers – 1305 devices across Spain, Canada, France, the USA and Hungary.
- Phoenix Contact DDI – 705 devices in Italy, Germany, India, Spain and Turkey.
- ProConOS SOCOMM – 236 devices in China, USA, Germany, Singapore and Hong Kong.
- Honeywell Trend Controls – 162 devices in France, Denmark, Italy, Spain and United Kingdom.
- Emerson Fanuc /PACSystems – 60 devices in the USA, Canada, Poland, Taiwan and Spain.
Specifically, 74% of vulnerable product families were certified for their security, a fact that reflects that these processes are not flawless.
Mitigation capabilities
The primary security recommendation is to apply the latest firmware updates from the vendor. Currently, however, not all referenced vendors have released patches for Icefall and there are also later vendors that need to take action.
Until a patch is available or installed, system administrators are advised to segment the network and monitor device traffic and activity
It is recommended that companies follow security advice from each vendor to learn more details about the specific impact each vulnerability has on an affected product.
Information source: bleepingcomputer.com
