Tycon Systems TPDIN-Monitor-WEB3
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and earlier have three separate vulnerabilities: a use of hard-coded credentials, a cross-site request forgery (CSRF) attack, and a missing authorization issue. Successful exploitation could lead to a man-in-the-middle attack, factory resets, credential theft, and extraction of system configurations. Tycon Systems has released firmware v2.4.2 to address these issues, and CISA recommends minimizing network exposure and isolating control systems.
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a series of security flaws. The first, a use of hard-coded credentials, allows an attacker to intercept sensitive information and credentials. Secondly, a cross-site request forgery (CSRF) vulnerability enables state-changing operations on the device. Finally, a missing authorization vulnerability permits the extraction of system credentials, configurations, or flash contents. These vulnerabilities were reported to CISA by Abdiwelli Guled. Tycon Systems has released firmware v2.4.2 to mitigate these risks. CISA recommends taking defensive measures to minimize the risk of exploitation, including minimizing network exposure for control system devices, isolating them from business networks, and utilizing secure remote access methods like VPNs. Organizations should perform impact analysis and risk assessments before deploying defensive strategies, and should implement cybersecurity best practices as outlined on the CISA ICS webpage. CISA also advises against clicking unsolicited links or opening attachments in emails and recommends reporting suspected malicious activity.