Exposed Fuel Tank Gauges Under Attack in the US
Internet-exposed fuel tank gauges in the United States are being targeted by cyberattacks, posing a significant risk to gas stations and industrial facilities. The Cybersecurity and Infrastructure Security Agency (CISA) and other US government agencies have issued a joint notice urging organizations to secure these systems, highlighting the vulnerability of legacy devices and the potential for disruption and manipulation of critical data. The majority of exposed ATGs are located in the US, with a notable concentration of 909 devices.
Cyberattacks are targeting internet-exposed automatic tank gauges (ATGs) in the United States, allowing threat actors to potentially alter tank readings, pump controls, and other settings. This vulnerability stems from the fact that many ATGs are built for reliability rather than security, often running outdated software and lacking proper patching. The FBI, CISA, and other agencies have issued a joint notice urging industrial organizations to take immediate action to harden these systems. The attacks could have dire consequences if plant operators are unaware of infiltration and the readings concern safety-critical systems, such as disabling alerts about abnormal conditions in a tank.
The majority of vulnerable ATGs are located in the US, with 909 devices discovered by The Shadowserver Foundation. This disparity is concerning, as a decade ago, nearly 6,000 ATGs were exposed on the web. Researchers have identified critical zero-day vulnerabilities in popular ATG models, including command-injection vulnerabilities with high CVSS scores. While nation-state actors like those linked to Iran could exploit these vulnerabilities for intelligence gathering or further attacks, a more immediate risk is the disruption of industrial operations by manipulating critical data.
Organizations are advised to remove ATGs from the open web to mitigate this risk. The agencies are aware of malicious cyber activity targeting these systems and are urging site owners to take swift action to secure their systems.
