US Power Grid Cyberattack Due to Unpatched Firewall: NERC

  /     /     /  
Publicated : 23/11/2024   Category : security


US Power Grid Cyberattack Due to Unpatched Firewall: NERC


A firewall vulnerability enabled attackers to repeatedly reboot the victim entitys firewalls, causing unexpected outages.



The North American Electric Reliability Corporation (NERC) reports that a cyberattack on the US power grid earlier this year was caused by a target entitys network perimeter firewall flaw.
On March 5, 2019, an incident targeted a low-impact grid control center and small power generation sites in the western US, according to an E&E News
update
. No signal outages lasted longer than five minutes, and the disruption didnt cause any blackouts. Still, the 10-hour attack was great enough to prompt the victim utility to contact the US Department of Energy.
A Lesson Learned post from NERC says attackers exploited a vulnerability in the web interface of a vendor firewall, enabling attackers to repeatedly reboot the devices and cause a denial-of-service condition. The unexpected reboots let to communication outages in firewalls that controlled communication between the control center and multiple remote generation sites, and between equipment on these sites. All firewalls were network perimeter devices.
Analysis revealed the target utility hadnt installed a firmware update that would have patched the vulnerability, and the outages stopped when the patch was applied. The victim reviewed its process for assessing and implementing firmware updates and has chosen to implement a more formal, frequent review of vendor updates monitored by internal compliance tracking software.
Read more details
here
.
Check out
The Edge
, Dark Readings new section for features, threat data, and in-depth perspectives. Todays top story:
Phishers Latest Tricks for Reeling in New Victims


Last News

▸ ArcSight prepares for future at user conference post HP acquisition. ◂
Discovered: 07/01/2025
Category: security

▸ Samsung Epic 4G: First To Use Media Hub ◂
Discovered: 07/01/2025
Category: security

▸ Many third-party software fails security tests ◂
Discovered: 07/01/2025
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
US Power Grid Cyberattack Due to Unpatched Firewall: NERC