By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Critical Flaws in Tank Gauge Systems Expose Gas Stations to Remote Attacks
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Critical Flaws in Tank Gauge Systems Expose Gas Stations to Remote Attacks
Tech News

Critical Flaws in Tank Gauge Systems Expose Gas Stations to Remote Attacks

By Viral Trending Content 8 Min Read
Share
SHARE
Gas Stations to Remote Attacks

Critical security vulnerabilities have been disclosed in six different Automatic Tank Gauge (ATG) systems from five manufacturers that could expose them to remote attacks.

Contents
Flaws Discovered in OpenPLC, Riello NetMan 204, and AJCloudCISA Warns of Continued Attacks Against OT Networks

“These vulnerabilities pose significant real-world risks, as they could be exploited by malicious actors to cause widespread damage, including physical damage, environmental hazards, and economic losses,” Bitsight researcher Pedro Umbelino said in a report published last week.

Making matters worse, the analysis found that thousands of ATGs are exposed to the internet, making them a lucrative target for malicious actors looking to stage disruptive and destructive attacks against gas stations, hospitals, airports, military bases, and other critical infrastructure facilities.

ATGs are sensor systems designed to monitor the level of a storage tank (e.g., fuel tank) over a period of time with the goal of determining leakage and parameters. Exploitation of security flaws in such systems could therefore have serious consequences, including denial-of-service (DoS) and physical damage.

Cybersecurity

The newly discovered 11 vulnerabilities affect six ATG models, namely Maglink LX, Maglink LX4, OPW SiteSentinel, Proteus OEL8000, Alisonic Sibylla, and Franklin TS-550. Eight of the 11 flaws are rated critical in severity –

  • CVE-2024-45066 (CVSS score: 10.0) – OS command injection in Maglink LX
  • CVE-2024-43693 (CVSS score: 10.0) – OS command injection in Maglink LX
  • CVE-2024-43423 (CVSS score: 9.8) – Hard-coded credentials in Maglink LX4
  • CVE-2024-8310 (CVSS score: 9.8) – Authentication bypass in OPW SiteSentinel
  • CVE-2024-6981 (CVSS score: 9.8) – Authentication bypass in Proteus OEL8000
  • CVE-2024-43692 (CVSS score: 9.8) – Authentication bypass in Maglink LX
  • CVE-2024-8630 (CVSS score: 9.4) – SQL injection in Alisonic Sibylla
  • CVE-2023-41256 (CVSS score: 9.1) – Authentication bypass in Maglink LX (a duplicate of a previously disclosed flaw)
  • CVE-2024-41725 (CVSS score: 8.8) – Cross-site scripting (XSS) in Maglink LX
  • CVE-2024-45373 (CVSS score: 8.8) – Privilege escalation in Maglink LX4
  • CVE-2024-8497 (CVSS score: 7.5) – Arbitrary file read in Franklin TS-550

“All these vulnerabilities allow for full administrator privileges of the device application and, some of them, full operating system access,” Umbelino said. “The most damaging attack is making the devices run in a way that might cause physical damage to their components or components connected to it.”

Flaws Discovered in OpenPLC, Riello NetMan 204, and AJCloud

Security flaws have also been uncovered in the open-source OpenPLC solution, including a critical stack-based buffer overflow bug (CVE-2024-34026, CVSS score: 9.0) that could be exploited to achieve remote code execution.

“By sending an ENIP request with an unsupported command code, a valid encapsulation header, and at least 500 total bytes, it is possible to write past the boundary of the allocated log_msg buffer and corrupt the stack,” Cisco Talos said. “Depending on the security precautions enabled on the host in question, further exploitation could be possible.”

Another set of security holes concern the Riello NetMan 204 network communications card used in its Uninterruptible Power Supply (UPS) systems that could enable malicious actors to take over control of the UPS and even tamper with the collected log data.

  • CVE-2024-8877 – SQL injection in three API endpoints /cgi-bin/db_datalog_w.cgi, /cgi-bin/db_eventlog_w.cgi, and /cgi-bin/db_multimetr_w.cgi that allows for arbitrary data modification
  • CVE-2024-8878 – Unauthenticated password reset via the endpoint /recoverpassword.html that could be abused to obtain the netmanid from the device, from which the recovery code for resetting the password can be calculated

“Inputting the recovery code in ‘/recoverpassword.html’ resets the login credentials to admin:admin,” CyberDanube’s Thomas Weber said, noting that this could grant the attacker the ability to hijack the device and turn it off.

Both vulnerabilities remain unpatched, necessitating that users limit access to the devices in critical environments until a fix is made available.

Also of note are several critical vulnerabilities in the AJCloud IP camera management platform that, if successfully exploited, could lead to the exposure of sensitive user data and provide attackers with full remote control of any camera connected to the smart home cloud service.

“A built-in P2P command, which intentionally provides arbitrary write access to a key configuration file, can be leveraged to either permanently disable cameras or facilitate remote code execution through triggering a buffer overflow,” Elastic Security Labs said, stating its efforts to reach the Chinese company have been unsuccessful to date.

CISA Warns of Continued Attacks Against OT Networks

The development comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) flagged increased threats to internet-accessible operational technology (OT) and industrial control systems (ICS) devices, including those in the Water and Wastewater Systems (WWS) Sector.

“Exposed and vulnerable OT/ICS systems may allow cyber threat actors to use default credentials, conduct brute force attacks, or use other unsophisticated methods to access these devices and cause harm,” CISA said.

Cybersecurity

Earlier this February, the U.S. government sanctioned six officials associated with the Iranian intelligence agency for attacking critical infrastructure entities in the U.S. and other countries.

These attacks involved targeting and compromising Israeli-made Unitronics Vision Series programmable logic controllers (PLCs) that are publicly exposed to the internet through the use of default passwords.

Industrial cybersecurity company Claroty has since open-sourced two tools called PCOM2TCP and PCOMClient that allow users to extract forensics information from Unitronics-integrated HMIs/PLCs.

“PCOM2TCP, enables users to convert serial PCOM messages into TCP PCOM messages and vice versa,” it said. “The second tool, called PCOMClient, enables users to connect to their Unitronics Vision/Samba series PLC, query it, and extract forensic information from the PLC.”

Furthermore, Claroty has warned that the excessive deployment of remote access solutions within OT environments – anywhere between four and 16 – creates new security and operational risks for organizations.

“55% of organizations deployed four or more remote access tools that connect OT to the outside world, a worrisome percentage of companies that have expansive attack surfaces that are complex and expensive to manage,” it noted.

“Engineers and asset managers should actively pursue to eliminate or minimize the use of low-security remote access tools in the OT environment, especially those with known vulnerabilities or those lacking essential security features such as MFA.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Best New Smartwatch of the Year: Tech Advisor Awards 2025-26

Why SEO Has Become an Important Compliance Consideration for Financial Services in the Age of AI

The Great Big Power Play

Silver Fox Targets Indian Users With Tax-Themed Emails Delivering ValleyRAT Malware

Using Self-Checking Loops GPT-5.2 Hits 75% on ARC-AGI

TAGGED: critical infrastructure, Cyber Security, Cybersecurity, industrial control system, Infrastructure Security, Internet, network security, Operational Technology
Share This Article
Facebook Twitter Copy Link
Previous Article It’s time for Android phones to embrace Apple’s MagSafe
Next Article Harris Struggles to Win Over Some Black Male Voters, a Key Democrat Voting Bloc
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Marvel Rivals' Lady Loki costume revealed, confirmed not to be Hela skin
Gaming News
Bitwise seeks SEC approval for 11 crypto ETFs covering Bittensor, Tron and DeFi tokens
Crypto
The Future Of Tech: How Blockchain AI And Will Converge By Late 2026
Crypto
Best New Smartwatch of the Year: Tech Advisor Awards 2025-26
Tech News
Rotherham frustrated as 4-0 thrashing by Blackpool makes it 8 league games without a win
Sports
At least six people injured and 100 evacuated after Italy cable car crash
World News
Warren Buffett retires today: Berkshire faces its first dawn without the Oracle of Omaha
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Marvel Rivals' Lady Loki costume revealed, confirmed not to be Hela skin

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Marvel Rivals' Lady Loki costume revealed, confirmed not to be Hela skin
December 31, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?