The odds are excellent that you've never even heard of most of the IoT's operating systems, nor the companies that make them. Take VxWorks by a company called Wind River, for example. It's the most popular Real Time Operating System (RTOS), used in a wide range of smart devices today. They don't get a lot of attention or oversight because almost nobody has heard of them.
The company has been in existence for 32 years. Yet, in that time, only 13 security flaws with a MITRE-assigned CVE have been found in the VxWorks RTOS, because again, nobody's paying attention.
The good news is that when someone finally started paying attention, Wind River responded quickly and resolved all eleven of the security flaws, issuing a patch to correct them. There's just one rather significant catch, however.
The company is claiming that the vulnerabilities are not unique to Wind River software and that the IPnet stack (where the vulnerabilities were found) was acquired by the company back in 2006. Prior to Wind River's acquisition of it, it was deployed in a wide range of other RTOS'.
All that to say, while Wind River is acting responsibly, there are an unknown number of other RTOS' out there that are vulnerable. The companies behind them may be doing little or nothing about it. In many ways, the OS ecosystem of the IoT is still very much a black box, and that's troublesome.
As a company, are you doing your part in securing your smart devices and your network? Or are you left in the dark about their vulnerabilities? Let SpartanTec, Inc. Wilmington help you find out if your business is at risk. Call now and learn more about their complimentary, one-time scan with Dark Web ID™ Credential Monitoring.
SpartanTec, Inc.Wilmington, NC 28412
(910) 218-9255
No comments:
Post a Comment