As stated in US-CERT advisory, the researcher Martin Aman found the vulnerability, CVE-2020-12493, in SWARCO’s CPU LS4000 traffic light controllers.
It was an improper access control flaw that achieved a CVSS base score of 10.0. Even a low-skilled attacker could easily exploit the bug and disrupt traffic controllers.
Though, exploiting the flaw required physical access to the target controllers. While that reduces the probability of the attack, in case of such an incident, the attacker could deactivate traffic lights causing huge traffic disruptions.
Describing the details of the flaw, the VDE-CERT stated,
An open port used for debugging grants root access to the device without access control via network. A malicious user could use this vulnerability to get access to the device and disturb operations with connected devices.Thankfully, no exploitation of the bug in the wild has been detected yet.
Following the researcher’s report, the vendors worked on a fix to address the flaw. While they have released the patch to fix the bug and close the port, users should make sure to update their systems.
Moreover, US-CERT also advises the users to mitigate the flaw via the following.
Let us know your thoughts in the comments.