Skip to main content

Posts

Showing posts with the label Vulnerable IoT Device

Denial-of-Service and Man-in-the-middle vulnerabilities found in Smart scale IoT device

An IoT device analyzed by researchers was found to have four security flaws that could allow attackers to perform denial of service (DoS) and man-in-the-middle(MITM) attacks. The device’s associated mobile apps on iOS and Android also had other privacy issues. A string of security flaws was found in an IoT device that monitored users’ weight and related body factors. The device, known as Smart Scale PW 5653 by AEG is prone to adversarial situations such as DoS and MITM attacks. On Monday, security firm Checkmarx discovered these security loopholes in their analysis of the device. In addition, mobile apps associated with Smart Scale also had privacy issues. As per the  report  by David Sopas of Checkmarx, vulnerabilities were mainly related to Bluetooth security. Attackers could exploit the Bluetooth Low Energy(BLE) technology in Smart Scale and conduct DoS as well as change internal settings in the device. The report classified the four vulnerabilities as ‘medium’ severity.

Japanese government plans to hack insecure IoT devices with an aim to protect them from hackers

  The program which is a part of a survey will help the government figure out the number of insecure IoT devices in the country. The survey is scheduled to kick off next month and involves the security test of over 200 million IoT devices. The Japanese government has approved a new amendment that would allow government officials to hack into citizens’ IoT devices. The program which is a part of a survey will help the government to figure out the number of insecure IoT devices in the country. About the survey The survey is scheduled to kick off next month and involves the security test of over 200 million IoT devices. Devices in homes and on enterprise networks will be tested alike under the penetration test program. The  survey  will be carried out by employees of the National Institute of Information and Communications Technology (NICT) under the supervision of the Ministry of Internal Affairs and Communications. A list of default passwords and password dictionarie