Send message to

Do you want to send the message without a subject?
Please note that your message can be maximum 1000 characters long
Special characters '<', '>' are not allowed in subject and message
reCaptcha is invalid.
reCaptcha failed because of a problem with the server.

Your message has been sent

You can find the message in your personal profile at "My messages".

An error occured

Please try again.

Make an appointment with

So that you can make an appointment, the calendar will open in a new tab on the personal profile of your contact person.

Create an onsite appointment with

So that you can make an onsite appointment, the appointment request will open in a new tab.

Forums it-sa Expo Knowledge Forum A

Critical infrastructures rely on PSIM. We hacked it!

Presentation for the German Association for Critical Infrastructure Protection - BSKI e.V.

calendar_today Thu, 27.10.2022, 12:15 - 12:45

event_available On site

Action Video

south_east

Action description

south_east

Speaker

south_east

Themes

Industry 4.0 / IoT / Edge Computing

Event

This action is part of the event Forums it-sa Expo

Action Video

grafischer Background
close

This video is available to the it-sa 365 community. 
Please register or log in with your login data.

Action description

A Physical Security Management System (PSIM) or in German - Gefahrenmanagementsystem (GMS) - is a software for efficient security management in properties, buildings and facilities. Via a multitude of interfaces, it records the statuses and enables the control of security-related systems, such as access control systems, video surveillance systems, intrusion detection systems, and many more. Depending on the application, such a system can be used to arm/disarm intrusion detection areas, open/lock doors, trigger fire alarms. Etc.

PSIM systems are particularly widespread in companies with increased or particularly high security requirements. They are often used by operators of critical infrastructures such as energy suppliers, network operators, water suppliers, airports, etc.

Within the scope of our security research, we have examined the leading PSIM system "WinGuard" of Advancis Software & Services GmbH and were able to identify relevant vulnerabilities. By exploiting these vulnerabilities, we were able to obtain admin rights and bring the system under our control.

Note: The publication of our findings is made in the context of a Responsible Disclosure. Advancis Software & Services GmbH closed all security vulnerabilities very quickly after our notice and provided their customers with a software update.
... read more

Language: German

Questions and Answers: No

Speaker

show more
close

This content or feature is available to the it-sa 365 community. 
Please register or log in with your login data.