Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Critical Infrastructure Security - Critical Infrastructure at Risk: Vulnerabilities Discovered in Automatic Tank Gauging
Critical Infrastructure Security Latest News News & Analysis Security

Critical Infrastructure at Risk: Vulnerabilities Discovered in Automatic Tank Gauging

ISB Staff ReporterBy ISB Staff ReporterOctober 1, 2024Updated:November 8, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Automatic Tank Gauging
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

A recent investigation by Bitsight TRACE has uncovered several critical 0-day vulnerabilities in six Automatic Tank Gauge (ATG) systems from five different vendors.

These vulnerabilities are substantial real-world threats, with the potential for exploitation by malicious actors, leading to severe consequences such as physical damage, environmental harm, and financial losses.

Even more alarming is that, despite repeated warnings, thousands of ATGs remain online and directly accessible via the internet, making them highly vulnerable to cyberattacks, particularly in sabotage or cyberwarfare contexts.

Industrial Control Systems (ICS) form the backbone of modern critical infrastructure, with ATG systems playing a key role in managing fuel storage across various industries.

These systems, responsible for monitoring fuel levels and detecting leaks, are essential for facilities ranging from gas stations to hospitals, airports, military bases, and power plants.

Real-World Risks and Potential Consequences

Pedro Umbelino, Principal Research Scientist at Bitsight, says the vulnerabilities could allow malefactors to exploit ATG systems, leading to potentially catastrophic outcomes, including environmental hazards, economic disruption, and even physical damage. Shockingly, despite past warnings, thousands of ATGs remain online and directly accessible via the internet, making them prime targets for cyberattacks.

Bitsight’s research found that threat actors could gain full control of ATG systems, allowing them to manipulate fuel levels, disable alarms, and even shut down fuel dispensing systems. The ability to control physical processes is a grave risk to critical infrastructure, which could cause fuel spills, equipment damage, or widespread service disruption at essential facilities like hospitals or emergency services. They could rename tank information, alter tank sizes to trigger overflows, disable leak detection, or even shut down fuel pumps, creating physical and environmental hazards.

The financial impact could also be severe, with attackers able to steal sensitive operational data or disable critical systems, potentially leading to hefty fines and regulatory penalties.

While some facilities may have implemented external controls to mitigate these risks, the widespread exposure of ATG systems online is alarming. Bitsight has stressed that even the most basic cybersecurity measures, like disconnecting ATGs from the internet, are often neglected.

Efforts to Mitigate the Threat

In response to these findings, Bitsight says it has collaborated with the US Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) to coordinate a responsible vulnerability disclosure process. For the past six months, the two organizations and CISA have worked closely with vendors to address the vulnerabilities and prevent exploitation. CISA has since published remediation advisories to guide organizations in securing their ATG systems.

However, despite these efforts, exposure remains high. Bitsight’s ongoing monitoring has revealed over 6,500 ATG systems are still connected to the internet without any security protections, leaving critical infrastructure vulnerable to cyberattacks.

Legacy Issues and Longstanding Vulnerabilities

This is not the first time vulnerabilities in ATG systems have been revealed. As far back as 2015, security researchers warned of exposed ATG systems on the internet, with thousands found to be accessible without password protection. Since then, several experiments and reports, including Trend Micro’s “GasPot” honeypot experiment, have illustrated the attractiveness of these systems to attackers.

Despite multiple warnings and ongoing research, the attack surface has only grown. Between 2015 and 2022, the number of vulnerable ATG systems increased by 120%, according to Cyborg Security. The problem persists today, with Bitsight’s discovery of new vendor-specific vulnerabilities shining a light on the critical need for enhanced security measures.

Why ATG Systems Must Prioritize Cybersecurity

While the vulnerabilities exposed do not necessarily present imminent physical damage or environmental disaster, the potential for harm is real. Bad actors could disrupt fuel supplies, cause economic loss, or damage essential services, particularly in industries that rely heavily on fuel management.

Securing ATG systems must become a priority for facility owners and operators. Disconnecting these systems from the internet, implementing strong access controls, and following CISA’s remediation advisories are key steps to reducing the risk of exploitation.

ISB Staff Reporter
  • ISB Staff Reporter
    Mass Exploit Lets Attackers Install Plugins Arbitrarily
  • ISB Staff Reporter
    Cyberattacks Soar 47% Globally – Attacks on Education Increase by 73%
  • ISB Staff Reporter
    CISA Warns of Two Known Exploited Vulnerabilities
  • ISB Staff Reporter
    JFrog Becomes an AI System of Record, Debuts JFrog ML

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The evolution of cyber risk: Addressing geopolitical threats

May 13, 20265 Mins Read

“Recovery Is the New Prevention”: a Q&A with CSO of Health-ISAC, Errol Weiss

May 7, 20266 Mins Read

Pro-Russian threat actors target Swedish heat and power plant in failed cyberattack

April 20, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}