Deral Heiland, Research Lead at Rapid7, is disclosing a vulnerability that reveals how popular home lighting systemOsram Lightify leaves users vulnerable to attack. A link to the blog post with additional details can be found here.

Specifically, a malicious actor can:

  • Execute commands to change lighting, and also execute commands to reconfigure the devices
  • Inject code which could modify the system configuration, exfiltrate or alter stored data, or take control of the product in order to launch browser-based attacks against the authenticated user’s workstation. Deral commented below.

Deral Heiland, Research Lead at Rapid7:

Deral Heiland“As consumer based IoT solutions find their way into our enterprise networks, we must continue to be diligent. Simple IoT technology solutions, such as lighting automation, can easily be overlooked as a risk. But as shown in my recent IoT research project even enterprise IoT lighting solution can suffer from a number of vulnerabilities.  If these issues go unchecked they can lead to increased risk for any organisations that deploy them such as unauthorised access to a corporate and home network when technology is compromised, and the extraction of data that can further compromise IoT systems, internal networks and authenticated user host systems attached to the IoT solutions.

That does not mean we should avoid leveraging these new automation technologies, but does show that we need to build better policy around managing the risk and develop processes on how to deploy these technologies in a manner that does not add any unnecessary risk.”

Experts Comments

Stay Tuned! Our Information Security Experts Community is responding .....

Submit Your Expert Comments

What do you think of the topic? Do you agree with expert(s) or share your expert opinion below.
Be part of our growing Information Security Expert Community (1000+), please register here.

Write Your Expert Comments *
Your Registered Email *
Notification Email (If different from your registered email)
* By using this form you agree with the storage and handling of your data by this web site.