기본 콘텐츠로 건너뛰기

시스코 탈로스 "삼성 스마트싱스 취약점 주시 권고"

[아이뉴스24 성지은 기자] 시스코의 보안연구 조직 탈로스는 삼성 스마트싱스(SmartThings) 허브에서 사용 중인 펌웨어 내부에서 여러 개의 취약점을 발견했다고 27일 발표했다. 

삼성 스마트싱스 허브는 스마트 플러그, LED 조명, 온도조절 장치, 카메라 등 스마트홈에 탑재되는 다양한 사물인터넷(IoT) 기기를 제어하고 감시하는 허브 역할을 한다. 사용자들은 스마트폰을 사용해 이러한 기기를 원격으로 제어할 수 있다. 

스마트싱스 허브에 사용되는 펌웨어는 리눅스(Linux) 기반으로 설계돼 이더넷·지그비(Zigbee)·지웨이브(Z-Wave)·블루투스 등 서로 다른 다양한 기술을 사용하는 IoT 기기들과 상호 통신한다.



탈로스에 따르면, 공격자는 관련 취약점에 감염된 기기들에 운영체제(OS) 명령, 임의적인 코드 실행 등을 단행할 수 있었다. 민감 정보에 접근하고 스마트홈 내 기기들을 감시·제어해 승인되지 않은 행동들에 활용할 수 있었던 것으로 보인다.

탈로스 측은 "허브 장치는 다양한 환경에서 구축 가능하기 때문에 허브 장치에 대한 공격이 성공할 경우 심각한 피해를 초래할 수 있어 가능한 빠른 업데이트를 권장한다"며 "삼성은 허브 장치에 자동 업데이트를 배포하기 때문에 대부분의 경우 수동 조작이 필요하지 않지만, 업데이트 버전이 실제로 장치에 적용돼 더 이상 취약점에 노출되지 않다는 점을 확인하는 것이 중요하다"고 조언했다.

한편, 탈로스는 사전 조율된 공개 정책에 따라 삼성과 협력으로 관련 이슈를 해결했으며, 펌웨어 업데이트가 제공되도록 지원했다. 삼성은 이번에 발견된 이슈들을 해결하는 펌웨어 업데이트를 배포했다.

http://news.inews24.com/php/news_view.php?g_serial=1112831&g_menu=020830&rrf=nv

댓글

이 블로그의 인기 게시물

BLACK LABEL Secured Automobile Smart Key Solution

Developed by MERCEDES BENZ for the first time 20 years ago, the SmartKey has been very convenient for motorists. However, since this technology has been applied so far, the smart key security has not been upgraded so that even if a simple wireless hacking device is purchased on the market, the password which is exchanged between the car and the smart key is wirelessly captured, the car door is opened, Things are happening in a random way. The biggest problem in smart key security so far is that the identification code exchanged between the smart key and the key is a fixed value and the security is difficult to hack the fixed single code value. However, if a mutual verification system, which is a security solution of BLACK LABEL, is applied to a smart key and a vehicle, it is impossible to access the vehicle even if the identification code value is fixed in a single code, Can be made. This is because the code that has been changed once and then discarded is discarded. ...

Avoiding Cryptocurrency Scams

The Money Makers Club now has 6 of 15 available seats. Learn more here! Everyone is always focused on the potential upside of buying cryptocurrency, but they forget there are always going to be hidden downsides as well. The downside risk of investing in cryptocurrencies is huge. Not only do you need to worry about the high volatility of these assets, but you also need to bear in mind that theft is always a possibility, and the assets are poorly regulated.  Lack of Regulation Creates Opportunity for Thieves In the equity and debt markets, there are stringent controls on the way capital is invested and the rules that govern investors. The goal is to protect investors from any fraud or wrongdoing, and even though there are times where it takes regulators longer than normal to catch on (see: Bernie Madoff), the general effect is a safer investment marketplace.  Fraud can occur in a variety of ways. It can be the result of false claims by the company regarding the s...

Cold Wallet Vs. Hot Wallet: What’s The Difference?

You may have heard about cold and hot digital wallets but do you know how they are different from each other? The simplest way to describe the difference between a cold wallet and a hot one is this: hot wallets are connected to the internet while cold wallets are not. Most people who hold digital assets have both cold and hot wallets because they are designed for different purposes. Hot wallets are like checking accounts while cold wallets are similar to savings accounts. People who have digital assets keep a small amount of money in their hot wallets for purchasing stuff. They keep the vast majority of their digital coins in their cold wallet. If you like Medium articles in video form, you’re in luck: SECURITY Q: Why do people keep most of their digital coins in a cold wallet? A: Hackers cannot steal digital assets that are not connected to the internet. Q: So then, how safe are hot wallets? A: The security of hot wallets is dependent upon the security ha...