BlackBerry software flaw could impact cars, medical devices: U.S. agencies

The software is used by automakers including Volkswagen, BMW and Ford Motor in many critical functions including the Advanced Driver Assistance System.

August 18, 2021 09:43 am | Updated 10:02 am IST

File photo.

File photo.

A cybersecurity flaw in a software designed by BlackBerry Ltd could put at risk cars and medical equipment that use it and expose highly sensitive systems to attackers, the U.S. drugs regulator and a federal agency said on Tuesday.

(Subscribe to our Today's Cache newsletter for a quick snapshot of top 5 tech stories. Click here to subscribe for free.)

The warning came after the Canadian company disclosed that its QNX Real Time Operating System (QNX RTOS) has a vulnerability that could allow an attacker to execute an arbitrary code or flood a server with traffic until it crashes or gets paralysed.

Also Read | Cyberattacks surge in the first half of 2021, ransomware attacks dominate, report finds

The software is used by automakers including Volkswagen, BMW and Ford Motor in many critical functions including the Advanced Driver Assistance System.

The issue does not impact current or recent versions of the QNX RTOS, but rather versions dating from 2012 and earlier, BlackBerry said, adding that, at this time, no customers have indicated that they have been impacted.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) said the software is used in a wide range of products and its compromise "could result in a malicious actor gaining control of highly sensitive systems, increasing risk to the Nation's critical functions", the CISA said .

The federal agency that comes under the Department of Homeland Security and the company said they were not yet aware of any case of active exploitation of the flaw.

Also Read | Tech titans join U.S. cyber team to fight ransomware

The U.S. Food and Drug Administration said it was not aware of any adverse events even as medical equipment manufacturers assess which systems could be affected.

The company also said it has notified potential customers that have been affected and has made software patches available to resolve the matter.

BlackBerry had initially denied that the vulnerability, dubbed as BadAlloc, impacted its products and later resisted making a public announcement, Politico reported , citing two people familiar with talks between the company and federal cybersecurity officials, including a government employee.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.