Critical Vulnerability in Schneider Electric APC NetBotz Exposes Data Centers
Key Takeaways Thousands of industrial control systems (ICS) and building automation systems (BAS) near U.S. data centers are exposed to the public internet. These exposed devices manage critical...
Key Takeaways
- Thousands of industrial control systems (ICS) and building automation systems (BAS) near U.S. data centers are exposed to the public internet.
- These exposed devices manage critical functions like cooling and power distribution, creating a significant attack surface for potential disruptions.
- Researchers identified over 6,300 such devices within one kilometer of 1,063 U.S. data centers, primarily using BACnet and Fox/Niagara protocols.
- Successful exploitation could lead to data center outages, equipment damage, or costly emergency responses.
- Mitigation involves removing direct public access, implementing strong authentication, network segmentation, and regular security audits of facility control systems.
A recent analysis reveals that thousands of industrial and building management controllers, crucial for the operational integrity of U.S. data centers, are directly accessible from the public internet. This widespread exposure presents a substantial risk to the physical infrastructure underpinning these vital facilities.
Table Of Content
These exposed devices are responsible for maintaining critical environmental conditions, managing power distribution, and regulating cooling systems within data centers. Should an unauthorized entity gain control, the consequences could range from widespread service disruptions and severe equipment damage to expensive emergency interventions.
The core of the problem lies in the direct internet connectivity of industrial control systems (ICS) and building automation systems (BAS). Cybercriminals can readily locate these systems online and exploit publicly available software details, misconfigurations, or known vulnerabilities to establish a foothold.
Research Uncovers Extensive Exposure
Researchers at TrendAI identified a staggering 6,300 industrial control and building automation devices situated within a one-kilometer radius of 1,063 data centers across the United States. This data, derived from passive Shodan scans rather than active probing, was detailed in a report shared by TrendAI. While the research cannot definitively link each device to a specific data center, it clearly delineates a significant and proximate attack surface.
The uninterrupted operation of cooling and power systems is as fundamental to a data center as its servers. A sudden compromise of cooling capacity can trigger thermal alarms and automatic shutdowns, while power disturbances can corrupt data or interrupt critical applications. Prior reports on power device security flaws underscore how vulnerabilities in management systems can escalate into large-scale availability incidents.
Internet-Exposed Controllers: A Closer Look
The TrendAI study found that the BACnet protocol on port 47808 and the Fox/Niagara protocol on port 1911 accounted for 81 percent of the identified exposed devices. These protocols are commonly employed for controlling air conditioning, environmental sensors, and access control systems. Additionally, the analysis revealed 159 Modbus devices, frequently associated with power meters and various industrial equipment, and 16 Vertiv/Liebert devices, which are typically used in precision cooling, uninterruptible power supplies (UPS), and power distribution hardware.
Exposed system banners often reveal sensitive information such as vendor names, firmware versions, zone labels, and equipment inventories. This information significantly reduces the effort required for attackers to select and target vulnerable systems. In one anonymized instance, researchers observed a device responding to both Modbus and BACnet, indicating a potential link between power monitoring and cooling controls through a single point of entry.
The risk is not confined to a single protocol or vendor. The researchers documented 143 multi-protocol devices, with 125 communicating via both Fox/Niagara and BACnet. Such gateways are particularly critical, as compromising one interface could provide access to multiple interconnected building systems.
Further insights into the risks posed by direct access to web-managed building controls can be gleaned from a related report on online Honeywell controller exposure.
Interestingly, newer data center facilities exhibited a higher rate of nearby exposed devices. Sites permitted from 2021 onwards showed a 13.1 percent exposure rate, compared to 4.9 percent for facilities constructed before 2010. This trend is attributed to rapid deployment cycles, increased reliance on remote management, and potentially deferred security assessments. It is important to note that IP geolocation identifies a network area, not a precise building, so these figures represent potential vulnerabilities rather than confirmed breaches within specific data centers.
What You Should Do
- Conduct Comprehensive Asset Discovery: Actively scan and inventory all public-facing IP address ranges to identify any internet-exposed building automation and industrial control systems. This must include devices managed by facilities teams, not just IT-controlled assets.
- Review Network Access Controls: Scrutinize router and firewall rules for any port forwarding configurations that expose BACnet (port 47808), Fox/Niagara (port 1911), Modbus, EtherNet/IP, or other ICS/BAS services directly to the public internet.
- Eliminate Direct Public Access: Wherever possible, remove direct public internet access to these critical control systems. Implement secure remote access solutions such as controlled VPNs, SSH tunnels, or zero-trust network access (ZTNA) services, ensuring strong multi-factor authentication and least-privilege permissions.
- Strengthen Authentication and Patch Management: Replace all default credentials with strong, unique passwords immediately. Ensure that all supported products are regularly patched and updated to address known vulnerabilities. For devices that have reached end-of-life, apply compensating network controls to mitigate risks.
- Implement Network Segmentation: Isolate building automation systems onto a separate operational technology (OT) network. Restrict traffic flow between the OT network, enterprise systems, and the internet to only what is absolutely necessary. This re-establishes a crucial security boundary often bypassed by direct internet connections for facilities equipment.
- Develop and Practice Incident Response Plans: Conduct regular tabletop exercises and drills with facilities staff and contractors to rehearse responses to cooling or power control incidents.
- Enhance Monitoring: Implement robust monitoring for unusual remote connections and unexpected changes in Modbus or BACnet traffic patterns. Early detection of anomalous behavior can significantly reduce the impact of a potential compromise, as demonstrated by incidents like the FrostyGoop malware, which focused on Modbus-based attacks to cause physical disruption.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.