Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

Unpatched Vulnerabilities Expose Novakon HMIs to Remote Hacking

Novakon HMIs are affected by remote code execution and information exposure vulnerabilities. 

HMI vulnerabilities

Some of the industrial control system (ICS) products made by Taiwan-based Novakon are affected by serious vulnerabilities, and the vendor does not appear to have released any patches. 

A subsidiary of iBASE Technology, Novakon designs and manufactures human-machine interfaces (HMIs), industrial PCs, and IIoT solutions. The company serves 18 countries across North America, Europe and Asia. Marketing materials show that 40,000 units of Novakon’s 7” HMIs have been deployed in global data centers. 

Researchers at CyberDanube, an IT/OT penetration testing and security consulting company, discovered that Novakon’s HMIs are affected by five types of vulnerabilities.

According to an advisory published by CyberDanube, the HMIs are affected by an unauthenticated buffer overflow allowing remote code execution with root privileges, a directory traversal that exposes files, and a couple of weak authentication issues that allow access to the device and applications.

The security firm’s researchers also discovered missing protection mechanisms and unnecessarily high permissions for certain processes. 

Sebastian Dietz, security researcher at CyberDanube, told SecurityWeek that the vulnerabilities can be exploited remotely without authentication.

Advertisement. Scroll to continue reading.

“An unauthenticated attacker could leverage these vulnerabilities to execute high privilege code on these devices,” Dietz explained. “As HMI devices are used to interact with machines and systems (eg, PLCs, production lines) in critical infrastructure, gaining arbitrary code execution could have severe consequences.”

Dietz noted that it’s difficult to determine how many devices may be vulnerable to attacks, “as they are normally deployed in critical infrastructure and (hopefully) not directly exposed via the internet”.

CyberDanube said Novakon has been sent a report describing its findings, but the vendor did not provide any feedback and ignored a vast majority of its communication attempts. 

Novakon has not responded to SecurityWeek’s request for comment.

Learn More at SecurityWeek’s ICS Cybersecurity Conference
The leading global conference series for Operations, Control Systems and OT/IT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.
ICS Cybersecurity Conference
October 27-30, 2025 | Atlanta
www.icscybersecurityconference.com

Related: DELMIA Factory Software Vulnerability Exploited in Attacks

Related: ICS Patch Tuesday: Rockwell Automation Leads With 8 Security Advisories

Related: Critical Flaws Patched in Rockwell FactoryTalk, Micro800, ControlLogix Products

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

In cyber-physical systems (CPS), just one hour of downtime can outweigh an entire annual security budget. Learn how to master the Return on Security Investment (ROSI) to align security goals with the bottom-line priorities.

Register

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

People on the Move

Jacki Monson has joined CVS Health as SVP, Deputy CISO.

Gigi Schumm has been promoted to Chief Revenue Officer at Securonix.

Chris Sistrunk has been promoted to Practice Leader for Mandiant's OT Security Consulting.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.