Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

Unpatched Vulnerabilities Expose Novakon HMIs to Remote Hacking

Novakon HMIs are affected by remote code execution and information exposure vulnerabilities. 

HMI vulnerabilities

Some of the industrial control system (ICS) products made by Taiwan-based Novakon are affected by serious vulnerabilities, and the vendor does not appear to have released any patches. 

A subsidiary of iBASE Technology, Novakon designs and manufactures human-machine interfaces (HMIs), industrial PCs, and IIoT solutions. The company serves 18 countries across North America, Europe and Asia. Marketing materials show that 40,000 units of Novakon’s 7” HMIs have been deployed in global data centers. 

Researchers at CyberDanube, an IT/OT penetration testing and security consulting company, discovered that Novakon’s HMIs are affected by five types of vulnerabilities.

According to an advisory published by CyberDanube, the HMIs are affected by an unauthenticated buffer overflow allowing remote code execution with root privileges, a directory traversal that exposes files, and a couple of weak authentication issues that allow access to the device and applications.

The security firm’s researchers also discovered missing protection mechanisms and unnecessarily high permissions for certain processes. 

Sebastian Dietz, security researcher at CyberDanube, told SecurityWeek that the vulnerabilities can be exploited remotely without authentication.

Advertisement. Scroll to continue reading.

“An unauthenticated attacker could leverage these vulnerabilities to execute high privilege code on these devices,” Dietz explained. “As HMI devices are used to interact with machines and systems (eg, PLCs, production lines) in critical infrastructure, gaining arbitrary code execution could have severe consequences.”

Dietz noted that it’s difficult to determine how many devices may be vulnerable to attacks, “as they are normally deployed in critical infrastructure and (hopefully) not directly exposed via the internet”.

CyberDanube said Novakon has been sent a report describing its findings, but the vendor did not provide any feedback and ignored a vast majority of its communication attempts. 

Novakon has not responded to SecurityWeek’s request for comment.

Learn More at SecurityWeek’s ICS Cybersecurity Conference
The leading global conference series for Operations, Control Systems and OT/IT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.
ICS Cybersecurity Conference
October 27-30, 2025 | Atlanta
www.icscybersecurityconference.com

Related: DELMIA Factory Software Vulnerability Exploited in Attacks

Related: ICS Patch Tuesday: Rockwell Automation Leads With 8 Security Advisories

Related: Critical Flaws Patched in Rockwell FactoryTalk, Micro800, ControlLogix Products

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

SolarWinds has appointed Justin Henkel as Chief Information Security Officer.

J. Paul Haynes has joined Cinchy as Chief Executive Officer.

Hatem Naguib has become Chief Executive Officer at Sysdig.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.