The appliances allow broadcasts to be interrupted to share emergency information Hardware appliances used by broadcasters to transmit emergency communications contained vulnerabilities that could be exploited over the Internet, although patches are now available.The appliances from Digital Alert Systems, which is a division of Monroe Electronics, are a crucial component of the Emergency Alert System, a national program intended to disseminate public safety information over broadcast outlets within about 10 minutes.Monroe Electronics issued a firmware update 2.0-2 for its DASDEC products on April 24, which the company said fixed several security problems.The most serious vulnerability in DASDEC could allow an attacker to login remotely since the systems shared a root SSH key. In that scenario, an attacker could take over the system and issue emergency messages. The vulnerabilities came to wider attention following recent advisories by the U.S. Computer Emergency Readiness Team, the Industrial Control Systems Cyber Emergency Response Team and vendor IOActive, which found the problems.IOActive issued a news release on Monday. Gunter Ollman, IOActive’s CTO, said in an email that the company held off releasing information on the problems even though Monroe Systems had released its advisory in April. IOActive was advised that it could take a while for companies using the equipment to apply patches, and there was a risk that malicious actors may try and exploit the issues, he said.In February, Emergency Alert System equipment belonging to broadcasters in Michigan, New Mexico and Montana was hacked.One of the fake messages warned “that the bodies of the dead are rising from their graves and attacking the living.”Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk Related content feature Top cybersecurity M&A deals for 2023 Fears of recession, rising interest rates, mass tech layoffs, and conservative spending trends are likely to make dealmakers cautious, but an ever-increasing need to defend against bigger and faster attacks will likely keep M&A activity steady in By CSO Staff Sep 22, 2023 24 mins Mergers and Acquisitions Mergers and Acquisitions Mergers and Acquisitions brandpost Unmasking ransomware threat clusters: Why it matters to defenders Similar patterns of behavior among ransomware treat groups can help security teams better understand and prepare for attacks By Joan Goodchild Sep 21, 2023 3 mins Cybercrime news analysis China’s offensive cyber operations support “soft power” agenda in Africa Researchers track Chinese cyber espionage intrusions targeting African industrial sectors. By Michael Hill Sep 21, 2023 5 mins Advanced Persistent Threats Cyberattacks Critical Infrastructure brandpost Proactive OT security requires visibility + prevention You cannot protect your operation by simply watching and waiting. It is essential to have a defense-in-depth approach. By Austen Byers Sep 21, 2023 4 mins Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe