Moneycontrol PRO
HomeNewsTechnologyBlackBerry software flaw could impact cars, medical devices

BlackBerry software flaw could impact cars, medical devices

The warning came after the Canadian company disclosed that its QNX Real Time Operating System has a vulnerability that could allow an attacker to execute an arbitrary code or flood a server with traffic until it crashes or gets paralyzed.

August 18, 2021 / 08:03 IST
FILE PHOTO - A Blackberry smartphone is displayed in this illustrative picture taken in Bordeaux, Southwestern France, August 22, 2016. REUTERS/Regis Duvignau/File Photo - RTX2VWC6

FILE PHOTO - A Blackberry smartphone is displayed in this illustrative picture taken in Bordeaux, Southwestern France, August 22, 2016. REUTERS/Regis Duvignau/File Photo - RTX2VWC6

A cybersecurity flaw in a software designed by BlackBerry Ltd could put at risk cars and medical equipment that use it and expose highly sensitive systems to attackers, the U.S. drugs regulator and a federal agency said on Tuesday.

The warning came after the Canadian company disclosed that its QNX Real Time Operating System has a vulnerability that could allow an attacker to execute an arbitrary code or flood a server with traffic until it crashes or gets paralyzed.

The software is used by automakers including Volkswagen, BMW and Ford Motor in many critical functions including the Advanced Driver Assistance System.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) said the software is used in a wide range of products and its compromise ”could result in a malicious actor gaining control of highly sensitive systems, increasing risk to the Nation’s critical functions”, the CISA said.

The federal agency that comes under the Department of Homeland Security and the company said they were not yet aware of any case of active exploitation of the flaw.

The U.S. Food and Drug Administration said it was not aware of any adverse events even as medical equipment manufacturers assess which systems could be affected.

BlackBerry had initially denied that the vulnerability, dubbed as BadAlloc, impacted its products and later resisted making a public announcement, Politico reported, citing two people familiar with talks between the company and federal cybersecurity officials, including a government employee.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Reuters
first published: Aug 18, 2021 08:03 am

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347