Moneycontrol PRO
HomeNewsTechnologyCritical security flaws exposed in 2 government cybersecurity apps, CERT-In raises alarm

Critical security flaws exposed in 2 government cybersecurity apps, CERT-In raises alarm

CERT-In said that the two applications, USB Pratirodh and AppSamvid, were using weak cryptographic algorithms.

March 06, 2024 / 10:56 IST
The Indian Compute Emergency Response Team (CERT-In) is the nodal cybersecurity agency of the country, operating under the Ministry of Electronics and Information Technology

The Indian Computer Emergency Response Team (CERT-In) has raised concerns about vulnerabilities in two government applications, which could potentially allow hackers to take control of the systems.

Ironically, these two apps, USB Pratirodh and AppSamvid 2.0.1, are designed for cybersecurity purposes. Both applications have been developed by the IT Ministry's Centre for Development and Advanced Computing (C-DAC).

This comes at a time when several Indian government websites, email ids, databases, and overall digital infrastructure are being routinely targeted by threat actors, either in a bid to steal sensitive information, or sell such stolen databases on the dark web for a hefty fee.

"Multiple vulnerabilities have been reported in AppSamvid software which could allow a local authenticated attacker to take control of the application or execute code on the targeted system," CERT-In's vulnerability note from March 4 said.

The CERT-In's alert for USB Pratirodh was also similar.

"A vulnerability has been reported in USB Pratirodh which could allow a local attacker to take control of the application and modify the access control of registered users or devices on the targeted system," the note said.

While USB Pratirodh controls the usage of pen drives, external hard drives and allows only authenticated users to access removable storage media, AppSamvid is an application that allows only "whitelisted" software to run on an operating system.

'AppSamvid and USB Pratirodh were using weak algorithms'

The nodal cybersecurity agency which functions under the IT Ministry also pointed out that the vulnerability in AppSamvid existed due to usage of "weaker cryptographic algorithm" in user login section.

"An attacker with local administrative privileges could exploit this to obtain the password of AppSamvid on the targeted system. Successful exploitation of this vulnerability could allow attacker to take complete control of the application on the targeted system," CERT-In said.

USB Pratirodh too has been found to be using weak cryptographic algorthim, CERT-In said. A hacker could have exploited this vulnerability to obtain the password of USB Pratirodh on a targeted system.

"Successful exploitation of this vulnerability could allow the attacker to take control of the application and modify the access control of registered users or devices on the targeted system," it added.

Govt's cybersecurity budget doubled

Moneycontrol previously reported that Pakistan-based intelligence operatives were targeting sensitive Indian installations and departments by sending malicious files through emails.

In its annual report released in November 2023, CERT-In stated that the agency handled 1,391,457 cybersecurity incidents in 2022.

Taking such attacks into cognisance, the Indian government, in the Interim Budget 2024, nearly doubled the allocation for cybersecurity projects from Rs 400 crore in 2023-2024 to Rs 759 crore in 2024-2025

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Aihik Sur covers tech policy, drones, space tech among other beats at Moneycontrol
first published: Mar 6, 2024 10:56 am

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347