
【EnOcean SmartServerの欠陥で、建物管理システムが遠隔侵害可能に】 SecurityWeekによると、Clarotyは EnOcean SmartServer に CVE-2026-22885 と CVE-2026-20761 を発見し、インターネット露出デバイスに対してメモリ保護回避、メモリ漏えい、任意コマンド実行が可能だと報告しました。対象はスマートビル、工場、データセンター向けの building automation ゲートウェイです。 この種の機器は“ITでもOTでもない境界装置”として見逃されがちですが、実際には施設制御、環境制御、保守導線のハブです。Linuxベースのデバイスを root で乗っ取られると、監視・制御・足場化のすべてが危険になります。 ビル管理・工場・データセンター運用では、クラウド接続や公開保守経路を含めて SmartServer の露出確認を急ぐべきです。 #ICS #OTSecurity #BuildingAutomation #EnOcean #RCE #BlueTeam https://www.securityweek.com/enocean-smartserver-flaws-expose-buildings-to-remote-hacking/
Post summary
EnOcean SmartServer is vulnerable to CVE‑2026‑22885 and CVE‑2026‑20761, allowing attackers to bypass memory protections, cause memory leaks, and execute arbitrary commands over the internet, posing a serious threat to building automation systems.

