
HP Study Reveals 70 Percent of Internet of Things Devices Vulnerable to AttackIoT devices averaged 25 vulnerabilities per product, indicating expanding attack surface for adversaries
PALO ALTO, Calif. - HP today released results of a study revealing 70 percent of the most commonly used Internet of Things (IoT) devices contain vulnerabilities, including password security, encryption and general lack of granular user access permissions.
With the rise of IoT, the number and diversity of connected devices is expected to increase exponentially. According to Gartner, the Internet of Things will include 26 billion units installed by 2020. IoT product and service suppliers will generate incremental revenue exceeding $300 billion, mostly in services, in 2020. (1)
This spike in demand is pushing manufacturers to quickly bring to market connected devices, cloud access capabilities and mobile applications in order to gain share. While this increase in IoT devices promises benefits to consumers, it also opens the doors for security threats ranging from software vulnerabilities to denial-of-service (DOS) attacks to weak passwords and cross-site scripting vulnerabilities.
While the Internet of Things will connect and unify countless objects and systems, it also presents a significant challenge in fending off the adversary given the expanded attack surface, said Mike Armistead, vice president and general manager, Fortify, Enterprise Security Products, HP. With the continued adoption of connected devices, it is more important than ever to build security into these products from the beginning to disrupt the adversary and avoid exposing consumers to serious threats.
HP leveraged HP Fortify on Demand to scan 10 of the most popular IoT devices, uncovering, on average, 25 vulnerabilities per device-totaling 250 security concerns across all tested products. The IoT devices tested-along with their cloud and mobile application components-were from manufacturers of TVs, webcams, home thermostats, remote power outlets, sprinkler controllers, hubs for controlling multiple devices, door locks, home alarms, scales and garage door openers.
The most common and easily addressable security issues reported include:
Privacy concerns: Eight of the 10 devices tested, along with their corresponding cloud and mobile application components, raised privacy concerns regarding the collection of consumer data such as name, email address, home address, date of birth, credit card credentials and health information. Moreover, 90 percent of tested devices collected at least one piece of personal information via the product itself, the cloud or its mobile application.
Insufficient authorization: 80 percent of IoT devices tested, including their cloud and mobile components, failed to require passwords of sufficient complexity and length, with most devices allowing password such as 1234. In fact, many of the test accounts HP configured with weak passwords were also used on the products' websites and mobile applications.
Lack of transport encryption: 70 percent of IoT devices analyzed did not encrypt communications to the internet and local network, while half of the devices' mobile applications performed unencrypted communications to the cloud, internet or local network. Transport encryption is crucial given that many of the tested devices collected and transmitted sensitive data across channels.
Insecure web interface: Six of the 10 devices evaluated raised security concerns with their user interfaces such as persistent XSS, poor session management, weak default credentials and credentials transmitted in clear text. Seventy percent of devices with cloud and mobile components would enable a potential attacker to determine valid user accounts through account enumeration or the password reset feature.
Inadequate software protection: 60 percent of devices did not use encryption when downloading software updates, an alarming number given that software powers the functionality of the tested devices. Some downloads could even be intercepted, extracted and mounted as a file system in Linux where the software could be viewed or modified.
To protect against security hazards that come along with the rise of IoT, it is imperative for organizations to implement an end-to-end approach to identify software vulnerabilities before they are exploited. Solutions like HP Fortify on Demand enable organizations to test the security of software quickly, accurately, affordably and without any software to install or manage-proactively eliminating the immediate risk in legacy applications and the systemic risk in application development.
Methodology
Conducted by HP Fortify and leveraging HP Fortify on Demand, the Internet of Things Security: State of the Union study tested 10 of the most commonly used IoT devices for vulnerabilities using standard testing techniques that combined manual testing along with the use of automated tools. Devices and their cloud, network and client application components were assessed based on the OWASP Internet of Things Top 10 list and the specific vulnerabilities associated within each category.
Additional information about application security and further details resulting from the study are available at hp.com/go/fortifyresearch/iot.
HP will be addressing the latest trends in enterprise security at the Black Hat USA 2014 conference, taking place Aug. 2-7 in Las Vegas. Visit the HP booth (No. 911) for an IoT product demo and Capture the Flag hacking contest. Additional information on HP's presence at the show can be found here.
(1) Gartner, Forecast: The Internet of Things, Worldwide, 2013, November 2013.
2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. The only warranties for HP products and services are set forth in the e
Most recent headlines
04/09/2025
Monumental Sports & Entertainment (MSE), in collaboration with Dalet, has been a...
19/04/2025
SDVI, the leading platform provider for cloud-native media supply chains, today announced that the company earned multiple awards at the 2025 NAB Show, with two...
19/04/2025
Ateliere Creative Technologies, a leading GenAI media software solutions company, today announced that Dan Goman has stepped down as CEO and David Bortis, Ateli...
19/04/2025
As Director of Media and Aerial Production at Terrible Herbst Motorsports, Bryan Moore is setting new standards in off-road racing media coverage thanks to his ...
19/04/2025
A next-generation collaboration device that redefines connectivity for meeting environments
Lightware, an industry-leading manufacturer of signal management so...
19/04/2025
Calrec is today announcing that its True Control 2.0 is a Remote Production winner in the 2025 NAB Show Product of the Year Awards. This official awards program...
19/04/2025
Appear, a global leader in live production technology, proudly announces it has been recognised alongside NBCUniversal with the prestigious NAB Show Delivery Pr...
19/04/2025
Deity Microphones, a leader in innovative audio equipment, is proud to announce the expected release of our Ultra-Wide Band IFB to the market. The THEOS DIFB wi...
19/04/2025
A world renowned broadcaster and long-standing LiveU customer has successfully completed a series of live connectivity tests using LiveU's revolutionary, aw...
19/04/2025
BitFire (bitfire.tv), a longtime leader in live video transport, today announced dual NAB Show award wins at the 2025 NAB Show in Las Vegas. The company's M...
19/04/2025
BitFire (bitfire.tv), a longtime leader in live video transport, today announced three major award wins at the 2025 NAB Show, April 5-9, in Las Vegas. The compa...
19/04/2025
AI video discovery company Moments Lab and Satisfaction Group, a leading independent unscripted television production company, are proud to announce a unique st...
19/04/2025
As the media industry navigates the triple challenge of AI-driven production, distributed teams, and skyrocketing content demand, DigitalGlue s creative.space h...
19/04/2025
Network technology startup Miri Technologies Inc. capped off its tremendously successful NAB Show debut by winning two prestigious industry awards for its cutti...
19/04/2025
CINCINNATI Scripp's Nuvyyo USA has concluded a deal with Warner Bros. Discovery to bring 45 FAST channels to Nuvyyo's Tablo TV device....
19/04/2025
In a ruling that could have broader implications on the legality of regulatory agencies levying fines through administrative proceedings, the 5th U.S. Circuit C...
19/04/2025
WASHINGTON Federal Communications Commission chair Brendan Carr has blasted Comcast over MSNBC's coverage of the deportation of Kilmar Abrego Garcia in a so...
19/04/2025
Berklee NYC and NYC Media Launch Season 3 of Inside Power Station @BerkleeNYC This season features faculty member Arun Pandian as the new host and interviews ...
18/04/2025
Director Andrew Ahn, alongside actors Youn Yuh-jung and Joan Chen, takes a photo of the audience after the premiere of his film The Wedding Banquet at Eccles ...
18/04/2025
In a ruling that could have a major impact on the digital advertising market, a federal judge has ruled that Google has monopolized some types of advertising te...
18/04/2025
Broadcast and cable TV news outlets saw strong social media growth in March, according to new data from the social video analytics company Tubular Labs ....
18/04/2025
Berklee Student Yukai Yang Named 2025 Yamaha Young Performing Artist The drummer secured a spot among the elite winners in this years competition.
By
Maddie...
18/04/2025
Boston Conservatory Alums Bring Real Women Have Curves to Broadway The Latin American immigrant community takes center stage in a new musical featuring Tatian...
18/04/2025
WASHINGTON The FCC's call for public comments and suggestions on outdated regulations that it should be eliminated, has prompted a slew of fillings from bro...
18/04/2025
In a ruling that could have a major impact on the digital advertising market, a federal judge has ruled that Google has monopolized some types of advertising te...
18/04/2025
PEARL RIVER, N.Y. Global media solutions company Active Media Services (AMS) has formed a new relationship with VideoAmp, a measurement company for linear TV, c...
18/04/2025
Netflix reported generally positive results for first-quarter 2025, with revenue up 13% year-over-year to $10.543 billion and operating income growing by 27% to...
18/04/2025
NHL Playoffs 2025: TNT Sports Hits the Road for Onsite Productions With Mobile U...
18/04/2025
EVSs S bastien Verlaine on U.S. Expansion, Next-Generation Products Beyond replay, offerings also target asset management and media infrastructure By Ken Kersc...
18/04/2025
ESPN Unleashes 4DREPLAY as NCAA Women's Gymnastics Championships Hit ABC Men's championships to follow Saturday night on ESPN2 By Brandon Costa, Direct...
18/04/2025
Visualizing Victory: The Latest in AR, XR, and Virtual Production in Live Sports This panel discussion featured leaders from ESPN, CBS Sports, Warner Bros. Disc...
18/04/2025
NHL Playoffs 2025: With 16 Games in First Six Days, ESPN Deploys Variety of Remo...
17/04/2025
Emilie Blichfeldt attends the 2025 Sundance Film Festival premiere of The Ugly ...
17/04/2025
R-GPS gives warfighters a decisive battlefield advantage by punching through adv...
17/04/2025
This year's NAB Show in Las Vegas marked a noticeable shift in the priorities of media and broadcast organisations. Gone are the days of chasing flashy, or ...
17/04/2025
class=attachment-thumbnail size-thumbnail f-align-center alt= decoding=async data-lazy-srcset=https://www.antonbauer.com/wp-content/uploads/2024/12/Amy-Daniel-1...
17/04/2025
SAN JOSE, Calif. Roku and Adobe have announced that they are collaborating on a real time data platform made possible by a a new integration of the Roku Data C...
17/04/2025
NEW YORK Internet advertising revenues demonstrated strong growth in 2024, increasing 14.9% year-over-year to $258.6 billion, according to the IAB Internet Adv...
17/04/2025
SDVI Earns Both Product and Project of the Year Awards at 2025 NAB Show
Brie Clayton April 17, 2025
0 Comments
Left to right, Geoff Stedman, CMO, SDVI...
17/04/2025
Singapore Polytechnic Readies Aspiring AV Professionals for Live IP Productions ...
17/04/2025
Calrec Wins 2025 NAB Show Product of the Year Award for True Control 2.0
Brie Clayton April 17, 2025
0 Comments
Image: The Calrec True Control 2.o on ...
17/04/2025
In Return to Berklee, Lucius Looks Back and Moves Forward From mood boards to live demos, the alumni band gave students an exclusive look at the process behin...
17/04/2025
DirecTV's free streaming service MyFree DirecTV has just added another eight channels from NBCUniversal....
17/04/2025
LOS ANGELES The virtual production company GameChanger has announced that it is expanding its global footprint by bringing its virtual production technology to ...
17/04/2025
DENVER The International Broadcaster Coalition Against Piracy (IBCAP) has announced that it has developed a proprietary, automated software-based system to iden...
17/04/2025
Pixalate's new CTV Device Market Share report for Q1 2025 shows that Roku has the highest open programmatic CTV device market share in the United States, wi...
17/04/2025
Edward J. Lewis III Named Senior Vice President of Institutional Advancement Lewis has more than 20 years of industry experience, leading fundraising initiati...
17/04/2025
The Curling Group Puts On Inaugural Curling All-Star Game in Nashville The location in Music City is intended to broaden the sport's appeal By Dan Daley, ...
17/04/2025
April 17th, 2025 Press Materials Available Here
Tribeca Festival 2025 Announces TV & NOW Lineup
World Premieres and Exclusive Cast Panels with Apple TV '...
17/04/2025
SVG Sit-Down: Cisco's Bryan Bedford on Providing End-to-End Support for Clie...