Executive Summary
In early 2024, cybersecurity researcher Gjoko Krstic uncovered hundreds of zero-day vulnerabilities within legacy building automation systems still widely deployed in hospitals, schools, and commercial facilities globally. The investigation, codenamed "Project Brainfog," revealed that outdated codebases, some as old as 18 years, exposed critical physical infrastructure to remote compromise by unauthenticated attackers. Exploitable weaknesses in authentication, encryption, and access controls allowed for the manipulation of HVAC, security, and energy systems, putting sensitive environments such as medical and educational facilities at operational risk, and making them potential targets for ransomware and espionage.
This incident highlights the growing threat of unpatched operational technology in critical sectors, as attackers increasingly target IoT and building control systems for both sabotage and lateral movement. As digital-physical convergence accelerates, organizations must rapidly modernize and secure these legacy environments to mitigate cascading risks.
Why This Matters Now
A surge of cyberattacks against critical infrastructure and smart buildings has exposed long-standing vulnerabilities in operational technology systems. With many organizations still relying on outdated building automation, the threat of disruption, safety risks, and regulatory non-compliance is urgent—particularly as threat actors pivot towards targeting physical processes.
Attack Path Analysis
Attackers exploited multiple zero-day vulnerabilities in legacy building automation systems to gain initial access, often via unencrypted or exposed network interfaces. They leveraged insufficient internal controls to elevate privileges and traverse internal networks, moving laterally to discover and exploit additional devices. Establishing command and control over compromised systems, adversaries maintained remote access and coordinated their actions. Sensitive building and tenant data was at risk of exfiltration due to weak egress controls and lack of traffic monitoring. Ultimately, the attack posed serious risks to operational integrity, safety, and downtime of critical smart building infrastructure.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited unpatched zero-day vulnerabilities in exposed, unencrypted building automation interfaces to gain foothold in smart buildings.
Related CVEs
CVE-2024-6298
CVSS 10A remote code execution vulnerability in ABB ASPECT building energy management platform allows unauthenticated attackers to execute arbitrary code remotely.
Affected Products:
ABB ASPECT – < 3.08.03
Exploit Status:
proof of conceptCVE-2023-0636
CVSS 9.8A vulnerability in ABB Cylon Aspect software allows attackers to exploit a network diagnostic component interface, potentially leading to unauthorized access.
Affected Products:
ABB Cylon Aspect – < 3.08.03
Exploit Status:
proof of conceptCVE-2024-6209
CVSS 9.8A vulnerability in ABB Cylon Aspect software allows attackers to extract plain-text user credentials without authentication, leading to potential unauthorized access.
Affected Products:
ABB Cylon Aspect – < 3.08.03
Exploit Status:
proof of conceptCVE-2018-17912
CVSS 8.6An XML External Entity (XXE) vulnerability in Sauter CASE Suite allows unauthenticated users to access sensitive information or configuration files.
Affected Products:
Sauter CASE Suite – <= 3.10
Exploit Status:
no public exploitCVE-2017-9650
CVSS 8.3An unrestricted file upload vulnerability in Automated Logic WebCTRL allows authenticated attackers to upload malicious files and execute arbitrary code.
Affected Products:
Automated Logic WebCTRL – 5.x, 6.x
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation of Remote Services
Valid Accounts
Exploitation for Privilege Escalation
Network Sniffing
System Information Discovery
Endpoint Denial of Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security of System Components with Known Vulnerabilities
Control ID: 6.2.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
NIS2 Directive – Incident Handling and Vulnerability Management
Control ID: Art. 21(2)(b)
CISA Zero Trust Maturity Model 2.0 – Inventory and Management of Assets
Control ID: Asset Management / Visibility
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Art. 8
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Health Care / Life Sciences
Hospitals running vulnerable 18-year-old building automation systems face critical zero-day exposures requiring immediate segmentation, encrypted traffic, and threat detection capabilities.
Higher Education/Acadamia
Schools with legacy building automation codebases need zero trust segmentation and anomaly detection to protect against hundreds of discovered vulnerabilities.
Commercial Real Estate
Office buildings worldwide running affected automation systems require multicloud visibility, egress security, and inline IPS protection against Project Brainfog vulnerabilities.
Government Administration
Government facilities using vulnerable building automation systems need comprehensive threat detection, encrypted communications, and compliance-mapped security controls for critical infrastructure protection.
Sources
- An 18-Year-Old Codebase Left Smart Buildings Wide Openhttps://www.darkreading.com/vulnerabilities-threats/18-year-old-codebase-left-smart-buildings-wide-openVerified
- Researcher Says ABB Building Control Products Affected by 1,000 Vulnerabilitieshttps://www.securityweek.com/researcher-says-abb-building-control-products-affected-by-1000-vulnerabilities/Verified
- Over 100 Flaws Expose Buildings to Hacker Attackshttps://www.securityweek.com/over-100-flaws-expose-buildings-hacker-attacks/Verified
- Sauter Quickly Patches Flaw in Building Automation Softwarehttps://www.securityweek.com/sauter-quickly-patches-flaw-building-automation-software/Verified
- Automated Logic Patches Flaws in Building Automation Systemhttps://www.securityweek.com/automated-logic-patches-flaws-building-automation-system/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Enforcing zero trust segmentation, encrypted traffic, granular visibility, and strict egress controls in the smart building networks would have contained the attacker, detected abnormal activity, and prevented both lateral movement and data exfiltration.
Control: Encrypted Traffic (HPE)
Mitigation: Encrypted interfaces and packet-level encryption would prevent credential theft and network snooping.
Control: Zero Trust Segmentation
Mitigation: Strict least-privilege segmentation would block privilege escalation across unrelated assets.
Control: East-West Traffic Security
Mitigation: Lateral movement attempts are blocked or alerted based on east-west traffic policy.
Control: Threat Detection & Anomaly Response
Mitigation: Anomalous connection attempts and remote access tool usage are detected and alerted immediately.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound data exfiltration attempts are blocked by strict FQDN and application egress policy.
Centralized visibility and policy orchestration enable a rapid, automated response to operational threats.
Impact at a Glance
Affected Business Functions
- Building Security
- HVAC Control
- Lighting Management
- Energy Management
Estimated downtime: 5 days
Estimated loss: $500,000
Potential exposure of sensitive building schematics, access credentials, and operational data, leading to unauthorized access and control over building systems.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce encrypted traffic (MACsec/IPsec) for all building systems to eliminate unencrypted attack vectors.
- • Deploy zero trust segmentation and workload isolation to prevent lateral movement and restrict unauthorized privilege escalation.
- • Implement strict egress controls and FQDN filtering to block data exfiltration and unauthorized C2 channels.
- • Continuously monitor for anomalies and threats across east-west and outbound traffic with advanced detection and incident response capabilities.
- • Centralize control and visibility across on-prem and cloud environments for consistent enforcement and rapid isolation of suspicious activity.



