Legacy BMS Exposure: Over 1,000 Buildings at Systemic Risk
⚠️ The Black Hat Europe 2025 talk by Gjoko Krstic of Zero Science Lab revealed that a widely deployed building management system, evolved through multiple acquisitions, now exposes over 1,000 buildings on public IPs and contains numerous long-standing vulnerabilities. Many issues trace back to an 18-year-old firmware codebase and to fixes that patched symptoms rather than root causes. The vendor recommends securing the platform behind a VPN; organizations should audit, patch and restrict access immediately.
