Executive brief
Wärtsilä FOS-Onboard is a maritime control system used to manage onboard vessel operations and updates. This vulnerability exposes a hardcoded cryptographic key used for client authentication in the robot testing framework component, allowing an attacker with network access to impersonate a privileged client and potentially execute unauthorized commands, deliver malicious updates, or extract additional credentials. The vulnerability is not exploitable under recommended installation practices, but organizations with non-standard deployments face significant risk to operational technology integrity.
Technical details
This vulnerability is a hardcoded cryptographic key (CWE-321) in the robot testing framework component of Wärtsilä FOS-Onboard that authenticates clients. An attacker with adjacent network access to the affected system can exploit the hardcoded client authentication key to impersonate a legitimate privileged client without requiring credentials. Successful exploitation allows delivery of unauthorized updates, code execution with system privileges, or extraction of additional credentials for further lateral movement. The vulnerability requires adjacent network access and specific connection conditions (AC:H), but carries high confidentiality, integrity, and availability impact across the system and connected components. Patch 5.08.4052.01 is available; Wärtsilä notes the vulnerability is not exploitable under recommended installation configurations.
Affected products
- Wärtsilä FOS-Onboard 5.07.0923.01
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Patch version 5.08.4052.01 available