• The controllers are used in supermarkets, cold-storage facilities and warehouses.
    The controllers are used in supermarkets, cold-storage facilities and warehouses.
Close×

Copeland and Danfoss responded quickly to fix vulnerabilities found in their refrigeration controllers which are used in supermarkets, cold-storage facilities, warehouses, and other commercial environments.

Claroty’s Team82 researchers recently discovered severe vulnerabilities in two supervisory controllers which are responsible for coordinating refrigeration equipment and ensuring stable operations.

In response Danfoss and Copeland released firmware to address the vulnerabilities for the Danfoss AK-SM 800A and Copeland XWEB Pro.

A Copeland spokesperson told CCN that protecting the operations of customers is a top priority.

“When Claroty notified us of potential vulnerabilities affecting certain XWEB monitoring solutions, we immediately investigated the issue and implemented the necessary fixes,” the spokesperson said.

“We kept affected customers informed throughout the process and provided actionable guidance to help them mitigate risk and maintain operational continuity.

“Safeguarding the security, quality and performance of our products is fundamental to everything we do, and we value collaboration with the cybersecurity research community to help advance industry-wide security standards.”

Recognising the vulnerabilities could grant attackers the ability to physically manipulate refrigeration systems and spoil their contents, Copeland provided firmware update version 1.13 to secure affected XWEB Pro devices.

Danfoss also investigated immediately releasing the necessary fixes and issuing security advisories to inform customers and stakeholders.

Danfoss Climate Solutions head of the monitoring & connectivity portfolio, Mirko Travaglin, told CCN cybersecurity is a top priority for Danfoss.

“We appreciate the responsible disclosure process with Claroty Team82, which enabled us to quickly investigate and address these vulnerabilities in firmware version R4.3.1,” he said.

“We remain committed to partnering with the security community, continuously improving our products, and safeguarding our customers’ operations.

“Customers using affected AK-SM 800A controllers were informed to upgrade to version R4.3.1 or later and ensure they are running the latest software releases from 2025 to benefit from the latest security protections.”

Claroty Team82 vulnerability researcher, Amir Zaltzman, said these issues underscore the need for stronger cybersecurity across the commercial refrigeration industry.

“As the research demonstrates, a handful of software vulnerabilities and weak credential generation mechanisms in a supervisory controller can quickly escalate into real-world physical consequences, from spoiled food to compromised temperature-sensitive medical supplies,” he warned.