• Cold-storage facility.
    Cold-storage facility.
Close×

Researchers have identified vulnerabilities in two popular refrigeration controller platforms commonly used in supermarkets, cold-storage facilities, warehouses, and other commercial environments.

The supervisory controllers - the Danfoss AK-SM 800A and Copeland XWEB Pro – are responsible for coordinating refrigeration equipment and ensuring stable operations.

As soon as the vulnerabilities were discovered Danfoss and Copeland released firmware to address the vulnerabilities and customers were advised to update as soon as possible.

Claroty’s Team82 found severe vulnerabilities in each system, which can grant attackers the ability to physically manipulate refrigeration systems and silently spoil the contents.

Claroty vulnerability researcher, Amir Zaltzman, said these vulnerabilities present a significant risk for Australian businesses, given modern cold-chain logistics depend on precise, uninterrupted climate control.

“Large distribution centres store tonnes of perishable food, while supermarkets operate extensive refrigerated display networks, and healthcare facilities safeguard temperature-sensitive pharmaceuticals,” he said.

“More broadly, these findings underscore the need for stronger cybersecurity across the commercial refrigeration industry. Predictable credentials, Internet-exposed management interfaces, and slow adoption of firmware updates continue to leave critical systems vulnerable.

“Improving resilience in the industry requires timely patching, network segmentation, restricting Internet exposure, and securing the supervisory controllers at the centre of these environments.”

Team82 researched the attack surface of the Danfoss AK-SM 800A platform and identified three vulnerabilities affecting the embedded web management interface.

The researchers privately reported these vulnerabilities to Danfoss through a coordinated vulnerability disclosure process. Danfoss investigated the findings and released firmware version R4.3.1, which addresses the vulnerabilities.

“Customers using affected AK-SM 800A controllers should upgrade to firmware version R4.3.1 or later as soon as possible,” Zaltzman said.

“Organisations should also avoid exposing management interfaces directly to the Internet and ensure that access to administrative services is restricted to trusted management networks or secured through VPNs and other appropriate network segmentation controls.”

Team82 also researched the attack surface of the Copeland XWEB Pro platform to assess its resilience against network-based attacks.

Claroty’s analysis uncovered a total of 23 vulnerabilities in the platform, 21 of which are high-severity.

Claroty disclosed the vulnerabilities to Copeland, which successfully patched these vulnerabilities and has uploaded firmware update version 1.13 to secure affected XWEB Pro devices.

“The boundary between digital networks and physical systems is exceptionally thin in operational technology (OT),” Zaltzman said.

“As the research demonstrates, a handful of software vulnerabilities and weak credential generation mechanisms in a supervisory controller can quickly escalate into real-world physical consequences, from spoiled food to compromised temperature-sensitive medical supplies.”