An Analysis on CVE Vulnerabilities of the Internet of Things
Anurag Kumar, Carol Fung · 2024
The rapid expansion in the use of Internet of Things (IoT)-based system across different industries has forced manufacturers to make their products available for early release without including necessary security features. The communication between IoT and other system typically includes users personal data. A cyberattack on IoT-based system could potentially lead to exposure of sensitive information and can put security of other connected systems at risk. Analysis of vulnerability types in IoT-based system will help in the mitigation of any security related challenges. This analysis can motivate in the inclusion of secure design strategy during the manufacturing phase of IoT devices. Also these analysis can promote the use of cryptography techniques and secure coding practices in the software development phase for any product integrated to a IoT-based system. The main aim of this paper is to analyze common vulnerability types for IoT reported in the Common Vulnerabilities and Exposures List (CVE List) from 2019 till 2023. We also analyzed risk severity values of vulnerabilities which can give additional information to organization for creating priority to address these vulnerabilities. Vulnerability types are created to group related vulnerability for the analysis purposes. In our analysis we found the main reason for vulnerability in IoT-based applications and devices are related to Software bugs. In comparison with other IoT categories namely Devices, Application and Network vulnerabilities reported for Operating Systems flaws are very high.