{"id":11423,"date":"2025-10-14T15:12:09","date_gmt":"2025-10-14T13:12:09","guid":{"rendered":"https:\/\/limessecurity.ninja\/?p=11423"},"modified":"2026-03-02T21:05:51","modified_gmt":"2026-03-02T20:05:51","slug":"breaching-the-ot-perimeter-authentication-bypass-in-claroty-secure-remote-access-cve-2025-54603","status":"publish","type":"post","link":"https:\/\/limessecurity.com\/de\/breaching-the-ot-perimeter-authentication-bypass-in-claroty-secure-remote-access-cve-2025-54603\/","title":{"rendered":"Breaching the OT-Perimeter: Authentication Bypass in Claroty Secure Remote Access (CVE-2025-54603)"},"content":{"rendered":"[vc_row type=&#8220;in_container&#8220; full_screen_row_position=&#8220;middle&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; scene_position=&#8220;center&#8220; text_color=&#8220;dark&#8220; text_align=&#8220;left&#8220; row_border_radius=&#8220;none&#8220; row_border_radius_applies=&#8220;bg&#8220; row_position_desktop=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; overlay_strength=&#8220;0.3&#8243; gradient_direction=&#8220;left_to_right&#8220; shape_divider_position=&#8220;bottom&#8220; bg_image_animation=&#8220;none&#8220;][vc_column column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; column_position=&#8220;default&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220;][vc_column_text css=&#8220;&#8220; text_direction=&#8220;default&#8220;]Remote-Access L\u00f6sungen stellen eine der kritischsten Angriffsfl\u00e4chen in OT-Umgebungen dar. Unternehmen nutzen zwar L\u00f6sungen, die von einfachen Jump-Hosts bis hin zu dedizierten OT-f\u00e4higen Plattformen reichen, doch die Sicherheit dieser Gateways wirkt sich direkt auf die Sicherheit industrieller Komponenten und Netzwerke aus.<br \/>\nClaroty Secure Remote Access (SRA) ist eine Premium-L\u00f6sung, die speziell f\u00fcr OT-Umgebungen entwickelt wurde und den Zugriff auf kritische, industrielle Systeme verwaltet. Bei einem routinem\u00e4\u00dfigen Pentest entdeckte Limes Security CVE-2025-54603 \u2013 eine kritische Sicherheitsl\u00fccke in der On-Premise OpenID Connect (OIDC)-Implementierung.[\/vc_column_text][\/vc_column][\/vc_row][vc_row type=&#8220;full_width_content&#8220; full_screen_row_position=&#8220;middle&#8220; column_margin=&#8220;5px&#8220; equal_height=&#8220;yes&#8220; content_placement=&#8220;top&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; scene_position=&#8220;center&#8220; top_padding=&#8220;2%&#8220; constrain_group_1=&#8220;yes&#8220; bottom_padding=&#8220;2%&#8220; left_padding_desktop=&#8220;0&#8243; constrain_group_2=&#8220;yes&#8220; right_padding_desktop=&#8220;0&#8243; left_padding_phone=&#8220;14px&#8220; constrain_group_6=&#8220;yes&#8220; right_padding_phone=&#8220;14px&#8220; top_margin=&#8220;0&#8243; bottom_margin=&#8220;0&#8243; text_color=&#8220;dark&#8220; text_align=&#8220;left&#8220; row_border_radius=&#8220;none&#8220; row_border_radius_applies=&#8220;bg&#8220; zindex=&#8220;10&#8243; row_position_desktop=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; advanced_gradient_angle=&#8220;0&#8243; overlay_strength=&#8220;0.3&#8243; gradient_direction=&#8220;left_to_right&#8220; shape_divider_position=&#8220;bottom&#8220; bg_image_animation=&#8220;none&#8220; shape_type=&#8220;&#8220; gradient_type=&#8220;default&#8220;][vc_column top_padding_desktop=&#8220;0&#8243; constrain_group_100=&#8220;yes&#8220; bottom_padding_desktop=&#8220;0&#8243; left_padding_desktop=&#8220;0&#8243; constrain_group_101=&#8220;yes&#8220; right_padding_desktop=&#8220;0&#8243; top_padding_tablet=&#8220;8vw&#8220; constrain_group_102=&#8220;yes&#8220; bottom_padding_tablet=&#8220;8vw&#8220; left_padding_tablet=&#8220;8vw&#8220; constrain_group_103=&#8220;yes&#8220; right_padding_tablet=&#8220;8vw&#8220; bottom_margin_tablet=&#8220;20&#8243; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;0px&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;15px&#8220; column_link_target=&#8220;_self&#8220; column_position=&#8220;default&#8220; overflow=&#8220;hidden&#8220; advanced_gradient_angle=&#8220;0&#8243; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_color=&#8220;rgba(10,10,10,0.1)&#8220; column_border_style=&#8220;solid&#8220; gradient_type=&#8220;default&#8220; column_padding_type=&#8220;advanced&#8220;][image_with_animation image_url=&#8220;11425&#8243; image_size=&#8220;full&#8220; max_width=&#8220;100%&#8220; max_width_mobile=&#8220;default&#8220; animation_type=&#8220;entrance&#8220; animation=&#8220;None&#8220; animation_movement_type=&#8220;transform_y&#8220; hover_animation=&#8220;none&#8220; alignment=&#8220;&#8220; border_radius=&#8220;none&#8220; box_shadow=&#8220;none&#8220; image_loading=&#8220;default&#8220;][divider line_type=&#8220;No Line&#8220; custom_height=&#8220;20&#8243;][\/vc_column][\/vc_row][vc_row type=&#8220;in_container&#8220; full_screen_row_position=&#8220;middle&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; scene_position=&#8220;center&#8220; top_padding=&#8220;1%&#8220; bottom_padding=&#8220;1%&#8220; text_color=&#8220;dark&#8220; text_align=&#8220;left&#8220; row_border_radius=&#8220;none&#8220; row_border_radius_applies=&#8220;bg&#8220; row_position_desktop=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; overlay_strength=&#8220;0.3&#8243; gradient_direction=&#8220;left_to_right&#8220; shape_divider_position=&#8220;bottom&#8220; bg_image_animation=&#8220;none&#8220; gradient_type=&#8220;default&#8220; shape_type=&#8220;&#8220;][vc_column column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; column_position=&#8220;default&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220;][vc_column_text css=&#8220;&#8220; text_direction=&#8220;default&#8220;]\n<h3>CVE-2025-54603<\/h3>\n[\/vc_column_text][divider line_type=&#8220;No Line&#8220;][vc_row_inner equal_height=&#8220;yes&#8220; content_placement=&#8220;top&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; text_align=&#8220;center&#8220; row_position=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; pointer_events=&#8220;all&#8220;][vc_column_inner column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; top_margin=&#8220;0&#8243; constrain_group_1=&#8220;yes&#8220; bottom_margin=&#8220;0&#8243; left_margin=&#8220;0&#8243; constrain_group_2=&#8220;yes&#8220; right_margin=&#8220;0&#8243; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; overflow=&#8220;visible&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/3&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220; column_padding_type=&#8220;default&#8220; gradient_type=&#8220;default&#8220;][vc_pie value=&#8220;95&#8243; label_value=&#8220;9.5&#8243; color=&#8220;#9e1510&#8243; css=&#8220;.vc_custom_1760449086215{background-position: center !important;background-repeat: no-repeat !important;background-size: cover !important;}&#8220; el_id=&#8220;orangePieChart&#8220; title=&#8220;CVSS v4.0 Score&#8220; units=&#8220;\/high&#8220;][\/vc_column_inner][vc_column_inner column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; centered_text=&#8220;true&#8220; desktop_text_alignment=&#8220;left&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; overflow=&#8220;visible&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;2\/3&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220; column_padding_type=&#8220;default&#8220; gradient_type=&#8220;default&#8220;][nectar_icon_list color=&#8220;default&#8220; direction=&#8220;vertical&#8220; icon_size=&#8220;small&#8220; icon_style=&#8220;border&#8220;][nectar_icon_list_item icon_type=&#8220;icon&#8220; text_full_html=&#8220;simple&#8220; title=&#8220;List Item&#8220; id=&#8220;1772481928467-8&#8243; icon_fontawesome=&#8220;fa fa-thumb-tack&#8220; header=&#8220;Produkt:&#8220; text=&#8220;Claroty SRA&#8220; tab_id=&#8220;1772481928468-10&#8243;][\/nectar_icon_list_item][nectar_icon_list_item icon_type=&#8220;icon&#8220; text_full_html=&#8220;simple&#8220; title=&#8220;List Item&#8220; id=&#8220;1772481928481-2&#8243; icon_fontawesome=&#8220;fa fa-thumb-tack&#8220; header=&#8220;Betroffene Versionen:&#8220; text=&#8220;Version 3.3.0 to 4.0.2&#8243; tab_id=&#8220;1772481928482-6&#8243;][\/nectar_icon_list_item][nectar_icon_list_item icon_type=&#8220;icon&#8220; text_full_html=&#8220;html&#8220; title=&#8220;List Item&#8220; id=&#8220;1772481928491-5&#8243; icon_fontawesome=&#8220;fa fa-thumb-tack&#8220; header=&#8220;CVE \/ Vendor ID:&#8220; tab_id=&#8220;1772481928492-4&#8243;]\n<p class=\"page-heading\"><a href=\"https:\/\/claroty.com\/product-security\/oidc-configurations-in-claroty-secure-access\" target=\"_blank\" rel=\"noopener\">CVE-2025-54603<\/a><\/p>\n[\/nectar_icon_list_item][nectar_icon_list_item icon_type=&#8220;icon&#8220; text_full_html=&#8220;simple&#8220; title=&#8220;List Item&#8220; id=&#8220;1772481928497-5&#8243; icon_fontawesome=&#8220;fa fa-thumb-tack&#8220; header=&#8220;Gefunden von:&#8220; text=&#8220;Nino F\u00fcrthauer &amp; Benjamin Oberdorfer, Limes Security<br \/>\nmit Fabian Burkhart&#8220; tab_id=&#8220;1772481928497-2&#8243;][\/nectar_icon_list_item][\/nectar_icon_list][\/vc_column_inner][\/vc_row_inner][nectar_btn size=&#8220;small&#8220; button_style=&#8220;regular&#8220; button_color_2=&#8220;Accent-Color&#8220; icon_family=&#8220;none&#8220; text=&#8220;CVSS:4.0\/AV:N\/AC:L\/AT:P\/PR:N\/UI:N\/VC:H\/VI:H\/VA:H\/SC:H\/SI:H\/SA:H&#8220; url=&#8220;https:\/\/www.first.org\/cvss\/calculator\/4-0#CVSS:4.0\/AV:N\/AC:L\/AT:P\/PR:N\/UI:N\/VC:H\/VI:H\/VA:H\/SC:H\/SI:H\/SA:H&#8220;][\/vc_column][vc_column column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; column_position=&#8220;default&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220;][\/vc_column][\/vc_row][vc_row type=&#8220;in_container&#8220; full_screen_row_position=&#8220;middle&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; scene_position=&#8220;center&#8220; text_color=&#8220;dark&#8220; text_align=&#8220;left&#8220; row_border_radius=&#8220;none&#8220; row_border_radius_applies=&#8220;bg&#8220; row_position_desktop=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; overlay_strength=&#8220;0.3&#8243; gradient_direction=&#8220;left_to_right&#8220; shape_divider_position=&#8220;bottom&#8220; bg_image_animation=&#8220;none&#8220;][vc_column column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; column_position=&#8220;default&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220;][vc_column_text css=&#8220;&#8220; text_direction=&#8220;default&#8220;]Der Fehler findet sich im OIDC-Feature, das von Claroty SRA-Versionen 3.3.0 bis 4.0.2 verwendet wird. Unter bestimmten Bedingungen k\u00f6nnen Angreifer:<\/p>\n<ul>\n<li>nicht autorisierte Benutzer mit Basisberechtigungen erstellen (Hinweis: Basisbenutzer haben KEINE Berechtigungen im System, au\u00dfer sich anzumelden).<\/li>\n<li>sich als vorhandene OIDC-User ausgeben und deren Zugriffsrechte \u00fcbernehmen.<\/li>\n<li>der Gruppe \u201eAdministratoren\u201d beitreten und vollst\u00e4ndige administrative Kontrolle erhalten.<\/li>\n<\/ul>\n<p>Wichtig zu wissen ist, dass diese Schwachstelle auch nach Deaktivierung von OIDC bestehen bleibt \u2013 die anf\u00e4llige Konfiguration bleibt bis zur ausdr\u00fccklichen Behebung bestehen und erm\u00f6glicht die Umgehung der 2FA.<\/p>\n<h3><\/h3>\n<h3>Aktueller Status<\/h3>\n<p>Das Problem wurde bereits von Claroty behoben und f\u00fcr alle betroffenen Versionen wurden Patches bereitgestellt. Wir empfehlen allen Usern der Claroty SRA-Versionen 3.3.0 bis 4.0.2, diese umgehend zu installieren.<\/p>\n<h3><\/h3>\n<h3>OT Impact Analysis<\/h3>\n<p>Die Umgehung der Authentifizierung ist im OT-Kontext besonders schwerwiegend:<\/p>\n<ul>\n<li><b>Direkter Zugriff auf Systeme:<\/b> Durch kompromittierte SRA erhalten Angreifer authentifizierten Zugriff auf verwaltete OT-Ger\u00e4te.<\/li>\n<li><b>Lateral Movement:<\/b> Der administrative Zugriff erm\u00f6glicht Konfigurations\u00e4nderungen und das Sammeln von Anmeldedaten.<\/li>\n<li><b>Persistenz:<\/b> Angreifer k\u00f6nnen Backdoor-Konten f\u00fcr langfristigen Zugriff erstellen.<\/li>\n<li><b>Verf\u00e4lschung von Logfiles:<\/b> Aktionen erscheinen durch gef\u00e4lschte Identit\u00e4ten als legitim.<\/li>\n<\/ul>\n<p>Im Gegensatz zu herk\u00f6mmlichen IT-Security Schwachstellen, gef\u00e4hrden OT-Schwachstellen physische Prozesse, Safety-Systeme und die Betriebskontinuit\u00e4t.<\/p>\n<p>Bemerkenswerterweise hat Limes Security 100 % der \u00f6ffentlich bekannten Schwachstellen in Claroty SRA (Stand: 08.2025) identifiziert \u2013 sowohl die LPE 2021 als auch diese Umgehung der Authentifizierung wurden durch unsere Security Assessments entdeckt, was die Bedeutung unabh\u00e4ngiger Security-Tests bei OT-L\u00f6sungen unterstreicht.<\/p>\n<h3><\/h3>\n<h3>Globale Angriffsoberfl\u00e4che<\/h3>\n<p>Mithilfe der AlphaStrike-Plattform, haben wir weltweit etwa 220 Claroty SRA-Instanzen identifiziert, die \u00fcber das Internet zug\u00e4nglich sind. Diese relativ geringe Anzahl spiegelt den Premium-Charakter der L\u00f6sung wider. Allerdings sch\u00fctzt jede exponierte Instanz potenziell den Zugriff auf kritische Infrastrukturen oder OT-Assets, die f\u00fcr den Betreiber von entscheidender Bedeutung sind.<\/p>\n<p>Es war nicht m\u00f6glich zu \u00fcberpr\u00fcfen, ob all diese Instanzen anf\u00e4llig waren, ohne diese aktiv auszunutzen!<\/p>\n<p>Es gilt auch zu ber\u00fccksichtigen, dass diese 220 F\u00e4lle nur die mit dem Internet verbundenen Systeme darstellen. Nach unserer Erfahrung setzt die Mehrheit der Claroty SRA-Kunden die L\u00f6sung intern ein, wobei der Zugriff nur \u00fcber VPNs oder interne Netzwerke m\u00f6glich ist. Dies reduziert zwar die Angriffsoberfl\u00e4che f\u00fcr externe Bedrohungen erheblich, allerdings bleibt die Schwachstelle f\u00fcr Insider-Bedrohungen oder Angreifer, die bereits einen ersten Netzwerkzugang erlangt haben, bestehen.<\/p>\n<h3><\/h3>\n<h3>Key Takeaway<\/h3>\n<p>F\u00fcr OT-Betreiber best\u00e4tigt dies, dass Fernzugriffsl\u00f6sungen strengen Sicherheitspr\u00fcfungen unterzogen werden m\u00fcssen und dass aufgrund ihrer privilegierten Position in der Netzwerkarchitektur, zus\u00e4tzliche Security-Ma\u00dfnahmen erforderlich sind, sollten Schwachstellen in diesen L\u00f6sungen auftreten.[\/vc_column_text][\/vc_column][\/vc_row][vc_row type=&#8220;in_container&#8220; full_screen_row_position=&#8220;middle&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; scene_position=&#8220;center&#8220; text_color=&#8220;dark&#8220; text_align=&#8220;left&#8220; row_border_radius=&#8220;none&#8220; row_border_radius_applies=&#8220;bg&#8220; row_position_desktop=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; overlay_strength=&#8220;0.3&#8243; gradient_direction=&#8220;left_to_right&#8220; shape_divider_position=&#8220;bottom&#8220; bg_image_animation=&#8220;none&#8220;][vc_column column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; column_position=&#8220;default&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220;][divider line_type=&#8220;No Line&#8220; custom_height=&#8220;30&#8243;][\/vc_column][\/vc_row]\n","protected":false},"excerpt":{"rendered":"<p>[vc_row type=&#8220;in_container&#8220; full_screen_row_position=&#8220;middle&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; scene_position=&#8220;center&#8220; text_color=&#8220;dark&#8220; text_align=&#8220;left&#8220; row_border_radius=&#8220;none&#8220; row_border_radius_applies=&#8220;bg&#8220; row_position_desktop=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; overlay_strength=&#8220;0.3&#8243; gradient_direction=&#8220;left_to_right&#8220; shape_divider_position=&#8220;bottom&#8220; bg_image_animation=&#8220;none&#8220;][vc_column column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220;&#8230;<\/p>\n","protected":false},"author":5,"featured_media":11425,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[281],"tags":[],"class_list":{"0":"post-11423","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-advisories"},"_links":{"self":[{"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/posts\/11423","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/comments?post=11423"}],"version-history":[{"count":0,"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/posts\/11423\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/media\/11425"}],"wp:attachment":[{"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/media?parent=11423"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/categories?post=11423"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/tags?post=11423"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}