Project
Wurm Beteiligungs GmbH

Execution of pentests with different target scenarios

The Wurm Group is a leading provider of automation systems for refrigeration systems and technical building management in the retail sector in Germany and Europe.

Back in 2018, secunet carried out several penetration tests on the externally and internally accessible IT systems at Wurm Beteiligungs GmbH in order to check the security level. The analyses culminated in an internal perpetrator simulation in which the possibilities of an attacker gaining access to the premises of Wurm Beteiligungs GmbH were tested.

From 2022, control devices that collect and transmit consolidated data from Wurm systems in customer environments were also analyzed. The analyzed devices offer several services that can be accessed via an Ethernet interface. The analysis was used to check what options an attacker with access to the Ethernet interface has to use the device without authorization.