Building-badge door controllers still run firmware last updated years ago, and the vendor has published critical fixes the city never applied. Which vulnerability class is primarily involved?
Select an answer to reveal the explanation.
Short Explanation
Badge controllers stuck on ancient firmware are a hardware/firmware vulnerability — physical access gear with a software underbelly that never got patched. Web XSS and SQLi live elsewhere. Inventory and update facility controllers like any other critical system.
Full Explanation
Outdated firmware on hardware devices is a hardware/firmware vulnerability class because embedded code may contain known flaws without endpoint-style patching habits. Objective 2.3 includes hardware and firmware vulnerabilities. XSS, SQLi, and watering-hole attacks are separate categories. Municipal physical-access systems require firmware lifecycle management and monitoring for vendor advisories.