Vertiv A.I CyberSecurity Scoring
Vertiv
Company Information
Website:http://www.Vertiv.com
Employees number:17,244
Number of followers:601,808
NAICS:335
Industry Type:Appliances, Electrical, and Electronics Manufacturing
Homepage:Vertiv.com
Vertiv Risk Score (AI oriented)
Between 750 and 799
VertivAppliances, Electrical, and Electronics Manufacturing
Updated:
14/09/2026
14/09/2026
787/1000
Fair
Baa
Vertiv Global Score (TPRM)
xxxx
VertivAppliances, Electrical, and Electronics Manufacturing
Score locked

VertivFair
Current Score
787Baa (FAIR)
01000
2 incidents
-4 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
787
AUGUST 2026
791
Vulnerability
13 Aug 2026 • Vertiv
Tridium, Vertiv, Trane, Liebert, Carrier and Delta Controls: 548 Internet-Exposed Building Automation Devices Run End-of-Life Products With No Future Security Patches
Critical Vulnerabilities Found in Internet-Exposed Building Automation Systems Near U.S. Data Centers
787
CRITICAL-4
LIEVERTRACARTRIDEL1786611575
Critical Vulnerabilities Found in Internet-Exposed Building Automation Systems Near U.S. Data Centers
A recent security study uncovered 548 internet-exposed building automation devices near U.S. data centers running end-of-life (EOL) software, leaving them permanently unpatched against known vulnerabilities. The affected systems Tridium NiagaraAX 3.x, Trane Tracer SC, and Carrier WebCTRL 7.0 control critical infrastructure such as HVAC, cooling, power monitoring, and environmental systems, posing severe risks to data center operations.
The research, part of a broader scan of industrial control systems (ICS) and building automation systems (BAS) near over 1,000 U.S. data center locations, identified 6,300 high-confidence internet-accessible devices after filtering 73,847 initial records. BACnet controllers (58%) and Fox/Niagara systems (23%) dominated the findings, with these legacy protocols often lacking modern security protections like authentication and encryption.
Among the 548 EOL devices, 434 were Tridium NiagaraAX systems, vulnerable to CVE-2012-4701, a critical flaw enabling directory traversal and remote code execution (RCE). Trane Tracer SC devices were linked to CVE-2021-38450 (CVSS 9.9), an authenticated RCE vulnerability, while 64 Carrier WebCTRL 7.0 devices were exposed to CVE-2024-8525 (CVSS 10.0), allowing unauthenticated RCE via file upload. The study also flagged 237 Delta Controls enteliBUS controllers still vulnerable to CVE-2019-9569, an RCE flaw exploitable through crafted BACnet traffic, despite a patch being available for years.
Geographically, California accounted for 39% of exposed devices, followed by the New York metro area. The risks are particularly acute for data centers, where a compromised BAS could disrupt cooling, trigger thermal shutdowns, or disable alarms, leading to service outages or physical damage. Vendors like Vertiv and Liebert, which specialize in precision cooling and power management, were highlighted as critical points of concern.
The findings underscore the challenges of patching operational technology (OT) and BAS, where legacy systems often remain exposed due to operational constraints. Unlike traditional IT systems, these devices directly control physical processes, making their compromise a high-impact threat to data center reliability.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
JULY 2026
791
JUNE 2026
791
MAY 2026
790
APRIL 2026
790
MARCH 2026
790
FEBRUARY 2026
790
JANUARY 2026
790
DECEMBER 2025
790
NOVEMBER 2025
790
OCTOBER 2025
790
SEPTEMBER 2024
785
Vulnerability
01 Sep 2024 • Vertiv
Tridium and Vertiv: 6,330 Internet-Exposed ICS Devices Near U.S. Data Centers Put Cooling and Power Systems at Risk
Thousands of Industrial Control Systems Exposed Near U.S. Data Centers, Raising Physical Security Risks
788
CRITICAL-3
TRIVER1786618728
Thousands of Industrial Control Systems Exposed Near U.S. Data Centers, Raising Physical Security Risks
A recent internet-exposure analysis has uncovered over 6,300 high-confidence industrial control system (ICS) and building automation devices accessible near 1,063 U.S. data centers, revealing a critical but often overlooked attack surface. The research, conducted by TrendAI Research using passive Shodan data, identified publicly reachable devices including BACnet controllers, Niagara Framework instances, PLC interfaces, and power-management systems within a one-kilometer radius of documented data center locations.
The findings highlight a fundamental security gap: while server networks may be hardened, the operational technology (OT) infrastructure responsible for cooling, power conditioning, and environmental monitoring often remains exposed. These systems regulate CRAC/CRAH units, chillers, UPS platforms, generators, and humidity controls, meaning a successful intrusion could allow adversaries to alter temperature setpoints, disrupt monitoring, lock out personnel, or trigger protective shutdowns leading to physical availability disruptions rather than just data loss.
Key vulnerabilities identified:
- BACnet devices accounted for 58% (3,664) of the exposed systems, while Niagara/Tridium systems made up 23% (1,453).
- 143 multi-protocol gateways (including 125 exposing both Niagara and BACnet) were found, acting as high-value aggregation points bridging HVAC, environmental, and electrical subsystems.
- Vertiv/Liebert devices, commonly used in data center cooling and power infrastructure, were also detected, suggesting some exposures may directly impact critical facility operations.
Geolocation data revealed clusters of exposed devices near hyperscale data centers in Silicon Valley, though IP-based proximity does not confirm exact physical locations. The study also challenged assumptions about newer infrastructure, finding that facilities permitted since 2021 had a 13.1% exposure rate nearly triple that of pre-2010 sites potentially due to rapid deployment and complex cooling demands outpacing OT security hardening.
The risks are not theoretical. Recent incidents, such as the 2024 attack on Arkansas City, Kansas’ water treatment facility, demonstrate how exposed ICS devices can lead to operational disruptions. U.S. agencies (CISA, NSA, FBI, and DOE) have warned that threat actors are actively developing tools to scan, compromise, and control ICS devices, including PLCs and OPC UA servers, often exploiting weak authentication and default credentials.
While the research did not involve direct probing, the findings underscore the need for data center operators to identify and secure all internet-reachable OT systems, enforce strict network segmentation, and monitor for abnormal control traffic. The exposure of these devices even if not directly inside data centers poses a regional risk, as adversaries could exploit them to disrupt critical infrastructure.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Vertiv ??
What was Vertiv's A.I Rankiteo Cyber Score in August 2026 ??
What was Vertiv's A.I Rankiteo Cyber Score in July 2026 ??
What was Vertiv's A.I Rankiteo Cyber Score in June 2026 ??
What was Vertiv's A.I Rankiteo Cyber Score in May 2026 ??
What was Vertiv's A.I Rankiteo Cyber Score in April 2026 ??
What was Vertiv's A.I Rankiteo Cyber Score in March 2026 ??
What was Vertiv's A.I Rankiteo Cyber Score in February 2026 ??
What was Vertiv's A.I Rankiteo Cyber Score in January 2026 ??
What was Vertiv's A.I Rankiteo Cyber Score in December 2025 ??
What was Vertiv's A.I Rankiteo Cyber Score in November 2025 ??
What was Vertiv's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on Vertiv's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Vertiv ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Vertiv's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?