Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Vertiv

Vertiv Vendor Cyber Rating & Cyber Score

Vertiv.com

Vertiv is a global leader in critical digital infrastructure for applications in data centers, communication networks, and commercial and industrial environments. As businesses, industries, and communities become more connected, we pioneer and deliver end-to-end power and cooling technologies to help our customers stay resilient, optimized, and future-ready. With our industry-leading innovative technologies and global services network, we are fueling the revolution of the digital world - keeping technology ecosystems running efficiently and without interruption. Vertiv is supercharging data’s potential; accelerating the pace of technology, raising the bar for accelerated compute and redefining the limits of densification. The world


Vertiv A.I CyberSecurity Scoring

Vertiv
Company Information
Website:http://www.Vertiv.com
Employees number:17,244
Number of followers:601,808
NAICS:335
Industry Type:Appliances, Electrical, and Electronics Manufacturing
Homepage:Vertiv.com
Vertiv Risk Score (AI oriented)
Between 750 and 799
logo
VertivAppliances, Electrical, and Electronics Manufacturing
Updated:
14/09/2026
787/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Vertiv Global Score (TPRM)
xxxx
logo
VertivAppliances, Electrical, and Electronics Manufacturing
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

VertivFair
Current Score
787Baa (FAIR)
01000
2 incidents
-4 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
787Before Incident
AUGUST 2026
791Before Incident
Vulnerability
13 Aug 2026Vertiv
Tridium, Vertiv, Trane, Liebert, Carrier and Delta Controls: 548 Internet-Exposed Building Automation Devices Run End-of-Life Products With No Future Security Patches

Critical Vulnerabilities Found in Internet-Exposed Building Automation Systems Near U.S. Data Centers

787After Incident
CRITICAL-4
LIEVERTRACARTRIDEL1786611575
Critical Vulnerabilities Found in Internet-Exposed Building Automation Systems Near U.S. Data Centers A recent security study uncovered 548 internet-exposed building automation devices near U.S. data centers running end-of-life (EOL) software, leaving them permanently unpatched against known vulnerabilities. The affected systems Tridium NiagaraAX 3.x, Trane Tracer SC, and Carrier WebCTRL 7.0 control critical infrastructure such as HVAC, cooling, power monitoring, and environmental systems, posing severe risks to data center operations. The research, part of a broader scan of industrial control systems (ICS) and building automation systems (BAS) near over 1,000 U.S. data center locations, identified 6,300 high-confidence internet-accessible devices after filtering 73,847 initial records. BACnet controllers (58%) and Fox/Niagara systems (23%) dominated the findings, with these legacy protocols often lacking modern security protections like authentication and encryption. Among the 548 EOL devices, 434 were Tridium NiagaraAX systems, vulnerable to CVE-2012-4701, a critical flaw enabling directory traversal and remote code execution (RCE). Trane Tracer SC devices were linked to CVE-2021-38450 (CVSS 9.9), an authenticated RCE vulnerability, while 64 Carrier WebCTRL 7.0 devices were exposed to CVE-2024-8525 (CVSS 10.0), allowing unauthenticated RCE via file upload. The study also flagged 237 Delta Controls enteliBUS controllers still vulnerable to CVE-2019-9569, an RCE flaw exploitable through crafted BACnet traffic, despite a patch being available for years. Geographically, California accounted for 39% of exposed devices, followed by the New York metro area. The risks are particularly acute for data centers, where a compromised BAS could disrupt cooling, trigger thermal shutdowns, or disable alarms, leading to service outages or physical damage. Vendors like Vertiv and Liebert, which specialize in precision cooling and power management, were highlighted as critical points of concern. The findings underscore the challenges of patching operational technology (OT) and BAS, where legacy systems often remain exposed due to operational constraints. Unlike traditional IT systems, these devices directly control physical processes, making their compromise a high-impact threat to data center reliability.
INCIDENT DETAILS -
TYPE
Vulnerability Exposure
IMPACT
Systems Affected: Building automation systems (BAS), HVAC, cooling, power monitoring, environmental systemsDowntime: Potential thermal shutdowns or service outagesOperational Impact: Disruption of critical data center infrastructure, potential physical damageBrand Reputation Impact: Potential reputational damage due to operational disruptions
JULY 2026
791Before Incident
JUNE 2026
791Before Incident
MAY 2026
790Before Incident
APRIL 2026
790Before Incident
MARCH 2026
790Before Incident
FEBRUARY 2026
790Before Incident
JANUARY 2026
790Before Incident
DECEMBER 2025
790Before Incident
NOVEMBER 2025
790Before Incident
OCTOBER 2025
790Before Incident
SEPTEMBER 2024
785Before Incident
Vulnerability
01 Sep 2024Vertiv
Tridium and Vertiv: 6,330 Internet-Exposed ICS Devices Near U.S. Data Centers Put Cooling and Power Systems at Risk

Thousands of Industrial Control Systems Exposed Near U.S. Data Centers, Raising Physical Security Risks

788After Incident
CRITICAL-3
TRIVER1786618728
Thousands of Industrial Control Systems Exposed Near U.S. Data Centers, Raising Physical Security Risks A recent internet-exposure analysis has uncovered over 6,300 high-confidence industrial control system (ICS) and building automation devices accessible near 1,063 U.S. data centers, revealing a critical but often overlooked attack surface. The research, conducted by TrendAI Research using passive Shodan data, identified publicly reachable devices including BACnet controllers, Niagara Framework instances, PLC interfaces, and power-management systems within a one-kilometer radius of documented data center locations. The findings highlight a fundamental security gap: while server networks may be hardened, the operational technology (OT) infrastructure responsible for cooling, power conditioning, and environmental monitoring often remains exposed. These systems regulate CRAC/CRAH units, chillers, UPS platforms, generators, and humidity controls, meaning a successful intrusion could allow adversaries to alter temperature setpoints, disrupt monitoring, lock out personnel, or trigger protective shutdowns leading to physical availability disruptions rather than just data loss. Key vulnerabilities identified: - BACnet devices accounted for 58% (3,664) of the exposed systems, while Niagara/Tridium systems made up 23% (1,453). - 143 multi-protocol gateways (including 125 exposing both Niagara and BACnet) were found, acting as high-value aggregation points bridging HVAC, environmental, and electrical subsystems. - Vertiv/Liebert devices, commonly used in data center cooling and power infrastructure, were also detected, suggesting some exposures may directly impact critical facility operations. Geolocation data revealed clusters of exposed devices near hyperscale data centers in Silicon Valley, though IP-based proximity does not confirm exact physical locations. The study also challenged assumptions about newer infrastructure, finding that facilities permitted since 2021 had a 13.1% exposure rate nearly triple that of pre-2010 sites potentially due to rapid deployment and complex cooling demands outpacing OT security hardening. The risks are not theoretical. Recent incidents, such as the 2024 attack on Arkansas City, Kansas’ water treatment facility, demonstrate how exposed ICS devices can lead to operational disruptions. U.S. agencies (CISA, NSA, FBI, and DOE) have warned that threat actors are actively developing tools to scan, compromise, and control ICS devices, including PLCs and OPC UA servers, often exploiting weak authentication and default credentials. While the research did not involve direct probing, the findings underscore the need for data center operators to identify and secure all internet-reachable OT systems, enforce strict network segmentation, and monitor for abnormal control traffic. The exposure of these devices even if not directly inside data centers poses a regional risk, as adversaries could exploit them to disrupt critical infrastructure.
INCIDENT DETAILS -
TYPE
Exposure of Critical Infrastructure
IMPACT
Systems Affected: Industrial control systems (ICS), building automation systems, power-management systemsDowntime: Potential physical availability disruptionsOperational Impact: Alteration of temperature setpoints, disruption of monitoring, lockout of personnel, protective shutdowns

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Vertiv ?
?
What was Vertiv's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Vertiv's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Vertiv's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Vertiv's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Vertiv's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Vertiv's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Vertiv's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Vertiv's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Vertiv's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Vertiv's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Vertiv's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on Vertiv's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Vertiv ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Vertiv's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?