Legacy Systems | Obsolescence Does Not Equal Security

02 November 2023 | < 1 min | Cybersecurity, Decommissioning of Legacy Systems

Author: Yannick Thommassier, CISO of TJC Group

One might think that obsolete systems are no longer affected by new vulnerabilities because they have reached their last available update level and no security researcher or hacker will try to corrupt them.

However, this is not the case, as recent vulnerabilities discovered in a library can ultimately affect all present and past versions of it.

Let’s take as an example the recent vulnerabilities CVE-2023-38545 and CVE-2023-38546 concerning the cURL library[LP1] [LP2] .

These vulnerabilities are certainly not trivial to exploit and require several conditions to be met. However, they illustrate the problem posed by the discovery of a vulnerability impacting all previous versions of a library.

The correction of old versions of this technical library, embedded in many systems that have become obsolete over time and are no longer maintained, is not at all guaranteed.

One must then hope for a hypothetical backport of the corrections to the source code of these older versions of the library to remain secure. This can take time and cause resulting incompatibilities: upgrading a library on an obsolete system is not easy.

This is why maintaining an obsolete IT system, even if updated with the latest patches released by the vendor, is not secure over time. Therefore, the medium or long-term storage of data in these systems does not come without security risks.

It is therefore necessary to consider decommissioning these systems and transferring their data to a modern, robust, and up-to-date archiving service designed for this purpose, in order to preserve the data with the highest level of security.

The following article might also interest you:
https://www.tjc-group.com/fr/blogs/est-il-prudent-de-conserver-des-anciennes-donnees-dans-un-systeme-legacy-sap/