At Danfoss, we prioritize product security and are committed to protecting our users by adhering to evolving global cybersecurity regulations and standards, such as RED and NIST.
To that end, we have phased out legacy products in the past and will continue to do so for products that can no longer be updated to meet the latest regulatory requirements or industry standards.
As part of this commitment, Danfoss ECS has achieved IEC 62443-4-1 certification for its secure development lifecycle process, ensuring that security is a priority in both current and new product development. This certification demonstrates our dedication to providing secure, future ready solutions.
In alignment with these standards, and driven by recent European cybersecurity legislation, we are enforcing a hard End of Service (EoS) policy for legacy products that have already reached their End of Life (EoL), as previously announced.
These products can no longer meet current regulatory or security requirements. Continuing to provide services for these products would place Danfoss under new legal obligations to maintain security updates.
For example:
- The AK SM 800 was officially declared End of Life in May 2021, as noted in the Product Note: System Manager Portfolio – Phase outs. According to that communication, End of Life status leads to End of Service. Although Danfoss extended minor support, such as EDx file updates, this is no longer permitted under the new legislation. Despite this, we have provided updates to EDx files, which constitute a violation of legislative requirements for an End-of-Life product.
We strongly encourage customers to contact Danfoss sales offices to discuss potential replacement projects. Danfoss will cease all services for legacy products. If you are still using one of the affected products, we highly recommend reaching out to your local Danfoss sales representative to explore secure replacement options.
Examples of affected products include
AK SM 800, AK SM 350, AK SM 720, PI 100/200/300 series, AKM, AKA, AK SC 255, AK SC 355, EM 100, AK CS, and EM 800.
Additionally, there may be other products that were phased out more than two years ago. For instance, the SC255 and SC355 were phased out in 2016, and the EM 100 in 2013, which is why we are reinforcing the End of Service for products phased out more than two years ago.
Additional technical explanation
Rising product vulnerabilities necessitate prompt action to prevent data breaches, as the cybersecurity landscape continues to evolve. Since all software contains bugs, legacy systems lacking modern security measures become increasingly susceptible to exploitation. Recent trends underscore how these vulnerabilities can:
- Enable unauthorized access
- Cause denial of service (DoS)
- Disrupt operations or system availability
- Lead to data leakage or manipulation
The ability to promptly address vulnerabilities and resolve them through a professional process is crucial at every stage of the product or service lifecycle. Over the past year, there has been a noticeable increase in reports from external security researchers highlighting vulnerabilities in Danfoss products. This trend aligns with the growing emphasis on security and upcoming regulations, and it is anticipated that it will continue to rise in the future.
Real world examples
• Russia, 2022:
Sixteen supermarkets using AK SM 800 were targeted by cyberattacks at the start of the war. The hacker group Anonymous publicly encouraged disrupting Russian infrastructure.
→ Recommended action: Migrate to AK SM 800A with hardened security features.
• Israel, 2022:
Forty stores were hacked. All affected stores lacked proper firewall or VPN protection, and all used AK SM 800. Only the SM800 was affected; however, our sales team reported that a mix of SM800 and SM800A units was installed.
→ Recommended action: Replace with AK SM 800A and follow secure installation practices.
• May 2023 – Danfoss AK EM 100:
An external security researcher discovered several serious issues in the Danfoss AK EM 100 product that could allow hackers to access and take control of the system. As the AK EM 100 is no longer supported, Danfoss identified six specific issues (CVEs) and advised immediate decommissioning and migration.
→ Recommended action: Upgrade to AK SM 800A with Alsense Cloud.
• August 2023 – Danfoss AK SM 800A:
An external security researcher reported that the Danfoss AK SM 800A product had vulnerabilities due to inadequate restrictions and input handling, potentially allowing hackers to take over the system. In response, Danfoss identified three specific issues and advised customers to resolve the problem by installing the latest software version, which at that time was V3.3.
→ This highlights the importance of using supported, actively maintained products