Comment CISA gave an updated statement (Score 2) 63
CISA has told The Register the train issue may not as bad as it sounds, and confirmed work is underway to get a replacement system deployed.
"[This] vulnerability has been understood and monitored by rail sector stakeholders for over a decade, CISA acting executive assistant director for cybersecurity Chris Butera told us in an email. "To exploit this issue, a threat actor would require physical access to rail lines, deep protocol knowledge, and specialized equipment, which limits the feasibility of widespread exploitation."
That last sentence: You mean like the guy who found this? In 2012? With outdated SDR equipment?