Twenty-three zero day holes found in SCADA systems

By

Systems open to remote code execution, denial of service attacks.

Researchers claimed to have found 23 vulnerabilities in SCADA  software that expose machinery to the risk of either remote code execution or denial-of-service attacks.

Twenty-three zero day holes found in SCADA systems

Exodus Intelligence research vice president Aaron Portnoy found the holes affecting SCADA gear from Rockwell Automation, Schneider Electric, Indusoft, RealFlex and Eaton.

Each was reported to the US ICS-Cert.

“The most interesting thing about these bugs was how trivial they were to find," Portnoy said. \

"The first exploitable zero-day took a mere seven minutes to discover from the time the software was installed.

“For someone who has spent a lot of time auditing software used in the enterprise and consumer space, SCADA was absurdly simple in comparison."

He said it was difficult to locate the SCADA software and planned to ask the ICS-Cert to establish a repository in which the applciations could be studied for vulnerability research.

The finds follow a series of SCADA vulnerability discoveries by research outfit ReVuln which privately sold the findings to its customers.

This article originally appeared at scmagazineuk.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, UK edition
Tags:

Most Read Articles

Woolworths' CSO is Optus-bound

Woolworths' CSO is Optus-bound

Australia's super funds told to assess authentication controls

Australia's super funds told to assess authentication controls

Hackers abuse modified Salesforce app to steal data, extort companies

Hackers abuse modified Salesforce app to steal data, extort companies

The Northern Beaches Women's Shelter hones focus on tech-enabled abuse

The Northern Beaches Women's Shelter hones focus on tech-enabled abuse

Log In

  |  Forgot your password?