Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Shlomi_Feldman
Employee Alumnus
Employee Alumnus

short Quiz

anyone got a clue, what is the sever vulnerability of the PLC in the image?

 

 
0 Kudos
2 Replies
Wolfgang
Authority
Authority

I believe, there is no username / password needed if services like HTTP, FTP are enabled on the device.

AccessControl is possible only by IP-address and this is not real problem to fake.

Wolfgang

0 Kudos
Shlomi_Feldman
Employee Alumnus
Employee Alumnus

you are close.

this PLC is old and full of known documented vulnerabilities. however this is not the issue.

Someone ever thought what is the operating system of this PLC? did you know that this PLC is running VxWorks operating system? Schneider electric just recently published this information, due to the fact that 11 different vulnerabilities were discovered to this operating system. The problem with the Momentum is more sever, as the Momentum family reached it end of sale and Schneider electric is not releasing security patches for it. as a result the only way to mitigate these vulnerabilities would be with external tools like our IPS

Upcoming Events

    CheckMates Events