Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Shlomi_Feldman
Employee
Employee

short Quiz

anyone got a clue, what is the sever vulnerability of the PLC in the image?

 

 
0 Kudos
2 Replies
Wolfgang
Authority
Authority

I believe, there is no username / password needed if services like HTTP, FTP are enabled on the device.

AccessControl is possible only by IP-address and this is not real problem to fake.

Wolfgang

0 Kudos
Shlomi_Feldman
Employee
Employee

you are close.

this PLC is old and full of known documented vulnerabilities. however this is not the issue.

Someone ever thought what is the operating system of this PLC? did you know that this PLC is running VxWorks operating system? Schneider electric just recently published this information, due to the fact that 11 different vulnerabilities were discovered to this operating system. The problem with the Momentum is more sever, as the Momentum family reached it end of sale and Schneider electric is not releasing security patches for it. as a result the only way to mitigate these vulnerabilities would be with external tools like our IPS

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events