- CheckMates
- :
- Products
- :
- Quantum
- :
- IoT Protect
- :
- short Quiz
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
short Quiz
anyone got a clue, what is the sever vulnerability of the PLC in the image?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I believe, there is no username / password needed if services like HTTP, FTP are enabled on the device.
AccessControl is possible only by IP-address and this is not real problem to fake.
Wolfgang
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
you are close.
this PLC is old and full of known documented vulnerabilities. however this is not the issue.
Someone ever thought what is the operating system of this PLC? did you know that this PLC is running VxWorks operating system? Schneider electric just recently published this information, due to the fact that 11 different vulnerabilities were discovered to this operating system. The problem with the Momentum is more sever, as the Momentum family reached it end of sale and Schneider electric is not releasing security patches for it. as a result the only way to mitigate these vulnerabilities would be with external tools like our IPS