Saturday, March 15, 2014

All your PLC are belong to us (2)

Fixes for Siemens S7 1500 PLC are published.
Thanks to Yury Goltsev, Ilya Karpov, Alexey Osipov, Dmitry Serebryannikov and Alex Timorin.
There are a lot of, but combination of Authentication bypass (INSUFFICIENT ENTROPY/CVE-2014-2251) and Hardcoded SNMP community string (once again)/NO-CVE/Unfixed is the best.

Links



http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-456423.pdf

http://ics-cert.us-cert.gov/advisories/ICSA-14-073-01

Some good stuff for 1200/TIA portal in queue.

Enjoy...

1 comment:

  1. Happy to see your blog as it is just what I’ve looking for and excited to read all the posts. I am looking forward to another great article from you. For More Information Visit Our Website: Best PLC Training in Chennai

    ReplyDelete