Welcome to our new forum
All users of the legacy CODESYS Forums, please create a new account at account.codesys.com. But make sure to use the same E-Mail address as in the old Forum. Then your posts will be matched. Close

3S CoDeSys Security Vulnerabliites?

spfeif
2013-01-22
2019-01-17
  • spfeif - 2013-01-22

    Hello Roland maybe you can shed some light on this? An article surfaced in Control Magazine email updates titled "Analysis of 3s CoDeSys Security Vulnerabilities for Industrial Control System Professionals". Here is the excerpt:

    A number of security vulnerabilities in the CoDeSys Control Runtime System were disclosed in January 2012. In October 2012, fully functional attack tools were also released to the general public. While CoDeSys is not widely known in the SCADA and ICS field, its product is embedded in many popular PLCs and industrial controllers from such vendors as ABB, DEIF, Eaton, Hitachi, Schneider, Turck and Wago. This list of reputable vendors represents only a fraction of those that are potentially vulnerable, and includes devices used in all sectors of manufacturing and infrastructure. As a result, there is a risk that criminals or political groups may attempt to exploit them for either financial or ideological gain. This white paper summarizes the currently known facts about these vulnerabilities and associated attack tools.

    And the link here: http://www.controlglobal.com/whitepaper ... DeSys.html

    The download goes into great detail of accessing the 3s PLC.

    I understand if you don't want to keep this published and remove this post but I thought I should make you aware. My main question is not the vulnerability by why did this company target 3s specifically? Typically you find out that it was a commissioned project by AB, Siemens or Mitsubishi.

     
  • spfeif - 2013-01-22

    You know I remember reading that and didn't link the two together. Dummy me.

     
  • Strucc - 2013-01-22

    Yep, but the second part of your question is still interesting ... I don't hope to receive an answer for that on this forum.
    Anyway, I think the press release and 3S reaction was correct.

     
  • pboughner - 2019-01-17

    Zombie post, I know. But....

    Has this been resolved and how?

     

Log in to post a comment.