ARN

Zero-Day Flaws Discovered in SCADA Systems

An Italian security researcher recently disclosed details about several zero-day vulnerabilities in supervisory control and data acquisition (SCADA) systems from several vendors.

The discovery -- the second such disclosure by researcher Luigi Auriemma this year -- is likely to reinforce concerns about weaknesses in the nation's critical infrastructure.

The most recent vulnerabilities affect SCADA products from Rockwell Automation, Cogent DataHub, Measuresoft and Progea, among other vendors.

Most of the vulnerabilities are remote code execution flaws that allow attackers to run code on the systems, and some of the flaws are easy to exploit, Auriemma said. At least three of the vendors have already issued fixes, and Rockwell is working on one, he said.

SCADA systems are used to control critical equipment at power plants, manufacturing facilities, water treatment plants and elsewhere. Security analysts fear that attacks against such systems could cripple critical infrastructure, including the electric grid and water supplies.

The Stuxnet worm, which exploited a weakness in a Siemens control system to disrupt operations at an Iranian nuclear power plant, is often cited as an example of the kind of threat that can be unleashed upon vulnerable SCADA systems.

This version of this story was originally published in Computerworld's print edition. It was adapted from an article that appeared earlier on Computerworld.com.

Read more about security in Computerworld's Security Topic Center.

Nominations for the 2012 ARN IT Industry Awards open on Tuesday, June 12.

More about: Rockwell, Siemens, Topic
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the ARN comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: Rockwell Automation, security, siemens
ARN Directory | Distributors relevant to this article
Avnet Technology Solutions , The IPL Group
rhs_login_lockGet exclusive access to ARN's news, research and invitation only events.
ARN Distributor Directory
ARN Vendor Directory

iAsset is a channel management ecosystem that automates all major aspects of the entire sales,marketing and service process, including data tracking, integrated learning, knowledge management and product lifecycle management.