8 comments on “What does a flightless bird and SCADA software have in common?

  1. If you’ve ever read the NERC standard you realize that whoever wrote it was looking at it from a purely forensic view and not anything to protect the systems in use by the power industry. It’s ludicrous.

    Instead of securing the SCADA devices and software, they just keep logs. Not very smart.

  2. SCADA – Supervisory Control and Data Acquasition
    The PLCs do all the real work, the PLC code has all the fail safes.
    It’s like claiming I can break into the bank by smashing the front window.
    BTW many ATMs contain a Windows95 PC

    • Yes, the 0 days only affects to front-end software, but if you manipulate the output values and confuse to operator only in the front-end(SCADA), you can be very bad thinks.

  3. I would certainly like to know a bit more on the specifics of the findings as it pertains to Schneider Electric Products and which flavor of their DDC/ SCADA platforms were found to have vulnerabilities. Could this be elaborated upon? Schneider offers quite a few SCADA packages. Simply saying Schneider Electric software has 3 remote code execution and 1 DDoS vulnerabilities does little beyond having me go wowie, what a Sherlock Holmes. Please identify the platforms/ products so that, as an integrator, I can better account for said vulnerabilities in network security design and mitigation strategies with the products we currently deploy and support.

  4. Besides vendors, can you list products and versions? Some of these vendors have multiple SCADA products.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s