Zero-Day Flaws Discovered in SCADA Systems
- 10 October, 2011 21:05
- Comments
An Italian security researcher recently disclosed details about several zero-day vulnerabilities in supervisory control and data acquisition (SCADA) systems from several vendors.
The discovery -- the second such disclosure by researcher Luigi Auriemma this year -- is likely to reinforce concerns about weaknesses in the nation's critical infrastructure.
The most recent vulnerabilities affect SCADA products from Rockwell Automation, Cogent DataHub, Measuresoft and Progea, among other vendors.
Most of the vulnerabilities are remote code execution flaws that allow attackers to run code on the systems, and some of the flaws are easy to exploit, Auriemma said. At least three of the vendors have already issued fixes, and Rockwell is working on one, he said.
SCADA systems are used to control critical equipment at power plants, manufacturing facilities, water treatment plants and elsewhere. Security analysts fear that attacks against such systems could cripple critical infrastructure, including the electric grid and water supplies.
The Stuxnet worm, which exploited a weakness in a Siemens control system to disrupt operations at an Iranian nuclear power plant, is often cited as an example of the kind of threat that can be unleashed upon vulnerable SCADA systems.
This version of this story was originally published in Computerworld's print edition. It was adapted from an article that appeared earlier on Computerworld.com.
Read more about security in Computerworld's Security Topic Center.
- Bookmark this page
- Share this article
- Got more on this story? Email TechWorld
- Follow TechWorld on twitter
- SCADA vulnerabilities prompt U.S. government warning - Computerworld
- Is Stuxnet the 'best' malware ever? - Computerworld
- Siemens SCADA hacking talk pulled over security concerns - Computerworld
- Researcher discloses zero-day flaws in SCADA systems - Computerworld
- Security Topic Center - Computerworld
- Businesses are ready for a new approach to IT - Simplify deployment and reduce complexity using systems integrated with expertise
- Delivering Tomorrow's Backup and Recovery Infrastructure
- Cost Effective Security and Compliance with Oracle Database 11g Release 2
- Six tips for choosing a unified threat management (UTM) solution
- CSO Security Buyers Guide 2011
-
CSIRO develops hands-free technology for mining repairs
-
Broadband Forum to improve IPTV performance with new spec
-
Amazon Web Services moves backups to cloud with new appliance
-
Callforfree.net.au offers free calls to 70 countries
-
Intel ponders solar-powered CPU tech in graphics, memory
-
Windows 7 for Dummies®
-
Windows 7 for Seniors for Dummies®
-
Windows 7 for Dummies® Dvd+book Bundle
-
Office 2007 for Dummies
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Office 2007 All-In-One Desk Reference for Dummies
-
Teach Yourself Visually Windows 7
-
Computers for Seniors for Dummies, 2nd Edition
-
MYOB Software for Dummies 6E Australian Edition








Comments
Post new comment