Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
×
Bug Security IT

ICS-CERT Warns of Serious Flaws In Tridium SCADA Software 34

Trailrunner7 writes "The DHS and ICS-CERT are warning users of some popular Tridium Niagara AX industrial control system software about a series of major vulnerabilities in the applications that are remotely exploitable and could be used to take over vulnerable systems. The bugs, discovered by researchers Billy Rios and Terry McCorkle, are just the latest in a series of vulnerabilities found in the esoteric ICS software packages that control utilities and other critical systems. The string of bugs reported by Rios and McCorkle include a directory traversal issue that gives an attacker the ability to access files that should be restricted. The researchers also discovered that the Niagara software stores user credentials in an insecure manner. There are publicly available exploits for some of the vulnerabilities."
This discussion has been archived. No new comments can be posted.

ICS-CERT Warns of Serious Flaws In Tridium SCADA Software

Comments Filter:
  • Big Suprise (Score:4, Insightful)

    by Infin1niteX ( 950492 ) on Thursday August 16, 2012 @04:45PM (#41016465)
    All of these SCADA system were using security by obscurity or just no security at all for years. So we're going to keep seeing these alerts and warning for a while. Shoot we still see them with major desktop and server operating systems. If there is a reason to exploit a system, someone will figure out how to.
  • After All (Score:4, Insightful)

    by TheSpoom ( 715771 ) <slashdot&uberm00,net> on Thursday August 16, 2012 @05:00PM (#41016671) Homepage Journal

    They would know.

  • by some old guy ( 674482 ) on Thursday August 16, 2012 @11:14PM (#41019813)

    Mod Superflex up = Informative.

    Every platform that I've ever worked with in 20+ years of industrial networking (yeah, I remember TISTAR over coax) has demonstrated it's own unique vulnerabilities that the vendors arrogantly ignore. The diligent engineer/integrator must, regardless of platform or deployment, be aware and take reasonable precautions.

    Automation as an industry shares the same classic security handicaps as the internet and telecom industries: Careless users, badly written code, and low-budget management. We get paid to try to plug the holes.

He has not acquired a fortune; the fortune has acquired him. -- Bion

Working...