Analysis of the 3S CoDeSys Security Vulnerabilities for Industrial Control System Professionals
A number of previously unknown security vulnerabilities in the CoDeSys Ladder Logic Runtime product, plus fully functional attack tools that exploit them, have been publically disclosed.
While CoDeSys is not widely known in the SCADA and ICS field, its product is embedded in many popular PLCs and industrial controllers. There is a risk that criminals or political groups may attempt to exploit the vulnerabilities for either financial or ideological gain.
This White Paper documents the current known facts about these vulnerabilities. It then summarizes the actions that operators of SCADA and ICS systems can take to protect critical operations.
CoDeSys is a trademark of 3S-Smart Software Solutions GmbH
Authors:
Eric Byres, CTO and VP Engineering, Tofino Security, Belden Inc.
Joel Langill, CSO, SCADAhacker.com
Version 1.1, released Nov 21, 2012:
-
clarifies who the affected vendors are
-
includes an analysis of Nessus plug-ins