White Paper: Analysis of Security Vulnerabilities for Industrial Control System Professionals

March 31, 2011
Earlier this week an Italian researcher published a list of 34 vulnerabilities against four SCADA/HMI products.

Today Joel Langill and Eric Byres are publishing a White Paper that analyzes the vulnerabilities for one of the product families, the ICONICS GENESIS HMI platform.

This White Paper covers:

• Vulnerability Details
• Affected Systems
• Detection and Removal
• Mitigations and Compensating Controls
• Frequently Asked Questions
• References

Although the vulnerabilities are relatively trivial, at a minimum they can be used to crash control system servers, causing a denial-of-service condition and loss of view. A more experienced attacker could exploit them to gain system access and then inject potentially malicious code.

This White Paper provides six measures that ICONICS GENESIS customers can take to protect their system from these vulnerabilities. Operators of other HMI products are advised to consider similar measures.

A blog article is also available about this White Paper:
"Protecting your ICONICS GENESIS SCADA HMI System from Security Vulnerabilities"

Byres Security Inc. - www.tofinosecurity.com

Sponsored Recommendations

Put the Plant Floor in Your Pocket with Ignition Perspective

Build mobile-responsive HTML applications that run natively on any screen.

Ignition: Industrial-Strength System Security and Stability

Ignition is built on a solid, unified architecture and proven, industrial-grade security technology, which is why industrial organizations all over the world have been trusting...

Iron Foundry Gains Competitive Edge & Increases Efficiency with Innovative Technology

With help from Artek, Ferroloy implemented Ignition to digitally transform their disconnected foundry through efficient data collection and analysis while integrating the new ...

Empowering Data Center Growth: Leveraging Ignition for Scalability and Efficiency

Data center growth has exploded over the past decade. Initially driven by organizations moving their computer assets to the cloud, this trend has only accelerated. With the rise...