Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

Cisco Finds 15 Vulnerabilities in AutomationDirect PLCs

Cisco Talos researchers have found over a dozen vulnerabilities in AutomationDirect PLCs, including flaws that could be valuable to attackers.

ICS security

Cisco’s Talos research and threat intelligence unit has discovered 15 vulnerabilities in programmable logic controllers (PLCs) made by US-based industrial automation products provider AutomationDirect.

The vulnerabilities impact AutomationDirect’s Productivity series PLCs. They have all been classified as having ‘high’ or ‘critical’ severity and they can be exploited for remote code execution or denial-of-service (DoS) attacks, which in general could have a significant impact in the case of industrial environments, as they can cause costly production disruptions. 

Yves Younan, senior manager at Talos Vulnerability Discovery and Research, told SecurityWeek that the impacted PLCs are typically not directly exposed to the internet, which means an attacker in most cases would need to establish a foothold in the targeted organization’s network before exploiting the vulnerabilities.

However, a Shodan search does show roughly 50 potential devices that may be directly connected to the internet.

“If this device were to be deployed under normal circumstances directly on the internet, then we would expect to get thousands of results,” Younan explained.

Learn more about industrial product vulnerabilities at 

Advertisement. Scroll to continue reading.

SecurityWeek’s 2024 ICS Cyber Security Conference

Regarding the potential impact of these vulnerabilities in a real-world attack scenario, Younan pointed out that several of the flaws can be used — either on their own or chained with other security holes — for arbitrary code execution.

“This would allow an attacker to perform any actions they like on this device, including manipulating the logic, shutting down the device or extracting information stored on the device,” the expert said. 

The US cybersecurity agency CISA, which informed organizations about these vulnerabilities in late May, says the impacted devices are used in the IT, commercial facilities and critical manufacturing sectors worldwide. 

Talos has published its own advisories for the AutomationDirect vulnerabilities discovered by its researchers. These advisories contain technical details for each issue. 

AutomationDirect was informed about the vulnerabilities in mid-February. The company has released firmware and programming software updates to address the flaws, and it has also shared some mitigations and general recommendations for securing systems. 

Related: Rockwell Automation Urges Customers to Disconnect ICS From Internet

Related: Cinterion Modem Flaws Pose Risk to Millions of Devices in Industrial, Other Sectors

Related: Critical Vulnerability in Honeywell Virtual Controller Allows Remote Code Execution

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Gwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.

Pietr Lindahal has been named Vice President and Chief Information Security Officer at Boston Scientific.

AI agent identity and enforcement company FIOR has appointed Gemma Ungoed-Thomas as Adviser.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.