ICS/OT

ICS-CERT Issues Warning After Full Disclosure of SCADA Flaws

ICS-CERT, the section of U.S. CERT that deals with Industrial Control Systems, is issuing an advisory after a researcher exposed four separate flaws within Pro-face Pro-server, a popular data management server that offers real-time reporting of automated manufacturing and production environments. Each of the flaws can be targeted remotely to trigger DoS conditions, or code execution.

<p><strong>ICS-CERT</strong>, the section of U.S. CERT that deals with Industrial Control Systems, is issuing an advisory after a researcher exposed four separate flaws within <strong>Pro-face Pro-server</strong>, a popular data management server that offers real-time reporting of automated manufacturing and production environments. Each of the flaws can be targeted remotely to trigger DoS conditions, or code execution.</p>

ICS-CERT, the section of U.S. CERT that deals with Industrial Control Systems, is issuing an advisory after a researcher exposed four separate flaws within Pro-face Pro-server, a popular data management server that offers real-time reporting of automated manufacturing and production environments. Each of the flaws can be targeted remotely to trigger DoS conditions, or code execution.

Researcher Luigi Auriemma is credited with the full disclosure of the flaws, and he is being condemned by ICS-CERT for releasing proof-of-concept code along with the vulnerability report without notification to the vendor (Pro-face) or ICS-CERT.

Pro-face’s Pro-server can be run as a standalone server, but Pro-face recommends that it be set as a Windows service during installation. According to ICS-CERT, Pro-face Pro-server can be found tied to SCADA systems within the oil and gas, food and beverage, and water and wastewater industries.

While it’s unclear how many Pro-face Pro-server’s are deployed and potentially vulnerable, the company claims that overall it’s products are installed in more than 300,000 factory-floor systems worldwide, with over 1.5 million operator interfaces in use today.

“ICS-CERT is aware of a public report of multiple vulnerabilities affecting Pro-face Pro-Server, a supervisory control and data acquisition/human-machine interface (SCADA/HMI) product. The vulnerabilities include invalid memory access, buffer overflow, unhandled exception, and memory corruption, with proof-of-concept (PoC) exploit code,” the advisory (PDF) states.

ICS-CERT has notified Pro-face and said they are working with them to develop mitigations. Currently there is no patch for the flaws, which impact versions 1.30.000 and earlier of Pro-server.

Advertisement. Scroll to continue reading.

SecurityWeek has contacted Auriemma to ask about his thoughts on full disclosure and ICS-CERT’s take on his methods. This article will be updated if we hear from him. Likewise, SecurityWeek has also contacted Pro-face for their reaction and additional information.

Earlier this month, researcher Dillon Beresford worked with ICS-CERT and Progea to resolve issues with in the Progea Movicon application. Unlike the Pro-face Pro-server disclosure however, there were no known attacks and the proof-of-concept code was withheld from the public.

Related Reading: A New Cyber Security Model for SCADA

Related Reading:  Are Industrial Control Systems Secure?

Related Reading: How to Make the Smart Grid Smarter than Cyber Attackers

Related Reading:  The Increasing Importance of Securing The Smart Grid

Related Reading: Stuck on Stuxnet – Are Grid Providers Prepared for Future Assaults?

Related Content

ICS/OT

The US government has warned that Iran-linked hackers are manipulating PLCs and SCADA systems to cause disruption.

ICS/OT

Join us as speakers from Cisco outline important steps industrial organizations can take to safeguard operations, achieve compliance, and enable sustainable growth.

ICS/OT

Over 20 advisories have been published by industrial giants this Patch Tuesday.

ICS/OT

Honeywell has patched several critical and high-severity vulnerabilities in its Experion PKS  industrial process control and automation product.

ICS/OT

Industrial solutions providers Siemens, Schneider Electric and Phoenix Contact have released July 2025 Patch Tuesday ICS security advisories.

ICS/OT

Censys researchers follow some clues and find hundreds of control-room dashboards for US water utilities on the public internet.

ICS/OT

More than 100 AutomationDirect MB-Gateway devices may be vulnerable to attacks from the internet due to CVE-2025-36535.

ICS/OT

Agencies say the attacks leverage basic intrusion techniques, but poor cyber hygiene within critical infrastructure organizations could lead to disruptions and damage.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version