A @Microsoft researcher discovered 16 new CODESYS vulnerabilities affecting hundreds of operational technology systems around the world
https://therecord.media/microsoft-reveals-vulnerabilities-codesys
SecurityAffairs: Multiple flaws in CODESYS V3 SDK could lead to RCE or DoS https://securityaffairs.com/149474/security/codesys-v3-sdk-rce-dos.html #informationsecuritynews #ITInformationSecurity #PierluigiPaganini #BreakingNews #SecurityNews #hackingnews #ICS-SCADA #Security #Hacking #CODESYS #OT
#informationsecuritynews #itinformationsecurity #pierluigipaganini #breakingnews #securitynews #hackingnews #ics #security #hacking #codesys #ot
Ars Technica: Microsoft finds vulnerabilities it says could be used to shut down power plants https://arstechnica.com/?p=1960538 #Tech #arstechnica #IT #Technology #industrialcontrolsystems #criticalinfrastructure #microsoft #Security #codesys #Biz&IT
#Tech #arstechnica #it #technology #industrialcontrolsystems #criticalinfrastructure #microsoft #security #codesys #biz
ICYMI: @G33KatWork of #Rapid7 put together a pretty amazing paper on #CODESYS, a proprietary PLC protocol used in all sorts of industrial environments. Check it:
https://www.rapid7.com/blog/post/2023/02/14/a-deep-dive-into-reversing-codesys/
And yes, I'm glad you asked! There is indeed a GitHub repo of tooling to go along with the paper:
3 #vulnerabilities have been disclosed affecting operational technology (#OT) products from two German companies: factory automation manufacturer #Festo and automation software company #CODESYS. https://bit.ly/3VGHdKe
#vulnerabilities #ot #festo #codesys
@Harald Guten Morgen Harald,
da du Werbung für #freepascal machst, hier noch Werbung von mir. Due trxtbasierte Programmierung von #codesys und #Beckhoff #TwinCat ist von Pascal abgeleitet. Das heisst, der Umstieg von Pascal auf die #sps Programmierung ist damit verhältnismäßig einfach *jubel*
Umgekehrt natürlich auch. Ich sollte mir das mal anschauen ;-)
#freepascal #codesys #Beckhoff #TwinCat #sps
Critical CODESYS Bug Allows Remote Code Execution - CVE-2020-10245, a heap-based buffer overflow that rates 10 out of 10 in severity, exists in the CO... more: https://threatpost.com/critical-codesys-bug-remote-code-execution/154213/ #programmablelogiccontroller #heap-basedbufferoverflow #industrialcontrolsystems #criticalinfrastructure #criticalvulnerability #vulnerabilities #cve-2020-10245 #websecurity #securitybug #webserver #codesys
#codesys #webserver #securitybug #websecurity #cve #vulnerabilities #criticalvulnerability #criticalinfrastructure #industrialcontrolsystems #heap #programmablelogiccontroller