+ All Categories
Home > Documents > Top 5 SCADA Security Vulnerabilities

Top 5 SCADA Security Vulnerabilities

Date post: 21-Mar-2022
Category:
Upload: others
View: 11 times
Download: 0 times
Share this document with a friend
19
People First, Performance Now Ministry of Science, Technology and Innovation Top 5 SCADA Security Vulnerabilities Muhammad Reza Shariff 14 November 2013
Transcript

People First, Performance Now

Ministry of Science, Technology and Innovation

Top 5 SCADA Security Vulnerabilities Muhammad Reza Shariff

14 November 2013

People First, Performance Now

Ministry of Science, Technology and Innovation

Our Experience 2013

2

Control System Security

Assessment

Oil & Gas Water Works

Airport Shipping Port

People First, Performance Now

Ministry of Science, Technology and Innovation

3

5

People First, Performance Now

Ministry of Science, Technology and Innovation

SCADA Security Policy Issues

4

Applying Corporate IT Policy

Lack of Enforcement

No or Incomplete SCADA Security Policy

People First, Performance Now

Ministry of Science, Technology and Innovation

5

4 Copyright © 2013 CyberS

People First, Performance Now

Ministry of Science, Technology and Innovation

Password Issues

6

No Access Control List

Default Password

All for One

People First, Performance Now

Ministry of Science, Technology and Innovation

PLC Web Enabled - Password

7

People First, Performance Now

Ministry of Science, Technology and Innovation

Annuaire.XML for Topkapi

8

People First, Performance Now

Ministry of Science, Technology and Innovation

Hardcoded Password in the Registry

9

People First, Performance Now

Ministry of Science, Technology and Innovation

10

3

People First, Performance Now

Ministry of Science, Technology and Innovation

Network Architecture and Design

11

Web Enabled RTU and PLC

Active Ports Available

No Segregation of Network

People First, Performance Now

Ministry of Science, Technology and Innovation

Coils Read & Write

12

People First, Performance Now

Ministry of Science, Technology and Innovation

13

2

People First, Performance Now

Ministry of Science, Technology and Innovation

Antivirus Issues

14

Fear of System Disruption

Missing AV or Updates

False Sense of Security – Closed Network

People First, Performance Now

Ministry of Science, Technology and Innovation

Antivirus Issues

15

People First, Performance Now

Ministry of Science, Technology and Innovation

16

1

People First, Performance Now

Ministry of Science, Technology and Innovation

Operating System & Applications

17

No Hardening

Obsolete OS, Missing Patches & Services Packs

Vulnerable to Malware, DOS, Hacking, & etc

People First, Performance Now

Ministry of Science, Technology and Innovation

Obsolete System

18

19


Recommended