|
Rapid7 has disclosed a number of vulnerabilities in a Japanese industrial control system software, Windows-based production control system CENTUM CS 3000 R3 sold by Yokogawa Electric Corporation. Over 7600 of those systems for plant operation and monitoring have been sold worldwide, with Yokogawa's customers including power plants, chemical and petrochemical plants in Europe, the USA and Asia.
The vulnerabilities, if exploited, could allow execution of arbitrary code with user and system privileges. Hackers could also take screenshots to gather information about running projects or hijack SCADA communications.
During the research, Rapid7 found some CENTUM installations that were vulnerable and directly connected the Internet.
Rapid7's security experts warn that the vulnerabilities could affect any organisation running CENTUM CS3000 engineering projects. They recommend upgrading the software, and protecting access to engineering projects by making sure they can only be accessed remotely through VPN or gateway products.
Yokogawa was alerted to the vulnerabilities in December 2013, and has started to publish patches on 7 March.
|