Vulnerability Research: A full chained exploit from IT network to PLC’s unconstrained code execution

No ratings

Presented at Grehack 2020 by

Nowadays, much of industrial companies own an Industrial Control System (ICS) environment regardless of their activity area. That mainly concerns critical sectors dealing with Operational Technology (OT) network such as in energy, automotive, water and so on. This presentation is intended to demonstrate the risk involved by the integration of such systems according to two major points. The first is that ICS implies a large attack surface due to the presence of many applications and embedded systems. The second is that an ICS is faced with many software design issues because security has not been historically considered. We would like to sensitize the public by emphasizing the points mentioned above through a real scenario based on our vulnerability research, resulting in several CVEs on a popular manufacturer. More precisely, we have succeeded in building a chained exploit which allowed us to take control of a PLC from an IT access by targeting the engineering station.Nicolas Delhaye has been a vulnerability researcher since 2010 and he is currently working at Airbus CyberSecurity. Most of these findings are mainly focused on both Windows OS and security applications by looking for vulnerabilities in user and kernel land.Flavian Dola is currently working at Airbus CyberSecurity as a vulnerability researcher specialized on embedded systems (IoT, ICS, …). His field of expertise lies on the areas of reverse engineering, fuzzing and exploit development.