12 de septiembre de 2026

SOCaaS

Centro de Operaciones de Seguridad como servicio

PLC vulnerabilities can enable deep lateral movement inside OT networks


Threat groups who target operational technology (OT) networks have so far focused their efforts on defeating segmentation layers to reach field controllers such as programmable logic controllers (PLCs) and alter the programs (ladder logic) running on them. However, researchers warn that these controllers should themselves be treated as perimeter devices and flaws in their firmware could enable deep lateral movement through the point-to-point and other non-routable connections they maintain to other low-level devices.

To exemplify such a scenario and highlight the risks, researchers from security firm Forescout used two vulnerabilities they discovered in Schneider Modicon PLCs to move deeper into a simulated OT architecture of a movable bridge and bypass all safety mechanisms to cause physical damage.

Authentication bypass and remote code execution

The two vulnerabilities found by Forescout affect PLCs from the Modicon Unity line that are managed with the EcoStruxure Control Expert and EcoStruxure Process Expert control systems using Schneider’s Unified Messaging Application Services (UMAS) protocol. This includes the following PLCs:

  • M340 (BMXP34*)
  • M580 (BMEP*, BMEH*)
  • M580 Safety (BMEP58*S, BMEH58*S)
  • MC80 (BMKC80)
  • Momentum Unity M1E (171CBU*)
  • Quantum Unity (140CPU65*)
  • Premium Unity (TSXP57*)

Modicon PLCs are among the most popular in the world being used in industries including water, power generation, mining, transportation, and manufacturing. The Control Expert PLCs are used for process automation and the M340 and M580 PLCs are the Unity’s line most prevalent products.

One of the vulnerabilities, tracked as CVE-2022-45789 and rated with 8.1 severity on the CVSS scale, allows attackers to hijack an already authenticated Modbus session and execute unauthorized Modbus functions on the controller. Modbus is a data communications protocol originally developed by Modicon in the late 1970s that is now a de-facto communications standard for industrial devices. UMAS is a proprietary variant based on it.

The issue was in the UMAS EnhancedCyberReserve mechanism, which is Modicon’s attempt to implement authentication in UMAS between the PLC and the engineering client programming it. Originally the protocol came without any authentication or encryption, and this was added later in several iterations as other vulnerabilities were found in it in the past. However, the Forescout researchers found that the current implementation is not completely safe either.



Nos llegó este contenido de ciberseguridad de: CSO Online

Podrás encontrar la noticia original en el siguiente enlace: https://www.csoonline.com/article/3687991/plc-vulnerabilities-can-enable-deep-lateral-movement-inside-ot-networks.html#tk.rss_news

Deja una respuesta

Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *