0% found this document useful (0 votes)
37 views6 pages

SCADA Metasploit Modules

The document lists various vendors and their associated systems or components, highlighting vulnerabilities and exploits related to SCADA systems. It includes details on specific vulnerabilities such as SQL injection, remote code execution, and buffer overflows across different platforms. Additionally, it provides Metasploit module information for exploiting these vulnerabilities, categorized by default ports and associated commands.

Uploaded by

davlorenzo36
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLS, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
37 views6 pages

SCADA Metasploit Modules

The document lists various vendors and their associated systems or components, highlighting vulnerabilities and exploits related to SCADA systems. It includes details on specific vulnerabilities such as SQL injection, remote code execution, and buffer overflows across different platforms. Additionally, it provides Metasploit module information for exploiting these vulnerabilities, categorized by default ports and associated commands.

Uploaded by

davlorenzo36
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLS, PDF, TXT or read online on Scribd

Vendor

Advantech WebAccess

General Electric
Schneider
Schneider

Schneider
Allen-Bradley/Rockwell
PhoenixContact PLC
Beckhoff
General Electric
General Electric
7-Technologies
Digi ADDP
Digi ADDP

Digi International

Digi International

Indusoft

Indusoft
Digital Bond
EsMnemon
EsMnemon and Arnaud Soullie
EsMnemon
Siemens Profinet
Sielco Sistemi

KeyHelp
TeeChart Professional
KingScada
BACnet
ScadaTec
ABB MicroSCADA
Schneider Electric
3S
3S
AzeoTech
Siemens Technomati
Siemens Technomati
General Electric
Iconics
Iconics

7-Technologies

7-Technologies
7-Technologies
7-Technologies
MOXA
Procyon
DATAC RealWin
DATAC RealWin

DATAC RealWin

DATAC RealWin

DATAC RealWin

DATAC RealWin
Measuresoft ScadaPro
Sunway Forcecontrol
Sielco Sistemi
Sielco Sistemi
Yokogawa

Yokogawa

Yokogawa

Yokogawa
Yokogawa
Yokogawa
System / Component

Advantech WebAccess SQL Injection

GE Proficy Cimplicity WebView [Link] Directory Traversal


Schneider Modicon Remote START/STOP Command
Schneider Modicon Quantum Password Recovery

Schneider Modicon Ladder Logic Upload/Download


Allen-Bradley/Rockwell Automation EtherNet/IP CIP Commands
PhoenixContact PLC Remote START/STOP Command
TwinCat
D20 PLC
D20 PLC
7-Technologies IGSS 9 [Link] DoS
Digi ADDP Remote Reboot Initiator
Digi ADDP Information Discovery

Advance device Discovery Protocol

Advance device Discovery Protocol

InduSoft Web Studio Arbitrary Upload Remote Code Execution

Indusoft WebStudio NTWebServer Remote File Access


Koyo DirectLogic PLC Password Brute Force Utility
Modbus Client Utility
Modbus Client Utility
Modbus Client Utility
Siemens Profinet Scanner
Winlog Remote File Access

KeyHelp ActiveX LaunchTriPane Remote Code Execution Vulnerability


TeeChart Professional ActiveX Control Trusted Integer Dereference
KingScada [Link] ActiveX Remote Code Execution
OPC Client
ModbusTag Server ScadaPhone
ABB MicroSCADA [Link] Remote Code Execution
CitectSCADA
SCADA 3S CoDeSys Gateway Server Directory Traversal
SCADA 3S CoDeSys CmpWebServer Stack Buffer Overflow
DAQ Factory
Siemens FactoryLink 8 CSService Logging Path Param Buffer Overflow
Siemens FactoryLink [Link] Opcode 9 Buffer Overflow
GE Proficy CIMPLICITY [Link] Remote Code Execution
Iconics GENESIS32 Integer Overflow Version [Link]
ICONICS WebHMI ActiveX Buffer Overflow

IGSS

IGSS
IGSS
IGSS
MOXA Device Manager Tool 2.1 Buffer Overflow
Procyon Core Server HMI [Link] Stack Buffer Overflow
DATAC RealWin SCADA Server Buffer Overflow
DATAC RealWin SCADA Server 2 On_FC_CONNECT_FCS_a_FILE Buffer Overflow

RealWin SCADA Server DATAC Login Buffer Overflow

DATAC RealWin SCADA Server SCPC_INITIALIZE Buffer Overflow

DATAC RealWin SCADA Server SCPC_INITIALIZE_RF Buffer Overflow

DATAC RealWin SCADA Server SCPC_TXTEVENT Buffer Overflow


Measuresoft ScadaPro Remote Command Execution
Sunway Forcecontrol SNMP [Link] Opcode 0x57
Sielco Sistemi Winlog Buffer Overflow
Sielco Sistemi Winlog Buffer Overflow 2.07.14 - 2.07.16
Yokogawa CENTUM CS 3000 [Link] Buffer Overflow

Yokogawa CS3000 [Link] Buffer Overflow

Yokogawa CS3000 BKFSim_vhfd.exe Buffer Overflow

Yokogawa CENTUM CS 3000 [Link] Buffer Overflow


Yokogawa CENTUM CS 3000 [Link] Heap Buffer Overflow
Yokogawa [Link] Client
Default Port Metasploit
auxiliary/admin/scada/
80
advantech_webaccess_dbvisitor_sqli
auxiliary/admin/scada/
80
ge_proficy_substitute_traversal
502 auxiliary/admin/scada/modicon_command
21 auxiliary/admin/scada/modicon_password_recovery

502 auxiliary/admin/scada/modicon_stux_transfer
44818 auxiliary/admin/scada/multi_cip_command
1962 auxiliary/admin/scada/phoenix_command
48899 auxiliary/dos/scada/beckhoff_twincat
2 auxiliary/gather/d20pass
69 auxiliary/dos/scada/d20_tftp_overflow
12401 auxiliary/dos/scada/igss9_dataserver
2362 auxiliary/scanner/scada/digi_addp_reboot
2362 auxiliary/scanner/scada/digi_addp_version
auxiliary/scanner/scada/
771
digi_realport_serialport_scan
771 auxiliary/scanner/scada/digi_realport_version

4322 exploit/windows/scada/indusoft_webstudio_exec
auxiliary/scanner/scada/
80
indusoft_ntwebserver_fileaccess
28784 auxiliary/scanner/scada/koyo_login
502 auxiliary/scanner/scada/modbus_findunitid
502 auxiliary/scanner/scada/modbusclient
502 auxiliary/scanner/scada/modbusdetect
auxiliary/scanner/scada/profinet_siemens
46824 auxiliary/scanner/scada/sielco_winlog_fileaccess
exploit/windows/browser/
80
keyhelp_launchtripane_exec
8080 exploit/windows/browser/teechart_pro
exploit/windows/browser/
8080
wellintech_kingscada_kxclientdownload
exploit/windows/fileformat/bacnet_csv
exploit/windows/fileformat/scadaphone_zip
12221 exploit/windows/scada/abb_wserver_exec
20222 exploit/windows/scada/citect_scada_odbc
exploit/windows/scada/
1211
codesys_gateway_server_traversal
8080 exploit/windows/scada/codesys_web_server
20034 exploit/windows/scada/daq_factory_bof
7580 exploit/windows/scada/factorylink_csservice
7579 exploit/windows/scada/factorylink_vrn_09
exploit/windows/scada/
80
ge_proficy_cimplicity_gefebt
38080 exploit/windows/scada/iconics_genbroker
exploit/windows/scada/
iconics_webhmi_setactivexguid
12401 exploit/windows/scada/igss9_igssdataserver_listall
exploit/windows/scada/
12401
igss9_igssdataserver_rename
exploit/windows/scada/igss9_misc
12397 exploit/windows/scada/igss_exec_17
exploit/windows/scada/moxa_mdmtool
23 exploit/windows/scada/procyon_core_server
910 exploit/windows/scada/realwin
910 exploit/windows/scada/realwin_on_fc_binfile_a

910 exploit/windows/scada/realwin_on_fcs_login

912 exploit/windows/scada/realwin_scpc_initialize

912 exploit/windows/scada/realwin_scpc_initialize_rf

912 exploit/windows/scada/realwin_scpc_txtevent
11234 exploit/windows/scada/scadapro_cmdexe
exploit/windows/scada/
2001
sunway_force_control_netdbsrv
46823 exploit/windows/scada/winlog_runtime
46824 exploit/windows/scada/winlog_runtime_2
20111 exploit/windows/scada/yokogawa_bkbcopyd_bof

34205 exploit/windows/scada/yokogawa_bkesimmgr_bof

20010 exploit/windows/scada/yokogawa_bkfsim_vhfd

20171 exploit/windows/scada/yokogawa_bkhodeq_bof
52302 auxiliary/dos/scada/yokogawa_logsvr
20111 auxiliary/admin/scada/yokogawa_bkbcopyd_client

Common questions

Powered by AI

SQL injection vulnerabilities pose threats to web-based industrial control interfaces by allowing attackers to manipulate database queries. For example, Advantech WebAccess is susceptible to SQL injection through the dbvisitor script, enabling an attacker to access or alter data unauthorizedly . This could result in data breaches or manipulation of control settings, compromising system integrity and potentially leading to unauthorized operations.

Open network ports in SCADA systems expose vulnerabilities that can be exploited by attackers to gain unauthorized access. For instance, many vulnerabilities in SCADA components, such as those in Yokogawa systems, are associated with open ports that can be abused for buffer overflow attacks . This can lead to unauthorized remote command execution or service disruptions, highlighting the need for network segmentation and firewall protection.

Buffer overflow functionality across SCADA products leads to similar consequences, such as unauthorized code execution or system crashes. Various products, including Yokogawa and DATAC RealWin, exhibit buffer overflow vulnerabilities allowing attackers to execute arbitrary code by sending specially crafted inputs . Despite differences in implementation, the commonality is the exploitation of memory allocation flaws, necessitating rigorous input validation and memory management practices.

Buffer overflow vulnerabilities in SCADA systems can lead to severe consequences including remote code execution and system crashes. For instance, Yokogawa's CENTUM CS 3000 system has several buffer overflow vulnerabilities which could be exploited to execute arbitrary code, potentially allowing attackers to take control over key system functions, alter data, or disrupt operations . This poses a significant risk to the reliability and safety of industrial operations.

Defending against SCADA system vulnerabilities presents distinct challenges compared to traditional IT systems due to unique operational requirements and architecture. SCADA systems often require high availability and real-time processing, limiting the deployment of traditional security measures like regular patching due to potential downtime risks . Additionally, the use of proprietary protocols and legacy systems complicates integrating standard IT security solutions, necessitating specialized security approaches tailored to the operational context of SCADA systems.

Mitigating risks associated with ActiveX Control vulnerabilities in SCADA environments involves several measures, such as disabling unnecessary ActiveX components and ensuring that all ActiveX controls run in safe mode. Ensuring that only signed ActiveX controls are allowed and continuously updating patches for known vulnerabilities, like the TeeChart Professional ActiveX control exploit, also strengthen defenses against unauthorized code execution . Implementing these strategies reduces the risk of exploitation through remote commands or executing malicious scripts.

Password recovery vulnerabilities can severely impact ICS security by allowing unauthorized access to control systems. For example, the Schneider Modicon Quantum has a known password recovery exploit that could enable an attacker to gain control over system processes by retrieving confidential passwords . Such vulnerabilities undermine the security integrity of ICS, potentially leading to operational disruptions or unauthorized manipulation of critical infrastructure systems.

Exploiting Directory Traversal vulnerabilities in an ICS environment allows attackers to access restricted files and directories outside the intended scope. For example, GE Proficy Cimplicity is susceptible to directory traversal attacks, potentially giving attackers access to sensitive configuration files and proprietary information . This could lead to further exploitation of the system, the gathering of confidential information, and unauthorized system control.

Remote code execution (RCE) vulnerabilities in web-based SCADA interfaces allow attackers to execute arbitrary code remotely, potentially gaining control over the application or entire system. For example, InduSoft Web Studio is vulnerable to arbitrary code injection via unsanitized file uploads, allowing attackers to manipulate control interfaces . The impact differs based on the criticality of the systems affected and the level of control the compromised interface has over connected operations, often leading to operational disruption or data modification.

Protocol misuse in SCADA systems, such as exploiting the Modbus protocol, can compromise system security by facilitating unauthorized command execution. Attackers could exploit weaknesses in the Modbus protocol to issue arbitrary start/stop commands or alter system outputs, impacting system stability and safety . Such attacks demonstrate the need for robust authentication and command verification to prevent unauthorized access and control operations.

You might also like