Stuxnet-Style Attacks Still Possible Against PLCs
Originally designed to target Siemens SIMATIC PLCs, researchers recently demonstrated vulnerabilities from Stuxnet-style exploits could also affect similar products from other vendors. According to the report, researchers at Airbus CyberSecurity determined that a vulnerability in Schneider Electric’s Modicon M340 and M580 PLCs can be exploited to upload malicious code by replacing one of the DLL files associated with the engineering software. The attack targeted the controller via Schneider’s EcoStruxure Control Expert engineering software, formerly known as Unity Pro.