Publié par : pintejp | avril 13, 2012

Rise of « forever day » bugs in industrial systems threatens critical infrastructure

The number of security holes that remain unpatched in software used to control refineries, factories, and other critical infrastructure is growing. It’s becoming so common that security researchers have coined the term « forever days » to refer to the unfixed vulnerabilities.

The latest forever day vulnerability was disclosed in robotics software marketed by ABB, a maker of ICS (industrial control systems) for utilities and factories. According to an advisory (PDF) issued last week by the US Cyber Emergency Response Team, the flaw in ABB WebWare Server won’t be fixed even though it provides the means to remotely execute malicious code on computers that run the application.

More information

http://arstechnica.com/business/news/2012/04/rise-of-ics-forever-day-vulnerabiliities-threaten-critical-infrastructure.ars


Laisser un commentaire

Catégories