Security Snippets: Rapid SCADA vulnerabilities create risk

Industrial automation platform Rapid SCADA contains seven key vulnerabilities.

CISA recently published an advisory about seven vulnerabilities in Rapid SCADA—an open-source industrial automation platform that provides tools for the quick creation of monitoring and control systems. According to CISA, these vulnerabilities may allow threat actors to remotely execute arbitrary code on systems running Rapid SCADA, which could result in the loss of control or data.

CISA flagged the energy and transportation sectors as being at risk in its advisory. Organizations may even see attacks from these vulnerabilities from the public internet directly, as, according to independent researchers, at least some Rapid SCADA systems have internet-facing IP addresses.

CISA recommends the following mitigations for potentially affected organizations:

  • Ensure control system devices are not accessible from the internet
  • Isolate control system networks from business networks
  • Use Virtual Private Networks (VPNs)

 

Authored by Nathan Salminen and Rachel Dalton.

Contacts
Nathan Salminen
Partner
Washington, D.C.
Rachel Dalton
Associate
Washington, D.C.

 

This website is operated by Hogan Lovells International LLP, whose registered office is at Atlantic House, Holborn Viaduct, London, EC1A 2FG. For further details of Hogan Lovells International LLP and the international legal practice that comprises Hogan Lovells International LLP, Hogan Lovells US LLP and their affiliated businesses ("Hogan Lovells"), please see our Legal Notices page. © 2024 Hogan Lovells.

Attorney advertising. Prior results do not guarantee a similar outcome.