Security News > 2021 > July > Unpatched Critical RCE Bug Allows Industrial, Utility Takeovers

The 'ModiPwn' bug lays open production lines, sensors, conveyor belts, elevators, HVACs and more that use Schneider Electric PLCs. A critical remote code-execution vulnerability in Schneider Electric programmable logic controllers has come to light, which allows unauthenticated cyberattackers to gain root-level control over PLCs used in manufacturing, building automation, healthcare and enterprise environments.
If exploited, attackers could impact production lines, sensors and conveyor belts in factory settings, according to the researchers at Armis who discovered the bug - as well as affect devices familiar to the everyday consumer, such as elevators, HVACs and other automated devices.
Any attack would begin with gaining network access to the same network to which the targeted Modicon PLC is attached, researchers said - a positive mitigation in that the extra, required first step makes it harder for an attacker to be successful.
UMAS is a proprietary protocol used to configure and monitor Schneider PLCs. Researchers added, "Using this hash, the attacker can take over the secure connection between the controller and its managing workstation to reconfigure the controller with a password-less configuration. This will allow the attacker to abuse additional undocumented commands that lead to remote-code-execution - a full takeover of the device."
It's arises because of missing authentication for critical functions, which can allow attackers to carry out unauthorized operations.
No in-the-wild attacks have been spotted, researchers said, but these kinds of vulnerabilities in industrial control systems have opened the door to concerning attacks in the past.
News URL
https://threatpost.com/unpatched-critical-rce-industrial-utility-takeovers/167751/
Related news
- Gladinet’s Triofox and CentreStack Under Active Exploitation via Critical RCE Vulnerability (source)
- Critical Erlang/OTP SSH pre-auth RCE is 'Surprisingly Easy' to exploit, patch now (source)
- Critical Erlang/OTP SSH RCE bug now has public exploits, patch now (source)
- Critical Commvault RCE vulnerability fixed, PoC available (CVE-2025-34028) (source)
- Critical Langflow RCE flaw exploited to hack AI app servers (source)
- SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version (source)
- Unpatched critical bugs in Versa Concerto lead to auth bypass, RCE (source)