ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

Flaw found in power-plant software

Tom Espiner ZDNet.co.uk

Published: 19 May 2008 13:27 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A hole has been found in software used by critical national infrastructure organisations including oil, gas and power companies that could lead to a successful denial-of-service attack.

The vulnerability is in a protocol used in versions of SuiteLink by Wonderware running on Microsoft Windows. The software is used to communicate between components in Supervisory Control and Data Acquisition (Scada) systems. The protocol is proprietary, and used over TCP/IP networks.

The flaw in the Wonderware SuiteLink Service, as reported by security researcher Sebastian Muniz  from Core Security Technologies, means unauthenticated client programs connecting to the SuiteLink Service prior to version 2.0 patch 1 can send a malformed packet that causes a memory allocation operation to fail, returning a null pointer.

Due to a lack of error-checking for the result of the memory allocation operation, the program later tries to use the pointer as a destination for memory copy operation, triggering an access violation error and terminating the service, reported Core Security.

The flaw is remotely exploitable, according to the Core Secure Technologies researcher. According to the Wonderware site: "One-third of the world's plants run Wonderware software solutions. Wonderware has sold over 450,000 software licences in approximately 100,000 plants worldwide, which is 33 percent of the world's 305,544 plants with 20 or more employees."

Software updates and advice on how to secure systems are available from the Wonderware website, and users must register on the site to view the advisory.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with Konica

Did you find this article useful?


Full Talkback thread

1 comment

  1. Is this news? tammy.newton

Company/Topic Alerts

Create a new alert from the list below:






Sentry Posts Blog

Toshiba touts Quantum Key Distribution

Toshiba research scientists have developed a method of distributing quantum keys more efficiently, the company has claimed in a statement: "[Quantum Key Distribution -- ] QKD --... More

Post a comment

Virtual Teams: Small Business Innovati...

Virtual Teams: Small Business Innovation Author: Eric Everson, Founder – MyMobiSafe.com As the founder of MyMobiSafe.com, I’ve found that because of our presence in the industry... More

Post a comment

Mobile Security and Innovation: An Ope...

Mobile Security and Innovation: An Open Case Author: Eric Everson, Founder MyMobiSafe.com The times are changing in the mobile industry as “big wireless” in the US Markets are calling... More

Post a comment