Security researchers have discovered three critical vulnerabilities in a popular industrial control system used by more than 7,600 power, chemical and petrochemical plants across the globe.
Metasploit engineering manager at Rapid 7, Tod Beardsley, told V3 the flaws are troubling as the control system is used by numerous factories and power plants across the globe, including some in the UK, and could be utilised by hackers to mount a variety of attacks.
"If you take a look at Yokogawa's client list you'll see several companies that have global operations, including the UK. The threats that are enabled by the vulnerabilities described range from simple information leakage (screenshots of active engineering projects) to total compromise of the human interface station (HIS)," he said.
"The HIS is ultimately Microsoft Windows machines running server software – if they are reachable from the internet, then an attack can be sourced from anywhere in the world. Since an attacker can control an HIS, he can then take control of the engineering devices that the HIS is intended to manage. This can include things like power turbines and factory floor equipment."
The fact that the vulnerabilities could be used to manipulate physical processes in the plant is particularly troubling as it could allow hackers to mount Stuxnet-level cyber sabotage attacks against the UK's critical infrastructure. Stuxnet is a notorious malware that was discovered in 2010 targeting Iranian nuclear facilities.
Yokogawa is aware of the vulnerabilities and has begun releasing security patches to fix them. Rapid 7 recommended that companies install the patch on any Centum CS 3000 R3 control systems as soon as possible.