Uploaded March 2013 | Updated September 2026, 1 week ago
October, 2012
Dale Peterson, Digital Bond
Reid Wightman, IOActive
CoDeSys Vulnerabilities: How Insecure By Design Library Affected 200+ SCADA PLC's
Join IOActive's Reid Wightman & Digital Bond's Dale Peterson as they discuss PLC security issues that affect most SCADA and DCS, including those that monitor and control the critical infrastructure.
Dale provides an introduction on Project Basecamp whose mission is to demonstrate that PLC's lack even basic security features such as authentication for critical functions. He reviews the insecure by design issues in PLCs from major vendors such as GE, Rockwell Automation and Schneider Electric.
After this introduction, Reid goes into detail on how an attacker can exploit the 3S CoDeSys Ladder Logic Runtime Engine to modify the process, as was done in Stuxnet. The issues go beyond typical PLC security issues though, as Reid explains the security flaw that allow an attacker to load and run arbitrary code on the underlying operating system. Finally, Reid demonstrates how the recently released CoDeSys IDS rules are easily bypassed and how even well written IDS rules have limited effectiveness when the attack is based on legitimate functions.
The 3S CoDeSys library is used in over 200 different PLC's and is not typically mentioned in the PLC product literature. These insecure by design issues have a widespread and often hidden impact on critical infrastructure cyber security.
October, 2012
Dale Peterson, Digital Bond
Reid Wightman, IOActive
CoDeSys Vulnerabilities: How Insecure By Design Library Affected 200+ SCADA PLC's
Join IOActive's Reid Wightman & Digital Bond's Dale Peterson as they discuss PLC security issues that affect most SCADA and DCS, including those that monitor and control the critical infrastructure.
Dale provides an introduction on Project Basecamp whose mission is to demonstrate that PLC's lack even basic security features such as authentication for critical functions. He reviews the insecure by design issues in PLCs from major vendors such as GE, Rockwell Automation and Schneider Electric.
After this introduction, Reid goes into detail on how an attacker can exploit the 3S CoDeSys Ladder Logic Runtime Engine to modify the process, as was done in Stuxnet. The issues go beyond typical PLC security issues though, as Reid explains the security flaw that allow an attacker to load and run arbitrary code on the underlying operating system. Finally, Reid demonstrates how the recently released CoDeSys IDS rules are easily bypassed and how even well written IDS rules have limited effectiveness when the attack is based on legitimate functions.
The 3S CoDeSys library is used in over 200 different PLC's and is not typically mentioned in the PLC product literature. These insecure by design issues have a widespread and often hidden impact on critical infrastructure cyber security.










