Uploaded April 2026 | Updated September 2026, 1 week ago
SoftPLCs are PLC code that runs on a traditional OS. A variety of vendors offer these such as Beckhoff, Phoenix Contact, Wago, and Codesys.
Embedding a full-fledged operating system within a programmable logic controller, vendors inadvertently inherit a wide range of traditional OS-level vulnerabilities. This growing complexity introduces serious security concerns, particularly when deployed in critical infrastructure contexts where reliability and safety are paramount.
Diego reveals a security analysis of several well-known softPLC platforms focusing on the enforcement and robustness of their built-in security models. Common classes of vulnerabilities will be presented as well as some vendor/model specific vulnerabilities. The presentation highlights the inherent risks that should be considered when leveraging general-purpose operating systems in softPLC design.
SoftPLCs are PLC code that runs on a traditional OS. A variety of vendors offer these such as Beckhoff, Phoenix Contact, Wago, and Codesys.
Embedding a full-fledged operating system within a programmable logic controller, vendors inadvertently inherit a wide range of traditional OS-level vulnerabilities. This growing complexity introduces serious security concerns, particularly when deployed in critical infrastructure contexts where reliability and safety are paramount.
Diego reveals a security analysis of several well-known softPLC platforms focusing on the enforcement and robustness of their built-in security models. Common classes of vulnerabilities will be presented as well as some vendor/model specific vulnerabilities. The presentation highlights the inherent risks that should be considered when leveraging general-purpose operating systems in softPLC design.










