While ICS units like PLCs and RTUs have been around a long time, introducing them into new environments like smart cities solutions, introduces new challenges unique to those environments. The devices are continuously gathering sensor data such as temperature and pressure, to make decisions on how to control different units, as well as sending the data to a central system that can monitor all buildings. This report has evaluated an implementation of a Beckhoff CX-9020 PLC and a web- port SCADA system. The evaluation was performed using a method with a focus on IoT implementations. No new vulnerabilities were reported, but previously discovered vulnerabilities, and problems with the device’s security configurations were found to be present. It was concluded that most of the vulnerabilities could be fixed by either keeping the devices up to date or making sure the correct configurations are used.
Medans ICS enheter som PLCer och RTUer har använts länge, när man introducera dem till nya miljöer som smarta städer, så uppstår nya utmaningar unika till de miljöerna. Enheterna samlar kontinuerligt sensor data som temperatur och tryck, som används för att bestämma beteendet av andra enheter, samt skicka data till ett centralt system som övervakar alla byggnader. Den här rapporten har evaluerat en implementation av en Beckhoff CX-9020 PLC och ett webport SCADA system. Evalueringen utfördes med en metod som fokuserar på IoT implementationer. Inga nya svagheter rapporterades, men tidigare funna svagheter, och problem med enheternas säkerhets konfigurationer hittades. Slutsatsen var att många av systemets svagheter kunde lösas genom att antingen hålla systemet uppdaterat eller se till att allt var korrekt konfigurerat.