Skip to content

Energetyka

|

CS.110

IT and OT Device Security Testing

Device security testing across 3 industrial sectors - 50+ reported vulnerabilities, 17 official CVEs.

Client

IT/OT device manufacturers and operators in the mining, energy, and industrial automation sectors

Challenge

Industrial device manufacturers and operators needed independent security verification of their products - from SCADA systems and controller firmware, through energy devices, to PLCs and OT firewalls.

Approach

01

Penetration testing

White-box and black-box security testing of devices from the mining, energy, and industrial automation sectors.

02

Firmware and hardware analysis

Device decomposition, embedded software analysis, and non-volatile memory data extraction.

03

Protocol fuzzing

Systematic testing of the communication protocol stack to identify bugs - including the DLMS/COSEM protocol of smart meters.

04

Reporting and CVE

Vulnerability documentation with CVSS scoring, reports to manufacturers, and official CVE registration.

Results

17 official CVEs reported by SEQRED
01

Over 50 reported vulnerabilities

02

17 official CVEs (Common Vulnerabilities and Exposures)

03

5 bugs in the DLMS/COSEM protocol stack of smart meters

04

Discovery of a vulnerability enabling meter freeze with a single 22-byte data frame

05

Identification of critical flaws: remote code execution, memory leak, command injection with root privileges

We'll discuss scope, methodology, and timeline.

Book a consultation

Free consultation, no strings attached.