[{"term":"Libraries_BA","id":0,"type":"QUICKLINKS"},{"term":"Instructions","id":1,"type":"QUICKLINKS"},{"term":"WAGO-I/O-PRO","id":2,"type":"QUICKLINKS"},{"term":"Building","id":3,"type":"QUICKLINKS"},{"term":"221","id":4,"type":"QUICKLINKS"}]
{ "@context": "https://schema.org", "@type": "BreadcrumbList", "itemListElement": [ { "@type": "ListItem", "position": 1, "name": "Homepage", "item": "https://www.wago.com/gb" }, { "@type": "ListItem", "position": 2, "name": "Solutions", "item": "https://www.wago.com/gb/industries" }, { "@type": "ListItem", "position": 3, "name": "Open Automation", "item": "https://www.wago.com/gb/open-automation" }, { "@type": "ListItem", "position": 4, "name": "Cybersecurity", "item": "https://www.wago.com/gb/open-automation/cybersecurity" }, { "@type": "ListItem", "position": 5, "name": "PSIRT", "item": "https://www.wago.com/gb/open-automation/cybersecurity/georgia-institute-warns-about-underestimated-risks" } ] } [{"url":"/industries","name":"Solutions","linkClass":null,"categoryCode":null},{"url":"/open-automation","name":"Open Automation","linkClass":null,"categoryCode":null},{"url":"/open-automation/cybersecurity","name":"Cybersecurity","linkClass":null,"categoryCode":null},{"url":"/open-automation/cybersecurity/georgia-institute-warns-about-underestimated-risks","name":"PSIRT","linkClass":"active","categoryCode":null}]
Topics 3 January 2025

High Number of Unreported Errors in Controllers Accessible via the Internet

Georgia Institute of Technology Warns Automation Community about Underestimated Risks of Externally Accessible Programmable Logic Controllers

Security is a top priority for WAGO. To guarantee the security of our customers’ systems, we hold our products to cybersecurity standards just as strict as our quality requirements.

In 2012, WAGO established a Product Security Incident Response Team (PSIRT) to manage potential vulnerabilities. We are certified according to IEC 62443-4-1 and support our customers in operating their WAGO products safely and in protecting existing processes in the context of industrial automation in the best possible way. Hackers’ searches for potential angles of attack are becoming more and more targeted and even include access via Internet. An additional risk comes from search engines like shodan.io and censys.io, which can find unsecured controllers with connections to the Internet, such as WAGO PFCs. That makes it all the more important for our customers to protect their controllers and configure them securely for their specific environments.

A study by the Georgia Institute of Technology has illustrated the relevance of this topic once again. The researchers found that significantly more programmable logic controllers (PLCs) are susceptible to remote attacks than was previously assumed. “Uncovering publicly accessible PLC devices is a crucial step toward securing critical infrastructure,” said Ryan Pickren, lead researcher for the study. “Attackers are actively using the public Internet to attack vulnerable PLCs, so operators need to know which devices are at risk,” explained Pickren. The study demonstrates the limitations of conventional ICS security research methods, which often rely on simple queries from services such as Shodan and Censys to identify at-risk PLCs. The “best-effort” queries used in previous studies tend to search only for simple static keywords that are disclosed by certain protocols. But this often fails to capture the dynamic nature of modern multi-protocol PLC devices, including those from WAGO.

{"container":false,"catalogVersion":"gb-wagoContentCatalog/Online","paragraph":"<p>Lead researcher for the study, Georgia Institute of Technology</p>","lastExportedVersion":7,"type":"Quote Component","dynamicVisibility":true,"cloneable":true,"uuid":"eyJpdGVtSWQiOiJjb21wX2RlXzAwMDBKT0dBIiwiY2F0YWxvZ0lkIjoiZ2Itd2Fnb0NvbnRlbnRDYXRhbG9nIiwiY2F0YWxvZ1ZlcnNpb24iOiJPbmxpbmUifQ==","ignoreOnTransfer":false,"uid":"comp_de_0000JOGA","quote":"Uncovering publicly accessible PLC devices is a crucial step toward securing critical infrastructure.","modifiedtime":"2025-12-12T06:17:35+0000","children":[],"onlyOneRestrictionMustApply":true,"lastLoad":1765520255730,"visible":true,"wagoColumnComponent":[],"imagePosition":"LEFT","availableLanguages":"AVAILABLE","passepartout":true,"restrictions":[],"searchable":true,"lead":"<p>Ryan Pickren</p>","typeCode":"WagoQuoteTeaserComponent","slots":["eyJpdGVtSWQiOiJjc19kZV8wMDAwSURCRSIsImNhdGFsb2dJZCI6ImdiLXdhZ29Db250ZW50Q2F0YWxvZyIsImNhdGFsb2dWZXJzaW9uIjoiT25saW5lIn0="],"itemtype":"WagoQuoteTeaserComponent","restricted":false,"name":"WagoQuoteTeaserComponent","synchronizationBlocked":true,"containers":[],"creationtime":"2025-01-03T11:18:05+0000","actions":[],"contentVersion":7,"parents":[]}