DEV Community

TechSavant Security Lab
TechSavant Security Lab

Posted on

Your Engineering Workstation Is the Weakest PLC Interface: A 45-Minute Audit Based on September 2026 ICS Advisories

Most OT security conversations start at the controller: firmware versions, Modbus exposure, whether the PLC is reachable from the corporate network. Those matter. But if you read the CISA ICS advisories published in early September 2026 side by side, a different pattern shows up: the weakest link was the software around the controller — the remote-access client, the firmware flashing tool, the SCADA gateway's default roles.

This post walks through three of those advisories and turns them into a short, repeatable audit for engineering workstations (EWS) and jump hosts. No exotic tooling: PowerShell, a spreadsheet, and about 45 minutes per site.

The three advisories

1. IXON VPN Client — CVE-2026-75925 (ICSA-26-246-02). The NVD/CVE record describes a CRLF injection in IXON VPN Client before 1.4.7 that "allows an attacker to execute commands as root or SYSTEM." Configuration values accepted by the local service are written to a file consumed by a privileged subprocess without neutralizing line endings, and "the configuration interface accepts changes without authenticating or verifying the origin of the requester." The injected config persists across reboots and the VPN keeps working normally, so the user sees nothing unusual. Scores: CVSS v3.1 9.6, CVSS v4.0 9.4. Fix: update to 1.4.7 or later, or uninstall if not needed (OpenCVE record, Security Boulevard summary).

2. Rockwell Automation ControlFLASH — CVE-2026-12663 (ICSA-26-246-03). Version 15.07 and earlier: the installer grants the Everyone group write access to a product directory, which can allow code execution at the logged-in user's privilege level. Fixed in 15.08; the interim workaround is removing Everyone from that directory's permissions. Reported as not remotely exploitable (Security Boulevard summary).

3. Inductive Automation Ignition — CVE-2026-77393 (ICSA-26-246-06). In 8.1.53 and earlier, the Create Project Role(s) setting ships blank, so any authenticated user who can run gateway scripts can create projects. CVSS v3.1 8.8. Fix: 8.1.54 or the 8.3 line; on 8.1 you can set Create Project Role(s) to your Designer role (Security Boulevard summary).

None of these had known public exploitation at publication. That's the point: this is the window to fix them quietly, before they show up in someone's playbook.

The pattern: trust you didn't know you granted

Each advisory is a different bug class (CRLF injection, insecure file permissions, insecure default config), but they share a root cause: a component on or near the EWS was trusted more than it deserved.

  • A local service accepted config from anyone who could talk to it.
  • A directory used by a firmware tool was writable by every user.
  • A gateway let any authenticated scripter create projects.

An attacker who lands on a jump host via phishing or a reused password doesn't need a PLC zero-day. They need one of these.

The 45-minute EWS audit

Run this on every engineering workstation, jump host, and HMI that runs Windows. Record results in a sheet: host, check, result, owner, due date.

Step 1 — Inventory OT software and versions (10 min)

You can't patch what you haven't listed. This PowerShell pulls installed software from both registry hives and filters for common OT vendors:

# Run as admin on each EWS / jump host
$paths = @(
  'HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\*',
  'HKLM:\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*'
)
$vendors = 'IXON|Rockwell|Inductive|Siemens|Schneider|ControlFLASH|FactoryTalk|RSLinx|Ignition|TeamViewer|AnyDesk|eWON|Secomea'

Get-ItemProperty $paths -ErrorAction SilentlyContinue |
  Where-Object { $_.DisplayName -match $vendors -or $_.Publisher -match $vendors } |
  Select-Object @{n='Host';e={$env:COMPUTERNAME}}, DisplayName, DisplayVersion, Publisher, InstallDate |
  Sort-Object DisplayName |
  Export-Csv -NoTypeInformation -Path ".\ot_inventory_$env:COMPUTERNAME.csv"
Enter fullscreen mode Exit fullscreen mode

Then compare against the advisories:

Product Vulnerable Fixed
IXON VPN Client < 1.4.7 1.4.7+
Rockwell ControlFLASH ≤ 15.07 15.08
Ignition (gateway) ≤ 8.1.53 8.1.54 / 8.3

Note anything you find that nobody can explain. A remote-access client nobody remembers installing is a finding on its own.

Step 2 — Find world-writable program directories (10 min)

The ControlFLASH bug is one instance of a common installer mistake. Check for it generally, not just in one product folder:

# Flags folders under Program Files where broad groups have write/modify rights
$roots = @("$env:ProgramFiles", "${env:ProgramFiles(x86)}", "$env:ProgramData")
$broad = 'Everyone|BUILTIN\\Users|Authenticated Users'
$rights = 'Write|Modify|FullControl'

foreach ($root in $roots) {
  Get-ChildItem $root -Directory -Depth 2 -ErrorAction SilentlyContinue | ForEach-Object {
    $acl = Get-Acl $_.FullName -ErrorAction SilentlyContinue
    foreach ($ace in $acl.Access) {
      if ($ace.IdentityReference -match $broad -and
          $ace.FileSystemRights -match $rights -and
          $ace.AccessControlType -eq 'Allow') {
        [pscustomobject]@{
          Path = $_.FullName
          Identity = $ace.IdentityReference
          Rights = $ace.FileSystemRights
        }
      }
    }
  }
} | Format-Table -AutoSize
Enter fullscreen mode Exit fullscreen mode

ProgramData will produce some expected hits (many apps need writable data folders). Focus on directories that contain executables or DLLs. Before removing permissions on a production EWS, check with the vendor guidance — for ControlFLASH, Rockwell's workaround is specifically to remove Everyone from the affected directory.

Step 3 — Review remote-access clients (10 min)

The IXON issue is a reminder that the VPN/remote-access client is a privileged service listening on the host. For each one found in Step 1:

  • [ ] Is it still needed? If not, uninstall (the advisory explicitly lists this as an option).
  • [ ] Is it on a supported, patched version?
  • [ ] Does it run as SYSTEM/root? Most do — treat it like a server.
  • [ ] Is it the approved remote-access path, or a shadow one installed by an integrator?
  • [ ] Are sessions logged somewhere outside the host?

List local listening services to see what's actually exposed:

Get-NetTCPConnection -State Listen |
  Select-Object LocalAddress, LocalPort,
    @{n='Process';e={(Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue).ProcessName}} |
  Sort-Object LocalPort
Enter fullscreen mode Exit fullscreen mode

Anything bound to 0.0.0.0 or :: that you didn't expect deserves a follow-up question.

Step 4 — Audit default roles on SCADA/HMI gateways (10 min)

The Ignition advisory is a configuration problem, not a code problem — and configuration problems survive patching. For every gateway (Ignition, or any SCADA server with a web admin):

  • [ ] Which roles can create or modify projects? Is that setting explicitly set, or blank/default?
  • [ ] Who has scripting rights? Scripting is code execution on the gateway.
  • [ ] Are there shared or generic accounts (operator, admin, integrator)?
  • [ ] Is the admin interface reachable only from the OT management network?
  • [ ] For Ignition 8.1 specifically: set Create Project Role(s) to your Designer role even after upgrading, so the intent is documented.

Step 5 — Write it down and set a re-check (5 min)

  • [ ] Record findings with an owner and a date.
  • [ ] Add these vendors to your advisory watch list (CISA ICS advisories RSS or email).
  • [ ] Schedule the inventory script quarterly; diff the CSVs.
  • [ ] Map findings to IEC 62443-3-3 requirements if you report against it — e.g. least privilege and software inventory controls — so they land in an existing process instead of a one-off spreadsheet.

Patching in OT: be realistic

You can't always update an EWS the same day. Some practical sequencing:

  1. Uninstall what's unused — zero downtime, removes the risk entirely.
  2. Apply config workarounds (ACL fix, role setting) — usually no restart.
  3. Patch remote-access clients — they're the internet-facing edge; prioritize.
  4. Patch engineering tools during the next planned maintenance window, after testing on a non-production EWS.

And keep a clean, offline image of each EWS. If one is compromised, rebuilding from a known-good image is much faster than forensics on the plant floor.

Takeaway

The September 2026 advisories didn't require breaking a PLC. They required trusting a Windows service, a folder, or a default setting a bit too much. An hour of inventory and permission checks per site closes most of that gap — and gives you an asset list you'll need anyway.


If you want a structured version of these checks for your next site visit, I put together a free OT/ICS Quick Audit Checklist covering asset inventory, remote access, accounts, and network segmentation — free to download and adapt for your own audits.

Top comments (0)