Research Article

An Automatic Planning-Based Attack Path Discovery Approach from IT to OT Networks

Table 3

Device information in the experimental environment.

Dev.IDDevice namePortVulnerabilityAffected component

Dev1Manager PCLNK remote code executionIcon of the shortcut in windows platform
Credentials leakConnected device login
Dev2Application server22OS command injectionOpenSSH(SCP)
Dev3ERP server3389BITS improper privilege managementWindows background intelligent transfer service
Dev4Data server3306Permissions and access controlsMySQL
Dev5Web server80Memory buffer overflowInternet information services
Dev6Mail server80Improper access controlRoundcube
Dev7DNS server53DNS server remote code executionWindows DNS server
Dev8Proxy server8090, 4900Path traversalLanproxy server
Dev9Proxy client12000Plaintext credentialLanproxy client
Dev10MES client445SMBv3 remote code executionMicrosoft server message block protocol
Credentials leakConnected device login
Dev11MES server22Kernel improper privilege managementLinux kernel
Dev12Historian80SQL server remote code executionMicrosoft SQL server reporting services
Dev13EWS1445, 139Code injectionMSRPC over SMB
Dev14EWS23389Brute forceRemote desktop services
Dev15OWS445SMB remote code executionMicrosoft server message block protocol
Dev16OPC server8080Unrestricted upload of fileApache tomcat
Dev17HMI1 (master)2308, 1033Modify configuration projectHMI configuration project in WinCC
Dev18HMI2 (slave)2308, 1034Modify configuration projectHMI Configuration project in WinCC
Fake MAC addressHMI and PLC communication
Dev19PLC1 (master)102Modify parameters/modesPLC automatic operation/states
Modify control logicPLC program project in TIA portal
Plaintext control commandLegacy S7Comm protocol
Dev20PLC2 (slave)102, 502Fake MAC addressHMI and PLC communication
Modify parameters/modesPLC automatic operation/states
Modify control logicPLC program project in TIA portal
Plaintext control commandModbus protocol
Uncontrolled resource consumptionProtocol common used port
Improper controlCPU defect mode