logo

Researchers: SCADA Mobile Apps Continue to Have ‘Shocking’ Number of Vulnerabilities

ID: 00bbb7ac-de02-57b7-8ba6-630349631913

STIX ID: report--00bbb7ac-de02-57b7-8ba6-630349631913

Feed Name: Security Ledger

Threat Score
70/100

Date Published: 2018-01-11

Date Updated: 2026-04-26

Author: Elizabeth Montalbano

...
...

Researchers from IOActive and Embedi analyzed 34 mobile SCADA applications and discovered 147 vulnerabilities that expose industrial control systems to attack. The flaws include insecure local storage and improper encryption, and enable three main attack vectors—physical access to devices, manipulation of unprotected communications (GSM/Wi‑Fi), and malicious apps on the same device—to allow data extraction, falsification, or direct influence of industrial processes; more than 20% of findings could directly misinform operators or affect process control. The report urges SCADA app developers and ICS operators to adopt secure coding practices and architecture changes to mitigate these risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.