started · updated
AI can port RCE exploits to industrial controllers, researchers find
Security researchers from Vedere Labs and Forescout have demonstrated that artificial intelligence can be used to port remote code execution (RCE) exploits between different models of WAGO programmable logic controllers (PLCs). Using Anthropic’s Claude, researchers successfully ported an exploit targeting a stack-based buffer overflow in the Nucleus FTP server (CVE-2021-31886) from one WAGO model to another, allowing for the execution of attacker-supplied ARM shellcode on live hardware.
While the experiment proved that AI can assist in targeting operational technology (OT), researchers noted significant practical barriers. The process required heavy human steering and substantial costs, with the final RCE development stage consuming over $535 in API usage during an eight-hour session. Additionally, an attempt to extend the exploit into a command-and-control implant resulted in the PLC being permanently bricked.
Experts suggest that while the ability to automate exploitation is a concerning development for critical infrastructure, the current difficulty, cost, and requirement for specialist expertise make such attacks less attractive to general cybercriminals compared to easier alternatives. However, nation-state actors remain a primary concern for OT security.
Entities
Anthropic · Claude · Forescout · Vedere Labs · WAGO