SCADA: EtherNet/IP CIP Unauthorized Command Execution
This signature detects malicious EtherNet/IP CIP commands sent to a SCADA PLC device. Such commands allow an unauthorized, remote attacker to shutdown or reset PLC CPU and ethernet interface, causing abnormal service disruption.
References
URL: http://www.digitalbond.com/tools/basecamp/metasploit-modules/
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3