Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

Summary

Researchers successfully used Anthropic's Claude AI to port a pre-authentication RCE exploit from one WAGO PLC model to another. The exploit leverages CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server's USER command handling, to execute attacker-supplied ARM shellcode on live hardware.

IFF Assessment

FOE

This development is bad news for defenders as it demonstrates how AI can be used to accelerate and automate the process of porting exploits, potentially increasing the effectiveness and reach of attackers.

Severity

9.8 Critical

Defender Context

This research highlights a concerning trend where AI tools are being used to simplify and speed up the process of developing and porting exploits for critical industrial control systems. Defenders need to be aware of the potential for AI to lower the barrier to entry for sophisticated attacks against OT environments and prioritize patching and hardening vulnerable PLCs.

Read Full Story →