In the wake of a researcher's public disclosure of flaws in Siemens products that could let an attacker take over a control system without even knowing the username and password, Siemens today said it will issue security updates in January to fix product vulnerabilities.
Security researcher Billy Rios on Tuesday posted details in his blog of some of the vulnerabilities he and fellow researcher Terry McCorke had found and reported to the ICS-CERT and Siemens in May. Siemens confirmed it was in the process of fixing the flaws today after Rios cried foul when the company appeared to deny the existence of the vulnerabilities that he and fellow researcher Terry McCorke had been working with the company on fixing.

The link for this article located at Dark Reading is no longer available.