Back to all lessons
Awareness Lessons
last month

AI-Assisted Exploit Porting Lowers the Bar for ICS/PLC Attacks

Researchers demonstrated that a known 2021 pre-authentication RCE vulnerability (CVE-2021-31886) in WAGO PLCs could be ported to a related model using AI assistance, significantly reducing the expertise barrier for attacking industrial control systems. The root issue is unpatched, legacy vulnerabilities persisting in operational technology (OT) environments where patching cycles are slow or non-existent. This matters because ICS/SCADA devices like PLCs often control critical physical infrastructure, meaning a successful exploit can cause real-world harm — including, as shown here, bricking hardware. The proliferation of AI tools means attackers can now adapt and repurpose known exploits across similar device families with less skill and effort than before, dramatically expanding the threat surface for industrial environments.

Tactical Insight

Immediate actions

  • Apply vendor patches for CVE-2021-31886 and audit all WAGO PLC models in your environment for related firmware vulnerabilities.
  • Isolate all PLCs and OT devices from internet-facing networks using strict firewall rules and VLANs.

Long-term improvements

  • Establish a formal OT/ICS vulnerability management program with defined patching SLAs that account for operational constraints.
  • Maintain a complete, up-to-date asset inventory of all OT/ICS devices including firmware versions, models, and communication dependencies.
  • Engage vendors proactively about end-of-life devices that can no longer receive security patches and plan for hardware refresh cycles.

Detection measures

  • Deploy OT-aware network monitoring (e.g., Claroty, Dragos, or Nozomi) to detect anomalous traffic or unexpected command sequences targeting PLCs.
  • Enable logging on engineering workstations and historian servers to capture lateral movement attempts toward OT segments.