When monitoring the communications of process control devices, Kaspersky Industrial CyberSecurity for Networks can determine when default passwords are used. If a connection is made to a device using a password that is set as the default password for the particular type of device, the application registers the corresponding event. To register default password detection events, the application uses the system event type for the detection of system commands.
Kaspersky Industrial CyberSecurity for Networks detects default passwords in the following cases:
Detection of default passwords is supported for certain types of devices and application-level protocols (see the table below).
Supported devices and protocols with default passwords
Devices |
Protocols |
System commands |
---|---|---|
ABB Relion series: RED670, REL670, RET670 |
ABB SPA-Bus |
DEFAULT PASSWORD ENTRY DEFAULT PASSWORD SET |
BECKHOFF CX series |
BECKHOFF ADS/AMS |
DEFAULT PASSWORD ENTRY DEFAULT PASSWORD READ DEFAULT PASSWORD SET |
Emerson ControlWave series |
Emerson ControlWave Designer |
DEFAULT PASSWORD ENTRY |
General Electric MULTILIN series: B30, C60 |
Modbus TCP |
DEFAULT PASSWORD ENTRY DEFAULT PASSWORD READ DEFAULT PASSWORD READ WITH TYPE DEFAULT PASSWORD SET |
Mitsubishi System Q E71 |
Mitsubishi MELSEC System Q |
DEFAULT PASSWORD SET |
Schneider Electric Modicon: M580, M340 |
Modbus TCP |
DEFAULT PASSWORD READ WITH TYPE |
Siemens SIMATIC S7-200, S7-300, S7-400 |
Siemens Industrial Ethernet Siemens S7comm |
DEFAULT PASSWORD ENTRY DEFAULT PASSWORD READ |
Siemens SIMATIC S7-1200, S7-1500 |
Siemens Industrial Ethernet Siemens S7comm-plus |
DEFAULT PASSWORD ENTRY DEFAULT PASSWORD READ DEFAULT PASSWORD SET |
Prosoft-Systems Regul R500, PLC with a runtime system for CODESYS V3 |
CODESYS V3 Gateway |
DEFAULT PASSWORD ENTRY DEFAULT PASSWORD READ DEFAULT PASSWORD SET |
EKRA 200 series |
Modbus TCP for devices of Ekra 200 series |
DEFAULT PASSWORD READ DEFAULT PASSWORD SET |
EKRA BE2502, BE2704 series |
ABB SPA-Bus |
DEFAULT PASSWORD ENTRY DEFAULT PASSWORD SET |
To register default password detection events, the following conditions must be met: