Live SCADA Purdue Topology & Attack Flow
[EXPOSED PATH DETECTED]
Level 4/5: Enterprise & Remote Access Ingress
Direct IP Exposed
Cellular Modem Gateway
●
IP: 166.142.x.x (Static Public)
Port 3982 / 502 Open
Remote VNC / Web HMI
●
Port 5800 / 80 unencrypted
No MFA Configured
Level 3: Operations & Supervisory SCADA
Unsegmented Subnet
SCADA Historian
WinCC / Wonderware DB
Shared Admin Passwords
Main Plant HMI Desk
Active Operator Console
Unauthenticated PCOM
Level 1/2: Field Control & Logic Controllers
Vulnerable to Defacement
Unitronics Vision V570
EXPLOITED
Default PIN: 1111 (Factory)
Booster & Chlorine Feed
AB MicroLogix 1400
EtherNet/IP Protocol
Cleartext Commands
Level 0: Physical Water Infrastructure & Actuators
Risk of Overpressure / Contamination
High-Service Booster Pump
Status: 3,200 GPM (Tripped by Threat Actor)
480V VFD Drive
Sodium Hypochlorite Dosing
Flow: 1.8 mg/L (Remote Override Risk)
Chemical Disinfection
Rapid Sand Filters
Differential PSI: 4.2
Backwash Logic
Threat Vector Engine:
ACTIVE INTRUSION PATHWAY
Node Inspector & Process Telemetry
Node: Unitronics Vision V570 PLC
Facility Risk Index
CRITICAL (94/100)
Cyber Risk Score
94
Attack Paths Open
3 / 3
PLC is directly reachable via public internet on port 3982. Adversary can issue unauthenticated PCOM commands to force HMI defacement and cut booster station power.
CISA / EPA Hardening Blueprints
Interactive Defense
MITRE ATT&CK for ICS Playbook
TTP Breakdown
T0886 - Remote Service Session Hijack: Public IP scanning on cellular port 3982 identified exposed Unitronics Vision PLC.
T0812 - Default Credentials: Automated authentication attempt with default PIN (1111) succeeded in 12ms.
T0843 - Program Download & Defacement: Adversary altered PLC display graphic to anti-Israel / hacktivist banner.
T0855 - Unauthorized Command Message: Force-coils sent to digital output DO4; booster pump contactor opened, dropping municipal line pressure.