
awesome-industrial-control-system-security
A curated list of resources related to Industrial Control System (ICS) security.

A curated list of resources related to Industrial Control System (ICS) security.

Proof-of-concept SQL injection exploit for FUXA SCADA software (<=1.1.12) via HTTP POST JSON id parameter, enabling extraction of SQLite database…

Defensive security demo: seL4 microkernel gateway protecting vulnerable ICS from CVE-2019-14462

Schneider Electric Magelis HMI Resource Consumption Vulnerabilities [ICSA-16-308-02, CVE-2016-8367, CVE-2016-8374]

ISF(Industrial Control System Exploitation Framework),a exploitation framework based on Python

Proof-of-concept exploit for CVE-2021-26828 enabling authenticated remote code execution on ScadaBR SCADA systems via JSP file upload. Supports…

Proof of Concept (PoC) for CVE: 2017-16744 and 2017-16748

OpenPLC 3 WebServer Authenticated Remote Code Execution.

Simple script to exploit open redirection vulnerability in Rockwell ControlLogix 1756-ENBT/A

To reproduce CVE-2021-31630

APOLOGEE is a Python script and Metasploit module that enumerates a hidden directory on Siemens APOGEE PXC BACnet Automation Controllers (all…

ScadaFlare Authenticated RCE Exploit Framework for ScadaBR (CVE-2021-26828) OpenPLC ScadaBR

ICS-Park Smart Park Management System v2.0

Proof-of-concept exploit for OPC UA authentication bypass using None security policy, including a simulated server to demonstrate unauthorized…

PoC for CVE-2018-12086 affecting various OPC UA stacks

Python exploit for CVE-2025-69985 targeting FUXA SCADA software. Sends crafted JSON payload to /api/runscript endpoint to bypass authentication and…

Exploit for CVE-2025-41744 targeting Sprecher Automation SPRECON-E-C ICS devices, extracting default cryptographic keys to decrypt and tamper with…

CVE-2018-7843