Исследователи из SEC Consult опубликовали подробный отчет о реверс-инжиниринге Siemens S7-1200 PLC
...
This means for the potential attackers:
- Hardware backdoors could be installed on the PCB of the Siemens PLC.
- All application programs on the PLC could be modified during run-time.
- A PLC-persistent malware could be designed.
- Since the NAND flash of the S7-1200v4 is write-able, it could be possible to place a backdoor in the firmware at this memory segment without leaving any trace (more complicated but invisible).
https://sec-consult.com/en/blog/2019/02/reverse-engineering-architecture-pinout-plc/