The document analyzes vulnerabilities in industrial control systems (ICS) from 2005 to 2012. Some key findings include:
1. The number of detected vulnerabilities has increased 20-fold since 2010, with more found in the first 10 months of 2012 than in all previous years combined.
2. Most common vulnerabilities allow remote code execution and authentication/authorization bypass. Approximately 65% are considered high or critical severity.
3. While most vendors fix the majority of issues, some vulnerabilities remain unpatched for over 30 days. Over 40% of internet-accessible ICS systems have known vulnerabilities.