Actively exploited vulnerability threatens hundreds of solar power stations
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-29303 | Unauthenticated Command Injection in Contec SolarView Compact CVE-2022-29303 is an unauthenticated OS command injection flaw (CWE-78) in Contec SolarView Compact version 6.00, reachable through the conf_mail.php script. Because the CVSS vector requires no privileges and no user interaction over the network, a remote attacker can send crafted input to the vulnerable script and have it executed as operating system commands. Successful exploitation yields remote code execution on the device with the privileges of the web service, which attackers can leverage to recruit exposed monitors into Mirai-style IoT botnets or as a foothold into energy-sector networks. Affected organizations are operators of internet-facing SolarView Compact (SV-CPT-MC310 firmware) solar power monitoring systems. The flaw is under active exploitation: it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-07-13, carries a 98% EPSS probability of exploitation within 30 days, and public reporting describes attacks threatening hundreds of solar power stations. Do: Apply Contec's updates per vendor instructions (CISA's required action), or discontinue use of the product if updates are unavailable; the affected release in the data is SolarView Compact 6.00, so update to any vendor-provided fixed release. Limit or remove internet exposure of the SolarView web interface and review access logs for unsolicited requests to conf_mail.php. Defenders should also watch for signs of IoT botnet compromise, as this flaw is among those used in Mirai campaigns. | 9.8 | 98% | KEV PoC ×2 |
| nichehundreds of internet-exposed solar power stations/monitoring systems |
Full article300 words · extracted from arstechnica.com · click to collapse
Hundreds of Internet-exposed devices inside solar farms remain unpatched against a critical and actively exploited vulnerability that makes it easy for remote attackers to disrupt operations or gain a foothold inside the facilities.
The devices, sold by Osaka, Japan-based Contec under the brand name SolarView, help people inside solar facilities monitor the amount of power they generate, store, and distribute. Contec says that roughly 30,000 power stations have introduced the devices, which come in various packages based on the size of the operation and the type of equipment it uses.
Searches on Shodan indicate that more than 600 of them are reachable on the open Internet. As problematic as that configuration is, researchers from security firm VulnCheck said Wednesday, more than two-thirds of them have yet to install an update that patches CVE-2022-29303, the tracking designation for a vulnerability with a severity rating of 9.8 out of 10. The flaw stems from the failure to neutralize potentially malicious elements included in user-supplied input, leading to remote attacks that execute malicious commands.
Security firm Palo Alto Networks said last month the flaw was under active exploit by an operator of Mirai, an open source botnet consisting of routers and other so-called Internet of Things devices. The compromise of these devices could cause facilities that use them to lose visibility into their operations, which could result in serious consequences depending on where the vulnerable devices are used.
“The fact that a number of these systems are Internet facing and that the public exploits have been available long enough to get rolled into a Mirai-variant is not a good situation,” VulnCheck researcher Jacob Baines wrote. “As always, organizations should be mindful of which systems appear in their public IP space and track public exploits for systems that they rely on.”
Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2023/07/actively-exploited-vulnerability-threatens-hundreds-of-solar-power-stations/