Unpatched SolarView Systems Vulnerable to Exploits
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-29303 | Unauthenticated Command Injection in Contec SolarView Compact CVE-2022-29303 is an unauthenticated OS command injection flaw (CWE-78) in Contec SolarView Compact version 6.00, reachable through the conf_mail.php script. Because the CVSS vector requires no privileges and no user interaction over the network, a remote attacker can send crafted input to the vulnerable script and have it executed as operating system commands. Successful exploitation yields remote code execution on the device with the privileges of the web service, which attackers can leverage to recruit exposed monitors into Mirai-style IoT botnets or as a foothold into energy-sector networks. Affected organizations are operators of internet-facing SolarView Compact (SV-CPT-MC310 firmware) solar power monitoring systems. The flaw is under active exploitation: it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-07-13, carries a 98% EPSS probability of exploitation within 30 days, and public reporting describes attacks threatening hundreds of solar power stations. Do: Apply Contec's updates per vendor instructions (CISA's required action), or discontinue use of the product if updates are unavailable; the affected release in the data is SolarView Compact 6.00, so update to any vendor-provided fixed release. Limit or remove internet exposure of the SolarView web interface and review access logs for unsolicited requests to conf_mail.php. Defenders should also watch for signs of IoT botnet compromise, as this flaw is among those used in Mirai campaigns. | 9.8 | 98% | KEV PoC ×2 |
| nichehundreds of internet-exposed solar power stations/monitoring systems | |
| CVE-2022-44354 | SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file. SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2023-23333 | There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through download There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php. NVD description · AI analysis pending | 9.8 | 99% | PoC |
| — |
Full article370 words · extracted from infosecurity-magazine.com · click to collapse
Security researchers at VulnCheck have highlighted the exploitation of vulnerabilities in the SolarView Series, an industrial control systems (ICS) hardware widely used for monitoring solar power generation and storage.
These findings come on the heels of Palo Alto Networks Unit 42's publication on June 22 2023, which revealed a Mirai botnet variant leveraging various new vulnerabilities.
Read more on Mirai botnet attacks: New Mirai Variant Campaigns are Targeting IoT Devices
According to a new blog post by VulnCheck, CVE-2022-29303, an unauthenticated and remote command injection vulnerability affecting the Contec SolarView Series, poses a significant threat to organizations relying on these ICS devices.
The firm’s investigation discovered that the impact of this vulnerability extends far beyond the initially reported subset of affected systems. Less than one-third of the internet-facing SolarView installations have applied the necessary patches, exposing many systems to exploitation.
“This shows that maintaining cyber hygiene on IoT/OT/ICS systems continues to be a struggle for most organizations, especially when it comes to keeping firmware on the latest (safest versions),” commented John Gallagher, vice president of Viakoo Labs.
“Seeing that less than one-third of impacted systems were patched should cause organizations to reassess their methods of patching systems and ensure they have automated methods.”
VulnCheck’s research uncovered two additional unauthenticated, remote code execution vulnerabilities affecting the SolarView Series. CVE-2023-23333 and CVE-2022-44354, which can enable attackers to execute arbitrary commands and upload malicious PHP web shells.
The company said the active exploitation of these vulnerabilities is evident from multiple sources, including Exploit-DB entries, GitHub exploits and even a publicly available YouTube video demonstrating an attack on a SolarView system.
To safeguard critical infrastructure and prevent unauthorized access, organizations using SolarView hardware must swiftly apply patches.
“Stacking CVEs or exploiting multiples at a time leads to greater risk. Greater risk can mean: service disruption, loss of revenue, espionage and potential safety concerns when dealing with energy/power systems,” explained Timothy Morris, chief security advisor at Tanium.
“If lateral movement to other corporate networks and systems is possible, then the likelihood of a data breach is greatly increased.”
The VulnCheck vulnerability comes hours after the Nagoya Port in Japan reported a significant system outage attributed to a ransomware attack.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/solarview-systems-vulnerable/