CVE-2022-29303 flaw in SolarView product can be exploited in attacks against the energy sector
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-29303 | Unauthenticated Command Injection in Contec SolarView Compact CVE-2022-29303 is an unauthenticated OS command injection flaw (CWE-78) in Contec SolarView Compact version 6.00, reachable through the conf_mail.php script. Because the CVSS vector requires no privileges and no user interaction over the network, a remote attacker can send crafted input to the vulnerable script and have it executed as operating system commands. Successful exploitation yields remote code execution on the device with the privileges of the web service, which attackers can leverage to recruit exposed monitors into Mirai-style IoT botnets or as a foothold into energy-sector networks. Affected organizations are operators of internet-facing SolarView Compact (SV-CPT-MC310 firmware) solar power monitoring systems. The flaw is under active exploitation: it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-07-13, carries a 98% EPSS probability of exploitation within 30 days, and public reporting describes attacks threatening hundreds of solar power stations. Do: Apply Contec's updates per vendor instructions (CISA's required action), or discontinue use of the product if updates are unavailable; the affected release in the data is SolarView Compact 6.00, so update to any vendor-provided fixed release. Limit or remove internet exposure of the SolarView web interface and review access logs for unsolicited requests to conf_mail.php. Defenders should also watch for signs of IoT botnet compromise, as this flaw is among those used in Mirai campaigns. | 9.8 | 98% | KEV PoC ×2 |
| nichehundreds of internet-exposed solar power stations/monitoring systems | |
| CVE-2022-44354 | SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file. SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — |
Full article363 words · extracted from securityaffairs.com · click to collapse

A vulnerability in SolarView product can be exploited in attacks targeting organizations in the energy sector.
Researchers from the cybersecurity firm VulnCheck reported that the vulnerability CVE-2022-29303 in the solar power monitoring Contec SolarView product can be exploited in attacks targeting organizations in the energy sector.
CVE-2022-29303 is an unauthenticated and remote command injection vulnerability impacting the Contec SolarView Series. Researchers at VulnCheck analyzed a number of public exploits for the above issue to determine the potential scale and impact of its exploitation.
According to Contec, the SolarView has been introduced at more than 30,000 power stations.
Hundreds of organizations in the energy sector could be exposed to cyber attacks exploiting the above issue that is known to be actively exploited in the wild.
Since March 2023, researchers at Palo Alto Networks Unit 42 have observed a new variant of the Mirai botnet targeting multiple vulnerabilities in popular IoT devices, including the CVE-2022-29303.
VulnCheck experts discovered, using Shodan, more than 615 internet-exposed SolarView installs, 425 of them running vulnerable versions.

“It turns out that less than one third of the internet-facing SolarView series systems are patched against CVE-2022-29303.” reads the analysis published by VulnCheck.
The experts also warned of other flaws affecting the SolarView Series, such as the vulnerbaility CVE-2022-44354, which can be exploited by an attacker to upload a PHP webshell of the system.
“We’ve looked at a few critical CVEs that affect the SolarView series and determined that there are a few hundred internet-facing systems that remain affected by these issues. When considered in isolation, exploitation of this system is not significant. The SolarView series are all monitoring systems, so loss of view (T0829) is likely the worst-case scenario.However, the impact of exploitation could be high impact depending on the network the SolarView hardware is integrated into.” concludes the report. “For instance, if the hardware is part of a solar power generation site, then the attacker may affect loss of productivity and revenue (T0828) by using the hardware as a network pivot to attack other ICS resources.”
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, health sector)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/148216/hacking/solarview-flaws-energy-sector.html