

Actively Exploited Vulnerability Threatens Hundreds of Solar Power Stations - Sl...
source link: https://it.slashdot.org/story/23/07/05/2316238/actively-exploited-vulnerability-threatens-hundreds-of-solar-power-stations
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

Actively Exploited Vulnerability Threatens Hundreds of Solar Power Stationsbinspamdupenotthebestofftopicslownewsdaystalestupid freshfunnyinsightfulinterestingmaybe offtopicflamebaittrollredundantoverrated insightfulinterestinginformativefunnyunderrated descriptive typodupeerror
Searches on Shodan indicate that more than 600 of them are reachable on the open Internet. As problematic as that configuration is, researchers from security firm VulnCheck said Wednesday, more than two-thirds of them have yet to install an update that patches CVE-2022-29303, the tracking designation for a vulnerability with a severity rating of 9.8 out of 10. The flaw stems from the failure to neutralize potentially malicious elements included in user-supplied input, leading to remote attacks that execute malicious commands. Security firm Palo Alto Networks said last month the flaw was under active exploit by an operator of Mirai, an open source botnet consisting of routers and other so-called Internet of Things devices. The compromise of these devices could cause facilities that use them to lose visibility into their operations, which could result in serious consequences depending on where the vulnerable devices are used.
"The fact that a number of these systems are Internet facing and that the public exploits have been available long enough to get rolled into a Mirai-variant is not a good situation," VulnCheck researcher Jacob Baines wrote. "As always, organizations should be mindful of which systems appear in their public IP space and track public exploits for systems that they rely on." Baines said that the same devices vulnerable to CVE-2022-29303 were also vulnerable to CVE-2023-23333, a newer command-injection vulnerability that also has a severity rating of 9.8. Although there are no known reports of it being actively exploited, exploit code has been publicly available since February. Incorrect descriptions for both vulnerabilities are one factor involved in the patch failures, Baines said. Both vulnerabilities indicate that SolarView versions 8.00 and 8.10 are patched against CVE-2022-29303 and CVE-2023-293333. In fact, the researcher said, only 8.10 is patched against the threats.
Recommend
-
32
GET YOUR UPDATE — Firefox gets patch for critical 0-day that’s being actively exploited Flaw allows attackers to access sensitive memory locations that are no...
-
9
Apple released patches for all its operating systems today to squash an actively exploited WebKit flaw Once again, WebKit is vulnerable to arbitrary code execution By...
-
10
News Critical flaw in Atlassian Confluence actively exploited The remote code execution vulnerability was recently patched for affected versions of Atlassian...
-
8
Important information: Detectify scans for actively exploited critical Apache Log4j vulnerability, CVE-2021-44228
-
5
News Apache Log4j vulnerability actively exploited, impacting millions of Java-based apps The vulnerability af...
-
7
News Analysis CISA warns about 15 actively exploited vulnerabilities The high-severity vulnerabilities...
-
6
An Activel...
-
12
Apple rushes macOS, iOS, and iPadOS updates to squash 'actively exploited' bugs...
-
6
patch now — New macOS 12.5.1 and iOS 15.6.1 updates patch “actively exploited” vulnerabilities Kernel and WebKit bugs can allow arbitrary code execution on Apple's devices....
-
10
GOT PATCHES? — Actively exploited vulnerability threatens hundreds of solar power stations Organizations using unpatched SolarView products face potentially serious consequ...
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK