Unpatched SolarView Systems Vulnerable to Exploits

Security researchers at VulnCheck highlighted the exploitation of vulnerabilities in the SolarView series, industrial control system (ICS) hardware widely used for monitoring solar power generation and storage.

These findings, which were released shortly after Palo Alto Networks Unit 42’s announcement on June 22, 2023, revealed variants of the Mirai botnet exploiting a variety of new vulnerabilities.

Read more about Mirai botnet attacks: New Mirai variant campaign targets IoT devices

According to a new VulnCheck blog post, CVE-2022-29303 is an unauthenticated remote command injection vulnerability affecting the Contec SolarView series, posing a significant threat to organizations relying on these ICS devices .

The company’s research found that the vulnerability’s impact extends far beyond the initially reported subset of affected systems. Less than a third of Internet-connected SolarView installations have the required patches, leaving many systems open to exploitation.

“This shows that maintaining cyber hygiene on IoT/OT/ICS systems continues to be a challenge for most organizations, especially when it comes to keeping firmware up-to-date (the most secure version).” Commented John Gallagher, Vice President of Viakoo Labs.

“Once we see that less than one-third of our affected systems are patched, organizations should reassess how they patch systems and ensure automated methods.”

VulnCheck’s research uncovered two additional unauthenticated remote code execution vulnerabilities affecting the SolarView series. CVE-2023-23333 and CVE-2022-44354. An attacker could execute arbitrary commands and upload a malicious PHP web shell.

The company says these vulnerabilities are being actively exploited by multiple sources, including Exploit-DB entries, GitHub exploits, and even publicly available YouTube videos demonstrating attacks on SolarView systems. said it is.

To protect critical infrastructure and prevent unauthorized access, organizations using SolarView hardware need to patch quickly.

“Stacking CVEs or exploiting more than one at once increases the risk. The greater the risk, the greater the risk of service disruption, loss of revenue, espionage, and potential safety hazards when dealing with energy/power systems. There may be concerns,” explained Tanium Chief Security Advisor Timothy Morris.

“If lateral movement to other corporate networks and systems is possible, the likelihood of a data breach increases significantly.”

The VulnCheck vulnerability came hours after the Port of Nagoya, Japan, reported a major system failure due to a ransomware attack.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *