Back

HIGH

Secheron SEPCOS Control and Protection Relay

Published Jun 24, 2022

Description

Client-side JavaScript controls may be bypassed by directly running a JS function to reboot the PLC (e.g., from the browser console) or by loading the corresponding, browser accessible PHP script

Affected products

Remediation

Vendor solution

Secheron recommends updating its software to the latest version:

SEPCOS Single Package firmware (1.23.xx feature level): Update to 1.23.22 or higher version SEPCOS Single Package firmware (1.24.xx feature level): Update to 1.24.8 or higher version SEPCOS Single Package firmware (1.25.xx feature level): Update to 1.25.3 or higher version

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner icscert
Published Jun 24, 2022
Updated Apr 16, 2025
Reserved May 10, 2022

CISA Vulnrichment

Updated Apr 16, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner icscert
Published Jun 24, 2022
Updated Apr 16, 2025

GitHub

No data