Secheron SEPCOS Control and Protection Relay
Published Jun 24, 2022
7.5
HIGHCVSS 3.1
EPSS 1.26%
Description
Client-side JavaScript controls may be bypassed by directly running a JS function to reboot the PLC (e.g., from the browser console) or by loading the corresponding, browser accessible PHP script
Affected products
-
Affected
- ≥ All versions, < 1.23.21
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Secheron | SEPCOS Control and Protection Relay firmware package | unknown | Affected
|
- ≥ 1.23.0 · < 1.23.21
- ≥ 1.24.0 · < 1.24.8
- ≥ 1.25.0 · < 1.25.3
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Secheron recommends updating its software to the latest version:
SEPCOS Single Package firmware (1.23.xx feature level): Update to 1.23.22 or higher version SEPCOS Single Package firmware (1.24.xx feature level): Update to 1.24.8 or higher version SEPCOS Single Package firmware (1.25.xx feature level): Update to 1.25.3 or higher version
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-24953 Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-03 x_refsource_MISCMitigationThird Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-24953 | Advisory | |
| https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-03 | x_refsource_MISCMitigationThird Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data