Secheron SEPCOS Control and Protection Relay
Published Jun 24, 2022
9.9
CRITICALCVSS 3.1
EPSS 1.10%
Description
The www-data (Apache web server) account is configured to run sudo with no password for many commands (including /bin/sh and /bin/bash).
Affected products
-
- Version All versionsStatusaffectedConstraints<1.23.21
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Secheron | SEPCOS Control and Protection Relay firmware package | n/a |
|
- ≥ 1.23.0 · < 1.23.21
- ≥ 1.24.0 · < 1.24.8
- ≥ 1.25.0 · < 1.25.3
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Secheron recommends updating its software to the latest version:
SEPCOS Single Package firmware (1.23.xx feature level): Update to 1.23.22 or higher version SEPCOS Single Package firmware (1.24.xx feature level): Update to 1.24.8 or higher version SEPCOS Single Package firmware (1.25.xx feature level): Update to 1.25.3 or higher version
References (1)
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-03 x_refsource_MISCMitigationThird Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-03 | x_refsource_MISCMitigationThird Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.