ICSA-23-012-01
·
Published 2023-01-12
·
View on CISA ICS-CERT ↗
Sewio RTLS Studio
CVSS 10.0
CRITICAL
Risk Summary
Successful exploitation of these vulnerabilities could allow an attacker to obtain unauthorized access to the server, alter information, create a denial-of-service condition, gain escalated privileges, and execute arbitrary code.
CVEs (9)
Remediations
- Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.
- Locate control system networks and remote devices behind firewalls and isolate them from business networks.
- For CVE-2022-45444: Manually change the database password.
- RTLS Studio: Update to version 3.0.0 or later (requires login) (Only for the following vulnerabilities: CVE-2022-47911, CVE-2022-43483, CVE-2022-45127, CVE-2022-47395, CVE-2022-47917, CVE-2022-46733, CVE-2022-43455)
Affected Vendors
Sewio
Affected Products (1)
Sewio
·
RTLS Studio
>= 2.0.0 | 2.6.2
Affected Sectors
Multiple
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more