← Back to home
ICSA-23-012-01  ·  Published 2023-01-12  ·  View on CISA ICS-CERT ↗

Sewio RTLS Studio

CVSS 10.0 CRITICAL

Risk Summary

Successful exploitation of these vulnerabilities could allow an attacker to obtain unauthorized access to the server, alter information, create a denial-of-service condition, gain escalated privileges, and execute arbitrary code.

Remediations

  • Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.
  • Locate control system networks and remote devices behind firewalls and isolate them from business networks.
  • For CVE-2022-45444: Manually change the database password.
  • RTLS Studio: Update to version 3.0.0 or later (requires login) (Only for the following vulnerabilities: CVE-2022-47911, CVE-2022-43483, CVE-2022-45127, CVE-2022-47395, CVE-2022-47917, CVE-2022-46733, CVE-2022-43455)

Affected Vendors

Sewio

Affected Products (1)

Sewio · RTLS Studio >= 2.0.0 | 2.6.2

Affected Sectors

Multiple

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more