← Back to home
ICSA-23-131-12  ·  Published 2023-05-12  ·  View on CISA ICS-CERT ↗

SDG PnPSCADA

CVSS 9.8 CRITICAL

Risk Summary

Successful exploitation of this vulnerability could allow an attacker to interact with the database and retrieve critical data.

CVEs (1)

Remediations

  • SDG PnpSCADA is aware of the issue and is currently developing a fix. For more information, contact PnpSCADA by email, [email protected]
  • The following workarounds are recommended to help reduce the risk:
  • Use prepared statements to help prevent SQL injections.
  • Avoid making assets publicly accessible.
  • Restrict public access: As a primary mitigation, it is crucial for all PnPSCADA users to avoid exposing their SCADA systems to the internet. By implementing proper network segmentation and isolating the SCADA system from public networks, users can significantly reduce the risk of unauthorized access and exploitation.
  • Implement strong access controls: Ensure that proper authentication and authorization mechanisms are in place to limit access to sensitive components of the SCADA system. This includes implementing role-based access control and regular audits of user privileges.
  • Monitor and log activity: Continuously monitor and log all activities within the SCADA environment. This helps with detecting any potential unauthorized access or attempts to exploit the vulnerability, enabling timely response and mitigation.

Affected Vendors

SDG Technologies

Affected Products (1)

SDG Technologies · PnPSCADA (cross platforms) 2.

Affected Sectors

Multiple Sectors

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more