← Back to home
ICSA-23-353-01  ·  Published 2023-12-19  ·  View on CISA ICS-CERT ↗

Subnet Solutions Inc. PowerSYSTEM Center

CVSS 7.8 HIGH

Risk Summary

Successful exploitation of this vulnerability could result in an attacker achieving arbitrary code execution and privilege escalation through the unquoted service path.

CVEs (1)

Remediations

  • Subnet Solutions recommends users upgrade to PowerSYSTEM Center versions 2020 Update 17 or later. To obtain this software, contact Subnet Solution's Customer Service.
  • Additionally, Subnet Solutions recommends users apply Application Allowlisting on PowerSYSTEM Center Device Communication Server (DCS) hosts to ensure only trusted executables are able to be run.
  • If unable to apply PowerSYSTEM Center 2020 Update 17, Subnet Solutions recommends users mitigate risk by logging in to the DCS as administrator, opening the Registry Editor, navigating to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services, locating all pscagent.* entries, and modifying the ImagePath key by enclosing it within double quotes ("). Restart computer when complete.

Affected Vendors

Subnet Solutions Inc.

Affected Products (1)

Subnet Solutions Inc. · PowerSYSTEM Center 2020 >=v5.0.x|<=5.16.x

Affected Sectors

Multiple

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more