ICSA-23-353-01
·
Published 2023-12-19
·
View on CISA ICS-CERT ↗
Subnet Solutions Inc. PowerSYSTEM Center
CVSS 7.8
HIGH
Risk Summary
Successful exploitation of this vulnerability could result in an attacker achieving arbitrary code execution and privilege escalation through the unquoted service path.
CVEs (1)
Remediations
- Subnet Solutions recommends users upgrade to PowerSYSTEM Center versions 2020 Update 17 or later. To obtain this software, contact Subnet Solution's Customer Service.
- Additionally, Subnet Solutions recommends users apply Application Allowlisting on PowerSYSTEM Center Device Communication Server (DCS) hosts to ensure only trusted executables are able to be run.
- If unable to apply PowerSYSTEM Center 2020 Update 17, Subnet Solutions recommends users mitigate risk by logging in to the DCS as administrator, opening the Registry Editor, navigating to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services, locating all pscagent.* entries, and modifying the ImagePath key by enclosing it within double quotes ("). Restart computer when complete.
Affected Vendors
Subnet Solutions Inc.
Affected Products (1)
Subnet Solutions Inc.
·
PowerSYSTEM Center 2020
>=v5.0.x|<=5.16.x
Affected Sectors
Multiple
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more