← Back to home
ICSA-24-275-01  ·  Published 2024-10-01  ·  View on CISA ICS-CERT ↗

Optigo Networks ONS-S8 - Spectra Aggregation Switch

CVSS 9.8 CRITICAL

Risk Summary

Successful exploitation of these vulnerabilities could allow an attacker to achieve remote code execution, arbitrary file upload, or bypass authentication.

Remediations

  • Optigo Networks recommends users always use a unique management VLAN for the port on the ONS-S8 that is used to connect to OneView.
  • Optigo Networks also recommends users implement at least one of the following additional mitigations:
  • Use a dedicated NIC on the BMS computer and exclusively this computer for connecting to OneView to manage your OT network configuration.
  • Set up a router firewall with a white list for the devices permitted to access OneView.
  • Connect to OneView via secure VPN.

Affected Vendors

Optigo Networks

Affected Products (1)

Optigo Networks · ONS-S8 - Spectra Aggregation Switch <=1.3.7

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more