ICSA-24-275-01
·
Published 2024-10-01
·
View on CISA ICS-CERT ↗
Optigo Networks ONS-S8 - Spectra Aggregation Switch
CVSS 9.8
CRITICAL
Risk Summary
Successful exploitation of these vulnerabilities could allow an attacker to achieve remote code execution, arbitrary file upload, or bypass authentication.
CVEs (2)
Remediations
- Optigo Networks recommends users always use a unique management VLAN for the port on the ONS-S8 that is used to connect to OneView.
- Optigo Networks also recommends users implement at least one of the following additional mitigations:
- Use a dedicated NIC on the BMS computer and exclusively this computer for connecting to OneView to manage your OT network configuration.
- Set up a router firewall with a white list for the devices permitted to access OneView.
- Connect to OneView via secure VPN.
Affected Vendors
Optigo Networks
Affected Products (1)
Optigo Networks
·
ONS-S8 - Spectra Aggregation Switch
<=1.3.7
Affected Sectors
Critical Manufacturing
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more