ICSA-26-132-02
·
Published 2026-05-12
·
View on CISA ICS-CERT ↗
Subnet Solutions PowerSYSTEM Center
CVSS 8.2
HIGH
Risk Summary
Successful exploitation of these vulnerabilities could allow an authenticated attacker to expose sensitive information or cause a CRLF injection.
Remediations
- Subnet Solutions recommends users update to the latest version of PowerSYSTEM Center PSC 2020 Update 29, PSC 2024 Update 2, and PSC 2026 GA Hotfix.
- For assistance in upgrading, users should contact a Subnet Solutions System Integration team member or customer support team at (403) 270-8885 or by email at [email protected].
- Subnet Solutions recommends users do the following in order to reduce risk:
- Monitor user activity records to ensure users are following acceptable usage policies of the application.
- Restrict access to Notification Settings to trusted Administrators Monitor "Send from Address" in settings and Activity Records.
- Configure a notification rule that triggers in any bulk account export activity.
Affected Vendors
Subnet Solutions Inc.
Affected Products (5)
Subnet Solutions Inc.
·
PowerSYSTEM Center 2020
<=5.28.x
Subnet Solutions Inc.
·
PowerSYSTEM Center 2020
>=5.8.x|<=5.28.x
Subnet Solutions Inc.
·
PowerSYSTEM Center 2020
>=5.11.x|<=5.28.x
Subnet Solutions Inc.
·
PowerSYSTEM Center 2024
>=6.0.x|<=6.1.x
Subnet Solutions Inc.
·
PowerSYSTEM Center 2026
7.0.x
Affected Sectors
Critical Manufacturing, Energy
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more