June 27, 2024, noon | CISA

All CISA Advisories www.cisa.gov

View CSAF


1. EXECUTIVE SUMMARY



  • CVSS v4 9.3

  • ATTENTION: Exploitable remotely/low attack complexity

  • Vendor: SDG Technologies

  • Equipment: PnPSCADA

  • Vulnerability: Missing Authorization


2. RISK EVALUATION


Successful exploitation of this vulnerability could allow an attacker to attach various entities without requiring system authentication. This breach could potentially lead to unauthorized control, data manipulation, and access to sensitive information within the SCADA system.


3. TECHNICAL DETAILS


3.1 AFFECTED PRODUCTS


The following versions of SDG Technologies PnPSCADA, a …

access attack attacker attention authentication authorization breach complexity control csaf cvss data data manipulation entities equipment evaluation executive exploitation information low manipulation missing risk sdg sdg technologies sensitive sensitive information system technologies unauthorized vendor vulnerability

Technology Risk & Controls Manager

@ LegalAndGeneral | London, United Kingdom

Solutions Architect - Prisma Cloud

@ Palo Alto Networks | Munich, Germany

Security Operations Engineer

@ Cognite | Oslo

Ingénieur Cybersécurité PKI

@ Alter Solutions | PARIS, France

Cyber Security Project Engineer

@ Dezign Concepts LLC | Chantilly, VA

Cloud Cybersecurity Incident Response Lead

@ Maveris | Martinsburg, West Virginia, United States