By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Network switch RCE flaw impacts critical infrastructure
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Network switch RCE flaw impacts critical infrastructure
Tech News

Network switch RCE flaw impacts critical infrastructure

By admin 3 Min Read
Share
SHARE

U.S. cybersecurity agency CISA is warning about two critical vulnerabilities that allow authentication bypass and remote code execution in Optigo Networks ONS-S8 Aggregation Switch products used in critical infrastructure.

The flaws concern weak authentication problems, allowing bypassing of password requirements, and user input validation issues potentially leading to remote code execution, arbitrary file uploads, and directory traversal.

The device is used in critical infrastructure and manufacturing units worldwide, and considering that the flaws are remotely exploitable with low attack complexity, the risk is deemed very high.

Currently, no fixes are available, so users are recommended to apply suggested mitigations proposed by the Canadian vendor.

The first flaw is tracked as CVE-2024-41925 and is classified as a PHP Remote File Inclusion (RFI) problem stemming from incorrect validation or sanitation of user-supplied file paths.

An attacker could use this vulnerability to perform directory traversal, bypass authentication, and execute arbitrary remote code.

The second issue, tracked as CVE-2024-45367, is a weak authentication problem arising from improper password verification enforcement on the authentication mechanism.

Exploiting this enables an attacker to gain unauthorized access to the switches’ management interface, alter configurations, access sensitive data, or pivot to other network points.

Both problems were discovered by Claroty Team82 and are rated as critical, with a CVSS v4 score of 9.3. The vulnerabilities impact all ONS-S8 Spectra Aggregation Switch versions up to and including 1.3.7.

Securing the switches

While CISA has not seen signs of these flaws being actively exploited, system administrators are recommended to perform the following actions to mitigate the flaws:

  1. Isolate ONS-S8 management traffic by placing it on a dedicated VLAN to separate it from normal network traffic and reduce exposure.
  2. Connect to OneView only through a dedicated NIC on the BMS computer to ensure secure and exclusive access for OT network management.
  3. Configure a router firewall to whitelist specific devices, limiting OneView access only to authorized systems and preventing unauthorized access.
  4. Use a secure VPN for all connections to OneView to ensure encrypted communication and protect against potential interception.
  5. Follow CISA’s cybersecurity guidance by performing risk assessments, implementing layered security (defense-in-depth), and adhering to best practices for ICS security.

CISA recommends that organizations observing suspicious activity on these devices follow their breach protocols and report the incident to the cybersecurity agency so that it can be tracked and correlated with other incidents.

You Might Also Like

One UI 9 Beta: Available to These Galaxy Phones Now

Why OpenAI Built Symphony and Gave It Away for Free

UK watchdog probes Microsoft over interoperability issues

TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates

After Struggling With EVs, US Automakers Pivot to Energy

TAGGED: Mitigation, Networking, Optigo, Switch, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article Biden, Harris view Helene devastation, 1,000 troops deployed
Next Article Matthew Perry’s Cause of Death: How the Late ‘Friends’ Actor Died
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Bitcoin Monthly Structure Signals Continuation Of Major Historical Trend
Crypto
007 First Light Could Do For Bond What Arkham Asylum Did For Batman
Gaming News
One UI 9 Beta: Available to These Galaxy Phones Now
Tech News
Gold vs oil: Which offers better protection from rising prices during the Iran war?
Business
Why OpenAI Built Symphony and Gave It Away for Free
Tech News
West Brom battling Ipswich to sign their biggest talent since Fellows
Sports
New NRG Energy CEO leans into growth with ‘bring your own power’ for the AI boom and affordability with ‘virtual power plants’
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

One UI 9 Beta: Available to These Galaxy Phones Now

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
One UI 9 Beta: Available to These Galaxy Phones Now
May 17, 2026
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?