New vulnerabilities threaten another Solar Winds-style security disaster


Eight new vulnerabilities were recently discovered in the Open Automation Software (OAS) platform which, if leveraged, could have triggered another supply chain security disaster.
According to Talos, Cisco’s cybersecurity arm, the flaws include two high-severity vulnerabilities – CVE-2022-26833 (severity score 9.4) and CVE-2022-26082 (severity score 9.1) – which could enable threat actors to change the configuration of the platform to create new security groups and run arbitrary code.
Various other vulnerabilities discovered in the platform could also have been abused to send network requests, draw down directory listing, steal passwords and launch denial of service attacks.
Vulnerabilities addressed
According to The Register, Cisco worked with OAS to address the vulnerabilities and issue patches.
Speaking to the publication, VP of solutions architecture for Cerberus Sentinel, Chris Clements, described the flaws as “among the scariest cybersecurity threats today,” mostly due to the fact that many major industrial enterprises use OAS.
Among its users are Volvo, General Dynamics, or AES, which use it to facilitate the transfer of data within their IT environments. OAS is described as essential to these organizations’ Industrial Internet of Things (IIoT) efforts.
“An attacker with the ability to disrupt or alter the function of those devices can inflict catastrophic damage on critical infrastructure facilities, but an attack can also be something that may not be immediately obvious,” Clements commented.
He likened the flaws with Stuxnet, a more than a decade-old worm that inflicted serious damage to the Iranian nuclear program. The worm was used to break certain components in nuclear facilities which, despite malfunctioning, reported back as operating normally.
What’s more, the affected systems are so pivotal to these organizations that many postpone taking them offline for patching for years.
“In some instances, air gaps can be a double-edged sword,” Clements said. “Malicious USB devices have been leveraged several times to spread malware on to air-gapped networks, and unless special considerations have been made to perform security patching on the isolated network, the malicious code often finds itself in an environment that’s ripe for exploitation.”
Via The Register (opens in new tab)
Audio player loading… Eight new vulnerabilities were recently discovered in the Open Automation Software (OAS) platform which, if leveraged, could have triggered another supply chain security disaster. According to Talos, Cisco’s cybersecurity arm, the flaws include two high-severity vulnerabilities – CVE-2022-26833 (severity score 9.4) and CVE-2022-26082 (severity score 9.1) –…
Recent Posts
- Lucid’s CEO steps down, as EV maker aims to double production
- iPhones are replacing ‘Trump’ with ‘racist’ during dictation – but Apple is fixing the problem
- The 9 Best Mirrorless Cameras (2025): Full-Frame, APS-C, and More
- Framework Desktop hands-on: a possible new direction for gaming desktops
- ChatGPT is a terrible, fascinating, and thrilling to-do list app
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010