Two simple give-me-control security bugs found in Optigo network switches used in critical manufacturing
ID: 3e428aaa-e602-59f7-ad36-12c9fecd8ff3
STIX ID: report--3e428aaa-e602-59f7-ad36-12c9fecd8ff3
Feed Name: The Register (Security)
Two critical vulnerabilities (CVSS v4 score 9.3) were disclosed in Optigo Spectra Aggregation Switch firmware (≤1.3.7): a PHP remote-file inclusion (CVE-2024-41925) enabling remote code execution and an authentication bypass (CVE-2024-45367) allowing unauthenticated access to the web UI; no patches are available, CISA and Claroty disclosed the issues, and Optigo recommended mitigating workarounds (restrict OneView access, use a dedicated management interface and VPN) while noting no known active exploitation so far.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
