logo

Two simple give-me-control security bugs found in Optigo network switches used in critical manufacturing

ID: 3e428aaa-e602-59f7-ad36-12c9fecd8ff3

STIX ID: report--3e428aaa-e602-59f7-ad36-12c9fecd8ff3

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-10-02

Date Updated: 2026-04-26

Author: Iain Thomson

...
...

Two critical vulnerabilities (CVSS v4 score 9.3) were disclosed in Optigo Spectra Aggregation Switch firmware (≤1.3.7): a PHP remote-file inclusion (CVE-2024-41925) enabling remote code execution and an authentication bypass (CVE-2024-45367) allowing unauthenticated access to the web UI; no patches are available, CISA and Claroty disclosed the issues, and Optigo recommended mitigating workarounds (restrict OneView access, use a dedicated management interface and VPN) while noting no known active exploitation so far.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.