logo

CISA: Network switch RCE flaw impacts critical infrastructure

ID: 0bd831cb-2a04-598c-a21a-ff035314bbd5

STIX ID: report--0bd831cb-2a04-598c-a21a-ff035314bbd5

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-10-02

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

CISA and Claroty Team82 disclosed two critical vulnerabilities in Optigo Networks ONS-S8 Spectra Aggregation Switches (<= 1.3.7): CVE-2024-41925 (PHP Remote File Inclusion permitting directory traversal and remote code execution) and CVE-2024-45367 (weak authentication allowing management interface access). Both are rated critical (CVSS v4 9.3), impact critical infrastructure, are remotely exploitable with low complexity, and currently lack fixes—CISA recommends network isolation, firewall whitelisting, VPN use, and other mitigations while urging reporting of suspicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.