CISA: Network switch RCE flaw impacts critical infrastructure
ID: 0bd831cb-2a04-598c-a21a-ff035314bbd5
STIX ID: report--0bd831cb-2a04-598c-a21a-ff035314bbd5
Feed Name: Bleeping Computer
CISA and Claroty Team82 disclosed two critical vulnerabilities in Optigo Networks ONS-S8 Spectra Aggregation Switches (<= 1.3.7): CVE-2024-41925 (PHP Remote File Inclusion permitting directory traversal and remote code execution) and CVE-2024-45367 (weak authentication allowing management interface access). Both are rated critical (CVSS v4 9.3), impact critical infrastructure, are remotely exploitable with low complexity, and currently lack fixes—CISA recommends network isolation, firewall whitelisting, VPN use, and other mitigations while urging reporting of suspicious activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
