Photovoltaic plants (PV) facing risk of cyberattack
ID: 197adc20-e455-5a2d-a55f-cb82682287c5
STIX ID: report--197adc20-e455-5a2d-a55f-cb82682287c5
Feed Name: Cyble Blog
### Executive Summary Cyble Research Labs discovered numerous public-facing Solar-Log web interfaces for photovoltaic plants with security misconfigurations and outdated firmware — over 900 instances found via scanning and Google dorking with 20+ investigated as vulnerable. The vulnerabilities (default credentials, unauthenticated config download exposing passwords, CSRF, arbitrary file upload, information disclosure, and unauth DoS) could allow attackers to obtain administrative access, manipulate plant data, upload malicious firmware for complete network takeover, and disrupt energy operations; the report recommends firmware updates, strong passwords and MFA, network segmentation, logging/monitoring, and incident response planning.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
