CVE-2021-26829
9.5 CISA KEVOpenPLC · ScadaBR
OpenPLC ScadaBR is vulnerable to a stored cross-site scripting (XSS) attack via the system_settings.shtm endpoint, allowing attackers to execute arbitrary scripts in the context of the application.
Executive summary
This critical vulnerability in OpenPLC ScadaBR allows for stored cross-site scripting and is currently being actively exploited by threat actors in the wild.
Vulnerability
This is a stored cross-site scripting vulnerability triggered via the system_settings.shtm file. The vulnerability requires authenticated access to the application, after which an attacker can inject malicious scripts that execute within the browser sessions of other users.
Business impact
The vulnerability carries a CVSS score of 9.5, reflecting its potential for severe impact on industrial control systems. Successful exploitation can lead to unauthorized session manipulation, defacement of critical HMI interfaces, and potential credential theft, which poses a significant risk to operational continuity and the integrity of industrial monitoring environments.
Remediation
Immediate Action: Upgrade ScadaBR to a fixed release, specifically versions beyond 0.9.1 for Linux or beyond 1.12.4 for Windows, as these versions contain the necessary security patches.
Proactive Monitoring: Review web server logs for suspicious activity targeting the system_settings.shtm endpoint and monitor HMI interfaces for unauthorized modifications or unexpected pop-ups.
Compensating Controls: Implement a Web Application Firewall (WAF) to filter malicious script injections and enforce strict access controls to prevent unauthorized users from reaching the administrative settings page.
Exploitation status
Public Exploit Available: Yes, a public video demonstration provides step-by-step exploitation guidance.
Analyst recommendation
Given the confirmed active exploitation and the critical nature of this flaw in an industrial control environment, immediate remediation is mandatory. Organizations currently running affected versions of ScadaBR should prioritize patching these systems and audit their environments for indicators of prior compromise, particularly if the systems are internet-facing or accessible to unauthorized users.