CVE-2025-13926
9.8Contemporary Controls · BASControl20
Contemporary Controls BASControl20 version 3.1 is vulnerable to packet forgery, allowing remote attackers to send arbitrary requests by sniffing network traffic.
Executive summary
A critical vulnerability in Contemporary Controls BASControl20 allows unauthenticated remote attackers to forge packets and execute unauthorized requests, leading to potential system control compromise.
Vulnerability
This is an improper check for unusual or exceptional conditions (CWE-807) where an attacker can perform network sniffing to forge packets and subsequently issue unauthorized commands to the device.
Business impact
Given the CVSS score of 9.8, this vulnerability allows for full, unauthenticated control over the affected industrial control device. Successful exploitation could lead to total operational disruption, loss of process integrity, and unauthorized command execution within the target environment.
Remediation
Immediate Action: Update the Contemporary Controls BASControl20 firmware to the latest version as directed by the vendor advisory (ICSA-26-099-01).
Proactive Monitoring: Monitor network traffic for suspicious packet patterns or unauthorized communication attempts directed at the BASControl20 management interfaces.
Compensating Controls: Isolate the BASControl20 devices within a segmented industrial network and implement encrypted communication channels where possible to prevent sniffing.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the critical nature of this vulnerability in an industrial control setting, organizations must prioritize updating the firmware immediately. Restricting network access to the device and implementing robust segmentation are essential to preventing unauthorized command execution.