CISA Advises Updates for Satel Netco Design Following Multiple Vulnerability Disclosure
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an industrial control systems advisory (ICSA-26-281-03) disclosing four vulnerabilities in Satel Netco Design software. The flaws affect all versions prior to v2.1.7 and include a stored cross-site scripting vulnerability, an inefficient regular expression complexity issue, and two relative path traversal flaws in data import and export functions. Exploitation could allow authenticated attackers to execute scripts in a user's browser, consume excessive system resources, enumerate and modify files, and potentially execute arbitrary code. Satel has advised users to update to v2.1.7 to remediate the issues.