Three critical Remote Code Execution bugs threaten industrial solar panels
Several solar power monitoring systems are facing a significant risk due to a trio of critical vulnerabilities that allow remote code execution (RCE). These vulnerabilities have exposed hundreds of systems to potential exploitation. Security experts have observed that both the notorious Mirai botnet and inexperienced attackers have already started taking advantage of these vulnerabilities, and it is likely that others will follow suit.
Researchers from Palo Alto Networks' Unit 42 had previously discovered that the Mirai botnet was spreading through a command injection flaw, known as CVE-2022-29303, found in the SolarView Series software developed by Contec, the manufacturer. Contec's website reveals that SolarView is deployed in more than 30,000 solar power stations.
VulnCheck, a vulnerability intelligence firm, has highlighted that CVE-2022-29303 is just one of three critical vulnerabilities affecting SolarView. As a result, not only are the Mirai hackers focusing on these vulnerabilities, but other malicious actors are also likely to target them.
https://www.darkreading.com/ics-ot/3-critical-rce-bugs-threaten-industrial-solar-panels