Toptech TMS7 and TopHAT
What happened
The issues have been addressed in release 7.8. Users can get the latest release and more information on these issues, at the Toptech Systems security blog.
This allows an attacker to predefine a session ID and reuse it after victim authentication, resulting in session takeover. Legal Notice and Terms of Use This product is provided subject to this Notification ( https://www.cisa.gov/notification ) and this Privacy & Use policy ( https://www.cisa.gov/privacy-policy ).
Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
Sources & evidence
- CISA Advisories Primary / official
Toptech TMS7 and TopHAT โ
https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02