Satel Netco Design
What happened
An authenticated user with Network Operator privileges could store untrusted content that is rendered without adequate neutralization. Successful exploitation could allow script execution in another user's browser when the affected content is viewed.
An authenticated user with Viewer privileges could submit crafted search input that causes excessive processing, potentially degrading the availability of the application. Satel Satel Netco Design: <v2.1.7 Product Status: known_affected Remediations Vendor fix Satel advises users to update to Satel Netco Design v2.1.7.
An authenticated user with Viewer privileges could access file paths outside the intended directory and use observable application responses to determine whether files exist on the host system. An authenticated user with Viewer privileges could write attacker influenced content to file system locations accessible to the application service.
Sources & evidence
- CISA Advisories Primary / official
Satel Netco Design โ
https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-03