Executive brief
ScadaBR is an open-source software platform used for monitoring and controlling industrial processes in sectors like energy and water management. A security flaw allows an attacker to trick a logged-in administrator into performing unintended actions by getting them to visit a malicious website. This could lead to unauthorized changes in the industrial control system, potentially disrupting operations or compromising sensitive data.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in ScadaBR version 1.2.0 due to insufficient validation of request origins. An attacker can craft a malicious webpage or link that, when visited by an authenticated ScadaBR user, executes unauthorized commands with the victim's privileges. This attack vector requires the victim to have an active session and interact with the attacker's malicious content. Successful exploitation can lead to full compromise of the application's functionality, including administrative actions. As of the advisory date, the vendor has not responded to mitigation requests, and users are advised to isolate the system from the internet and use VPNs for remote access.
Affected products
- ScadaBR ScadaBR 1.2.0
Timeline
- 2026-05-19: advisory: CISA and NVD published the advisory.