ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Exploits

Critical Security Vulnerabilities in Rapid SCADA Expose Industrial Systems

Kyle by Kyle
January 18, 2024
in Exploits
Reading Time: 1 min read
Critical vulnerabilities in Rapid SCADA expose industrial systems to remote attacks, raising concerns for unpatched risks in vital infrastructures.
Share on FacebookShare on Twitter

Last week, the US cybersecurity agency CISA issued a crucial advisory regarding seven vulnerabilities detected by Claroty researchers in Rapid SCADA, a widely used system for developing monitoring and control solutions in industrial settings, including industrial automation, IIoT systems, energy accounting, and process control systems.

Overview of Vulnerabilities

  • Read sensitive files
  • Remotely execute arbitrary code
  • Gain access through phishing attacks
  • Escalate privileges
  • Obtain administrator passwords
  • Access sensitive data about the application’s internal code

According to CISA, these vulnerabilities pose a severe risk, with one classified as ‘critical’ and two as ‘high severity.’ Despite being notified in early July 2023, developers have not yet released patches, exposing industrial systems.

Efforts by CISA and Claroty to contact Rapid SCADA developers have been unsuccessful.

You might also like

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

Critical Vulnerabilities Exposed in Ruijie Networks Cloud Platform

Noam Moshe, a vulnerability researcher at Claroty, emphasized the widespread use of Rapid SCADA in various operational technology (OT) fields. Despite being a popular choice for small and medium-sized companies due to its free and open-source nature, the system’s vulnerabilities could have serious consequences.

Remote Code Execution and Internet Accessibility

Moshe highlighted that unauthenticated attackers can exploit certain vulnerabilities for remote code execution. Additionally, there are instances of Rapid SCADA directly accessible from the internet, posing a significant risk to organizations. Moshe said, “The vulnerabilities we discovered enable attackers to achieve remote code execution on Rapid SCADA Servers, meaning attackers could fully control these servers. After a successful exploit, the attackers could alter the behavior of services controlled by the Rapid SCADA server, move laterally inside the victim’s networks, etc.”

Tags: SCADA
Previous Post

Exploitation of CVE-2023-36025 Unveils Phemedrone Stealer Malware

Next Post

Ransomware Attacks up 128% in 2023

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Photo of the CISCO logo and text saying "You have been hacked!"

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

March 6, 2026
What is DoubleClickJacking?

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

Critical Vulnerabilities Exposed in Ruijie Networks Cloud Platform

December 25, 2024

Vulnerability (CVE-2024-54143 ) Discovered in OpenWrt’s Firmware Upgrade System

December 13, 2024

Cybercriminals Unleash Advanced Phishing-as-a-Service Toolkit Targeting Microsoft 365 Users

November 29, 2024

Major Security Vulnerability Uncovered in qBittorrent Client

November 1, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.