CISA Warns of OpenPLC ScadaBR File Upload Vulnerability Exploited in Attacks
A critical vulnerability has been identified in OpenPLC ScadaBR systems, now listed in CISA's Known Exploited Vulnerabilities. This vulnerability involves a file-upload flaw that allows remote authenticated users to upload and execute arbitrary JSP files…
A critical vulnerability has been identified in OpenPLC ScadaBR systems, now listed in CISA's Known Exploited Vulnerabilities. This vulnerability involves a file-upload flaw that allows remote authenticated users to upload and execute arbitrary JSP files through the view_edit.shtm interface, posing significant risks to industrial control system environments.
OpenPLC ScadaBR File Upload Vulnerability
OpenPLC ScadaBR, a web-based industrial automation platform, is affected by an unrestricted file upload vulnerability classified under CWE-434 (Unrestricted Upload of File with Dangerous Type). This vulnerability enables authenticated attackers to bypass security controls, injecting malicious code directly into vulnerable systems.
The ability to upload and execute JSP files grants attackers persistent access and the ability to execute code within the industrial environment.
Field Details
CVE ID CVE-2021-26828
Vulnerability Type Unrestricted Upload of File with Dangerous Type
A critical vulnerability has been identified in OpenPLC ScadaBR systems, now listed in CISA's Known Exploited Vulnerabilities.
Affected Product OpenPLC ScadaBR
Attack Vector Network-based, Remote
CVSS Severity Critical
Impact Remote Code Execution (RCE) via JSP file upload
This vulnerability could disrupt critical operations or facilitate lateral movement within industrial networks. Organizations are urged to address this issue by December 24, 2025, as per CISA's deadline. Federal agencies and critical infrastructure operators should prioritize immediate remediation.
Apply vendor-supplied mitigations according to manufacturer instructions. For cloud-based deployments, follow the guidance outlined in Binding Operational Directive (BOD 22-01). Discontinue use of OpenPLC ScadaBR if adequate mitigations are unavailable.
While CISA has not confirmed the use of this vulnerability in active ransomware campaigns, the nature of the flaw makes it attractive to threat actors targeting industrial control systems. File upload vulnerabilities in industrial automation platforms present a direct path to system compromise, particularly in environments with limited security monitoring.
Organizations using OpenPLC ScadaBR should immediately inventory affected systems and validate their current patch status. Security teams should implement network segmentation to limit access to administrative interfaces, restrict file uploads through firewall rules where possible, and enhance monitoring for suspicious JSP file uploads.
Additionally, organizations should review access logs for evidence of exploitation and coordinate with their industrial automation vendors to confirm patch availability and deployment procedures. This CISA alert highlights ongoing risks in industrial control systems and underscores the importance of maintaining current patch management practices in operational environments.
Based on reporting by Cyber Security News.
