
CISA Adds OpenPLC ScadaBR XSS Vulnerability (CVE-2021-26829) to Known Exploited Vulnerabilities Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a cross-site scripting (XSS) vulnerability in OpenPLC ScadaBR, tracked as CVE-2021-26829 with a CVSS score of 5.4, to its Known Exploited Vulnerabilities (KEV) catalog. This vulnerability affects both Windows and Linux versions via the system_settings.shtm file. OpenPLC ScadaBR is an open-source implementation of the PLC standard, widely used in industrial control systems (ICS) and SCADA environments. XSS vulnerabilities allow attackers to inject malicious scripts into web pages, potentially leading to data theft or session hijacking. The inclusion in CISA's KEV catalog indicates active exploitation in the wild. While the CVSS score is medium, the impact on ICS/SCADA systems can be significant due to their critical role in industrial processes. Cybersecurity professionals should prioritize patching affected systems and implement additional security measures such as network segmentation and intrusion detection to mitigate risks.