Impact
The vulnerability originates from a server‑side method that omits authorization checks. Any authenticated user, even one with read‑only permissions, can invoke this endpoint to execute arbitrary operating‑system commands. The commands run with root privileges because the ScadaLTS server process itself operates as root, allowing an attacker to fully compromise the underlying host. This flaw is a classic example of missing authorization (CWE‑862).
Affected Systems
The reported exposed method exists in the ScadaLTS product from SCADA‑LTS, specifically version 2.7.8.1. No other versions are listed as affected in the advisory.
Risk and Exploitability
The CVSS score of 9.9 signals a severe impact and low exploitation complexity. The EPSS score is not available, and the vulnerability is not yet included in CISA’s KEV catalog. Exploitation requires that an attacker obtain valid credentials—whether through phishing, credential theft, or by using an existing low‑privilege account. Once authenticated, the attacker can execute arbitrary code with full root rights on the device, leading to systemic compromise.
OpenCVE Enrichment