Impact
Scada‑LTS version 2.8.1‑release‑candidate build 0 contains a flaw in the DWR "DataSourceEditDwr" class where the "validateScript" method compiles and executes attacker‑supplied JavaScript through Rhino. Because no authorization checks are performed, a user with any authenticated, even low‑privilege, account can trigger arbitrary code execution, potentially compromising the application's confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects only the Scada‑LTS product, specifically the 2.8.1‑release‑candidate build 0. No other Scada‑LTS versions are listed as vulnerable.
Risk and Exploitability
The flaw carries a CVSS score of 8.8, classifying it as high severity, but the EPSS score of less than 1% indicates a low likelihood of active exploitation at this time. It is not listed in the CISA KEV catalog. An attacker would need to authenticate to the SCADA system, after which they could exploit the missing authorization and DWR routing bypass to execute arbitrary JavaScript, potentially spawning system commands with the process privileges of the SCADA service.
OpenCVE Enrichment