CISA discloses four flaws in Satel Netco Design
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
Satel Netco Design before v2.1.7 has four vulnerabilities including stored XSS, DoS via regex, and path traversal; patch available, no known exploitation.
CISA published an ICS advisory covering four vulnerabilities in Satel Netco Design, a product used in the communications sector by the Finnish vendor Satel, deployed worldwide. The flaws range from a stored cross-site scripting issue exploitable by an authenticated Network Operator, to an inefficient regular expression complexity issue allowing authenticated Viewer-level users to degrade application availability through crafted search input. Two relative path traversal vulnerabilities in the data import and export functionality could allow authenticated Viewer-level users to enumerate file existence outside intended directories, or write attacker-influenced content to filesystem locations, potentially leading to unauthorized file creation, modification, or arbitrary code execution.
All four issues affect Satel Netco Design versions prior to v2.1.7, and Satel has released a vendor fix addressing them in that version. Exploitation of these flaws requires authenticated access at Viewer or Network Operator privilege levels, limiting the attack surface to users with some level of existing access or compromised credentials. CISA states no known public exploitation targeting these vulnerabilities has been reported.
Defenders operating Satel Netco Design should prioritize upgrading to v2.1.7 or later, and in the interim apply CISA's standard ICS guidance: minimize internet exposure of control system devices, isolate control networks behind firewalls, and use VPNs for any required remote access. The vulnerabilities were responsibly reported to CISA by Alex Williams of Pellera Technologies.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-03
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 11,090 reports from 148 sources, 491 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs