Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability has been identified in the service console interface of openPDC and openHistorian, allowing for potential remote code execution. This issue stems from the deserialization of client-supplied data, which, under certain configurations, can be exploited by unauthenticated network attackers to gain control of affected systems. The main concern is confirming the relevance and exposure of this vulnerability within your environment.
- Arbitrary code execution via data deserialization.
- Critical security flaw affecting industrial control systems.
- Assess exposure and relevance to your operations.
Attack Path
How an attacker could exploit the issue
An attacker can reach a service console interface on openPDC and openHistorian, a component that processes client-supplied data. If Windows Authentication is not used, this interface is directly accessible over the network without any prior authentication, allowing an attacker to send specially crafted data that triggers the deserialization of an arbitrary object graph. This process can lead to remote code execution with the privileges of the service account.
- Network accessible without authentication.
- Deserializes client-supplied data.
- Remote code execution.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could impact systems running openPDC and openHistorian by allowing an attacker to execute arbitrary code. The service console interface, which handles client-supplied data structures, is susceptible to deserialization of an untrusted object graph. This could lead to remote code execution with the privileges of the service account, potentially affecting system integrity and availability when Windows Authentication is not enforced.
- System data and service behavior at risk.
- Deserialization of arbitrary object graphs.
- Remote code execution possible.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Platform or Infrastructure team is likely responsible for managing the openPDC and openHistorian services. The first practical step is to identify all instances of these services, confirm their network reachability and business criticality, and then locate the accountable owner to initiate a risk-based remediation plan.
- Identify and confirm service ownership.
- Verify network exposure and criticality.
- Plan remediation based on risk.