No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

3 Critical RCE Bugs Threaten Industrial Solar Panels

July 5, 2023
in Protection
0
3 Critical RCE Bugs Threaten Industrial Solar Panels



Hundreds of solar power monitoring systems are vulnerable to a trio of critical remote code execution (RCE) vulnerabilities. The hackers behind the Mirai botnet and even amateurs have already started taking advantage, and others will follow, experts are predicting.

Palo Alto Networks’ Unit 42 researchers previously discovered that the Mirai botnet is spreading through CVE-2022-29303, a command injection flaw in SolarView Series software developed by the manufacturer Contec. According to Contec’s website, SolarView has been used in more than 30,000 solar power stations.

On Wednesday, vulnerability intelligence firm VulnCheck pointed out in a blog post that CVE-2022-29303 is one of three critical vulnerabilities in SolarView, and it’s more than just the Mirai hackers targeting them.

“The most likely worst-case scenario is losing visibility into the equipment that’s being monitored and having something break down,” explains Mike Parkin, senior technical engineer at Vulcan Cyber. It’s also theoretically possible, though, that “the attacker is able to leverage control of the compromised monitoring system to do greater damage or get deeper into the environment.”

Three Ozone-Sized Holes in SolarView

CVE-2022-29303 is borne from a particular endpoint in the SolarView Web server, confi_mail.php, which fails to sufficiently sanitize user input data, enabling the remote malfeasance. In the month it was released, the bug received some attention from security bloggers, researchers, and one YouTuber who showed off the exploit in a still publicly accessible video demonstration. But it was hardly the only problem inside SolarView.

For one thing, there’s CVE-2023-23333, an entirely similar command injection vulnerability. This one affects a different endpoint, downloader.php, and was first revealed in February. And there’s CVE-2022-44354, published near the end of last year. CVE-2022-44354 is an unrestricted file upload vulnerability affecting yet a third endpoint, enabling attackers to upload PHP Web shells to targeted systems.

VulnCheck noted that these two endpoints, like confi_mail.php, “appear to generate hits from malicious hosts on GreyNoise meaning that they too are likely under some level of active exploitation.”

All three vulnerabilities were assigned “critical” 9.8 (out of 10) CVSS scores.

How Big of a Cyber Problem Are the SolarView Bugs?

Only Internet-exposed instances of SolarView are at risk of remote compromise. A quick Shodan search by VulnCheck revealed 615 cases connected to the open Web as of this month.

This, says Parkin, is where the unnecessary headache starts. “Most of these things are designed to be operated within an environment and shouldn’t need access from the open Internet under most use cases,” he says. Even where remote connectivity is absolutely necessary, there are workarounds that can protect IoT systems from the scary parts of the wider Internet, he adds. “You can put them all on their own virtual local area networks (VLANs) in their own IP address spaces, and restrict access to them to a few specific gateways or applications, etc.”

Operators might risk remaining online if, at least, their systems are patched. Remarkably, however, 425 of those Internet-facing SolarView systems — more than two thirds of the total — were running versions of the software lacking the necessary patch.

At least when it comes to critical systems, this may be understandable. “IoT and operational technology devices are often a lot more challenging to update compared to your typical PC or mobile device. It sometimes has management making the choice to accept the risk, rather than take their systems off-line long enough to install security patches,” Parkin says.

All three CVEs were patched in SolarView version 8.00.

Editorial Team

Editorial Team

Related Posts

I Tried Copilot’s New Tools for Word, Excel, and Powerpoint, and I’m Not Sure I Will Again
Protection

I Tried Copilot’s New Tools for Word, Excel, and Powerpoint, and I’m Not Sure I Will Again

April 27, 2026
These Ryobi Tools Are up to 60% Off Right Now
Protection

These Ryobi Tools Are up to 60% Off Right Now

April 27, 2026
The Samsung Galaxy S26+ Is $175 Off Right Now
Protection

The Samsung Galaxy S26+ Is $175 Off Right Now

April 27, 2026
The Xteink X4 E-Reader Is Under $60 on Amazon for the Next Few Hours
Protection

The Xteink X4 E-Reader Is Under $60 on Amazon for the Next Few Hours

April 25, 2026
What 'Zone 2' Cardio Actually Means
Protection

What ‘Zone 2’ Cardio Actually Means

April 25, 2026
The Sony WH-CH720N Noise-Canceling Headphones Are Nearly Half Off
Protection

The Sony WH-CH720N Noise-Canceling Headphones Are Nearly Half Off

April 25, 2026
Load More
Next Post
Live news: ExxonMobil profits to take $2bn hit from lower natural gas prices

Live news: ExxonMobil profits to take $2bn hit from lower natural gas prices

Popular News

  • CES 2026: This Tiny Computer Is like a Mac Mini for PC Users

    CES 2026: This Tiny Computer Is like a Mac Mini for PC Users

    0 shares
    Share 0 Tweet 0
  • Samson Mow Breaks Down Bitcoin Market Crash

    0 shares
    Share 0 Tweet 0
  • IOG launches Lace 1.0, a new web3 platform on Cardano

    0 shares
    Share 0 Tweet 0
  • Bigme Is Making a Dual-Screen E-Ink/LCD Smartphone

    0 shares
    Share 0 Tweet 0
  • Global Sell-Off Hits Metals And Crypto As Binance Open Interest Returns To Pre–October 10 Levels

    0 shares
    Share 0 Tweet 0

Latest News

I Tried Copilot’s New Tools for Word, Excel, and Powerpoint, and I’m Not Sure I Will Again

I Tried Copilot’s New Tools for Word, Excel, and Powerpoint, and I’m Not Sure I Will Again

April 27, 2026
0

Google's Gemini AI has recently become more agentic and capable inside Google Docs, Sheets, and Slides—and now Microsoft is pushing...

Michael Saylor’s Strategy adds 3.2K Bitcoin at nearly $78K per BTC

Michael Saylor’s Strategy adds 3.2K Bitcoin at nearly $78K per BTC

April 27, 2026
0

Michael Saylor’s Strategy bought 3,273 Bitcoin for $255 million between April 20 and 26, bringing total holdings to 818,334 BTC.

Obra Capital appoints new MD to expand ABF strategy

Obra Capital appoints new MD to expand ABF strategy

April 27, 2026
0

Alternative asset manager Obra Capital has appointed Ashish Sinha as managing director of asset-based finance (ABF). Sinha will be based...

Where to Go in Goa, India, According to a Local Artist and Restaurateur

Where to Go in Goa, India, According to a Local Artist and Restaurateur

April 27, 2026
0

Of growing up in Northern Goa, Siddharth Kerkar recalls when the town of “Calangute only had the Taj hotel and...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.