Home
CRITICAL: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCRITICAL: 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
All versions
affected
Description
All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web interface. Malicious users that use the vulnerable endpoint are potentially able to cause remote code execution.
Problem types
Product status
All versions
Credits
Adem El Adeb reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-26-055-01
github.com/...p/csaf_files/OT/white/2026/icsa-26-055-01.json