การยินยอมใช้คุกกี้

COOKIE CONSENT

เราใช้คุกกี้เพื่อปรับปรุงประสบการณ์การใช้งาน วิเคราะห์การเข้าใช้เว็บไซต์ และนำเสนอเนื้อหาที่เกี่ยวข้อง ท่านสามารถเลือกประเภทคุกกี้ที่ยินยอมได้ ดูรายละเอียดเพิ่มเติมใน ประกาศคุกกี้

Vulnerability

Critical Session Hijacking Risk in OpenPLC Runtime v3

FORTSECURE GLOBAL· 2026-09-23🛰 CISA Cybersecurity Advisories
#Vulnerability#ICS#Session Hijacking#Control Systems

A vulnerability in OpenPLC Runtime v3 enables attackers to hijack session cookies, granting unauthorized control over physical industrial processes.

Technical Impact Analysis

Security researchers have discovered an 'Improper Neutralization of Input During Web Page Generation' vulnerability within OpenPLC Runtime v3 (CVE-2026-88020). This flaw allows an adversary to perform session hijacking by capturing cookies, enabling them to masquerade as an authenticated operator. The impact is severe, as the attacker can send state-changing requests to the programmable logic controller (PLC). Consequently, unauthorized parties could manipulate the physical processes controlled by these units, posing substantial safety and operational risks.

Operational Safeguards

Securing operational technology (OT) is paramount when dealing with vulnerabilities that affect physical infrastructure. We recommend the following steps:

  • Immediate Patching: Users of OpenPLC Runtime v3 should consult the latest vendor guidance to apply security updates that address input sanitization issues.
  • Restrict Access: Limit access to the web management interface of PLC devices to trusted, internal IP addresses only using VPN or secure gateway solutions.
  • Monitoring: Implement strict monitoring on network traffic originating from or directed toward PLC devices to detect anomalous state-changing requests.
  • Principle of Least Privilege: Ensure that the user sessions connecting to these devices are temporary and strictly monitored.

แหล่งที่มา: CISA Cybersecurity Advisories เผยแพร่ครั้งแรก: Tue, 22 Sep 26 12:00:00 +0000 บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: CISA Cybersecurity Advisories

เผยแพร่ครั้งแรก: Tue, 22 Sep 26 12:00:00 +0000

บทความต้นฉบับ: https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-09

อ่านบทความต้นฉบับ ↗
ถูกใจบทความนี้

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog