FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to execute arbitrary code on the server when the Node-RED plugin is enabled. This has been patched in FUXA version 1.2.11.
The vulnerability results from errors of the CWE-290 class (authentication mechanism bypass via spoofing) and CWE-306 class (missing authentication for critical functionality). When the Node-RED plugin is enabled in FUXA, an attacker can bypass required authentication and gain access to functionality reserved for authenticated users. As a result, it is possible to upload and execute arbitrary code on the server without possessing any credentials.
An attacker without authentication can remotely execute arbitrary code on the server (RCE), which in a SCADA/HMI environment may lead to complete system takeover, disruption of industrial processes, or further lateral movement in the OT/IT network.
FUXA should be updated to version 1.2.11, in which the vulnerability has been fixed. The patch is available in the official GitHub repository at the address indicated in the references (commit 5e7679b and release v1.2.11). Until the update is applied, it is recommended to disable the Node-RED plugin and restrict access to the FUXA interface to trusted networks only.
Frangoteam FUXA in versions 1.2.8 to 1.2.10 (inclusive) with the Node-RED plugin enabled.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XFrangoteam Fuxa
APPFrangoteam1.2.8 – 1.2.11 (excl.)
Related vulnerabilities
FUXA – pominięcie uwierzytelnienia przez nagłówek Referer prowadzące do RCE
FUXA SCADA/HMI: Auth Bypass + RCE przez API heartbeat
Path traversal w FUXA SCADA/HMI umożliwia zapis dowolnych plików
FUXA SCADA: domyślny sekret JWT umożliwia nieautoryzowany dostęp i RCE
FUXA SCADA: authorization bypass umożliwia modyfikację schedulerów bez uwierzytelnienia