FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization bypass vulnerability in the FUXA allows an unauthenticated, remote attacker to create and modify arbitrary schedulers, exposing connected ICS/SCADA environments to follow-on actions. This has been patched in FUXA version 1.2.11.
The vulnerability results from missing required authorization controls (CWE-862) on scheduler operations in the FUXA web interface. A remote attacker, without possessing any credentials, can send requests to endpoints responsible for scheduler management and create or modify them arbitrarily. The lack of user identity validation at the level of these operations means that the protection provided by login mechanisms is completely bypassed.
An attacker can create and modify any schedulers in the FUXA system without authentication, which in ICS/SCADA environments can lead to disruption of industrial processes, unauthorized control of connected devices, and further actions after taking control over the operation schedule.
The FUXA software should be updated to version 1.2.11, in which the vulnerability has been fixed. The patch is available in the official project repository on GitHub (release v1.2.11).
FUXA (Frangoteam) versions 1.2.8 through 1.2.10 inclusive
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XFrangoteam Fuxa
APPFrangoteam1.2.8 – 1.2.11 (excl.)
Related vulnerabilities
FUXA – pominięcie uwierzytelnienia przez nagłówek Referer prowadzące do RCE
FUXA SCADA/HMI: Auth Bypass + RCE przez API heartbeat
Path traversal w FUXA SCADA/HMI umożliwia zapis dowolnych plików
FUXA SCADA: domyślny sekret JWT umożliwia nieautoryzowany dostęp i RCE
FUXA SCADA/HMI – pominięcie uwierzytelnienia umożliwiające RCE przez plugin Node-RED