CISA advarer om højrisiko-sårbarheder i DuraComm DP-10iN-100-MU

juli 23, 2025 • César Daniel Barreto

CISA advarer om højrisiko-sårbarheder i DuraComm DP-10iN-100-MU

On July 22, 2025, CISA published advisory ICSA-25-203-01 covering three vulnerabilities in the DuraComm SPM-500 DP-10iN-100-MU, a DC power distribution and monitoring panel used in industrial settings. All versions up to and including 4.10 are affected. The flaws were reported to CISA by Brandon Vincent of Arizona Public Service, and no public exploitation was known at the time of publication.

Three distinct weaknesses

CVE-2025-41425 (CVSS v3.1 7.1) is a cross-site scripting flaw that could be used to prevent legitimate users from reaching the web interface. CVE-2025-48733 (CVSS v3.1 7.5) is a missing-authentication issue: a function that should require authentication does not, letting an attacker repeatedly reboot the device and cause a denial of service. CVE-2025-53703 (CVSS v3.1 7.5) is a cleartext-transmission flaw — sensitive data is sent without encryption, so anyone able to observe the network traffic can intercept it.

Impact

All three are network-exploitable with low attack complexity; the missing-authentication and cleartext flaws require no privileges at all, while the XSS requires only low privileges. CISA’s overall assessment is that successful exploitation could allow an attacker to disclose sensitive information or cause a denial-of-service condition — knocking the panel offline through forced reboots or blocking access to its management interface.

Fix and mitigations

DuraComm has released a fix in version 4.10A, and operators should update to it. Beyond patching, CISA recommends the standard control-system hygiene: minimize network exposure so the panel is not reachable from the internet, place it behind a firewall, isolate it from business networks, and use secure, up-to-date remote access when needed.

César Daniel Barreto, Cybersecurity Author at Security Briefing

César Daniel Barreto

César Daniel Barreto er en anerkendt cybersikkerhedsskribent og -ekspert, der er kendt for sin dybdegående viden og evne til at forenkle komplekse cybersikkerhedsemner. Med omfattende erfaring inden for netværks sikkerhed og databeskyttelse bidrager han regelmæssigt med indsigtsfulde artikler og analyser om de seneste cybersikkerhedstendenser og uddanner både fagfolk og offentligheden.

da_DKDanish