CISA Cảnh Báo Về Các Lỗ Hổng Nguy Cơ Cao Trong DuraComm DP-10iN-100-MU

Tháng 7 23, 2025 • César Daniel Barreto

CISA Cảnh Báo Về Các Lỗ Hổng Nguy Cơ Cao Trong DuraComm DP-10iN-100-MU

On July 22, 2025, CISA published advisory ICSA-25-203-01 covering three vulnerabilities in the DuraComm SPM-500 DP-10iN-100-MU, a DC power distribution and monitoring panel used in industrial settings. All versions up to and including 4.10 are affected. The flaws were reported to CISA by Brandon Vincent of Arizona Public Service, and no public exploitation was known at the time of publication.

Three distinct weaknesses

CVE-2025-41425 (CVSS v3.1 7.1) is a cross-site scripting flaw that could be used to prevent legitimate users from reaching the web interface. CVE-2025-48733 (CVSS v3.1 7.5) is a missing-authentication issue: a function that should require authentication does not, letting an attacker repeatedly reboot the device and cause a denial of service. CVE-2025-53703 (CVSS v3.1 7.5) is a cleartext-transmission flaw — sensitive data is sent without encryption, so anyone able to observe the network traffic can intercept it.

Impact

All three are network-exploitable with low attack complexity; the missing-authentication and cleartext flaws require no privileges at all, while the XSS requires only low privileges. CISA’s overall assessment is that successful exploitation could allow an attacker to disclose sensitive information or cause a denial-of-service condition — knocking the panel offline through forced reboots or blocking access to its management interface.

Fix and mitigations

DuraComm has released a fix in version 4.10A, and operators should update to it. Beyond patching, CISA recommends the standard control-system hygiene: minimize network exposure so the panel is not reachable from the internet, place it behind a firewall, isolate it from business networks, and use secure, up-to-date remote access when needed.

César Daniel Barreto, Tác giả về An ninh mạng tại Security Briefing

César Daniel Barreto

César Daniel Barreto là một nhà văn và chuyên gia an ninh mạng được kính trọng, nổi tiếng với kiến thức sâu rộng và khả năng đơn giản hóa các chủ đề an ninh mạng phức tạp. Với kinh nghiệm sâu rộng về bảo mật mạng và bảo vệ dữ liệu, ông thường xuyên đóng góp các bài viết và phân tích sâu sắc về các xu hướng an ninh mạng mới nhất, giáo dục cả chuyên gia và công chúng.

viVietnamese