"value":"The web service for ONS-S8 - Spectra Aggregation Switch includes functions which do not properly validate user input, allowing an attacker to traverse directories, bypass authentication, and execute remote code."
"value":"<p>Optigo Networks recommends users always use a unique management VLAN for the port on the ONS-S8 that is used to connect to OneView.</p><p>Optigo Networks also recommends users implement at least one of the following additional mitigations:</p><ul><li>Use a dedicated NIC on the BMS computer and exclusively this computer for connecting to OneView to manage your OT network configuration.</li><li>Set up a router firewall with a white list for the devices permitted to access OneView.</li><li>Connect to OneView via secure VPN.</li></ul>\n\n<br>"
}
],
"value":"Optigo Networks recommends users always use a unique management VLAN for the port on the ONS-S8 that is used to connect to OneView.\n\nOptigo Networks also recommends users implement at least one of the following additional mitigations:\n\n * Use a dedicated NIC on the BMS computer and exclusively this computer for connecting to OneView to manage your OT network configuration.\n * Set up a router firewall with a white list for the devices permitted to access OneView.\n * Connect to OneView via secure VPN."
}
],
"credits":[
{
"lang":"en",
"value":"Claroty Team82 reported this vulnerability to CISA."