Cyber Control, in its 1.650 version, is affected by a vulnerability in the generation on the server of pop-up windows with the messages "PNTMEDIDAS", "PEDIR", "HAYDISCOA" or "SPOOLER". A complete denial of service can be achieved by sending multiple requests simultaneously on a core.
No PoCs from references.
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/sapellaniz/CVE-2022-4896